You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-endpoint/onboard-windows-server-2012r2-2016.md
+16-15Lines changed: 16 additions & 15 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -69,33 +69,33 @@ The following diagram shows the general steps required to successfully onboard s
69
69
70
70
2. Follow the guidance for your preferred tool to install Defender for Endpoint:
71
71
72
-
-**Command line**: Run this command: `Msiexec /i md4ws.msi /quiet`
72
+
-**Modern, unified solution**: [Migrating servers from Microsoft Monitoring Agent to the modern, unified solution](application-deployment-via-mecm.md)
73
73
-**Local script**: [Onboard Windows devices using a local script](configure-endpoints-script.md)
74
74
-**Group Policy**: [Onboard Windows devices using Group Policy](configure-endpoints-gp.md)
75
-
-**Microsoft Configuration Manager**:
76
-
-**VDI scripts**:
75
+
-**Microsoft Configuration Manager**:[Onboard Windows devices using Configuration Manager](configure-endpoints-sccm.md)
76
+
-**VDI scripts**:[Onboard non-persistent virtual desktop infrastructure (VDI) devices in Microsoft Defender XDR](configure-endpoints-vdi.md)
77
77
-**Direct onboarding with Defender for Cloud**: [Connect your non-Azure machines to Microsoft Defender for Cloud with Defender for Endpoint](/azure/defender-for-cloud/onboard-machines-with-defender-for-endpoint)
78
78
79
79
For Windows Server, version 1803 or Windows Server 2019 and later, see [Onboard Windows Server, version 1803, Windows Server 2019, and Windows Server 2025 to the Microsoft Defender for Endpoint service](onboard-windows-server.md).
80
80
81
81
> [!NOTE]
82
82
> Windows Hyper-V Server editions aren't supported.
83
83
84
-
85
84
## Functionality in the modern unified solution
86
85
87
-
The previous implementation (before April of 2022) of onboarding Windows Server 2016 and Windows Server 2012 R2 required the use of Microsoft Monitoring Agent (MMA). The modern, unified solution package makes it easier to onboard servers by removing dependencies and installation steps. It also provides a much expanded feature set. For more information, see [Tech Community Blog: Defending Windows Server 2012 R2 and 2016](https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/defending-windows-server-2012-r2-and-2016/ba-p/2783292).
86
+
The previous implementation (before April of 2022) of onboarding Windows Server 2016 and Windows Server 2012 R2 required the use of Microsoft Monitoring Agent (MMA). The modern, unified solution package makes it easier to onboard servers by removing dependencies and installation steps. It also provides a much expanded feature set. For more information, see the following resources:
87
+
88
+
-[Server migration scenarios from the previous, MMA-based Microsoft Defender for Endpoint solution](server-migration.md)
89
+
-[Tech Community Blog: Defending Windows Server 2012 R2 and 2016](https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/defending-windows-server-2012-r2-and-2016/ba-p/2783292)
88
90
89
91
Depending on the server that you're onboarding, the unified solution installs Defender for Endpoint and/or the EDR sensor on the server. The following table indicates what component is installed and what is built in by default.
|Windows Server 2012 R2|||
94
96
|Windows Server 2016|Built-in||
95
97
|Windows Server 2019 and later|Built-in|Built-in|
96
98
97
-
If you've previously onboarded your servers using MMA, follow the guidance provided in [Server migration](server-migration.md) to migrate to the new solution.
98
-
99
99
> [!IMPORTANT]
100
100
> Before proceeding with onboarding, see the section [Known issues and limitations in the new, unified solution package for Windows Server 2012 R2 and Windows Server 2016](#known-issues-and-limitations-in-the-modern-unified-solution).
101
101
@@ -106,12 +106,6 @@ If you intend to use a non-Microsoft anti-malware solution, you need to run Micr
106
106
> [!NOTE]
107
107
> If you're installing Defender for Endpoint on servers with McAfee Endpoint Security (ENS) or VirusScan Enterprise (VSE), the version of the McAfee platform might need to be updated to ensure Microsoft Defender Antivirus isn't removed or disabled. For more information including the specific version numbers required, see [McAfee Knowledge Center article](https://kcm.trellix.com/corporate/index?page=content&id=KB88214).
108
108
109
-
## Update packages for Windows Server 2016 or Windows Server 2012 R2
110
-
111
-
To receive regular product improvements and fixes for the Defender for Endpoint component, ensure Windows Update [KB5005292](https://go.microsoft.com/fwlink/?linkid=2168277) gets applied or approved. In addition, to keep protection components updated, see [Manage Microsoft Defender Antivirus updates and apply baselines](microsoft-defender-antivirus-updates.md#platform-and-engine-releases).
112
-
113
-
If you're using Windows Server Update Services (WSUS) and/or [Microsoft Endpoint Configuration Manager](/mem/configmgr/core/understand/introduction), this new "Microsoft Defender for Endpoint update for EDR Sensor" is available under the category "Microsoft Defender for Endpoint."
114
-
115
109
### Known issues and limitations in the modern unified solution
116
110
117
111
The following points apply to Windows Server 2016 and Windows Server 2012 R2:
@@ -122,12 +116,19 @@ The following points apply to Windows Server 2016 and Windows Server 2012 R2:
122
116
123
117
- The user interface on Windows Server 2016 and Windows Server 2012 R2 only allows for basic operations. To perform operations on a device locally, refer to [Manage Defender for Endpoint with PowerShell, WMI, and MPCmdRun.exe](preferences-setup.md). As a result, features that specifically rely on user interaction, such as where the user is prompted to make a decision or perform a specific task, may not work as expected. It's recommended to disable or not enable the user interface nor require user interaction on any managed server as it may impact protection capability.
124
118
125
-
- Not all Attack Surface Reduction rules are applicable to all operating systems. See [Attack surface reduction rules](attack-surface-reduction-rules-reference.md).
119
+
- Not all attack surface reduction rules are applicable to all operating systems. See [Attack surface reduction rules](attack-surface-reduction-rules-reference.md).
126
120
127
121
- Operating system upgrades aren't supported. Offboard then uninstall before upgrading. The installer package can only be used to upgrade installations that haven't yet been updated with new antimalware platform or EDR sensor update packages.
128
122
129
123
- To automatically, deploy and onboard the new solution using Microsoft Endpoint Configuration Manager (MECM) you need to be on [version 2207 or later](/mem/configmgr/core/plan-design/changes/whats-new-in-version-2207#improved-microsoft-defender-for-endpoint-mde-onboarding-for-windows-server-2012-r2-and-windows-server-2016). You can still configure and deploy using version 2107 with the hotfix rollup, but this requires extra deployment steps. See [Microsoft Endpoint Configuration Manager migration scenarios](server-migration.md#microsoft-endpoint-configuration-manager-migration-scenarios) for more information.
130
124
125
+
## Update packages for Windows Server 2016 or Windows Server 2012 R2
126
+
127
+
To receive regular product improvements and fixes for the Defender for Endpoint component, ensure Windows Update [KB5005292](https://go.microsoft.com/fwlink/?linkid=2168277) gets applied or approved. In addition, to keep protection components updated, see [Manage Microsoft Defender Antivirus updates and apply baselines](microsoft-defender-antivirus-updates.md#platform-and-engine-releases).
128
+
129
+
If you're using Windows Server Update Services (WSUS) and/or [Microsoft Endpoint Configuration Manager](/mem/configmgr/core/understand/introduction), this new "Microsoft Defender for Endpoint update for EDR Sensor" is available under the category "Microsoft Defender for Endpoint."
130
+
131
+
131
132
## Verify the onboarding and installation
132
133
133
134
Verify that Microsoft Defender Antivirus and Defender for Endpoint are running.
0 commit comments