Skip to content

Commit 8aac2a5

Browse files
authored
Merge branch 'main' into patch-1
2 parents a29c849 + 425437e commit 8aac2a5

10 files changed

+341
-205
lines changed

defender-business/mdb-manage-subscription.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ ms.author: chrisda
77
manager: deniseb
88
audience: ITPro
99
ms.topic: overview
10-
ms.date: 01/03/2024
10+
ms.date: 12/30/2024
1111
ms.service: defender-business
1212
ms.localizationpriority: medium
1313
ms.reviewer: shlomiakirav, efratka
@@ -48,12 +48,12 @@ This article describes how to apply either Defender for Business or Defender for
4848

4949
> [!IMPORTANT]
5050
> Keep the following important points in mind before you save your changes:
51-
>
5251
> - Make sure you have enough licenses for the subscription you're using for all users in your organization.
5352
> - If you select **Only Microsoft Defender for Endpoint Plan 2**, the simplified configuration experience for Defender for Business is replaced with advanced settings that you can configure in Defender for Endpoint. If this change is applied, you can't undo it.
54-
> - It can take up to three hours for your changes to be applied.
53+
> - It can take up to six hours for your changes to be applied.
5554
> - Make sure to review your security policies and settings. To get help with Defender for Endpoint policies and settings, see [Configure Defender for Endpoint capabilities](/defender-endpoint/onboard-configure). To get help with Defender for Business policies and settings, see [Review and edit your security policies and settings in Defender for Business](mdb-configure-security-settings.md).
5655
56+
5757
## Review license usage
5858

5959
The license usage report is estimated based on sign-in activities on the device. Defender for Endpoint Plan 2 licenses are assigned to users, and each user can have up to five concurrent, onboarded devices. To learn more about license terms, see [Microsoft Licensing](https://www.microsoft.com/licensing/default).

defender-endpoint/TOC.yml

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -791,6 +791,12 @@
791791
href: microsoft-defender-endpoint-antivirus-performance-mode.md
792792
- name: Compatibility with other security products
793793
href: microsoft-defender-antivirus-compatibility.md
794+
- name: Microsoft Defender Antivirus and third-party antivirus solutions without
795+
Defender for Endpoint
796+
href: defender-antivirus-compatibility-without-mde.md
797+
displayName: Microsoft Defender Antivirus and non-Microsoft
798+
antivirus/antimalware solutions, Antivirus protection without Defender for
799+
Endpoint
794800
- name: Find malware detection names for Microsoft Defender for Endpoint
795801
href: find-defender-malware-name.md
796802

defender-endpoint/configure-endpoints-vdi.md

Lines changed: 53 additions & 118 deletions
Large diffs are not rendered by default.
Lines changed: 115 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,115 @@
1+
---
2+
title: Microsoft Defender Antivirus and non-Microsoft antivirus/antimalware solutions Antivirus protection without Defender for Endpoint
3+
description: Microsoft Defender Antivirus and non-Microsoft antivirus/antimalware solutions Antivirus protection without Defender for Endpoint
4+
author: denisebmsft
5+
ms.author: deniseb
6+
ms.reviewer: yongrhee
7+
ms.service: defender-endpoint
8+
ms.topic: conceptual
9+
ms.date: 12/30/2024
10+
ms.subservice: ngp
11+
search.appverid: met150
12+
ms.localizationpriority: medium
13+
14+
---
15+
16+
# Microsoft Defender Antivirus and non-Microsoft antivirus solutions without Defender for Endpoint
17+
18+
**Applies to**:
19+
20+
- [Microsoft Defender for Endpoint Plan 1](defender-endpoint-plan-1.md)
21+
- [Microsoft Defender for Individuals](https://www.microsoft.com/microsoft-365/microsoft-defender-for-individuals)
22+
- Microsoft Defender Antivirus
23+
24+
This section describes what happens when you use Microsoft Defender Antivirus alongside non-Microsoft antivirus/antimalware products on endpoints that aren't onboarded to Defender for Endpoint.
25+
26+
Microsoft Defender Antivirus doesn't run in passive mode on devices that aren't onboarded to Defender for Endpoint.
27+
28+
The following table summarizes what to expect:
29+
30+
| Windows version |Primary antivirus/antimalware solution|Microsoft Defender Antivirus state|
31+
| -------- | -------- | -------- |
32+
|Windows 11 and Windows 10 |Microsoft Defender Antivirus|Active mode|
33+
|Windows 11 and Windows 10|A non-Microsoft antivirus solution|Disabled mode (happens automatically).|
34+
|Windows Server 2025, Windows Server 2022, Windows Server 2019, Windows Server, version 1803 or newer, Windows Server 2016|Microsoft Defender Antivirus|Active mode|
35+
|Windows Server 2025, Windows Server 2022, Windows Server 2019, Windows Server, version 1803 or newer, Windows Server 2016|A non-Microsoft antivirus solution|Disabled (set manually; see the note that follows this table)|
36+
37+
> [!NOTE]
38+
> On Windows Server, if you're running a non-Microsoft antivirus product, you can uninstall Microsoft Defender Antivirus by using the following PowerShell cmdlet (as an administrator): `Uninstall-WindowsFeature Windows-Defender`. Restart your server to finish removing Microsoft Defender Antivirus. On Windows Server 2016, you might see *Windows Defender Antivirus* instead of *Microsoft Defender Antivirus*. If you uninstall your non-Microsoft antivirus product, make sure that Microsoft Defender Antivirus is re-enabled. See **[Re-enable Microsoft Defender Antivirus on Windows Server if it was disabled](/defender-endpoint/enable-update-mdav-to-latest-ws)**.
39+
40+
Check the services and filter drivers for Microsoft Defender Antivirus by using the following command:
41+
42+
```powershell
43+
44+
gsv WinDefend, WdBoot, WdFilter, WdNisSvc, WdNisDrv | ft -auto DisplayName, Name, StartType, Status
45+
46+
```
47+
48+
|Display Name|Name|StartType|Status when Microsoft Defender Antivirus is enabled| Status when Microsoft Defender Antivirus is disabled| Comments |
49+
| -------- | -------- | -------- | -------- | -------- | -------- |
50+
|Microsoft Defender Antivirus Boot Driver |`WdBoot`|Boot |Stopped (`0x0 Boot_start`)| Stopped (`0x3 Demand_start`)|It's normal to be stopped after boot. |
51+
|Microsoft Defender Antivirus Mini-Filter Driver|`WdFilter`|Manual |Running (`0x0 Boot_start`)|Stopped (`0x3 Demand_start`)|If a non-Microsoft antivirus solution is installed, expect status to be stopped. |
52+
|Microsoft Defender Antivirus Network Inspection System Driver |`WdNisDrv`|Manual|Running (`0x3 Demand_start`)|Stopped (`0x3 Demand_start`)|If a non-Microsoft antivirus solution is installed, expect status to be stopped. |
53+
|Microsoft Defender Antivirus Network Inspection Service |`WdNisSvc`|Manual|Running (`0x3 Demand_start`)|Stopped (`0x3 Demand_start`)|If a non-Microsoft antivirus solution is installed, expect status to be stopped. |
54+
|Microsoft Defender Antivirus Service|`WinDefend`|Automatic|Running (`0x2 Auto_start`)|Stopped (`0x3 Demand_start`)|If a non-Microsoft antivirus solution is installed, expect status to be stopped.|
55+
56+
### Frequently Asked Questions (FAQ)
57+
58+
Q: Can I update Microsoft Defender Antivirus components such as "Security intelligence update" or "Engine update" "Platform update" when Microsoft Defender Antivirus is disabled?
59+
60+
A: No. When Microsoft Defender Antivirus is disabled, since the services and drivers aren't running, you won't be able to update the components such as "Security intelligence update" or "Engine update" "Platform update".
61+
62+
> [!TIP]
63+
> If you are migrating to Microsoft Defender for Endpoint, when onboarded, Microsoft Defender Antivirus goes into passive mode automatically on Windows clients, and can be set to passive mode using a registry key on Windows Server. You can update the different components of Microsoft Defender Antivirus.
64+
65+
Q: Can I manually change the start type of the services and drivers for Microsoft Defender Antivirus?
66+
67+
A: We don't support the manual modification of the start type of the services and drivers for Microsoft Defender Antivirus in Windows images. On Windows clients, the supported method is by registering your non-Microsoft antivirus in Windows Security (WSC) API. Or, on Windows Server, you can uninstall the Microsoft Defender Antivirus feature by using roles and features MMC or by running the following PowerShell command (as an administrator):
68+
69+
```powershell
70+
71+
Uninstall-WindowsFeature Windows-Defender
72+
73+
```
74+
75+
Q: Can I use Microsoft Defender Antivirus in passive mode without onboarding to Microsoft Defender for Endpoint?
76+
77+
A: No. Passive mode is functionality in Microsoft Defender for Endpoint Plan 2.
78+
79+
Q: Can I use [EDR in block mode](edr-in-block-mode.md) without onboarding to Microsoft Defender for Endpoint?
80+
81+
A: No. EDR in block mode is a functionality in Microsoft Defender for Endpoint Plan 2.
82+
83+
Q: Can I use indicators, such as file hashes, IP addresses, URLs, or certificates with Microsoft Defender Antivirus (in active mode) with my Microsoft 365 E3/A3 license?
84+
85+
A: Yes. See [Tech Community Blog: Microsoft Defender for Endpoint Plan 1 Now Included in Microsoft 365 E3/A3 Licenses](https://techcommunity.microsoft.com/blog/microsoftdefenderatpblog/microsoft-defender-for-endpoint-plan-1-now-included-in-m365-e3a3-licenses/3060639) and [Overview of Microsoft Defender for Endpoint Plan 1](/defender-endpoint/defender-endpoint-plan-1).
86+
87+
## See also
88+
89+
- [Use Microsoft Defender for Endpoint Security Settings Management to manage Microsoft Defender Antivirus](/defender-endpoint/mde-security-settings-management)
90+
91+
- [Microsoft Intune securely manages identities, manages apps, and manages devices](/mem/intune/fundamentals/what-is-intune)
92+
93+
- [Defender CSP](/windows/client-management/mdm/defender-csp)
94+
95+
- [Policy CSP - Defender](/windows/client-management/mdm/policy-csp-defender)
96+
97+
- [How to create and deploy antimalware policies for Endpoint Protection in Configuration Manager](/mem/configmgr/protect/deploy-use/endpoint-antimalware-policies)
98+
99+
- [Use Group Policy settings to configure and manage Microsoft Defender Antivirus](/defender-endpoint/use-group-policy-microsoft-defender-antivirus)
100+
101+
- [Use PowerShell cmdlets to configure and manage Microsoft Defender Antivirus](/defender-endpoint/use-powershell-cmdlets-microsoft-defender-antivirus)
102+
103+
- [Exclusions overview](/defender-endpoint/navigate-defender-endpoint-antivirus-exclusions)
104+
105+
- [Address false positives/negatives in Microsoft Defender for Endpoint](/defender-endpoint/defender-endpoint-false-positives-negatives)
106+
107+
- [Troubleshoot Microsoft Defender Antivirus settings](/defender-endpoint/troubleshoot-settings)
108+
109+
- [Run the client analyzer on Windows](/defender-endpoint/run-analyzer-windows)
110+
111+
- [Performance analyzer for Microsoft Defender Antivirus](/defender-endpoint/tune-performance-defender-antivirus)
112+
113+
> [!TIP]
114+
> Do you want to learn more? Engage with the Microsoft Security community in our Tech Community: **[Microsoft Defender for Endpoint Tech Community](https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/bd-p/MicrosoftDefenderATP)**.
115+

0 commit comments

Comments
 (0)