How to prevent Azure Arc ESU (Extended software updates) causing With Secure EPP and EDR to give false positives?

Tomi Aaltonen 20 Reputation points
2023-10-19T05:40:20.6866667+00:00

Hi All.

We set up With secure EPP (End Point protection) and EDR (Endpoint Detection and Response) few weeks ago and a week before that we had onboarded all of our servers to Azure Arc for scheduled patching etc.

Everything was fine until I enabled ESU on our three win 2012 R2 servers. Almost immediatly after enabling ESU on these three servers we stared to get alerts from EDR and EPP about these three servers.

It would be great if you could confirm that GC_Service.exe is doing what it is supposed to do and is there anything else I could to besides excluding GC_service.exe from EPP/EDR

Alerts are triggered because of Base64 decoding and GC_Server.exe using powershell.

Here is the detection tree

User's image

User's image

User's image

User's image

User's image

Azure Arc
Azure Arc
A Microsoft cloud service that enables deployment of Azure services across hybrid and multicloud environments.
527 questions
0 comments No comments
{count} votes

Accepted answer
  1. Monalla-MSFT 13,071 Reputation points Moderator
    2023-10-25T16:58:09.0366667+00:00

    @Tomi Aaltonen - Welcome to Microsoft Q&A and thanks for reaching out to us.

    It's doing what's expected Guest Config and can be excluded from End Point Detection and Response.

    Hope this helps. and please feel free to reach out if you have any further questions.


    If the above response was helpful, please feel free to "Accept as Answer" and click "Yes" so it can be beneficial to the community.

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.