Edit

Assess Defender for Endpoint EDR settings

Microsoft Defender for Cloud integrates natively with Microsoft Defender for Endpoint as an endpoint detection and response (EDR) solution. This article explains how Defender for Cloud uses agentless scanning to assess EDR settings, detect misconfigurations, and surface actionable recommendations to help you remediate them.

Understand EDR capabilities in Defender for Endpoint

EDR capabilities in Defender for Endpoint detect, investigate, and respond to advanced threats. These capabilities include advanced threat hunting (see Advanced threat hunting overview) and automatic investigation and remediation (see Automatic investigation and remediation).

Assess Defender for Endpoint settings

When machines run Defender for Endpoint as their EDR solution, Defender for Servers scans them agentlessly. These checks confirm that Defender for Endpoint is configured correctly. Checks include:

  • Full and quick scans are older than seven days
  • Signatures are out of date
  • Antivirus is off or partially configured

If misconfigurations are found, Defender for Cloud presents recommendations such as:

  • EDR configuration issues should be resolved on virtual machines
  • EDR configuration issues should be resolved on EC2s
  • Anti-Virus component in your EDR is off or partially configured
  • Anti-Virus component of your EDR uses outdated signatures

Once you locate these recommendations (Review security recommendations), you can remediate them (Implement security recommendations).

Next step