You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
|There has been no communication from the Defender for Identity sensor. The default time span for this alert is 5 minutes.|Network traffic is no longer captured by the network adapter on the Defender for Identity sensor. This affects Defender for Identity's ability to detect suspicious activities, since network traffic isn't able to reach the Defender for Identity cloud service.|Check that the port used for the communication between the Defender for Identity sensor and Defender for Identity cloud service isn't blocked by any routers or firewalls.|Medium|Sensors health issues tab|
106
+
|There has been no communication from the Defender for Identity sensor. The default time span for this alert is 5 minutes.|This indicates that the sensor failed to send data or a keep-alive signal to the Defender for Identity services for a period exceeding the allowed time. This typically suggests either a network issue in the environment that prevented data transmission or a server restart that took longer than the acceptable time frame, impacting Defender for Identity's ability to detect suspicious activities.|Check the communication between the Defender for Identity sensor and Defender for Identity cloud service isn't blocked by any routers or firewalls.|Medium|Sensors health issues tab|
Defender for Identity sensors can be installed on the following operating systems:
9
9
10
10
-**Windows Server 2016**
11
-
-**Windows Server 2019**. Requires [KB4487044](https://support.microsoft.com/topic/february-12-2019-kb4487044-os-build-17763-316-6502eb5d-dde8-6902-e149-27ef359ed616) or a newer cumulative update. Sensors installed on Server 2019 without this update will be automatically stopped if the *ntdsai.dll* file version found in the system directory is older than *10.0.17763.316*
11
+
-**Windows Server 2019**. Requires [KB4487044](https://support.microsoft.com/topic/february-12-2019-kb4487044-os-build-17763-316-6502eb5d-dde8-6902-e149-27ef359ed616) or a newer cumulative update. Sensors installed on Server 2019 without this update will be automatically stopped if the `ntdsai.dll` file version found in the system directory is older `than 10.0.17763.316`
12
12
-**Windows Server 2022**
13
+
-**Windows Server 2025**
13
14
14
15
For all operating systems:
15
16
16
17
- Both servers with desktop experience and server cores are supported.
17
-
- Nano servers are not supported.
18
+
- Nano servers aren't supported.
18
19
- Installations are supported for domain controllers, AD FS, and AD CS servers.
Copy file name to clipboardExpand all lines: ATPDocs/index.yml
+13-13Lines changed: 13 additions & 13 deletions
Original file line number
Diff line number
Diff line change
@@ -1,18 +1,18 @@
1
1
### YamlMime:Landing
2
2
3
-
title: Microsoft Defender for Identity documentation
4
-
summary: Microsoft Defender for Identity cloud service helps protect your enterprise hybrid environments from multiple types of advanced targeted cyber attacks and insider threats.
3
+
title: Microsoft Defender for Identity documentation
4
+
summary: Microsoft Defender for Identity cloud service helps protect your enterprise hybrid environments from multiple types of advanced targeted cyber attacks and insider threats.
5
5
metadata:
6
6
title: Microsoft Defender for Identity documentation
7
-
description: Microsoft Defender for Identity cloud service helps protect your enterprise hybrid environments from multiple types of advanced targeted cyber attacks and insider threats.
7
+
description: Microsoft Defender for Identity cloud service helps protect your enterprise hybrid environments from multiple types of advanced targeted cyber attacks and insider threats.
Copy file name to clipboardExpand all lines: defender-business/mdb-manage-subscription.md
+3-3Lines changed: 3 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,7 +7,7 @@ ms.author: chrisda
7
7
manager: deniseb
8
8
audience: ITPro
9
9
ms.topic: overview
10
-
ms.date: 01/03/2024
10
+
ms.date: 12/30/2024
11
11
ms.service: defender-business
12
12
ms.localizationpriority: medium
13
13
ms.reviewer: shlomiakirav, efratka
@@ -48,12 +48,12 @@ This article describes how to apply either Defender for Business or Defender for
48
48
49
49
> [!IMPORTANT]
50
50
> Keep the following important points in mind before you save your changes:
51
-
>
52
51
> - Make sure you have enough licenses for the subscription you're using for all users in your organization.
53
52
> - If you select **Only Microsoft Defender for Endpoint Plan 2**, the simplified configuration experience for Defender for Business is replaced with advanced settings that you can configure in Defender for Endpoint. If this change is applied, you can't undo it.
54
-
> - It can take up to three hours for your changes to be applied.
53
+
> - It can take up to six hours for your changes to be applied.
55
54
> - Make sure to review your security policies and settings. To get help with Defender for Endpoint policies and settings, see [Configure Defender for Endpoint capabilities](/defender-endpoint/onboard-configure). To get help with Defender for Business policies and settings, see [Review and edit your security policies and settings in Defender for Business](mdb-configure-security-settings.md).
56
55
56
+
57
57
## Review license usage
58
58
59
59
The license usage report is estimated based on sign-in activities on the device. Defender for Endpoint Plan 2 licenses are assigned to users, and each user can have up to five concurrent, onboarded devices. To learn more about license terms, see [Microsoft Licensing](https://www.microsoft.com/licensing/default).
Copy file name to clipboardExpand all lines: defender-endpoint/configure-advanced-scan-types-microsoft-defender-antivirus.md
+4-1Lines changed: 4 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -9,7 +9,7 @@ ms.custom: nextgen
9
9
ms.reviewer: pahuijbr
10
10
manager: deniseb
11
11
ms.subservice: ngp
12
-
ms.date: 11/01/2024
12
+
ms.date: 12/26/2024
13
13
ms.collection:
14
14
- m365-security
15
15
- tier2
@@ -75,6 +75,9 @@ For details on configuring Microsoft Configuration Manager (current branch), see
75
75
> [!NOTE]
76
76
> If real-time protection is turned on, files are scanned before they are accessed and executed. The scanning scope includes all files, including files on mounted removable media, such as USB drives. If the device performing the scan has real-time protection or on-access protection turned on, the scan also includes network shares.
77
77
78
+
> [!TIP]
79
+
> If you have a Network-Attached Storage (NAS) or Storage Area Network (SAN), you can use Internet Content Adaption Protocol (ICAP) scanning with the Microsoft Defender Antivirus engine. For more information, see **[Tech Community Blog: MetaDefender ICAP with Windows Defender Antivirus: World-class security for hybrid environments](https://techcommunity.microsoft.com/t5/windows-it-pro-blog/metadefender-icap-with-windows-defender-antivirus-world-class/ba-p/800234)**.
80
+
78
81
## Use PowerShell to configure scanning options
79
82
80
83
For more information on how to use PowerShell with Microsoft Defender Antivirus, see the following articles:
0 commit comments