Endpoint protection on 2019 Core Confusion

Alex Creech 21 Reputation points
2020-07-10T15:09:03.537+00:00

I'm using 2019 Core for my azure servers and I'm confused on a few things regarding endpoint protection.

The first is the IaasAntimalware vm extension. Is IaasAntimalware Windows Defender or something else? If it's windows defender, isn't that installed and enabled by default? What is the extension doing?

Second, is Windows Defender ATP different than Windows Defender? Should I be using that instead of IaasAntimalware?

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,163 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,199 questions
{count} votes

Accepted answer
  1. Leon Laude 85,666 Reputation points
    2020-07-10T15:31:31.147+00:00

    Hi,

    The "IaasAntimalware" is an Azure VM antimalware extension, it is a free real-time protection that helps identify and remove viruses, spyware, and other malicious software. It generates alerts when known malicious or unwanted software tries to install itself or run on your Azure systems.

    The solution is built on the same antimalware platform as Microsoft Security Essentials [MSE], Microsoft Forefront Endpoint Protection, Microsoft System Center Endpoint Protection, Windows Intune, and Windows Defender. Microsoft Antimalware for Azure is a single-agent solution for applications and tenant environments, designed to run in the background without human intervention.

    Note: Windows Defender is the built-in Antimalware enabled in Windows Server 2016/2019. The Windows Defender Interface is also enabled by default on some Windows Server 2016/2019 SKU's see here for more information. The Azure VM Antimalware extension can still be added to a Windows Server 2016/2019 Azure VM with Windows Defender, but in this scenario the extension will apply any optional configuration policies to be used by Windows Defender, the extension will not deploy any additional antimalware services. You can read more about this update here.

    Reference:
    https://learn.microsoft.com/en-us/azure/security/fundamentals/antimalware

    Windows Defendet ATP vs Windows Defender:
    Microsoft Defender Antivirus is the next-generation protection component of Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP).

    Although you can use a non-Microsoft antivirus solution with Microsoft Defender ATP, there are advantages to using Microsoft Defender Antivirus together with Microsoft Defender ATP. Not only is Microsoft Defender Antivirus an excellent next-generation antivirus solution, but combined with other Microsoft Defender ATP capabilities, such as endpoint detection and response and automated investigation and remediation, you get better protection that's coordinated across products and services.

    Reference:
    https://learn.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-antivirus/why-use-microsoft-defender-antivirus

    Best regards,
    Leon

    0 comments No comments

0 additional answers

Sort by: Most helpful