You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Microsoft Defender for Endpoint is a comprehensive security solution designed to protect your devices from evolving threats. One of its key features is *passive mode*, which enables Microsoft Defender Antivirus to coexist with non-Microsoft antivirus solutions while still providing valuable endpoint detection and response capabilities.
21
+
#Defender Antivirus in passive mode
22
22
23
-
Some of the key benefits of passive mode are:
23
+
Microsoft Defender for Endpoint is a comprehensive security solution designed to protect your devices from evolving threats. One of its key features enables Microsoft Defender Antivirus to coexist with non-Microsoft antimalware solutions while still providing valuable endpoint detection and response capabilities.
24
24
25
-
***Endpoint Detection and Response (EDR)** - Microsoft Defender for Endpoint monitors activity and provides alerts about malicious artifacts post-breach. In block mode, EDR can detect and remediate threats even if the primary antivirus solution fails to prevent an attack.
25
+
Some of the key benefits of Defender Antivirus in passive mode are:
26
26
27
-
***Threat Scanning** - Files are scanned, and detection information is shared with the Defender for Endpoint service.
27
+
***EDR Block mode** - Post-breach protection by detecting and remediating threats missed by the active antimalware solution
28
+
29
+
***Data Loss Prevention (DLP)** - Endpoint DLP functionalities operate normally, ensuring sensitive data is safeguarded.
28
30
29
31
***Security intelligence updates** - Microsoft Defender Antivirus continues to receive updates to stay aware of the latest threats.
30
32
@@ -37,16 +39,17 @@ Some of the key benefits of passive mode are:
37
39
38
40
* Operating system
39
41
* Windows 10 or newer
40
-
* Windows Server 2012 R2
41
-
* Windows Server 2016, or newer (requires onboarding using the modern unified solution)
42
+
* Windows Server 2012 R2 or newer
42
43
43
-
* The endpoint must be onboarded to Microsoft Defender for Endpoint
44
+
* The device must be onboarded to Microsoft Defender for Endpoint
44
45
45
-
* Microsoft Defender Antivirus has to be installed on the endpoint
46
+
* Microsoft Defender Antivirus has to be installed and enabled
46
47
47
48
## Configure passive mode
48
49
49
-
Follow the instructions in this section to configure passive mode for Microsoft Defender for Endpoint.
50
+
On Windows 10 or newer, Defender Antivirus will automatically enter passive mode when a non-Microsoft antimalware solution is installed and registered.
51
+
52
+
For Windows Server operating systems, follow the instructions in this section to configure passive mode for Microsoft Defender for Endpoint.
50
53
51
54
### Set the registry key
52
55
@@ -94,7 +97,7 @@ The `AMRunningMode` value indicates the current Defender Antivirus state:
94
97
95
98
### Windows security app
96
99
97
-
Follow these steps to verify the Microsoft Defender Antivirus is in passive mode.
100
+
Follow these steps to verify that Microsoft Defender Antivirus is in passive mode (Windows 10 and later only).
98
101
99
102
1. Open the Windows Security app.
100
103
@@ -106,4 +109,4 @@ Follow these steps to verify the Microsoft Defender Antivirus is in passive mode
106
109
107
110
## Additional resources
108
111
109
-
[Microsoft Defender Antivirus compatibility with other security products](microsoft-defender-antivirus-compatibility.md)
112
+
[Microsoft Defender Antivirus compatibility with other security products](microsoft-defender-antivirus-compatibility.md)
0 commit comments