You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-endpoint/mde-linux-prerequisites.md
+41-44Lines changed: 41 additions & 44 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -23,12 +23,11 @@ ms.date: 11/11/2025
23
23
> [!TIP]
24
24
> Microsoft Defender for Endpoint on Linux now extends support for Arm64-based Linux servers in GA.
25
25
26
-
27
26
This article lists hardware and software requirements for Defender for Endpoint on Linux. For more information about Defender for Endpoint on Linux, such as what's included in this offering, see the following articles:
28
27
29
-
-[Defender for Endpoint on Linux](microsoft-defender-endpoint-linux.md)
28
+
-[Defender for Endpoint on Linux](microsoft-defender-endpoint-linux.md)
30
29
31
-
-[What's new in Defender for Endpoint on Linux](linux-whatsnew.md)
30
+
-[What's new in Defender for Endpoint on Linux](linux-whatsnew.md)
@@ -70,42 +69,40 @@ For detailed licensing information, see [Product Terms: Microsoft Defender for E
70
69
71
70
The following Linux server distributions and x64 (AMD64/EM64T) versions are supported:
72
71
73
-
- Red Hat Enterprise Linux 7.2 and higher
74
-
- Red Hat Enterprise Linux 8.x
75
-
- Red Hat Enterprise Linux 9.x
76
-
- Red Hat Enterprise Linux 10.x
77
-
78
-
- CentOS 7.2 and higher, excluding CentOS Stream
72
+
- Red Hat Enterprise Linux 7.2 and higher
73
+
- Red Hat Enterprise Linux 8.x
74
+
- Red Hat Enterprise Linux 9.x
75
+
- Red Hat Enterprise Linux 10.x
76
+
- CentOS 7.2 and higher, excluding CentOS Stream
79
77
- CentOS 8.x
80
-
81
-
- Ubuntu 16.04 LTS
82
-
- Ubuntu 18.04 LTS
83
-
- Ubuntu 20.04 LTS
84
-
- Ubuntu 22.04 LTS
85
-
- Ubuntu 24.04 LTS
86
-
- Debian 9 - 12
87
-
- SUSE Linux Enterprise Server 12.x
88
-
- SUSE Linux Enterprise Server 15.x
89
-
- Oracle Linux 7.2 and higher
90
-
- Oracle Linux 8.x
91
-
- Oracle Linux 9.x
92
-
- Amazon Linux 2
93
-
- Amazon Linux 2023
78
+
- Ubuntu 16.04 LTS
79
+
- Ubuntu 18.04 LTS
80
+
- Ubuntu 20.04 LTS
81
+
- Ubuntu 22.04 LTS
82
+
- Ubuntu 24.04 LTS
83
+
- Debian 9 - 12
84
+
- SUSE Linux Enterprise Server 12.x
85
+
- SUSE Linux Enterprise Server 15.x
86
+
- Oracle Linux 7.2 and higher
87
+
- Oracle Linux 8.x
88
+
- Oracle Linux 9.x
89
+
- Amazon Linux 2
90
+
- Amazon Linux 2023
94
91
- Fedora 33-42
95
-
- Rocky 8.7 and higher
96
-
- Rocky 9.2 and higher
97
-
- Alma 8.4 and higher
98
-
- Alma 9.2 and higher
99
-
- Mariner 2
92
+
- Rocky 8.7 and higher
93
+
- Rocky 9.2 and higher
94
+
- Alma 8.4 and higher
95
+
- Alma 9.2 and higher
96
+
- Mariner 2
100
97
101
98
**The following Linux server distributions on ARM64 are now GA:**
102
99
103
-
- Ubuntu 20.04 ARM64
104
-
- Ubuntu 22.04 ARM64
100
+
- Ubuntu 20.04 ARM64
101
+
- Ubuntu 22.04 ARM64
105
102
- Ubuntu 24.04 ARM64
106
103
- Debian 11, 12 ARM64
107
-
- Amazon Linux 2 ARM64
108
-
- Amazon Linux 2023 ARM64
104
+
- Amazon Linux 2 ARM64
105
+
- Amazon Linux 2023 ARM64
109
106
- RHEL 8.x ARM64
110
107
- RHEL 9.x ARM64
111
108
- RHEL 10.x ARM64
@@ -114,16 +111,17 @@ The following Linux server distributions and x64 (AMD64/EM64T) versions are supp
114
111
- SUSE Linux Enterprise Server 15 (SP5, SP6) ARM64
115
112
116
113
> [!NOTE]
117
-
> Distributions and versions that aren't explicitly listed above, and custom operating systems, are unsupported (even if they're derived from the officially supported distributions).
118
-
> Microsoft Defender for Endpoint is kernel-version agnostic for all other supported distributions and versions. The minimal requirement for the kernel version is`3.10.0-327`or later.
114
+
> Distributions and versions that aren't explicitly listed above, and custom operating systems, are unsupported (even if they're derived from the officially supported distributions).
115
+
> Microsoft Defender for Endpoint is kernel-version agnostic for all other supported distributions and versions. The minimal requirement for the kernel version is`3.10.0-327`or later.
119
116
120
117
> [!WARNING]
121
118
> Running Defender for Endpoint on Linux alongside other fanotify-based security solutions is not supported and may lead to unpredictable behavior, including system hangs.
122
119
> If any applications use fanotify in blocking mode, they will appear in the conflicting_applications field of the mdatp health command output.
123
-
> You can still safely take advantage of Defender for Endpoint on Linux by setting antivirus enforcement level to passive. See [Configure security settings in Microsoft Defender for Endpoint on Linux](/defender-endpoint/linux-preferences).> **EXCEPTION:** The Linux `FAPolicyD` feature, which also uses Fanotify in blocking mode, is supported with Defender for Endpoint in active mode on RHEL and Fedora platforms, provided that mdatp health reports a healthy status. This exception is based on validated compatibility specific to these distributions.
124
-
>
125
-
>
126
-
## Supported filesystems for real-time protection and quick, full, and custom scans
120
+
> You can still safely take advantage of Defender for Endpoint on Linux by setting antivirus enforcement level to passive. See [Configure security settings in Microsoft Defender for Endpoint on Linux](/defender-endpoint/linux-preferences).> **EXCEPTION:** The Linux `FAPolicyD` feature, which also uses Fanotify in blocking mode, is supported with Defender for Endpoint in active mode on RHEL and Fedora platforms, provided that mdatp health reports a healthy status. This exception is based on validated compatibility specific to these distributions.
121
+
>
122
+
>
123
+
124
+
## Supported filesystems for real-time protection and quick, full, and custom scans
127
125
128
126
|Real-time protection and quick/full scans|Custom scans|
129
127
|---|---|
@@ -145,7 +143,7 @@ The following Linux server distributions and x64 (AMD64/EM64T) versions are supp
145
143
|`xfs`|
146
144
147
145
> [!NOTE]
148
-
> To scan NFS v3 mount points, make sure to set the`no_root_squash`export option. Without this option, scanning NFS v3 can potentially fail due to lack of permissions.
146
+
> To scan NFS v3 mount points, make sure to set the`no_root_squash`export option. Without this option, scanning NFS v3 can potentially fail due to lack of permissions.
149
147
150
148
## Verify if devices can connect to Defender for Endpoint cloud services
151
149
@@ -154,16 +152,16 @@ The following Linux server distributions and x64 (AMD64/EM64T) versions are supp
154
152
2. Connect Defender for Endpoint on Linux through a proxy server by using the following discovery methods:
3. Permit anonymous traffic in the previously listed URLs, if a proxy or firewall blocks traffic.
160
158
161
-
> [!NOTE]
159
+
> [!NOTE]
162
160
> Configuration for transparent proxies isn't needed for Defender for Endpoint. See [Manual Static Proxy Configuration.](/defender-endpoint/linux-static-proxy-configuration)
163
161
164
162
> [!WARNING]
165
-
> PAC, WPAD, and authenticated proxies aren't supported.
166
-
> Use only static or transparent proxies.
163
+
> PAC, WPAD, and authenticated proxies aren't supported.
164
+
> Use only static or transparent proxies.
167
165
> SSL inspection and intercepting proxies aren't supported for security reasons.
168
166
> Configure an exception for SSL inspection and your proxy server to allow direct data pass-through from Defender for Endpoint on Linux to the relevant URLs without interception.
169
167
> Adding your interception certificate to the global store doesn't enable interception.
@@ -187,7 +185,6 @@ If the Microsoft Defender for Endpoint installation fails due to missing depende
187
185
> - For DEBIAN, the mdatp package requires `auditd`.
188
186
> - For Mariner, the mdatp package requires `audit`.
189
187
190
-
191
188
## Installation instructions
192
189
193
190
There are several methods and tools that you can use to deploy Microsoft Defender for Endpoint on Linux (applicable to AMD64 and ARM64 Linux servers):
0 commit comments