Edit

Remediate EDR solution recommendations

Microsoft Defender for Cloud helps improve security posture for supported machines with endpoint detection and response (EDR). Defender for Cloud:

Based on scan results, Defender for Cloud provides recommendations to help you install and run EDR solutions correctly. This article describes how to fix those recommendations.

Note

  • Defender for Cloud uses agentless scanning to assess EDR settings.
  • Agentless scanning replaces the Log Analytics agent (also known as the Microsoft Monitoring Agent (MMA)), which was previously used to collect machine data.
  • Scanning using the MMA was deprecated in November 2024.
  • To exempt resources from these EDR assessments, ensure that the Azure CSPM initiative is assigned. This initiative is enabled by default when Defender cloud security posture management (Defender CSPM) is turned on.

Prerequisites

Before you investigate or remediate EDR solution recommendations, make sure you meet these requirements.

Requirement Details
Plan Defender for Cloud must be available in the Azure subscription and one of these plans must be enabled:

- Defender for Servers Plan 2
- Defender cloud security posture management (Defender CSPM)
Agentless scanning Agentless scanning for machines must be turned on. Agentless scanning is enabled by default in both Defender for Servers Plan 2 and Defender CSPM. If you need to turn it on manually, see Enable agentless scanning for VMs.

Investigate EDR solution recommendations

To review EDR recommendations for your machines:

  1. In Defender for Cloud, open Recommendations.

  2. Search for and select one of these recommendations:

    • EDR solution should be installed on Virtual Machines
    • EDR solution should be installed on EC2s
    • EDR solution should be installed on Virtual Machines (GCP)
  3. In the recommendation details, select the Healthy resources tab.

  4. Find the EDR solution for each machine in the Discovered EDRs column.

    Screenshot of the Healthy resources tab, which shows where you can see which endpoint detection and response solution is enabled on your machine.

Remediate EDR solution recommendations

To remediate EDR solution recommendations:

  1. Select the relevant recommendation.

    Screenshot of the recommendations page showing the identified endpoint solution recommendations.

  2. Select one of the listed recommended actions to see the remediation steps for that action.

Enable Defender for Endpoint integration

The Enable Microsoft Defender for Endpoint integration action appears when Defender for Endpoint can be installed on a machine. This action is available only when no supported non-Microsoft EDR solution is detected on the machine.

Enable Defender for Endpoint on the machine as follows:

  1. Select the affected machine. You can also select multiple machines with the Enable Microsoft Defender for Endpoint integration recommended action.

  2. Select Fix.

    Screenshot that shows where the fix button is located.

  3. In Enable EDR solution, select Enable. This installs the Defender for Endpoint sensor on all Windows and Linux servers in the subscription.

    After the process completes, it can take up to 24 hours for your machine to appear in the Healthy resources tab.

    Screenshot that shows the pop-up window from which to enable the Defender for Endpoint integration on.

Turn on the required Defender plan

The Upgrade Defender plan action is available when:

Fix the recommendation as follows:

  1. Select the affected machine. You can also select multiple machines with the Upgrade Defender plan recommended action.

  2. Select Fix.

    Screenshot that shows where the fix button is located on the screen.

  3. In Enable EDR solution, select a plan in the dropdown menu. Each plan has a cost. See Defender for Cloud pricing details.

  4. Select Enable.

    Screenshot that shows the pop-up window that allows you to select which Defender for Servers plan to enable on your subscription.

After the process completes, it can take up to 24 hours for your machine to appear on the Healthy resources tab.

Troubleshoot Defender for Endpoint onboarding

The Troubleshoot onboarding action appears when Defender for Endpoint is found on a machine but didn't onboard correctly.

  1. Select the affected VM.

  2. Select Remediation steps.

    Screenshot that shows where the remediation steps are located in the recommendation.

  3. Fix onboarding issues for your platform:

After you finish, it can take up to 24 hours for your machine to show on the Healthy resources tab.