Skip to content

Commit 964f9db

Browse files
authored
Update mde-plugin-wsl.md
1 parent 4c29457 commit 964f9db

File tree

1 file changed

+17
-17
lines changed

1 file changed

+17
-17
lines changed

defender-endpoint/mde-plugin-wsl.md

Lines changed: 17 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ ms.collection:
1515
ms.custom:
1616
- partner-contribution
1717
audience: ITPro
18-
ms.date: 07/26/2024
18+
ms.date: 08/05/2024
1919
search.appverid: MET150
2020
---
2121

@@ -33,33 +33,33 @@ Windows Subsystem for Linux (WSL) 2, which replaces the previous version of WSL
3333

3434
## Known issues and limitations
3535

36-
Be aware of the following before you start:
36+
Be aware of the following considerations before you start:
3737

38-
1. The plug-in doesn't support automatic updates on versions prior to `1.24.522.2`. On version `1.24.522.2` and later; updates are supported through Windows Update across all rings. Updates through Windows Server Update services (WSUS), System Center Configuration Manager (SCCM) and Microsoft Update catalog are supported only in the Production ring to ensure package stability.
38+
1. The plug-in doesn't support automatic updates on versions prior to `1.24.522.2`. On version `1.24.522.2` and later, updates are supported through Windows Update across all rings. Updates through Windows Server Update services (WSUS), System Center Configuration Manager (SCCM) and Microsoft Update catalog are supported only in the Production ring to ensure package stability.
3939

4040
2. It takes a few minutes for the plug-in to fully instantiate, and up to 30 minutes for a WSL2 instance to onboard itself. Short-lived WSL container instances might result in the WSL2 instance not showing up in the Microsoft Defender portal ([https://security.microsoft.com](https://security.microsoft.com)). Once any distribution has been running long enough (at least 30 minutes), it does show up.
4141

4242
3. Running a custom kernel and custom kernel command line is not supported. Although the plug-in does not block running in that configuration, it does not guarantee visibility within WSL when you're running a custom kernel and custom kernel command line. We recommend to block such configurations with help of [Microsoft Intune wsl settings](/windows/wsl/intune).
4343

44-
4. OS Distribution is displayed **None** in Device overview page of WSL device in Microsoft Defender portal.
44+
4. OS Distribution is displayed **None** in the **Device overview** page of a WSL device in the Microsoft Defender portal.
4545

4646
5. The plug-in is not supported on machines with ARM64 processor.
4747

48-
6. The plug-in provides visibility into events from WSL but other features like antimalware, threat and vulnerability management and response commands are not available for the WSL logical device.
48+
6. The plug-in provides visibility into events from WSL, but other features like antimalware, threat and vulnerability management, and response commands are not available for the WSL logical device.
4949

5050
## Software prerequisites
5151

5252
- WSL version 2.0.7.0 or later must be running with at least one active distro.
5353

54-
Run `wsl --update` to make sure you are on the latest version. If `wsl -–version` shows a version older than 2.0.7.0, run `wsl -–update –pre-release` to get the latest update.
54+
Run `wsl --update` to make sure you are on the latest version. If `wsl -–version` shows a version older than `2.0.7.0`, run `wsl -–update –pre-release` to get the latest update.
5555

5656
- The Windows client device must be onboarded to Defender for Endpoint.
5757

5858
- The Windows client device must be running Windows 10, version 2004 and later (build 19044 and later), or Windows 11 to support the WSL versions that can work with the plug-in.
5959

6060
## Software components and installer file names
6161

62-
Installer: `DefenderPlugin-x64-0.24.426.1.msi`. You can download it from the onboarding page in the [Microsoft Defender portal](https://security.microsoft.com).
62+
Installer: `DefenderPlugin-x64-0.24.426.1.msi`. You can download it from the onboarding page in the [Microsoft Defender portal](https://security.microsoft.com). (Go to **Settings** > **Endpoints** > **Onboarding**.)
6363

6464
Installation directories:
6565

@@ -69,9 +69,9 @@ Installation directories:
6969

7070
Components installed:
7171

72-
- `DefenderforEndpointPlug-in.dll`. This DLL is the library to load Defender for Endpoint to work within WSL. You can find it at **%ProgramFiles%\Microsoft Defender for Endpoint plug-in for WSL\plug-in**.
72+
- `DefenderforEndpointPlug-in.dll`. This DLL is the library to load Defender for Endpoint to work within WSL. You can find it at `%ProgramFiles%\Microsoft Defender for Endpoint plug-in for WSL\plug-in`.
7373

74-
- `healthcheck.exe`. This program checks the health status of Defender for Endpoint and enables you to see the installed versions of WSL, plug-in, and Defender for Endpoint. You can find it at **%ProgramFiles%\Microsoft Defender for Endpoint plug-in for WSL\tools**.
74+
- `healthcheck.exe`. This program checks the health status of Defender for Endpoint and enables you to see the installed versions of WSL, plug-in, and Defender for Endpoint. You can find it at `%ProgramFiles%\Microsoft Defender for Endpoint plug-in for WSL\tools`.
7575

7676
## Installation steps
7777

@@ -138,10 +138,10 @@ If your host machine contains multiple proxy settings, the plug-in selects the p
138138

139139
3. Network & Internet proxy settings.
140140

141-
Example: If your host machine has both *Winhttp proxy* and *Network & Internet proxy*, the plug-in selects `Winhttp proxy` as the proxy configuration.
141+
For example, if your host machine has both `Winhttp proxy` and `Network & Internet proxy`, the plug-in selects `Winhttp proxy` as the proxy configuration.
142142

143143
> [!NOTE]
144-
> The `DefenderProxyServer` registry key is no longer supported. Follow the above mentioned steps to configure proxy in plug-in.
144+
> The `DefenderProxyServer` registry key is no longer supported. Follow the steps described earlier in this article to configure proxy in plug-in.
145145
146146
## Connectivity test for Defender running in WSL
147147

@@ -162,7 +162,7 @@ The following procedure describes how to confirm that Defender in Endpoint in WS
162162

163163
2. Run the command `wsl`.
164164

165-
4. Wait for 5 minutes and then run `healthcheck.exe` (located at `%ProgramFiles%\Microsoft Defender for Endpoint plug-in for WSL\tools` for the results of the connectivity test).
165+
4. Wait for five minutes, and then run `healthcheck.exe` (located at `%ProgramFiles%\Microsoft Defender for Endpoint plug-in for WSL\tools` for the results of the connectivity test).
166166

167167
If successful, you can see that the connectivity test was successful. If failed, you can see that the connectivity test was `invalid` indicating that the client connectivity from WSL to Defender for Endpoint service URLs is failing.
168168

@@ -202,7 +202,7 @@ To test the plug-in after installation, follow these steps:
202202
An alert should appear in the portal after a few minutes for a detection on the WSL2 instance.
203203

204204
> [!NOTE]
205-
> It takes about 5 minutes for the events to appear on the Microsoft Defender portal.
205+
> It takes about five minutes for the events to appear on the Microsoft Defender portal.
206206
207207
Treat the machine as if it were a regular Linux host in your environment to perform testing against. In particular, we would like to get your feedback on the ability to surface potentially malicious behavior using the new plug-in.
208208

@@ -246,21 +246,21 @@ DeviceProcessEvents
246246

247247
## Troubleshooting
248248

249-
1. The command `healthcheck.exe` shows the output, "Launch WSL distro with 'bash' command and retry in 5 minutes."
249+
1. The command `healthcheck.exe` shows the output, "Launch WSL distro with 'bash' command and retry in five minutes."
250250

251251
:::image type="content" source="media/mdeplugin-wsl/wsl-health-check.png" alt-text="Screenshot showing PowerShell output." lightbox="media/mdeplugin-wsl/wsl-health-check.png":::
252252

253253
2. If the previously mentioned error occurs, take the following steps:
254254

255255
1. Open a terminal instance and run the command `wsl`.
256256

257-
2. Wait for at least 5 minutes before rerunning the health check.
257+
2. Wait for at least five minutes before rerunning the health check.
258258

259-
3. The `healthcheck.exe` command might show the output, "Waiting for Telemetry. Please retry in 5 minutes."
259+
3. The `healthcheck.exe` command might show the output, "Waiting for Telemetry. Please retry in five minutes."
260260

261261
:::image type="content" source="media/mdeplugin-wsl/wsl-health-check-telemetry.png" alt-text="Screenshot showing health telemetry status." lightbox="media/mdeplugin-wsl/wsl-health-check-telemetry.png":::
262262

263-
If that error occurs, wait for 5 minutes and rerun `healthcheck.exe`.
263+
If that error occurs, wait for five minutes and rerun `healthcheck.exe`.
264264

265265
4. If you don't see any devices in the Microsoft Defender portal, or you don't see any events in the timeline, check the following things:
266266

0 commit comments

Comments
 (0)