You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-endpoint/mde-side-by-side.md
+11-5Lines changed: 11 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -3,7 +3,7 @@ title: Microsoft Defender for Endpoint alongside other security solutions
3
3
description: See recommendations for running Defender for Endpoint alongside other security solutions.
4
4
ms.service: defender-endpoint
5
5
ms.localizationpriority: medium
6
-
ms.date: 05/27/2025
6
+
ms.date: 05/30/2025
7
7
ms.topic: conceptual
8
8
author: emmwalshh
9
9
ms.author: ewalsh
@@ -25,27 +25,33 @@ search.appverid: met150
25
25
-[Microsoft Defender for Endpoint Plan 1](microsoft-defender-endpoint.md)
26
26
-[Microsoft Defender for Endpoint Plan 2](microsoft-defender-endpoint.md)
27
27
28
+
## Considerations with concurrent security solutions
29
+
28
30
Large organizations use a wide variety of security solutions, and running multiple security solutions concurrently can lead to performance issues and conflicts. To help minimize interoperability issues, trusted security solutions can often be configured to mitigate conflicts with each other. Organizations should understand the potential benefits, risks, and mitigation recommendations to make informed choices.
29
31
30
32
1.**Disable duplication**. Running multiple security solutions that perform the same function can lead to performance issues and conflicts. It's recommended to avoid redundant capabilities, as this increases the likelihood of problematic product interactions.
31
33
32
34
Microsoft Defender for Endpoint can be configured to disable endpoint detection and response (EDR) in Block Mode, Automated Investigation & Remediation, PUA Protection, Network Discovery & Response, and other capabilities. This can reduce overlap with detection and response functions provided by non-Microsoft endpoint security solutions. Responsibility for these functions falls to the solution actively providing those functions.
33
35
34
-
Similarly, setting Microsoft Defender Antivirus in "Passive Mode" ensures that when another anti-malware solution is present, Defender Antivirus doesn't perform active protection, remediation, or malware blocking. Responsibility for malware protection shifts to the active anti-malware solution.
36
+
Similarly, setting Microsoft Defender Antivirus in passive mode ensures that when another anti-malware solution is present, Microsoft Defender Antivirus doesn't perform active protection, remediation, or malware blocking. Responsibility for malware protection shifts to the active anti-malware solution.
35
37
36
38
2.**Exclusions**. Security exclusions are used to prevent certain entities from being scanned or blocked by security software. Creating mutual exclusions between security solutions can help avoid performance issues and compatibility problems. Exclusions can potentially decrease protection, so it's important to only exclude processes and paths that are confidently benign.
37
39
38
40
When creating mutual exclusions between two security solutions, organizations are deferring protection for those solutions to their respective vendors. If a non-Microsoft EDR solution is unable to monitor Microsoft Defender for Endpoint binaries, for example, then Microsoft is being trusted to protect its own solution. Likewise, if Microsoft Defender for Endpoint is unable to monitor a non-Microsoft solution, then that vendor is being trusted to protect its own solution. These gaps in protection need to be actively managed as solutions change, to help minimize risk.
39
41
40
-
> [!NOTE]
41
-
> For Microsoft Windows performance, for example, see [Performance overview - Windows Client | Microsoft Learn](/troubleshoot/windows-client/performance/performance-overview) and [Performance overview - Windows Server | Microsoft Learn](/troubleshoot/windows-server/performance/performance-overview).
42
+
> [!NOTE]
43
+
> For Microsoft Windows performance, for example, see [Performance overview - Windows Client | Microsoft Learn](/troubleshoot/windows-client/performance/performance-overview) and [Performance overview - Windows Server | Microsoft Learn](/troubleshoot/windows-server/performance/performance-overview).
42
44
43
45
3.**Configurations**. Device hardware and software configurations can have a significant impact on performance and stability, which might be unrelated to security solution interoperability. Solutions and scenario guides are available to help troubleshoot and self-solve performance-related issues, or organizations can leverage available support resources.
44
46
45
47
Delegating security functionality, creating exclusions, and configuring settings can help reduce the likelihood of interoperability issues, but these might not be eliminated completely. Acceptable risk is different for every organization; optimizing for usability might increase risk, and optimizing for security will likely impact usability. Organizations should weigh the benefits of interoperability over potential risks.
46
48
49
+
## Customer support
50
+
47
51
Commercially reasonable support is provided through Microsoft Customer Service and Support and Microsoft managed support offerings. In troubleshooting performance, reliability, and other issues, customers might be asked to temporarily remove potentially conflicting solutions to identify the source of the issue. Depending on the issue, customers might be asked to engage with the vendor of the non-Microsoft solution. Managing security often means finding an acceptable balance between productivity and risk; if a particular security configuration is causing significant performance problems, some organizations choose to disable the additional protection in favor of increased usability for select device groups. This should also be considered for other device-impacting settings.
48
52
49
-
## Example of the "include" that can be added to pages that are relevant to a side by side scenario, this will not be shown on this page (for review only)
53
+
## Example of the "include" that can be added to pages that are relevant to a side by side scenario
54
+
55
+
This content won't be shown on this page (for review only)
0 commit comments