You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-endpoint/onboard-windows-server-2012r2-2016.md
+11-28Lines changed: 11 additions & 28 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -53,14 +53,13 @@ This article describes how to onboard Windows Server 2012 R2 and Windows Server
53
53
- Download and install the latest platform version using Windows Update. Alternatively, download the update package manually from the [Microsoft Update Catalog](https://www.catalog.update.microsoft.com/Search.aspx?q=KB4052623) or from [MMPC](https://go.microsoft.com/fwlink/?linkid=870379&arch=x64).
54
54
- On Windows Server 2016, Microsoft Defender Antivirus must be installed as a feature and fully updated before installation. See [information for Windows Server 2012 R2 and Windows Server 2016](switch-to-mde-phase-2.md#are-you-using-windows-server-2012-r2-or-windows-server-2016).
55
55
56
-
57
56
## Onboarding Windows Server 2016 and Windows Server 2012 R2
58
57
59
58
The following diagram shows the general steps required to successfully onboard servers.
60
59
61
60
:::image type="content" source="media/server-onboarding-tools-methods.png" alt-text="An illustration of onboarding flow for Windows Servers and Windows 10 devices.":::
62
61
63
-
1. Download the installation package and onboarding package.
62
+
1. Download the installation package and onboarding package by following these steps:
64
63
65
64
1. In the [Microsoft Defender portal](https://security.microsoft.com), go to **Settings** > **Endpoints** > **Onboarding**.
66
65
2.**Windows Server 2016 and Windows Server 2012 R2**.
@@ -69,7 +68,7 @@ The following diagram shows the general steps required to successfully onboard s
69
68
70
69
2. Follow the guidance for your preferred tool to install Defender for Endpoint:
71
70
72
-
-**Modern, unified solution**: [Migrating servers from Microsoft Monitoring Agent to the modern, unified solution](application-deployment-via-mecm.md)
71
+
-**Migrate from MMA to the modern unified solution**: [Migrating servers from Microsoft Monitoring Agent to the modern unified solution](server-migration.md)
73
72
-**Local script**: [Onboard Windows devices using a local script](configure-endpoints-script.md)
74
73
-**Group Policy**: [Onboard Windows devices using Group Policy](configure-endpoints-gp.md)
75
74
-**Microsoft Configuration Manager**: [Onboard Windows devices using Configuration Manager](configure-endpoints-sccm.md)
@@ -96,16 +95,6 @@ Depending on the server that you're onboarding, the unified solution installs De
96
95
|Windows Server 2016|Built-in||
97
96
|Windows Server 2019 and later|Built-in|Built-in|
98
97
99
-
> [!IMPORTANT]
100
-
> Before proceeding with onboarding, see the section [Known issues and limitations in the new, unified solution package for Windows Server 2012 R2 and Windows Server 2016](#known-issues-and-limitations-in-the-modern-unified-solution).
101
-
102
-
## Important information about running Defender for Endpoint with non-Microsoft security solutions
103
-
104
-
If you intend to use a non-Microsoft anti-malware solution, you need to run Microsoft Defender Antivirus in passive mode. You must remember to set to passive mode during the installation and onboarding process.
105
-
106
-
> [!NOTE]
107
-
> If you're installing Defender for Endpoint on servers with McAfee Endpoint Security (ENS) or VirusScan Enterprise (VSE), the version of the McAfee platform might need to be updated to ensure Microsoft Defender Antivirus isn't removed or disabled. For more information including the specific version numbers required, see [McAfee Knowledge Center article](https://kcm.trellix.com/corporate/index?page=content&id=KB88214).
108
-
109
98
### Known issues and limitations in the modern unified solution
110
99
111
100
The following points apply to Windows Server 2016 and Windows Server 2012 R2:
@@ -122,16 +111,18 @@ The following points apply to Windows Server 2016 and Windows Server 2012 R2:
122
111
123
112
- To automatically, deploy and onboard the new solution using Microsoft Endpoint Configuration Manager (MECM) you need to be on [version 2207 or later](/mem/configmgr/core/plan-design/changes/whats-new-in-version-2207#improved-microsoft-defender-for-endpoint-mde-onboarding-for-windows-server-2012-r2-and-windows-server-2016). You can still configure and deploy using version 2107 with the hotfix rollup, but this requires extra deployment steps. See [Microsoft Endpoint Configuration Manager migration scenarios](server-migration.md#microsoft-endpoint-configuration-manager-migration-scenarios) for more information.
124
113
125
-
## Update packages for Windows Server 2016 or Windows Server 2012 R2
114
+
## Important information about running Defender for Endpoint with non-Microsoft security solutions
126
115
127
-
To receive regular product improvements and fixes for the Defender for Endpoint component, ensure Windows Update [KB5005292](https://go.microsoft.com/fwlink/?linkid=2168277) gets applied or approved. In addition, to keep protection components updated, see [Manage Microsoft Defender Antivirus updates and apply baselines](microsoft-defender-antivirus-updates.md#platform-and-engine-releases).
116
+
If you intend to use a non-Microsoft anti-malware solution, you need to run Microsoft Defender Antivirus in passive mode. You must remember to set to passive mode during the installation and onboarding process.
128
117
129
-
If you're using Windows Server Update Services (WSUS) and/or [Microsoft Endpoint Configuration Manager](/mem/configmgr/core/understand/introduction), this new "Microsoft Defender for Endpoint update for EDR Sensor" is available under the category "Microsoft Defender for Endpoint."
118
+
> [!NOTE]
119
+
> If you're installing Defender for Endpoint on servers with McAfee Endpoint Security (ENS) or VirusScan Enterprise (VSE), the version of the McAfee platform might need to be updated to ensure Microsoft Defender Antivirus isn't removed or disabled. For more information including the specific version numbers required, see [McAfee Knowledge Center article](https://kcm.trellix.com/corporate/index?page=content&id=KB88214).
130
120
121
+
## Update packages for Windows Server 2016 or Windows Server 2012 R2
131
122
132
-
## Verify the onboarding and installation
123
+
To receive regular product improvements and fixes for the Defender for Endpoint component, ensure Windows Update [KB5005292](https://go.microsoft.com/fwlink/?linkid=2168277) gets applied or approved. In addition, to keep protection components updated, see [Manage Microsoft Defender Antivirus updates and apply baselines](microsoft-defender-antivirus-updates.md#platform-and-engine-releases).
133
124
134
-
Verify that Microsoft Defender Antivirus andDefender for Endpoint are running.
125
+
If you're using Windows Server Update Services (WSUS) and/or [Microsoft Endpoint Configuration Manager](/mem/configmgr/core/understand/introduction), this new "Microsoft Defender for Endpoint update for EDR Sensor" is available under the category "Microsoft Defender for Endpoint."
135
126
136
127
## Run a detection test to verify onboarding
137
128
@@ -149,9 +140,7 @@ After onboarding the device, you can choose to run a detection test to verify th
149
140
sc.exe query Windefend
150
141
```
151
142
152
-
If the result is 'The specified service doesn't exist as an installed service', then you need to install Microsoft Defender Antivirus.
153
-
154
-
For information on how to use Group Policy to configure and manage Microsoft Defender Antivirus on your Windows servers, see [Use Group Policy settings to configure and manage Microsoft Defender Antivirus](use-group-policy-microsoft-defender-antivirus.md).
143
+
If the result is, "The specified service doesn't exist as an installed service," then you need to install Microsoft Defender Antivirus.
155
144
156
145
2. Run the following command to verify that Defender for Endpoint is running:
157
146
@@ -161,10 +150,6 @@ After onboarding the device, you can choose to run a detection test to verify th
161
150
162
151
The result should show it's running. If you encounter issues with onboarding, see [Troubleshoot onboarding](troubleshoot-onboarding.md).
163
152
164
-
## Run a detection test
165
-
166
-
Follow the steps in [Run a detection test on a newly onboarded device](run-detection-test.md) to verify that the server is reporting to Defender for the Endpoint service.
167
-
168
153
## Next steps
169
154
170
155
After successfully onboarding devices to the service, you'll need to configure the individual components of Defender for Endpoint. Follow [Configure capabilities](onboard-configure.md#configure-capabilities) to be guided on enabling the various components.
@@ -178,9 +163,7 @@ You can offboard Windows Server 2012 R2, Windows Server 2016, Windows Server (SA
178
163
-[Offboard devices using Mobile Device Management tools](configure-endpoints-mdm.md#offboard-devices-using-mobile-device-management-tools)
179
164
-[Offboard devices using a local script](configure-endpoints-script.md#offboard-devices-using-a-local-script)
180
165
181
-
After offboarding, you can proceed to uninstall the unified solution package on Windows Server 2016 and Windows Server 2012 R2.
182
-
183
-
For other Windows server versions, you have two options to offboard Windows servers from the service:
166
+
After offboarding, you can proceed to uninstall the unified solution package on Windows Server 2016 and Windows Server 2012 R2. For other Windows server versions, you have two options to offboard Windows servers from the service:
184
167
185
168
- Uninstall the MMA agent
186
169
- Remove the Defender for Endpoint workspace configuration
0 commit comments