Skip to content

Commit 9a388f4

Browse files
committed
Update defender-antivirus-compatibility-without-mde.md
1 parent 3ce7c54 commit 9a388f4

File tree

1 file changed

+30
-31
lines changed

1 file changed

+30
-31
lines changed

defender-endpoint/defender-antivirus-compatibility-without-mde.md

Lines changed: 30 additions & 31 deletions
Original file line numberDiff line numberDiff line change
@@ -1,26 +1,23 @@
11
---
2-
# Required metadata
3-
# For more information, see https://review.learn.microsoft.com/en-us/help/platform/learn-editor-add-metadata?branch=main
4-
# For valid values of ms.service, ms.prod, and ms.topic, see https://review.learn.microsoft.com/en-us/help/platform/metadata-taxonomies?branch=main
5-
62
title: Microsoft Defender Antivirus and non-Microsoft antivirus/antimalware solutions Antivirus protection without Defender for Endpoint
73
description: Microsoft Defender Antivirus and non-Microsoft antivirus/antimalware solutions Antivirus protection without Defender for Endpoint
8-
author: YongRhee-MSFT # GitHub alias
9-
ms.author: yongrhee # Microsoft alias
4+
author: denisebmsft
5+
ms.author: deniseb
6+
ms.reviewer: yongrhee
107
ms.service: defender-endpoint
11-
ms.topic: article
12-
ms.date: 12/27/2024
8+
ms.topic: conceptual
9+
ms.date: 12/30/2024
1310
ms.subservice: ngp
14-
---
11+
search.appverid: met150
12+
ms.localizationpriority: medium
1513

16-
# Microsoft Defender Antivirus and third-party antivirus solutions without Defender for Endpoint
14+
---
1715

18-
__Applies to:__
16+
# Microsoft Defender Antivirus and non-Microsoft antivirus solutions without Defender for Endpoint
1917

20-
- [Microsoft Defender for Endpoint Plan 1](/defender-endpoint/microsoft-defender-endpoint)
18+
**Applies to**:
2119

2220
- [Microsoft Defender for Individuals](https://www.microsoft.com/microsoft-365/microsoft-defender-for-individuals)
23-
2421
- Microsoft Defender Antivirus
2522

2623
This section describes what happens when you use Microsoft Defender Antivirus alongside non-Microsoft antivirus/antimalware products on endpoints that aren't onboarded to Defender for Endpoint.
@@ -39,50 +36,52 @@ The following table summarizes what to expect:
3936
> [!NOTE]
4037
> On Windows Server, if you're running a non-Microsoft antivirus product, you can uninstall Microsoft Defender Antivirus by using the following PowerShell cmdlet (as an administrator): `Uninstall-WindowsFeature Windows-Defender`. Restart your server to finish removing Microsoft Defender Antivirus. On Windows Server 2016, you might see *Windows Defender Antivirus* instead of *Microsoft Defender Antivirus*. If you uninstall your non-Microsoft antivirus product, make sure that Microsoft Defender Antivirus is re-enabled. See **[Re-enable Microsoft Defender Antivirus on Windows Server if it was disabled](/defender-endpoint/enable-update-mdav-to-latest-ws)**.
4138
42-
Check the services and filter drivers for Microsoft Defender Antivirus
43-
39+
Check the services and filter drivers for Microsoft Defender Antivirus by using the following command:
4440

4541
```powershell
42+
4643
gsv WinDefend, WdBoot, WdFilter, WdNisSvc, WdNisDrv | ft -auto DisplayName, Name, StartType, Status
44+
4745
```
4846

49-
|Display Name|Name|StartType|Status when Defender AV is enabled| Status when Defender AV is disabled| Comments |
47+
|Display Name|Name|StartType|Status when Microsoft Defender Antivirus is enabled| Status when Microsoft Defender Antivirus is disabled| Comments |
5048
| -------- | -------- | -------- | -------- | -------- | -------- |
51-
|Microsoft Defender Antivirus Boot Driver |WdBoot|Boot |Stopped (0x0 Boot_start)| Stopped (0x3 Demand_start)|Its normal to be stopped after boot. |
52-
|Microsoft Defender Antivirus Mini-Filter Driver|WdFilter|Manual |Running (0x0 Boot_start)|Stopped (0x3 Demand_start)|If a 3rd party AV is installed, then this will be stopped. |
53-
|Microsoft Defender Antivirus Network Inspection System Driver |WdNisDrv|Manual|Running (0x3 Demand_start)|Stopped (0x3 Demand_start)|If a 3rd party AV is installed, then this will be stopped. |
54-
|Microsoft Defender Antivirus Network Inspection Service |WdNisSvc|Manual|Running (0x3 Demand_start)|Stopped (0x3 Demand_start)|If a 3rd party AV is installed, then this will be stopped. |
55-
|Microsoft Defender Antivirus Service|WinDefend|Automatic|Running (0x2 Auto_start)|Stopped (0x3 Demand_start)|If a 3rd party AV is installed, then this will be stopped.|
49+
|Microsoft Defender Antivirus Boot Driver |`WdBoot`|Boot |Stopped (`0x0 Boot_start`)| Stopped (`0x3 Demand_start`)|It's normal to be stopped after boot. |
50+
|Microsoft Defender Antivirus Mini-Filter Driver|`WdFilter`|Manual |Running (`0x0 Boot_start`)|Stopped (`0x3 Demand_start`)|If a non-Microsoft antivirus solution is installed, expect status to be stopped. |
51+
|Microsoft Defender Antivirus Network Inspection System Driver |`WdNisDrv`|Manual|Running (`0x3 Demand_start`)|Stopped (`0x3 Demand_start`)|If a non-Microsoft antivirus solution is installed, expect status to be stopped. |
52+
|Microsoft Defender Antivirus Network Inspection Service |`WdNisSvc`|Manual|Running (`0x3 Demand_start`)|Stopped (`0x3 Demand_start`)|If a non-Microsoft antivirus solution is installed, expect status to be stopped. |
53+
|Microsoft Defender Antivirus Service|`WinDefend`|Automatic|Running (`0x2 Auto_start`)|Stopped (`0x3 Demand_start`)|If a non-Microsoft antivirus solution is installed, expect status to be stopped.|
5654

5755
### Frequently Asked Questions (FAQ)
5856

5957
Q: Can I update Microsoft Defender Antivirus components such as "Security intelligence update" or "Engine update" "Platform update" when Microsoft Defender Antivirus is disabled?
6058

61-
A: No. When Microsoft Defender Antivirus is disabled, since the services and drivers are not running, you will not be able to update the components such as "Security intelligence update" or "Engine update" "Platform update".
59+
A: No. When Microsoft Defender Antivirus is disabled, since the services and drivers are not running, you will not be able to update the components such as "Security intelligence update" or "Engine update" "Platform update".
6260

6361
> [!TIP]
64-
> If you are migrating to Microsoft Defender for Endpoint, when onboarded, Microsoft Defender Antivirus will go into 'passive mode' in Windows clients and via a registry key in Windows Servers, where you will be able to update the different components of Microsoft Defender Antivirus.
62+
> If you are migrating to Microsoft Defender for Endpoint, when onboarded, Microsoft Defender Antivirus goes into passive mode automatically on Windows clients, and can be set to passive mode using a registry key on Windows Server. You can update the different components of Microsoft Defender Antivirus.
6563
6664
Q: Can I manually change the start type of the services and drivers for Microsoft Defender Antivirus?
6765

68-
A: We do not support the manual modification of the start type of the services and drivers for Microsoft Defender Antivirus in Windows images. On Windows clients, the supported method is via the third-party antivirus solution registering to Windows Security Center (WSC) api. Or on Windows Servers uninstalling Microsoft Defender Antivirus feature, via the Roles and Features MMC or via Powershell (Run as admin):
69-
66+
A: We do not support the manual modification of the start type of the services and drivers for Microsoft Defender Antivirus in Windows images. On Windows clients, the supported method is by registring your non-Microsoft antivirus in Windows Security (WSC) api. Or, on Windows Server, you can uninstall the Microsoft Defender Antivirus feature by using roles and features MMC or by running the following PowerShell command (as an administrator):
7067

7168
```powershell
69+
7270
Uninstall-WindowsFeature Windows-Defender
71+
7372
```
7473

75-
Q: Can I use Microsoft Defender Antivirus in "passive mode" without onboarding to Microsoft Defender for Endpoint?
74+
Q: Can I use Microsoft Defender Antivirus in passive mode without onboarding to Microsoft Defender for Endpoint?
7675

77-
A: No. "Passive mode" is a functionality of Microsoft Defender for Endpoint Plan 2.
76+
A: No. Passive mode is functionality in Microsoft Defender for Endpoint Plan 2.
7877

79-
Q: Can I use "EDR in block mode" without onboarding to Microsoft Defender for Endpoint?
78+
Q: Can I use [EDR in block mode](edr-in-block-mode.md) without onboarding to Microsoft Defender for Endpoint?
8079

81-
A: No. "EDR in block mode" is a functionality of Microsoft Defender for Endpoint Plan 2.
80+
A: No. EDR in block mode is a functionality in Microsoft Defender for Endpoint Plan 2.
8281

83-
Q: Can I use "Indicators" - "File hash" or "IP address/URL's" or "Certificates" with Microsoft Defender Antivirus (active mode) with M365 E3/A3 license?
82+
Q: Can I use indicators, such as file hash, IP address/URL's, or certificates with Microsoft Defender Antivirus (in active mode) with my Microsoft 365 E3/A3 license?
8483

85-
A: Yes, please review [Microsoft Defender for Endpoint Plan 1 Now Included in M365 E3/A3 Licenses](https://techcommunity.microsoft.com/blog/microsoftdefenderatpblog/microsoft-defender-for-endpoint-plan-1-now-included-in-m365-e3a3-licenses/3060639) and [Overview of Microsoft Defender for Endpoint Plan 1](/defender-endpoint/defender-endpoint-plan-1)
84+
A: Yes. See [Tech Community Blog: Microsoft Defender for Endpoint Plan 1 Now Included in M365 E3/A3 Licenses](https://techcommunity.microsoft.com/blog/microsoftdefenderatpblog/microsoft-defender-for-endpoint-plan-1-now-included-in-m365-e3a3-licenses/3060639) and [Overview of Microsoft Defender for Endpoint Plan 1](/defender-endpoint/defender-endpoint-plan-1)
8685

8786
## See also
8887

0 commit comments

Comments
 (0)