You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-endpoint/microsoft-defender-endpoint-linux.md
+22-30Lines changed: 22 additions & 30 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -15,7 +15,7 @@ ms.collection:
15
15
ms.topic: conceptual
16
16
ms.subservice: linux
17
17
search.appverid: met150
18
-
ms.date: 07/17/2024
18
+
ms.date: 09/09/2024
19
19
---
20
20
21
21
# Microsoft Defender for Endpoint on Linux
@@ -48,7 +48,7 @@ Microsoft Defender for Endpoint for Linux includes anti-malware and endpoint det
48
48
> Linux distribution using system manager, except for RHEL/CentOS 6.x support both SystemV and Upstart.
49
49
50
50
- Beginner-level experience in Linux and BASH scripting
51
-
- Administrative privileges on the device (in case of manual deployment)
51
+
- Administrative privileges on the device (for manual deployment)
52
52
53
53
> [!NOTE]
54
54
> Microsoft Defender for Endpoint on Linux agent is independent from [OMS agent](/azure/azure-monitor/agents/agents-overview#log-analytics-agent). Microsoft Defender for Endpoint relies on its own independent telemetry pipeline.
@@ -78,7 +78,14 @@ In general you need to take the following steps:
78
78
79
79
### System requirements
80
80
81
-
- Supported Linux server distributions and x64 (AMD64/EM64T) and x86_64 versions:
81
+
- Disk space: 2 GB
82
+
> [!NOTE]
83
+
> An additional 2 GB disk space might be needed if cloud diagnostics are enabled for crash collections. Please make sure that you have free disk space in /var.
84
+
- Cores: 2 minimum, 4 preferred
85
+
> [!NOTE]
86
+
> If you are on Passive or RTP ON mode, 2 Cores are minimum and 4 Cores are preferred. If you are turning on BM, then a minimum of 4 Cores is required.
87
+
- Memory: 1 GB minimum, 4 preferred
88
+
- List of supported Linux server distributions and x64 (AMD64/EM64T) and x86_64 versions:
82
89
- Red Hat Enterprise Linux 6.7 or higher (In preview)
83
90
- Red Hat Enterprise Linux 7.2 or higher
84
91
- Red Hat Enterprise Linux 8.x
@@ -97,21 +104,18 @@ In general you need to take the following steps:
97
104
- Oracle Linux 9.x
98
105
- Amazon Linux 2
99
106
- Amazon Linux 2023
100
-
- Fedora 33-38
101
-
107
+
- Fedora 33-38
102
108
- Rocky 8.7 and higher
103
-
- Rocky 9.2 and higher
104
-
109
+
- Rocky 9.2 and higher
105
110
- Alma 8.4 and higher
106
-
- Alma 9.2 and higher
107
-
111
+
- Alma 9.2 and higher
108
112
- Mariner 2
109
-
110
-
> [!NOTE]
111
-
> Distributions and version that are not explicitly listed are unsupported (even if they are derived from the officially supported distributions).
112
-
> With RHEL 6 support for 'extended end of life' coming to an end by June 30, 2024; MDE Linux support for RHEL 6 will also be deprecated by June 30, 2024
113
-
> MDE Linux version 101.23082.0011 is the last MDE Linux release supporting RHEL 6.7 or higher versions (does not expire before June 30, 2024). Customers are advised to plan upgrades to their RHEL 6 infrastructure aligned with guidance from Red Hat.
114
-
> Microsoft Defender Vulnerablity Management is not supported on Rocky and Alma currently.
113
+
114
+
> [!NOTE]
115
+
> Distributions and version that are not explicitly listed are unsupported (even if they are derived from the officially supported distributions).
116
+
> With RHEL 6 support for 'extended end of life' coming to an end by June 30, 2024; MDE Linux support for RHEL 6 will also be deprecated by June 30, 2024
117
+
> MDE Linux version 101.23082.0011 is the last MDE Linux release supporting RHEL 6.7 or higher versions (does not expire before June 30, 2024). Customers are advised to plan upgrades to their RHEL 6 infrastructure aligned with guidance from Red Hat.
118
+
> Microsoft Defender Vulnerablity Management is not supported on Rocky and Alma currently.
115
119
116
120
- List of supported kernel versions
117
121
@@ -161,20 +165,6 @@ In general you need to take the following steps:
161
165
> [!CAUTION]
162
166
> Running Defender for Endpoint on Linux side by side with other `fanotify`-based security solutions is not supported. It can lead to unpredictable results, including hanging the operating system. If there are any other applications on the system that use `fanotify` in blocking mode, applications are listed in the `conflicting_applications` field of the `mdatp health` command output. The Linux **FAPolicyD** feature uses `fanotify` in blocking mode, and is therefore unsupported when running Defender for Endpoint in active mode. You can still safely take advantage of Defender for Endpoint on Linux EDR functionality after configuring the antivirus functionality Real Time Protection Enabled to [Passive mode](linux-preferences.md#enforcement-level-for-antivirus-engine).
163
167
164
-
- Disk space: 2 GB
165
-
166
-
> [!NOTE]
167
-
> An additional 2 GB disk space might be needed if cloud diagnostics are enabled for crash collections.
168
-
169
-
- /opt/microsoft/mdatp/sbin/wdavdaemon requires executable permission. For more information, see "Ensure that the daemon has executable permission" in [Troubleshoot installation issues for Microsoft Defender for Endpoint on Linux](linux-support-install.md).
170
-
171
-
- Cores: 2 minimum, 4 preferred
172
-
173
-
- Memory: 1 GB minimum, 4 preferred
174
-
175
-
> [!NOTE]
176
-
> Please make sure that you have free disk space in /var.
177
-
178
168
- List of supported filesystems for RTP, Quick, Full and Custom Scan.
179
169
180
170
|RTP, Quick, Full Scan| Custom Scan|
@@ -197,13 +187,15 @@ In general you need to take the following steps:
197
187
|xfs|
198
188
199
189
200
-
After you've enabled the service, you m need to configure your network or firewall to allow outbound connections between it and your endpoints.
190
+
After you've enabled the service, you need to configure your network or firewall to allow outbound connections between it and your endpoints.
201
191
202
192
- Audit framework (`auditd`) must be enabled.
203
193
204
194
> [!NOTE]
205
195
> System events captured by rules added to `/etc/audit/rules.d/` will add to `audit.log`(s) and might affect host auditing and upstream collection. Events added by Microsoft Defender for Endpoint on Linux will be tagged with `mdatp` key.
206
196
197
+
- /opt/microsoft/mdatp/sbin/wdavdaemon requires executable permission. For more information, see "Ensure that the daemon has executable permission" in [Troubleshoot installation issues for Microsoft Defender for Endpoint on Linux](linux-support-install.md).
198
+
207
199
### External package dependency
208
200
The following external package dependencies exist for the mdatp package:
0 commit comments