إشعار
يتطلب الوصول إلى هذه الصفحة تخويلاً. يمكنك محاولة تسجيل الدخول أو تغيير الدلائل.
يتطلب الوصول إلى هذه الصفحة تخويلاً. يمكنك محاولة تغيير الدلائل.
توفر هذه المقالة عينات من شيفرة PowerShell لتمكين وتكوين برامج مكافحة خبيثة من مايكروسوفت لخدمات Azure المختلفة بما في ذلك:
- الأجهزة الظاهرية لـ Azure Resource Manager
- Azure Service Fabric clusters
- خدمات Azure السحابية (extended support)
- الخوادم الممكنة بواسطة Azure Arc
استخدم هذه العينات لنشر وتكوين إضافة Microsoft Anti Ware عبر بيئات Azure الخاصة بك.
Deploy Microsoft Antimalware on Azure Resource Manager VMs
إشعار
قبل تشغيل عينة الكود هذه، قم بإلغاء التعليق على المتغيرات وقدم القيم المناسبة.
تحذير
يتم استبدال أو نشر هذه الإضافة بإعدادات Microsoft Defender Antivirus الحالية، بما في ذلك الاستثناءات. للحفاظ على إعداداتك، حددها في إعدادات الامتداد. لمزيد من المعلومات، راجع إعدادات مضادة للبرمجيات الخبيثة الافتراضية والمخصصة.
# Script to add Microsoft Antimalware extension to Azure Resource Manager VMs
# Specify your subscription ID
$subscriptionId= " SUBSCRIPTION ID HERE "
# Specify location, resource group, and VM for the extension
$location = " LOCATION HERE " # For example, "Southeast Asia" or "Central US"
$resourceGroupName = " RESOURCE GROUP NAME HERE "
$vmName = " VM NAME HERE "
# Enable Antimalware with default policies
$settingString = '{"AntimalwareEnabled": true}'
# Enable Antimalware with custom policies
# $settingString = '{
# "AntimalwareEnabled": true,
# "RealtimeProtectionEnabled": true,
# "ScheduledScanSettings": {
# "isEnabled": true,
# "day": 0,
# "time": 120,
# "scanType": "Quick"
# },
# "Exclusions": {
# "Extensions": ".ext1,.ext2",
# "Paths":"",
# "Processes":"sampl1e1.exe, sample2.exe"
# },
# "SignatureUpdates": {
# "FileSharesSources": "",
# "FallbackOrder": "",
# "ScheduleDay": 0,
# "UpdateInterval": 0,
# },
# "CloudProtection": true
#
# }'
# Sign in to Azure and select the subscription to use
Connect-AzAccount
Set-AzContext -SubscriptionId $subscriptionId
# Retrieve the most recent version number of the extension
$allVersions = (Get-AzVMExtensionImage -Location $location -PublisherName "Microsoft.Azure.Security" -Type "IaaSAntimalware").Version
$versionString = $allVersions[($allVersions.Count)-1].Split(".")[0] + "." + $allVersions[($allVersions.Count)-1].Split(".")[1]
# Set the extension by using prepared values
Set-AzVMExtension -ResourceGroupName $resourceGroupName -Location $location -VMName $vmName -Name "IaaSAntimalware" -Publisher "Microsoft.Azure.Security" -ExtensionType "IaaSAntimalware" -TypeHandlerVersion $versionString -SettingString $settingString
Add Microsoft Antimalware to Azure Service Fabric clusters
يستخدم Azure Service Fabric مجموعات مقياس الآلة الافتراضية Azure لإنشاء مجموعات Service Fabric. قالب مجموعات مقياس الآلة الافتراضية الذي ينشئ عناقيد Service Fabric غير مفعل مع إضافة Anti Ware الخبيثة. قم بتفعيل برنامج مكافحة البرمجيات الخبيثة بشكل منفصل على مجموعات المقاييس. عندما تقوم بتفعيله على مجموعات المقياس، ترث جميع العقد التي تم إنشاؤها تحت مجموعات مقياس الآلة الافتراضية وتحصل على الامتداد تلقائيا.
يوضح نموذج الكود التالي كيفية تفعيل امتداد IaaS لمكافحة البرمجيات الخبيثة باستخدام ملفات Az.Compute PowerShell.
إشعار
قبل تشغيل عينة الكود هذه، قم بإلغاء التعليق على المتغيرات وقدم القيم المناسبة.
تحذير
يتم استبدال أو نشر هذه الإضافة بإعدادات Microsoft Defender Antivirus الحالية، بما في ذلك الاستثناءات. للحفاظ على إعداداتك، حددها في إعدادات الامتداد. لمزيد من المعلومات، راجع إعدادات مضادة للبرمجيات الخبيثة الافتراضية والمخصصة.
# Script to add Microsoft Antimalware extension to a virtual machine scale set (VMSS) and Service Fabric cluster
# Sign in to Azure and select the subscription to use
Connect-AzAccount
# Specify your subscription ID
$subscriptionId="SUBSCRIPTION ID HERE"
Set-AzContext -SubscriptionId $subscriptionId
# Specify location, resource group, and VMSS for the extension
$location = "LOCATION HERE" # For example, "West US", "Southeast Asia", or "Central US"
$resourceGroupName = "RESOURCE GROUP NAME HERE"
$vmScaleSetName = "YOUR VM SCALE SET NAME"
# Customize the configuration.json configuration file according to the documentation: https://msdn.microsoft.com/library/dn771716.aspx
$settingString = '{"AntimalwareEnabled": true}'
# Enable Antimalware with custom policies
# $settingString = '{
# "AntimalwareEnabled": true,
# "RealtimeProtectionEnabled": true,
# "ScheduledScanSettings": {
# "isEnabled": true,
# "day": 0,
# "time": 120,
# "scanType": "Quick"
# },
# "Exclusions": {
# "Extensions": ".ext1,.ext2",
# "Paths":"",
# "Processes":"sampl1e1.exe, sample2.exe"
# } ,
# "SignatureUpdates": {
# "FileSharesSources": "",
# "FallbackOrder": "",
# "ScheduleDay": 0,
# "UpdateInterval": 0,
# },
# "CloudProtection": true
# }'
# Retrieve the most recent version number of the extension
$allVersions = (Get-AzVMExtensionImage -Location $location -PublisherName "Microsoft.Azure.Security" -Type "IaaSAntimalware").Version
$versionString = $allVersions[($allVersions.Count)-1].Split(".")[0] + "." + $allVersions[($allVersions.Count)-1].Split(".")[1]
$vmss = Get-AzVmss -ResourceGroupName $resourceGroupName -VMScaleSetName $vmScaleSetName
Add-AzVmssExtension -VirtualMachineScaleSet $vmss -Name "IaaSAntimalware" -Publisher "Microsoft.Azure.Security" -Type "IaaSAntimalware" -TypeHandlerVersion $versionString -Setting $settingString
Update-AzVmss -ResourceGroupName $resourceGroupName -VMScaleSetName $vmScaleSetName -VirtualMachineScaleSet $vmss
Add Microsoft Antimalware إلى خدمات Azure السحابية باستخدام الدعم الموسع
يوضح نموذج الكود التالي كيفية إضافة أو تكوين برنامج Microsoft Antimalware إلى خدمات Azure السحابية باستخدام دعم موسع عبر PowerShell cmdlets.
إشعار
قبل تشغيل عينة الكود هذه، قم بإلغاء التعليق على المتغيرات وقدم القيم المناسبة.
تحذير
يتم استبدال أو نشر هذه الإضافة بإعدادات Microsoft Defender Antivirus الحالية، بما في ذلك الاستثناءات. للحفاظ على إعداداتك، حددها في إعدادات الامتداد. لمزيد من المعلومات، راجع إعدادات مضادة للبرمجيات الخبيثة الافتراضية والمخصصة.
# Create an Antimalware extension object, where file is AntimalwareSettings
$xmlconfig = [IO.File]::ReadAllText("C:\path\to\file.xml")
$extension = New-AzCloudServiceExtensionObject -Name "AntimalwareExtension" -Type "PaaSAntimalware" -Publisher "Microsoft.Azure.Security" -Setting $xmlconfig -TypeHandlerVersion "1.5" -AutoUpgradeMinorVersion $true
# Get existing Cloud Service
$cloudService = Get-AzCloudService -ResourceGroup "ContosOrg" -CloudServiceName "ContosoCS"
# Add Antimalware extension to existing Cloud Service extension object
$cloudService.ExtensionProfile.Extension = $cloudService.ExtensionProfile.Extension + $extension
# Update Cloud Service
$cloudService | Update-AzCloudService
إليك مثال على ملف XML الخاص بالتكوين الخاص:
<?xml version="1.0" encoding="utf-8"?>
<AntimalwareConfig
xmlns:i="http://www.w3.org/2001/XMLSchema-instance">
<AntimalwareEnabled>true</AntimalwareEnabled>
<RealtimeProtectionEnabled>true</RealtimeProtectionEnabled>
<ScheduledScanSettings isEnabled="true" day="1" time="120" scanType="Full" />
<Exclusions>
<Extensions>
<Extension>.ext1</Extension>
<Extension>.ext2</Extension>
</Extensions>
<Paths>
<Path>c:\excluded-path-1</Path>
<Path>c:\excluded-path-2</Path>
</Paths>
<Processes>
<Process>excludedproc1.exe</Process>
<Process>excludedproc2.exe</Process>
</Processes>
</Exclusions>
</AntimalwareConfig>
Add Microsoft Antimalware for Azure Arc-enabled servers
يوضح نموذج الكود التالي كيفية إضافة برنامج Microsoft Antimalware لخوادم Azure Arc الداعمة من خلال PowerShell cmdlets.
إشعار
قبل تشغيل عينة الكود هذه، قم بإلغاء التعليق على المتغيرات وقدم القيم المناسبة.
# Before you use Azure PowerShell to manage VM extensions on your hybrid server managed by Azure Arc-enabled servers, install the Az.ConnectedMachine module. Run the following command on your Azure Arc-enabled server:
# If Az.ConnectedMachine is installed, ensure the version is at least 0.4.0
Install-Module -Name Az.ConnectedMachine
Import-Module -Name Az.ConnectedMachine
# Specify location, resource group, and machine for the extension
$subscriptionid =" SUBSCRIPTION ID HERE "
$location = " LOCATION HERE " # For example, "Southeast Asia" or "Central US"
$resourceGroupName = " RESOURCE GROUP NAME HERE "
$machineName = "MACHINE NAME HERE "
# Enable Antimalware with default policies
$setting = @{"AntimalwareEnabled"=$true}
# Enable Antimalware with custom policies
$setting2 = @{
"AntimalwareEnabled"=$true;
"RealtimeProtectionEnabled"=$true;
"ScheduledScanSettings"= @{
"isEnabled"=$true;
"day"=0;
"time"=120;
"scanType"="Quick"
};
"Exclusions"= @{
"Extensions"=".ext1, .ext2";
"Paths"="";
"Processes"="sampl1e1.exe, sample2.exe"
};
"SignatureUpdates"= @{
"FileSharesSources"="";
"FallbackOrder"="";
"ScheduleDay"=0;
"UpdateInterval"=0;
};
"CloudProtection"=$true
}
# Sign in to Azure
Connect-AzAccount
# Enable Antimalware with the policies
New-AzConnectedMachineExtension -Name "IaaSAntimalware" -ResourceGroupName $resourceGroupName -MachineName $machineName -Location $location -SubscriptionId $subscriptionid -Publisher "Microsoft.Azure.Security" -Settings $setting -ExtensionType "IaaSAntimalware"