Skip to content

Commit 5a6aaea

Browse files
Updated fapolicyd exception communication
updated file mde-linux-prerequisites.md
1 parent 577714b commit 5a6aaea

File tree

1 file changed

+7
-4
lines changed

1 file changed

+7
-4
lines changed

defender-endpoint/mde-linux-prerequisites.md

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -120,11 +120,14 @@ The following Linux server distributions and x64 (AMD64/EM64T) versions are supp
120120
> Microsoft Defender for Endpoint is kernel-version agnostic for all other supported distributions and versions. The minimal requirement for the kernel version is `3.10.0-327` or later.
121121
122122
> [!WARNING]
123-
> Running Defender for Endpoint on Linux with other fanotify-based security solutions isn't supported. It can lead to unpredictable results, including hanging the operating system.
124-
> If there are any other applications on the system that use fanotify in blocking mode, applications are listed in the conflicting_applications field of the mdatp health command output.
125-
> You can still safely take advantage of Defender for Endpoint on Linux EDR functionality after configuring the antivirus functionality Real Time Protection Enabled to passive mode. See [Enforcement level for Microsoft Defender Antivirus](/defender-endpoint/linux-preferences#enforcement-level-for-microsoft-defender-antivirus).
123+
> Running Defender for Endpoint on Linux alongside other fanotify-based security solutions is not supported and may lead to unpredictable behavior, including system hangs.
124+
> If any applications use fanotify in blocking mode, they will appear in the conflicting_applications field of the mdatp health command output.
126125
>
127-
> **The Linux FAPolicyD is an exception in this. It is supported with Linux Defender for Endpoint on RHEL & FEDORA platforms as long as the "mdatp health" shows true.**
126+
> You can still safely take advantage of Defender for Endpoint on Linux EDR functionality by setting antivirus enforcement level to passive. See Configure security settings in Microsoft Defender for Endpoint on Linux - Microsoft Defender for Endpoint | Microsoft Learn
127+
>
128+
> [Exception]
129+
>
130+
> **The Linux FAPolicyD feature, which also uses Fanotify in blocking mode, is supported with Defender for Endpoint on RHEL and Fedora platforms, provided that mdatp health reports a healthy status. This exception is based on validated compatibility specific to these distributions.**
128131
## Supported filesystems for real-time protection and quick, full, and custom scans
129132

130133
|Real-time protection and quick/full scans|Custom scans|

0 commit comments

Comments
 (0)