Skip to content

Commit 3fefae4

Browse files
authored
Update microsoft-defender-endpoint-linux.md
1 parent fe1224a commit 3fefae4

File tree

1 file changed

+19
-18
lines changed

1 file changed

+19
-18
lines changed

defender-endpoint/microsoft-defender-endpoint-linux.md

Lines changed: 19 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -122,24 +122,25 @@ In general you need to take the following steps:
122122
> Running Defender for Endpoint on Linux side by side with other `fanotify`-based security solutions is not supported. It can lead to unpredictable results, including hanging the operating system. If there are any other applications on the system that use `fanotify` in blocking mode, applications are listed in the `conflicting_applications` field of the `mdatp health` command output. The Linux **FAPolicyD** feature uses `fanotify` in blocking mode, and is therefore unsupported when running Defender for Endpoint in active mode. You can still safely take advantage of Defender for Endpoint on Linux EDR functionality after configuring the antivirus functionality Real Time Protection Enabled to [Passive mode](linux-preferences.md#enforcement-level-for-antivirus-engine).
123123
124124
- List of supported filesystems for RTP, Quick, Full and Custom Scan.
125-
|RTP, Quick, Full Scan| Custom Scan|
126-
|---|---|
127-
|btrfs|All filesystems supported for RTP, Quick, Full Scan|
128-
|ecryptfs|Efs|
129-
|ext2|S3fs|
130-
|ext3|Blobfuse|
131-
|ext4|Lustr|
132-
|fuse|glustrefs|
133-
|fuseblk|Afs|
134-
|jfs|sshfs|
135-
|nfs (v3 only)|cifs|
136-
|overlay|smb|
137-
|ramfs|gcsfuse|
138-
|reiserfs|sysfs|
139-
|tmpfs||
140-
|udf||
141-
|vfat||
142-
|xfs||
125+
126+
|RTP, Quick, Full Scan| Custom Scan|
127+
|---|---|
128+
|`btrfs`|All filesystems supported for RTP, Quick, Full Scan|
129+
|`ecryptfs`|`Efs`|
130+
|`ext2`|`S3fs`|
131+
|`ext3`|`Blobfuse`|
132+
|`ext4`|`Lustr`|
133+
|`fuse`|`glustrefs`|
134+
|`fuseblk`|`Afs`|
135+
|`jfs`|`sshfs`|
136+
|`nfs` (v3 only)|`cifs`|
137+
|`overlay`|`smb`|
138+
|`ramfs`|`gcsfuse`|
139+
|`reiserfs`|`sysfs`|
140+
|`tmpfs`||
141+
|`udf`||
142+
|`vfat`||
143+
|`xfs`||
143144

144145
- Audit framework (`auditd`) must be enabled if you are using auditd as your primary event provider.
145146

0 commit comments

Comments
 (0)