Skip to content

Commit f39c687

Browse files
committed
Update onboard-windows-server-2012r2-2016.md
1 parent 91639e5 commit f39c687

File tree

1 file changed

+11
-28
lines changed

1 file changed

+11
-28
lines changed

defender-endpoint/onboard-windows-server-2012r2-2016.md

Lines changed: 11 additions & 28 deletions
Original file line numberDiff line numberDiff line change
@@ -53,14 +53,13 @@ This article describes how to onboard Windows Server 2012 R2 and Windows Server
5353
- Download and install the latest platform version using Windows Update. Alternatively, download the update package manually from the [Microsoft Update Catalog](https://www.catalog.update.microsoft.com/Search.aspx?q=KB4052623) or from [MMPC](https://go.microsoft.com/fwlink/?linkid=870379&arch=x64).
5454
- On Windows Server 2016, Microsoft Defender Antivirus must be installed as a feature and fully updated before installation. See [information for Windows Server 2012 R2 and Windows Server 2016](switch-to-mde-phase-2.md#are-you-using-windows-server-2012-r2-or-windows-server-2016).
5555

56-
5756
## Onboarding Windows Server 2016 and Windows Server 2012 R2
5857

5958
The following diagram shows the general steps required to successfully onboard servers.
6059

6160
:::image type="content" source="media/server-onboarding-tools-methods.png" alt-text="An illustration of onboarding flow for Windows Servers and Windows 10 devices.":::
6261

63-
1. Download the installation package and onboarding package.
62+
1. Download the installation package and onboarding package by following these steps:
6463

6564
1. In the [Microsoft Defender portal](https://security.microsoft.com), go to **Settings** > **Endpoints** > **Onboarding**.
6665
2. **Windows Server 2016 and Windows Server 2012 R2**.
@@ -69,7 +68,7 @@ The following diagram shows the general steps required to successfully onboard s
6968

7069
2. Follow the guidance for your preferred tool to install Defender for Endpoint:
7170

72-
- **Modern, unified solution**: [Migrating servers from Microsoft Monitoring Agent to the modern, unified solution](application-deployment-via-mecm.md)
71+
- **Migrate from MMA to the modern unified solution**: [Migrating servers from Microsoft Monitoring Agent to the modern unified solution](server-migration.md)
7372
- **Local script**: [Onboard Windows devices using a local script](configure-endpoints-script.md)
7473
- **Group Policy**: [Onboard Windows devices using Group Policy](configure-endpoints-gp.md)
7574
- **Microsoft Configuration Manager**: [Onboard Windows devices using Configuration Manager](configure-endpoints-sccm.md)
@@ -96,16 +95,6 @@ Depending on the server that you're onboarding, the unified solution installs De
9695
|Windows Server 2016|Built-in|![Yes](media/svg/check-yes.svg)|
9796
|Windows Server 2019 and later|Built-in|Built-in|
9897

99-
> [!IMPORTANT]
100-
> Before proceeding with onboarding, see the section [Known issues and limitations in the new, unified solution package for Windows Server 2012 R2 and Windows Server 2016](#known-issues-and-limitations-in-the-modern-unified-solution).
101-
102-
## Important information about running Defender for Endpoint with non-Microsoft security solutions
103-
104-
If you intend to use a non-Microsoft anti-malware solution, you need to run Microsoft Defender Antivirus in passive mode. You must remember to set to passive mode during the installation and onboarding process.
105-
106-
> [!NOTE]
107-
> If you're installing Defender for Endpoint on servers with McAfee Endpoint Security (ENS) or VirusScan Enterprise (VSE), the version of the McAfee platform might need to be updated to ensure Microsoft Defender Antivirus isn't removed or disabled. For more information including the specific version numbers required, see [McAfee Knowledge Center article](https://kcm.trellix.com/corporate/index?page=content&id=KB88214).
108-
10998
### Known issues and limitations in the modern unified solution
11099

111100
The following points apply to Windows Server 2016 and Windows Server 2012 R2:
@@ -122,16 +111,18 @@ The following points apply to Windows Server 2016 and Windows Server 2012 R2:
122111

123112
- To automatically, deploy and onboard the new solution using Microsoft Endpoint Configuration Manager (MECM) you need to be on [version 2207 or later](/mem/configmgr/core/plan-design/changes/whats-new-in-version-2207#improved-microsoft-defender-for-endpoint-mde-onboarding-for-windows-server-2012-r2-and-windows-server-2016). You can still configure and deploy using version 2107 with the hotfix rollup, but this requires extra deployment steps. See [Microsoft Endpoint Configuration Manager migration scenarios](server-migration.md#microsoft-endpoint-configuration-manager-migration-scenarios) for more information.
124113

125-
## Update packages for Windows Server 2016 or Windows Server 2012 R2
114+
## Important information about running Defender for Endpoint with non-Microsoft security solutions
126115

127-
To receive regular product improvements and fixes for the Defender for Endpoint component, ensure Windows Update [KB5005292](https://go.microsoft.com/fwlink/?linkid=2168277) gets applied or approved. In addition, to keep protection components updated, see [Manage Microsoft Defender Antivirus updates and apply baselines](microsoft-defender-antivirus-updates.md#platform-and-engine-releases).
116+
If you intend to use a non-Microsoft anti-malware solution, you need to run Microsoft Defender Antivirus in passive mode. You must remember to set to passive mode during the installation and onboarding process.
128117

129-
If you're using Windows Server Update Services (WSUS) and/or [Microsoft Endpoint Configuration Manager](/mem/configmgr/core/understand/introduction), this new "Microsoft Defender for Endpoint update for EDR Sensor" is available under the category "Microsoft Defender for Endpoint."
118+
> [!NOTE]
119+
> If you're installing Defender for Endpoint on servers with McAfee Endpoint Security (ENS) or VirusScan Enterprise (VSE), the version of the McAfee platform might need to be updated to ensure Microsoft Defender Antivirus isn't removed or disabled. For more information including the specific version numbers required, see [McAfee Knowledge Center article](https://kcm.trellix.com/corporate/index?page=content&id=KB88214).
130120
121+
## Update packages for Windows Server 2016 or Windows Server 2012 R2
131122

132-
## Verify the onboarding and installation
123+
To receive regular product improvements and fixes for the Defender for Endpoint component, ensure Windows Update [KB5005292](https://go.microsoft.com/fwlink/?linkid=2168277) gets applied or approved. In addition, to keep protection components updated, see [Manage Microsoft Defender Antivirus updates and apply baselines](microsoft-defender-antivirus-updates.md#platform-and-engine-releases).
133124

134-
Verify that Microsoft Defender Antivirus and Defender for Endpoint are running.
125+
If you're using Windows Server Update Services (WSUS) and/or [Microsoft Endpoint Configuration Manager](/mem/configmgr/core/understand/introduction), this new "Microsoft Defender for Endpoint update for EDR Sensor" is available under the category "Microsoft Defender for Endpoint."
135126

136127
## Run a detection test to verify onboarding
137128

@@ -149,9 +140,7 @@ After onboarding the device, you can choose to run a detection test to verify th
149140
sc.exe query Windefend
150141
```
151142

152-
If the result is 'The specified service doesn't exist as an installed service', then you need to install Microsoft Defender Antivirus.
153-
154-
For information on how to use Group Policy to configure and manage Microsoft Defender Antivirus on your Windows servers, see [Use Group Policy settings to configure and manage Microsoft Defender Antivirus](use-group-policy-microsoft-defender-antivirus.md).
143+
If the result is, "The specified service doesn't exist as an installed service," then you need to install Microsoft Defender Antivirus.
155144

156145
2. Run the following command to verify that Defender for Endpoint is running:
157146

@@ -161,10 +150,6 @@ After onboarding the device, you can choose to run a detection test to verify th
161150

162151
The result should show it's running. If you encounter issues with onboarding, see [Troubleshoot onboarding](troubleshoot-onboarding.md).
163152

164-
## Run a detection test
165-
166-
Follow the steps in [Run a detection test on a newly onboarded device](run-detection-test.md) to verify that the server is reporting to Defender for the Endpoint service.
167-
168153
## Next steps
169154

170155
After successfully onboarding devices to the service, you'll need to configure the individual components of Defender for Endpoint. Follow [Configure capabilities](onboard-configure.md#configure-capabilities) to be guided on enabling the various components.
@@ -178,9 +163,7 @@ You can offboard Windows Server 2012 R2, Windows Server 2016, Windows Server (SA
178163
- [Offboard devices using Mobile Device Management tools](configure-endpoints-mdm.md#offboard-devices-using-mobile-device-management-tools)
179164
- [Offboard devices using a local script](configure-endpoints-script.md#offboard-devices-using-a-local-script)
180165

181-
After offboarding, you can proceed to uninstall the unified solution package on Windows Server 2016 and Windows Server 2012 R2.
182-
183-
For other Windows server versions, you have two options to offboard Windows servers from the service:
166+
After offboarding, you can proceed to uninstall the unified solution package on Windows Server 2016 and Windows Server 2012 R2. For other Windows server versions, you have two options to offboard Windows servers from the service:
184167

185168
- Uninstall the MMA agent
186169
- Remove the Defender for Endpoint workspace configuration

0 commit comments

Comments
 (0)