You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
- Enterprise U.S. Government customers should allow the following URLs:
47
66
48
67
-`*.events.data.microsoft.com`
@@ -71,3 +90,31 @@ The following table summarizes where you can view Microsoft Defender Antivirus p
71
90
72
91
To learn more about the Microsoft Defender Core service configurations and experimentation (ECS), see [Microsoft Defender Core service configurations and experimentation](microsoft-defender-core-service-configurations-and-experimentation.md).
73
92
93
+
Frequently Asked Questions (FAQ's):
94
+
95
+
Q: What's the recommendation for Microsoft Defender Core service?
96
+
97
+
A: We highly recommend to let the default settings of keeping the Microsoft Defender Core service running and reporting.
98
+
99
+
Q: What data storage and privacy does the Microsoft Defender Core service adhere to?
100
+
101
+
A: Please review [Microsoft Defender for Endpoint data storage and privacy](/microsoft-365/security/defender-endpoint/data-storage-privacy)
102
+
103
+
Q: Does the [MDE Client Analyzer](/microsoft-365/security/defender-endpoint/run-analyzer-windows) check the URL's for Microsoft Defender for Endpoint **standard** device connectivity experience?
104
+
105
+
A: Not yet, work is in progress to include these new URL's.
106
+
107
+
Q: Can I enforce keeping the Microsoft Defender Core service running as an Administrator?
108
+
109
+
A: Yes, you can enforce it by using any of these management tools:
110
+
111
+
112
+
|Management tool| Description|
113
+
| -------- | -------- |
114
+
| Microsoft Defender for Endpoint Security Settings Management| On the roadmap|
115
+
| Intune | On the roadmap |
116
+
| Configuration Manager Tenant Attach | On the roadmap |
117
+
| Configuration Manager Co-Management | Info |
118
+
| Group Policy | Go to **Computer Configuration** > **Administrative Templates** > **Windows Components** > **Microsoft Defender Antivirus**, and set Experimentation and Configuration Service (ECS) integration for Defender Core Service to either **Not configured** or **Enabled** (this is the default setting). <br/><br/>The Microsoft Defender Core Service uses ECS to rapidly deliver critical, org-specific fixes for Microsoft Defender Antivirus and other Defender software. <br/><br/>When disabled, the Microsoft Defender Core Service stops using ECS. <br/><br/>For false positives, fixes are delivered via Security Intelligence updates. <br/><br/>For Platform and/or Engine updates, fixes are delivered thru Microsoft Update, Microsoft Update Catalog or WSUS. <br/><br/>When you set telemetry for the Microsoft Defender Core Service to **Not configured** or **Enabled** (this is the default setting), the Microsoft Defender Core Service collects telemetry from Microsoft Defender Antivirus and other Defender software. When disabled, the Microsoft Defender Core Service stops collecting telemetry from Microsoft Defender Antivirus and other Defender software. Disabling this setting can impact Microsoft's ability to quickly recognize and address problems, such as slow performance and false positives.|
0 commit comments