Skip to content

Commit 4b2f88c

Browse files
Merge pull request #5882 from MicrosoftDocs/main
[AutoPublish] main to live - 12/10 07:35 PST | 12/10 21:05 IST
2 parents 25bb66c + 1746e3e commit 4b2f88c

File tree

2 files changed

+5
-4
lines changed

2 files changed

+5
-4
lines changed

defender-endpoint/mde-linux-prerequisites.md

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -125,10 +125,11 @@ The following Linux server distributions and x64 (AMD64/EM64T) versions are supp
125125
> [!WARNING]
126126
> Running Defender for Endpoint on Linux alongside other fanotify-based security solutions is not supported and may lead to unpredictable behavior, including system hangs.
127127
> If any applications use fanotify in blocking mode, they will appear in the conflicting_applications field of the mdatp health command output.
128-
> You can still safely take advantage of Defender for Endpoint on Linux by setting antivirus enforcement level to passive. See [Configure security settings in Microsoft Defender for Endpoint on Linux](/defender-endpoint/linux-preferences).> **EXCEPTION:** The Linux `FAPolicyD` feature, which also uses Fanotify in blocking mode, is supported with Defender for Endpoint in active mode on RHEL and Fedora platforms, provided that mdatp health reports a healthy status. This exception is based on validated compatibility specific to these distributions.
129-
>
128+
> You can still safely take advantage of Defender for Endpoint on Linux by setting antivirus enforcement level to passive. See [Configure security settings in Microsoft Defender for Endpoint on Linux](/defender-endpoint/linux-preferences).
129+
> **EXCEPTION:** The Linux `FAPolicyD` feature, which also uses Fanotify in blocking mode, is supported with Defender for Endpoint in active mode on RHEL and Fedora platforms, provided that mdatp health reports a healthy status. This exception is based on validated compatibility specific to these distributions.
130130
>
131131
132+
132133
## Supported filesystems for real-time protection and quick, full, and custom scans
133134

134135
|Real-time protection and quick/full scans|Custom scans|
@@ -174,7 +175,7 @@ The following Linux server distributions and x64 (AMD64/EM64T) versions are supp
174175
> Configure an exception for SSL inspection and your proxy server to allow direct data pass-through from Defender for Endpoint on Linux to the relevant URLs without interception.
175176
> Adding your interception certificate to the global store doesn't enable interception.
176177
177-
For troubleshooting steps, see [Troubleshoot cloud connectivity issues for Microsoft Defender for Endpoint on Linux](/defender-endpoint/linux-support-connectivity)
178+
For troubleshooting steps, see [Troubleshoot cloud connectivity issues for Microsoft Defender for Endpoint on Linux](/defender-endpoint/linux-support-connectivity).
178179

179180
## External package dependency
180181

defender-xdr/alerts-incidents-correlation.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -49,7 +49,7 @@ For more information on moving an alert from one incident to another, see [Move
4949

5050
## Incident correlation and merging
5151

52-
The Defender portal's correlation activities don't stop when incidents are created. Defender continues to detect commonalities and relationships between incidents and alerts across incidents. When multiple incidents are determined to be sufficiently alike, Defender merges the incidents into a single incident.
52+
The Defender portal's correlation activities don't stop when incidents are created. Defender continues to detect commonalities and relationships between incidents and alerts across incidents. When multiple incidents are determined to be alike, Defender merges the incidents into a single incident.
5353

5454
### Criteria for merging incidents
5555

0 commit comments

Comments
 (0)