Poznámka:
Přístup k této stránce vyžaduje autorizaci. Můžete se zkusit přihlásit nebo změnit adresáře.
Přístup k této stránce vyžaduje autorizaci. Můžete zkusit změnit adresáře.
Tento článek obsahuje ukázky kódu PowerShellu, které umožňují povolit a nakonfigurovat Microsoft Antimalware pro různé služby Azure, mezi které patří:
- Azure Resource Manager virtuální počítače
- Azure Service Fabric clusters
- Cloudové služby Azure (rozšířená podpora)
- servery s podporou Azure Arc
Použijte tyto ukázky k nasazení a konfiguraci rozšíření Microsoft Antimalware napříč vašimi Azure prostředími.
Nasazení Antimalwaru Microsoftu na virtuální počítače Azure Resource Manager
Poznámka:
Než spustíte tento vzor kódu, odkomentujte proměnné a zadejte odpovídající hodnoty.
Výstraha
Nasazení nebo aktualizace tohoto rozšíření nahrazuje stávající nastavení antivirové ochrany Microsoft Defender včetně vyloučení. Pokud chcete zachovat nastavení, zadejte je v konfiguraci rozšíření. Další informace naleznete v tématu Výchozí a vlastní antimalwarová konfigurace.
# Script to add Microsoft Antimalware extension to Azure Resource Manager VMs
# Specify your subscription ID
$subscriptionId= " SUBSCRIPTION ID HERE "
# Specify location, resource group, and VM for the extension
$location = " LOCATION HERE " # For example, "Southeast Asia" or "Central US"
$resourceGroupName = " RESOURCE GROUP NAME HERE "
$vmName = " VM NAME HERE "
# Enable Antimalware with default policies
$settingString = '{"AntimalwareEnabled": true}'
# Enable Antimalware with custom policies
# $settingString = '{
# "AntimalwareEnabled": true,
# "RealtimeProtectionEnabled": true,
# "ScheduledScanSettings": {
# "isEnabled": true,
# "day": 0,
# "time": 120,
# "scanType": "Quick"
# },
# "Exclusions": {
# "Extensions": ".ext1,.ext2",
# "Paths":"",
# "Processes":"sampl1e1.exe, sample2.exe"
# },
# "SignatureUpdates": {
# "FileSharesSources": "",
# "FallbackOrder": "",
# "ScheduleDay": 0,
# "UpdateInterval": 0,
# },
# "CloudProtection": true
#
# }'
# Sign in to Azure and select the subscription to use
Connect-AzAccount
Set-AzContext -SubscriptionId $subscriptionId
# Retrieve the most recent version number of the extension
$allVersions = (Get-AzVMExtensionImage -Location $location -PublisherName "Microsoft.Azure.Security" -Type "IaaSAntimalware").Version
$versionString = $allVersions[($allVersions.Count)-1].Split(".")[0] + "." + $allVersions[($allVersions.Count)-1].Split(".")[1]
# Set the extension by using prepared values
Set-AzVMExtension -ResourceGroupName $resourceGroupName -Location $location -VMName $vmName -Name "IaaSAntimalware" -Publisher "Microsoft.Azure.Security" -ExtensionType "IaaSAntimalware" -TypeHandlerVersion $versionString -SettingString $settingString
Přidejte Microsoft Antimalware do clusterů Azure Service Fabric
Azure Service Fabric používá Azure virtual machine scale sety k vytváření Service Fabric clusterů. Šablona pro sady škálování virtuálních počítačů, která vytváří clustery Service Fabric, není vybavena rozšířením Antimalware. Povolte ochranu proti malwaru samostatně na škálovacích sadách. Když to povolíte pro škálovací sady, všechny uzly vytvořené v rámci škálovacích sad virtuálních počítačů toto rozšíření automaticky zdědí.
Následující ukázka kódu ukazuje, jak povolit rozšíření IaaS Antimalware pomocí Az.Compute PowerShell cmdletů.
Poznámka:
Než spustíte tento vzor kódu, odkomentujte proměnné a zadejte odpovídající hodnoty.
Výstraha
Nasazení nebo aktualizace tohoto rozšíření nahrazuje stávající nastavení antivirové ochrany Microsoft Defender včetně vyloučení. Pokud chcete zachovat nastavení, zadejte je v konfiguraci rozšíření. Další informace naleznete v tématu Výchozí a vlastní antimalwarová konfigurace.
# Script to add Microsoft Antimalware extension to a virtual machine scale set (VMSS) and Service Fabric cluster
# Sign in to Azure and select the subscription to use
Connect-AzAccount
# Specify your subscription ID
$subscriptionId="SUBSCRIPTION ID HERE"
Set-AzContext -SubscriptionId $subscriptionId
# Specify location, resource group, and VMSS for the extension
$location = "LOCATION HERE" # For example, "West US", "Southeast Asia", or "Central US"
$resourceGroupName = "RESOURCE GROUP NAME HERE"
$vmScaleSetName = "YOUR VM SCALE SET NAME"
# Customize the configuration.json configuration file according to the documentation: https://msdn.microsoft.com/library/dn771716.aspx
$settingString = '{"AntimalwareEnabled": true}'
# Enable Antimalware with custom policies
# $settingString = '{
# "AntimalwareEnabled": true,
# "RealtimeProtectionEnabled": true,
# "ScheduledScanSettings": {
# "isEnabled": true,
# "day": 0,
# "time": 120,
# "scanType": "Quick"
# },
# "Exclusions": {
# "Extensions": ".ext1,.ext2",
# "Paths":"",
# "Processes":"sampl1e1.exe, sample2.exe"
# } ,
# "SignatureUpdates": {
# "FileSharesSources": "",
# "FallbackOrder": "",
# "ScheduleDay": 0,
# "UpdateInterval": 0,
# },
# "CloudProtection": true
# }'
# Retrieve the most recent version number of the extension
$allVersions = (Get-AzVMExtensionImage -Location $location -PublisherName "Microsoft.Azure.Security" -Type "IaaSAntimalware").Version
$versionString = $allVersions[($allVersions.Count)-1].Split(".")[0] + "." + $allVersions[($allVersions.Count)-1].Split(".")[1]
$vmss = Get-AzVmss -ResourceGroupName $resourceGroupName -VMScaleSetName $vmScaleSetName
Add-AzVmssExtension -VirtualMachineScaleSet $vmss -Name "IaaSAntimalware" -Publisher "Microsoft.Azure.Security" -Type "IaaSAntimalware" -TypeHandlerVersion $versionString -Setting $settingString
Update-AzVmss -ResourceGroupName $resourceGroupName -VMScaleSetName $vmScaleSetName -VirtualMachineScaleSet $vmss
Přidejte Microsoft Antimalware do Azure Cloud Services pomocí rozšířené podpory
Následující ukázka kódu ukazuje, jak přidat nebo nakonfigurovat Microsoft Antimalware do Azure Cloud Services pomocí rozšířené podpory přes PowerShell cmdlet.
Poznámka:
Než spustíte tento vzor kódu, odkomentujte proměnné a zadejte odpovídající hodnoty.
Výstraha
Nasazení nebo aktualizace tohoto rozšíření nahrazuje stávající nastavení antivirové ochrany Microsoft Defender včetně vyloučení. Pokud chcete zachovat nastavení, zadejte je v konfiguraci rozšíření. Další informace naleznete v tématu Výchozí a vlastní antimalwarová konfigurace.
# Create an Antimalware extension object, where file is AntimalwareSettings
$xmlconfig = [IO.File]::ReadAllText("C:\path\to\file.xml")
$extension = New-AzCloudServiceExtensionObject -Name "AntimalwareExtension" -Type "PaaSAntimalware" -Publisher "Microsoft.Azure.Security" -Setting $xmlconfig -TypeHandlerVersion "1.5" -AutoUpgradeMinorVersion $true
# Get existing Cloud Service
$cloudService = Get-AzCloudService -ResourceGroup "ContosOrg" -CloudServiceName "ContosoCS"
# Add Antimalware extension to existing Cloud Service extension object
$cloudService.ExtensionProfile.Extension = $cloudService.ExtensionProfile.Extension + $extension
# Update Cloud Service
$cloudService | Update-AzCloudService
Zde je příklad soukromého konfiguračního XML souboru:
<?xml version="1.0" encoding="utf-8"?>
<AntimalwareConfig
xmlns:i="http://www.w3.org/2001/XMLSchema-instance">
<AntimalwareEnabled>true</AntimalwareEnabled>
<RealtimeProtectionEnabled>true</RealtimeProtectionEnabled>
<ScheduledScanSettings isEnabled="true" day="1" time="120" scanType="Full" />
<Exclusions>
<Extensions>
<Extension>.ext1</Extension>
<Extension>.ext2</Extension>
</Extensions>
<Paths>
<Path>c:\excluded-path-1</Path>
<Path>c:\excluded-path-2</Path>
</Paths>
<Processes>
<Process>excludedproc1.exe</Process>
<Process>excludedproc2.exe</Process>
</Processes>
</Exclusions>
</AntimalwareConfig>
Přidání Antimalwaru Microsoftu pro servery s podporou Azure Arc
Následující ukázka kódu ukazuje, jak přidat Microsoft Antimalware pro servery podporující Azure Arc pomocí PowerShell cmdletů.
Poznámka:
Než spustíte tento vzor kódu, odkomentujte proměnné a zadejte odpovídající hodnoty.
# Before you use Azure PowerShell to manage VM extensions on your hybrid server managed by Azure Arc-enabled servers, install the Az.ConnectedMachine module. Run the following command on your Azure Arc-enabled server:
# If Az.ConnectedMachine is installed, ensure the version is at least 0.4.0
Install-Module -Name Az.ConnectedMachine
Import-Module -Name Az.ConnectedMachine
# Specify location, resource group, and machine for the extension
$subscriptionid =" SUBSCRIPTION ID HERE "
$location = " LOCATION HERE " # For example, "Southeast Asia" or "Central US"
$resourceGroupName = " RESOURCE GROUP NAME HERE "
$machineName = "MACHINE NAME HERE "
# Enable Antimalware with default policies
$setting = @{"AntimalwareEnabled"=$true}
# Enable Antimalware with custom policies
$setting2 = @{
"AntimalwareEnabled"=$true;
"RealtimeProtectionEnabled"=$true;
"ScheduledScanSettings"= @{
"isEnabled"=$true;
"day"=0;
"time"=120;
"scanType"="Quick"
};
"Exclusions"= @{
"Extensions"=".ext1, .ext2";
"Paths"="";
"Processes"="sampl1e1.exe, sample2.exe"
};
"SignatureUpdates"= @{
"FileSharesSources"="";
"FallbackOrder"="";
"ScheduleDay"=0;
"UpdateInterval"=0;
};
"CloudProtection"=$true
}
# Sign in to Azure
Connect-AzAccount
# Enable Antimalware with the policies
New-AzConnectedMachineExtension -Name "IaaSAntimalware" -ResourceGroupName $resourceGroupName -MachineName $machineName -Location $location -SubscriptionId $subscriptionid -Publisher "Microsoft.Azure.Security" -Settings $setting -ExtensionType "IaaSAntimalware"