Microsoft Antimalware Extension

Bombbe 1,611 Reputation points
2020-07-30T07:15:13.577+00:00

Hi, since Windows Defender is not supported on Server 2012 R2 I'm looking for endpoint protection solutions to vms in Azure. I came a cross Microsoft Antimalware Extension for Windows which could solve my issues but have few questions about this service still.

Refering to this:
https://learn.microsoft.com/en-us/azure/virtual-machines/extensions/iaas-antimalware-windows#internet-connectivity
"The Microsoft Antimalware for Windows requires that the target virtual machine is connected to the internet to receive regular engine and signature updates."

  1. Does anybody know if is possible to get updates to Signature, Antimalware Engine and Antimalware Platform from WSUS? Most of our vms don't have internet access and they are getting their normal Windows updates from WSUS so it would be easy to configure servers to get those updates from WSUS.
  2. Where or how I can see reports if Microsoft Antimalware has detected antimalware or if it has done something to it (like put in quarantine)? Logs are available from "System logs" but are Extension giving more than just logs?
  3. When installing that extension, it installs System Center Endpoint Protection to my server, but when I try to open the software it just prompts " Your System admistator has restricted access to this app" 14521-scep.png

So Do I need to have SCCM licences to use that software which means that Microsoft Antimalware is not free even tho Microsoft is saying that. Or does Microsoft Antimalware protect vms in background but I don't have "access" to it and when I need to update e.g exclusions I need to install extension newly, because Portal is only place where I have access to it?

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,160 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,201 questions
0 comments No comments
{count} vote

Accepted answer
  1. Bombbe 1,611 Reputation points
    2020-08-04T09:40:33.433+00:00

    Got this working by my self

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Sudhakar Penki 96 Reputation points
    2020-11-06T11:31:31.84+00:00

    Please use the below command for the below error: Same worked for me.
    "Your System admistator has restricted access to this app".

    ==================================================================== Execute the below command in elevated admin command prompt.

    C:\Packages\Plugins\Microsoft.Azure.Security.IaaSAntimalware\Version(Eg:1.5.5.49)>SCEPINSTALL /forceclean

    0 comments No comments