Events
May 19, 6 PM - May 23, 12 AM
Calling all developers, creators, and AI innovators to join us in Seattle @Microsoft Build May 19-22.
Register todayThis browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Microsoft Defender for Endpoint and Microsoft Defender Vulnerability Management integrate natively with Defender for Cloud to provide:
Defender for Cloud integrates security capabilities provided by Defender for Endpoint and Defender Vulnerability Management.
Vulnerability management: Provided by Defender Vulnerability Management.
Attack surface reduction: Use of attack surface reduction rules to reduce security exposure.
Next-generation protection providing antimalware and antivirus protection.
Endpoint detection and response (EDR): EDR detects, investigates, and responds to advanced threats, including advanced threat hunting, and automatic investigation and remediation capabilities.
Threat analytics. Get threat intelligence data provided by Microsoft threat hunters and security teams, augmented by intelligence provided by partners. Security alerts are generated when Defender for Endpoint identifies attacker tools, techniques, and procedures.
Defender for Endpoint automatically creates a tenant when you use Defender for Cloud to monitor your machines.
Defender for Endpoint stores collected data in the tenant's geo-location as identified during provisioning.
You can move Defender for Endpoint between subscriptions in the same tenant or between different tenants.
Move to a different subscription in the same tenant: To move your Defender for Endpoint extension to a different subscription in the same tenant, delete either the MDE.Linux
or MDE.Windows
extension from the virtual machine. Defender for Cloud will automatically redeploy it.
Move subscriptions between tenants: If you move your Azure subscription between Azure tenants, some manual preparatory steps are required before Defender for Cloud deploys Defender for Endpoint. For full details, contact Microsoft support.
Defender for Servers provides visibility to the Defender for Endpoint agents installed on your VMs.
You must have either:
Defender for Servers provides visibility into two main types of health issues:
Installation Issues: Errors during the agent's installation.
Heartbeat Issues: Problems where the agent is installed but not reporting correctly.
Sometimes, Defender for Endpoint doesn't apply to certain servers. This status is also shown as described in the last query.
Defender for Servers shows specific error messages for each issue type. These messages explain the problem. When available, you'll also find instructions to fix the issue.
Health status updates every four hours. This ensures the issue reflects the state from the last four hours.
To see Defender for Endpoint health issues, use the security explorer as follows:
To find all the unhealthy virtual machines (VMs) with the issues mentioned, run the following query:
Another way to access this data:
To find all the healthy VMs where Defender for Endpoint works correctly, run the following query:
To get the list of VMs where Defender for Endpoint isn't applicable, run the following query:
Learn more about EDR recommendations in Defender for Servers.
Events
May 19, 6 PM - May 23, 12 AM
Calling all developers, creators, and AI innovators to join us in Seattle @Microsoft Build May 19-22.
Register today