You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-business/mdb-manage-devices.md
+33-27Lines changed: 33 additions & 27 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -9,7 +9,7 @@ audience: Admin
9
9
ms.topic: how-to
10
10
ms.service: defender-business
11
11
ms.localizationpriority: medium
12
-
ms.date: 02/28/2025
12
+
ms.date: 05/21/2025
13
13
ms.reviewer: nehabha
14
14
f1.keywords: NOCSH
15
15
ms.collection:
@@ -33,54 +33,60 @@ In Defender for Business, you can manage devices as follows:
33
33
34
34
:::image type="content" source="/defender/media/defender-business/mdb-device-inventory.png" alt-text="Screenshot of device inventory":::
35
35
36
-
1. Go to the Microsoft Defender portal ([https://security.microsoft.com](https://security.microsoft.com)) and sign in.
36
+
1. In the Microsoft Defender portal at <https://security.microsoft.com>, go to **Assets**\>**Devices**. Or, to go directly to the **Device inventory** page, use <https://security.microsoft.com/machines>.
37
+
2. On the **Device inventory** page, you can see the list of devices and view some information about them.
38
+
3. Select a device from the list to open the details flyout for the device, where you can learn more about the status of the device and take actions.
37
39
38
-
2. In the navigation pane, go to **Assets** > **Devices**.
39
-
40
-
3. Select a device to open its flyout panel, where you can learn more about its status and take action.
41
-
42
-
If you don't have any devices listed yet, [Onboard devices to Defender for Business](mdb-onboard-devices.md)
40
+
If no devices are listed, see [Onboard devices to Defender for Business](mdb-onboard-devices.md)
43
41
44
42
## Take action on a device that has threat detections
45
43
46
44
:::image type="content" source="/defender/media/defender-business/mdb-selected-device.png" alt-text="Screenshot of a selected device with details and actions available.":::
47
45
48
-
1. In the Microsoft Defender portal ([https://security.microsoft.com](https://security.microsoft.com)), in the navigation pane, go to **Assets** > **Devices**.
46
+
1. In the Microsoft Defender portal at <https://security.microsoft.com>, go to **Assets**\>**Devices**. Or, to go directly to the **Device inventory** page, use <https://security.microsoft.com/machines>.
47
+
2. On the **Device inventory** page, select a device from the list.
48
+
3. In the details flyout that opens, select :::image type="icon" source="media/m365-cc-sc-more-actions-icon.png" border="false"::: **More**, and then select an available action (for example, **Run antivirus scan** or **Initiate Automated Investigation**).
49
+
50
+
## View the state of Microsoft Defender Antivirus
49
51
50
-
2. Select a device to open its flyout panel, and review the information that is displayed.
52
+
Microsoft Defender Antivirus is a key component of next-generation protection in Defender for Business. To view the state of Microsoft Defender Antivirus, you have several options:
51
53
52
-
3. Select the ellipsis (**...**) to open the actions menu.
54
+
- Use the [Device health report](mdb-reports.md#device-health-report).
55
+
- Use one of the methods described in [How to confirm the state of Microsoft Defender Antivirus](/defender-endpoint/microsoft-defender-antivirus-compatibility#how-to-confirm-the-state-of-microsoft-defender-antivirus).
53
56
54
-
4. Select an action, such as **Run antivirus scan** or **Initiate Automated Investigation**.
57
+
Microsoft Defender Antivirus has one of the following states on devices:
55
58
56
-
## View the state of Microsoft Defender Antivirus
59
+
-**Active mode** (*recommended*): Microsoft Defender Antivirus is the exclusive antivirus app on a device onboarded to Defender for Business. Files are scanned and threats are remediated. Detection information is reported in the Microsoft Defender portal and in the Windows Security app on Windows devices.
60
+
61
+
We recommend active mode so devices onboarded to Defender for Business get all of the following types of protection:
57
62
58
-
Microsoft Defender Antivirus is a key component of next-generation protection in Defender for Business. When devices are onboarded to Defender for Business, Microsoft Defender Antivirus can have one of the following states:
63
+
-**Real-time protection**: Locates and stops malware from running on devices.
64
+
-**Cloud protection**: Works with Microsoft Defender Antivirus and the Microsoft cloud to identify new threats, sometimes even before a single device is affected.
65
+
-**Network protection**: Helps protect against phishing scams, exploit-hosting sites, and malicious content on the internet.
66
+
-**Web content filtering**: Regulates access to websites based on content categories (such as adult content, high bandwidth, and legal liability) across all browsers.
67
+
-**Protection from potentially unwanted applications**: For example:
68
+
- Advertising software.
69
+
- Bundled software that offers to install other, unsigned software.
70
+
- Evasion software that attempts to evade security features.
59
71
60
-
- Active mode
61
-
- Passive mode
62
-
- Disabled (or uninstalled) mode
72
+
-**Passive mode**: A non-Microsoft antivirus/antimalware product is installed on a device onboarded to Defender for Business. Microsoft Defender Antivirus can detect threats and can receive security intelligence and platform updates. But Microsoft Defender Antivirus doesn't remediate threats.
63
73
64
-
To view the state of Microsoft Defender Antivirus, you can choose from several options, such as:
74
+
You can automatically switch to active mode by uninstalling the non-Microsoft antivirus/antimalware product.
65
75
66
-
- Reports, like the [Device health report](mdb-reports.md#device-health-report); or
67
-
- One of the methods described in [How to confirm the state of Microsoft Defender Antivirus](/defender-endpoint/microsoft-defender-antivirus-compatibility#how-to-confirm-the-state-of-microsoft-defender-antivirus).
76
+
-**Disabled mode**: Also known as *uninstalled mode*. A non-Microsoft antivirus/antimalware product is installed on a device that isn't onboarded to Defender for Business. Microsoft Defender Antivirus isn't currently running on the device; it might be automatically disabled or manually disabled. Microsoft Defender Antivirus can't detect or remediate threats on the device.
68
77
69
-
The following table describes each state and what it means.
78
+
You can switch to active mode by doing the following steps:
70
79
71
-
|Microsoft Defender Antivirus state|What it means|
72
-
|---|---|
73
-
|**Active mode** <br/>(*recommended*)|Microsoft Defender Antivirus is used as the antivirus app on the machine. Files are scanned, threats are remediated, and detection information is reported in the Microsoft Defender portal and in the Windows Security app on a device running Windows.<br/><br/>We recommend running Microsoft Defender Antivirus in active mode so that devices onboarded to Defender for Business will get all of the following types of protection: <br/>- **Real-time protection**, which locates and stops malware from running on devices. <br/> - **Cloud protection**, which works with Microsoft Defender Antivirus and the Microsoft cloud to identify new threats, sometimes even before a single device is affected.<br/> - **Network protection**, which helps protect against phishing scams, exploit-hosting sites, and malicious content on the internet.<br/> - **Web content filtering**, which regulates access to websites based on content categories (such as adult content, high bandwidth, and legal liability) across all browsers.<br/> - **Protection from potentially unwanted applications**, such as advertising software, bundling software that offers to install other, unsigned software, and evasion software that attempts to evade security features.|
74
-
|**Passive mode**|A non-Microsoft antivirus/antimalware product is installed on the device, and even though the device has been onboarded to Defender for Business, Microsoft Defender Antivirus can detect threats but doesn't remediate them. Devices with Microsoft Defender Antivirus can still receive security intelligence and platform updates. <br/><br/>You can switch Microsoft Defender Antivirus to active mode automatically by uninstalling the non-Microsoft antivirus/antimalware product.|
75
-
|**Disabled mode**|A non-Microsoft antivirus/antimalware product is installed on the device, and the device hasn't been onboarded to Defender for Business. Whether Microsoft Defender Antivirus went into disabled mode automatically or was set manually, it's not currently running on the device. In this case, Microsoft Defender Antivirus neither detects nor remediates threats on the device.<br/><br/>You can switch Microsoft Defender Antivirus to active mode by uninstalling the non-Microsoft antivirus/antimalware solution and onboarding the device to Defender for Business.|
80
+
1. Uninstall the non-Microsoft antivirus/antimalware solution.
81
+
2. Onboard the device to Defender for Business.
76
82
77
83
## Onboard a device
78
84
79
-
See[Onboard devices to Defender for Business](mdb-onboard-devices.md).
85
+
For more information, see[Onboard devices to Defender for Business](mdb-onboard-devices.md).
80
86
81
87
## Offboard a device
82
88
83
-
See[Offboarding a device](mdb-offboard-devices.md).
89
+
For more information, see[Offboarding a device](mdb-offboard-devices.md).
0 commit comments