Skip to content

Commit e464849

Browse files
authored
Merge pull request #3013 from MicrosoftDocs/winserver2025
Winserver2025
2 parents 9155af6 + b12c1ae commit e464849

11 files changed

+39
-33
lines changed

defender-endpoint/api/get-live-response-result.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -69,6 +69,8 @@ Before you can initiate a session on a device, make sure you fulfill the followi
6969

7070
- **Windows Server 2022**
7171

72+
- **Windows Server 2025**
73+
7274
## Permissions
7375

7476
One of the following permissions is required to call this API. To learn more,

defender-endpoint/api/initiate-autoir-investigation.md

Lines changed: 6 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -49,12 +49,13 @@ Your organization must have Defender for Endpoint (see [Minimum requirements for
4949

5050
Currently, AIR only supports the following OS versions:
5151

52-
- Windows Server 2019
53-
- Windows Server 2022
54-
- Windows 10, version 1709 (OS Build 16299.1085 with [KB4493441](https://support.microsoft.com/help/4493441/windows-10-update-kb4493441)) or later
55-
- Windows 10, version 1803 (OS Build 17134.704 with [KB4493464](https://support.microsoft.com/help/4493464/windows-10-update-kb4493464)) or later
56-
- Windows 10, version [1803](/windows/release-information/status-windows-10-1809-and-windows-server-2019) or later
5752
- Windows 11
53+
- Windows 10, version [1803](/windows/release-information/status-windows-10-1809-and-windows-server-2019) or later
54+
- Windows 10, version 1803 (OS Build 17134.704 with [KB4493464](https://support.microsoft.com/help/4493464/windows-10-update-kb4493464)) or later
55+
- Windows 10, version 1709 (OS Build 16299.1085 with [KB4493441](https://support.microsoft.com/help/4493441/windows-10-update-kb4493441)) or later
56+
- Windows Server 2025
57+
- Windows Server 2022
58+
- Windows Server 2019
5859

5960
## Permissions
6061

defender-endpoint/api/run-live-response.md

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -85,11 +85,15 @@ Before you can initiate a session on a device, make sure you fulfill the followi
8585
- Version 1809 (with [KB4537818](https://support.microsoft.com/help/4537818/windows-10-update-kb4537818))
8686

8787
- **Windows Server 2022**
88+
89+
- **Windows Server 2025**
90+
8891
- **macOS** [(requires other configuration profiles)](../microsoft-defender-endpoint-mac.md)
8992
- 13 (Ventura)
9093
- 12 (Monterey)
9194
- 11 (Big Sur)
92-
- **Linux**
95+
96+
- **Linux Server**
9397
- [Supported Linux server distributions and kernel versions](../microsoft-defender-endpoint-linux.md)
9498

9599
## Permissions

defender-endpoint/respond-file-alerts.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ ms.collection:
1414
ms.topic: conceptual
1515
ms.subservice: edr
1616
search.appverid: met150
17-
ms.date: 06/26/2024
17+
ms.date: 03/04/2025
1818
---
1919

2020
# Take response actions on a file
@@ -200,7 +200,8 @@ This feature doesn't work if sample submission is turned off. If automatic sampl
200200
> - Antivirus engine version is 1.1.17300.4 or later. See [Monthly platform and engine versions](microsoft-defender-antivirus-updates.md#platform-and-engine-releases)
201201
> - Cloud–based protection is enabled. See [Turn on cloud-delivered protection](enable-cloud-protection-microsoft-defender-antivirus.md)
202202
> - Sample submission is turned on
203-
> - Devices have Windows 10 version 1703 or later, or Windows server 2016 or 2019, or Windows Server 2022, or Windows 11
203+
> - Client devices must be running Windows 11 or Windows 10, version 1703 or later
204+
> - Server devices must be running Windows Server 2025, Windows Server 2022, Windows Server 2019, or Windows Server 2016
204205
205206
### Collect files
206207

defender-endpoint/respond-machine-alerts.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ ms.service: defender-endpoint
55
ms.author: diannegali
66
author: diannegali
77
ms.localizationpriority: medium
8-
ms.date: 12/03/2024
8+
ms.date: 03/04/2025
99
manager: deniseb
1010
audience: ITPro
1111
ms.collection:
@@ -211,7 +211,7 @@ Depending on the severity of the attack and the sensitivity of the device, you m
211211
**Important points to keep in mind**:
212212

213213
- Isolating devices from the network is supported for macOS for client version 101.98.84 and above. You can also use live response to run the action. For more information on live response, see [Investigate entities on devices using live response](live-response.md)
214-
- Full isolation is available for devices running Windows 11, Windows 10, version 1703 or later, Windows Server 2022, Windows Server 2019, Windows Server 2016 and Windows Server 2012 R2.
214+
- Full isolation is available for devices running Windows 11, Windows 10, version 1703 or later, Windows Server 2025, Windows Server 2022, Windows Server 2019, Windows Server 2016 and Windows Server 2012 R2.
215215
- You can use the device isolation capability on all supported Microsoft Defender for Endpoint on Linux listed in [System requirements](microsoft-defender-endpoint-linux.md#system-requirements). Ensure that the following prerequisites are enabled:
216216
- `iptables`
217217
- `ip6tables`

defender-endpoint/sandbox-mdav.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -44,8 +44,8 @@ Microsoft Defender Antivirus with its built-in antivirus capabilities can run wi
4444
Before you begin, you must meet the following requirements:
4545

4646
- Microsoft Defender Antivirus (active mode)
47-
- Windows 11 or Windows 10 version 1703 or newer
48-
- Windows Server 2022 or Windows Server 2019 or Windows Server 2016 or newer
47+
- Windows client devices must be running Windows 11 or Windows 10 version 1703 or newer
48+
- Windows server devices must be running Windows Server 2025, Windows Server 2022, Windows Server 2019, Windows Server 2016
4949

5050
## Why run Microsoft Defender Antivirus in a sandbox?
5151

defender-endpoint/switch-to-mde-phase-2.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -160,7 +160,7 @@ The specific exclusions to configure depend on which version of Windows your end
160160
| OS |Exclusions |
161161
|:--|:--|
162162
|[Windows 11](/windows/whats-new/windows-11-overview) <br/><br/>Windows 10, [version 1803](/lifecycle/announcements/windows-server-1803-end-of-servicing) or later (See [Windows 10 release information](/windows/release-health/release-information))<br/><br/>Windows 10, version 1703 or 1709 with [KB4493441](https://support.microsoft.com/help/4493441) installed |`C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe`<br/><br/>`C:\Program Files\Windows Defender Advanced Threat Protection\SenseCncProxy.exe`<br/><br/>`C:\Program Files\Windows Defender Advanced Threat Protection\SenseSampleUploader.exe`<br/><br/>`C:\Program Files\Windows Defender Advanced Threat Protection\SenseIR.exe`<br/><br/>`C:\Program Files\Windows Defender Advanced Threat Protection\SenseCM.exe`<br/><br/>`C:\Program Files\Windows Defender Advanced Threat Protection\SenseNdr.exe`<br/><br/>`C:\Program Files\Windows Defender Advanced Threat Protection\Classification\SenseCE.exe`<br/><br/>`C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\DataCollection`<br/><br/>`C:\Program Files\Windows Defender Advanced Threat Protection\SenseTVM.exe`|
163-
|[Windows Server 2022](/windows/release-health/status-windows-server-2022)<br/><br/>[Windows Server 2019](/windows/release-health/status-windows-10-1809-and-windows-server-2019) <br/><br/>[Windows Server 2016](/windows/release-health/status-windows-10-1607-and-windows-server-2016)<br/><br/>[Windows Server 2012 R2](/windows/release-health/status-windows-8.1-and-windows-server-2012-r2)<br/><br/>[Windows Server, version 1803](/windows-server/get-started/whats-new-in-windows-server-1803) | On Windows Server 2012 R2 and Windows Server 2016 running the [modern, unified solution](/defender-endpoint/configure-server-endpoints#functionality-in-the-modern-unified-solution), the following exclusions are required after updating the Sense EDR component using [KB5005292](https://support.microsoft.com/topic/microsoft-defender-for-endpoint-update-for-edr-sensor-f8f69773-f17f-420f-91f4-a8e5167284ac):<br/> <br/> `C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Platform\*\MsSense.exe` <br/><br/>`C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Platform\*\SenseCnCProxy.exe`<br/><br/>`C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Platform\*\SenseIR.exe`<br/><br/>`C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Platform\*\SenseCE.exe`<br/><br/>`C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Platform\*\SenseSampleUploader.exe`<br/><br/>`C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Platform\*\SenseCM.exe` <br/><br/>`C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\DataCollection`<br/><br/>`C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Platform\*\SenseTVM.exe` |
163+
|Windows Server 2025 <br/>[Windows Server 2022](/windows/release-health/status-windows-server-2022)<br/><br/>[Windows Server 2019](/windows/release-health/status-windows-10-1809-and-windows-server-2019) <br/><br/>[Windows Server 2016](/windows/release-health/status-windows-10-1607-and-windows-server-2016)<br/><br/>[Windows Server 2012 R2](/windows/release-health/status-windows-8.1-and-windows-server-2012-r2)<br/><br/>[Windows Server, version 1803](/windows-server/get-started/whats-new-in-windows-server-1803) | On Windows Server 2012 R2 and Windows Server 2016 running the [modern, unified solution](/defender-endpoint/configure-server-endpoints#functionality-in-the-modern-unified-solution), the following exclusions are required after updating the Sense EDR component using [KB5005292](https://support.microsoft.com/topic/microsoft-defender-for-endpoint-update-for-edr-sensor-f8f69773-f17f-420f-91f4-a8e5167284ac):<br/> <br/> `C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Platform\*\MsSense.exe` <br/><br/>`C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Platform\*\SenseCnCProxy.exe`<br/><br/>`C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Platform\*\SenseIR.exe`<br/><br/>`C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Platform\*\SenseCE.exe`<br/><br/>`C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Platform\*\SenseSampleUploader.exe`<br/><br/>`C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Platform\*\SenseCM.exe` <br/><br/>`C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\DataCollection`<br/><br/>`C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Platform\*\SenseTVM.exe` |
164164
|[Windows 8.1](/windows/release-health/status-windows-8.1-and-windows-server-2012-r2)<br/><br/>[Windows 7](/windows/release-health/status-windows-7-and-windows-server-2008-r2-sp1)<br/><br/>[Windows Server 2008 R2 SP1](/windows/release-health/status-windows-7-and-windows-server-2008-r2-sp1) |`C:\Program Files\Microsoft Monitoring Agent\Agent\Health Service State\Monitoring Host Temporary Files 6\45\MsSenseS.exe`<br/><br/>**NOTE**: Monitoring Host Temporary Files 6\45 can be different numbered subfolders.<br/><br/>`C:\Program Files\Microsoft Monitoring Agent\Agent\AgentControlPanel.exe`<br/><br/>`C:\Program Files\Microsoft Monitoring Agent\Agent\HealthService.exe`<br/><br/>`C:\Program Files\Microsoft Monitoring Agent\Agent\HSLockdown.exe`<br/><br/>`C:\Program Files\Microsoft Monitoring Agent\Agent\MOMPerfSnapshotHelper.exe`<br/><br/>`C:\Program Files\Microsoft Monitoring Agent\Agent\MonitoringHost.exe`<br/><br/>`C:\Program Files\Microsoft Monitoring Agent\Agent\TestCloudConnection.exe` |
165165

166166
> [!IMPORTANT]

defender-endpoint/switch-to-mde-phase-3.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ ms.custom:
1717
- migrationguides
1818
- admindeeplinkDEFENDER
1919
ms.topic: how-to
20-
ms.date: 08/15/2024
20+
ms.date: 03/04/2025
2121
ms.reviewer: jesquive, chventou, jonix, chriggs, owtho, yongrhee
2222
search.appverid: met150
2323
---
@@ -82,7 +82,7 @@ To verify that your onboarded devices are properly connected to Defender for End
8282

8383
|Operating system|Guidance|
8484
|---|---|
85-
|Windows 10 or later<br/><br/>Windows Server 2022<br/><br/>Windows Server 2019<br/><br/>Windows Server, version 1803, or later<br/><br/>Windows Server 2016<br/><br/>Windows Server 2012 R2|See [Run a detection test](run-detection-test.md).|
85+
|Windows 10 or later<br/><br/>Window Server 2025<br/><br/>Windows Server 2022<br/><br/>Windows Server 2019<br/><br/>Windows Server, version 1803, or later<br/><br/>Windows Server 2016<br/><br/>Windows Server 2012 R2|See [Run a detection test](run-detection-test.md).|
8686
|macOS (see [System requirements](microsoft-defender-endpoint-mac.md))| Download and use the DIY app at [https://aka.ms/mdatpmacosdiy](https://aka.ms/mdatpmacosdiy). Also see [Run the connectivity test](troubleshoot-cloud-connect-mdemac.md#run-the-connectivity-test).|
8787
|Linux (see [System requirements](microsoft-defender-endpoint-linux.md#system-requirements))|1. Run the following command, and look for a result of **1**: `mdatp health --field real_time_protection_enabled`.<br/><br/>2. Open a Terminal window, and run the following command: `curl -o ~/Downloads/eicar.com.txt https://www.eicar.org/download/eicar.com.txt`.<br/><br/>3. Run the following command to list any detected threats: `mdatp threat list`.<br/><br/>For more information, see [Defender for Endpoint on Linux](microsoft-defender-endpoint-linux.md).|
8888

@@ -101,7 +101,7 @@ Now that your endpoints have been onboarded to Defender for Endpoint, your next
101101
102102
### Set Microsoft Defender Antivirus on Windows Server to passive mode manually
103103

104-
To set Microsoft Defender Antivirus to passive mode on Windows Server, version 1803 or newer, or Windows Server 2019, or Windows Server 2022, follow these steps:
104+
To set Microsoft Defender Antivirus to passive mode on Windows Server 2025, Windows Server 2022, Windows Server 2019, or Windows Server, version 1803 or newer, follow these steps:
105105

106106
1. Open Registry Editor, and then navigate to `Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection`.
107107

defender-endpoint/troubleshoot-onboarding.md

Lines changed: 10 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -23,13 +23,13 @@ ms.date: 01/15/2025
2323

2424
**Applies to:**
2525

26-
- [Microsoft Defender for Endpoint Plan 1](microsoft-defender-endpoint.md)
27-
28-
- [Microsoft Defender for Endpoint Plan 2](microsoft-defender-endpoint.md)
26+
- [Microsoft Defender for Endpoint Plan 1 and 2](microsoft-defender-endpoint.md)
27+
- [Microsoft Defender XDR](/defender-xdr)
2928

29+
**Windows Server**
3030
- Windows Server 2012 R2
3131
- Windows Server 2016
32-
- [Microsoft Defender XDR](/defender-xdr)
32+
- Windows Server 2019 and later
3333

3434
You might need to troubleshoot the Microsoft Defender for Endpoint onboarding process if you encounter issues.
3535
This page provides detailed steps to troubleshoot onboarding issues that might occur when deploying with one of the deployment tools and common errors that might occur on the devices.
@@ -328,7 +328,7 @@ You might also need to check the following:
328328

329329
There may be instances when onboarding is deployed on a newly built device but not completed.
330330

331-
The steps below provide guidance for the following scenario:
331+
The steps in this article provide guidance for the following scenario:
332332

333333
- Onboarding package is deployed to newly built devices
334334
- Sensor doesn't start because the Out-of-box experience (OOBE) or first user logon hasn't been completed
@@ -337,10 +337,12 @@ The steps below provide guidance for the following scenario:
337337

338338
> [!NOTE]
339339
> User Logon after OOBE is no longer required for SENSE service to start on the following or more recent Windows versions:
340-
> Windows 10, version 1809 or Windows Server 2019, or Windows Server 2022 with [April 22 2021 update rollup](https://support.microsoft.com/kb/5001384).
341-
> Windows 10, version 1909 with [April 2021 update rollup](https://support.microsoft.com/kb/5001396).
342-
> Windows 10, version 2004/20H2 with [April 28 2021 update rollup](https://support.microsoft.com/kb/5001391).
340+
> - Windows 10, version 1809 or newer
341+
> - Windows Server 2025
342+
> - Windows Server 2022
343+
> - Windows Server 2019
343344
345+
## Troubleshoot onboarding with Microsoft Endpoint Configuration Manager
344346

345347
> [!NOTE]
346348
> The following steps are only relevant when using Microsoft Endpoint Configuration Manager. For more information about onboarding using Microsoft Endpoint Configuration Manager, see [Microsoft Defender for Endpoint](/mem/configmgr/protect/deploy-use/windows-defender-advanced-threat-protection).

defender-endpoint/validate-antimalware.md

Lines changed: 2 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -22,21 +22,16 @@ ms.date: 03/04/2025
2222

2323
**Applies to:**
2424

25-
- [Microsoft Defender for Endpoint Plan 2](microsoft-defender-endpoint.md)
26-
25+
- [Microsoft Defender for Endpoint Plan 1 or Plan 2](microsoft-defender-endpoint.md)
2726
- [Microsoft Defender for Business](https://www.microsoft.com/security/business/endpoint-security/microsoft-defender-business)
28-
29-
- [Microsoft Defender for Endpoint Plan 1](microsoft-defender-endpoint.md)
30-
3127
- [Microsoft Defender Antivirus](microsoft-defender-antivirus-windows.md)
32-
3328
- [Microsoft Defender for Individuals](https://www.microsoft.com/microsoft-365/microsoft-defender-for-individuals)
3429

3530
Scenario requirements and setup
3631

3732
- Windows 11, Windows 10, Windows 8.1, Windows 7 SP1
3833

39-
- Windows Server 2022, Windows Server 2019, Windows Server 2016, Windows Server 2012, and Windows Server 2008 R2
34+
- Windows Server 2025, Windows Server 2022, Windows Server 2019, Windows Server 2016, Windows Server 2012, and Windows Server 2008 R2
4035

4136
- Linux
4237

0 commit comments

Comments
 (0)