Clarifying MDE and Windows Defender Interactions in Azure

$@chin 200 Reputation points
2025-05-28T14:04:20.8966667+00:00

Hi,

  1. If defender for server is enabled and which installed an packages on Azure servers, will it reactivate Windows Defender, even if Windows Defender has been explicitly uninstalled ?

2a. What is the purpose of the PowerShell script located at:

C:\Packages\Plugins\Microsoft.Azure.AzureDefenderForServers.MDE.Windows\1.0.11.4\HandlerUtilities.psm1

2b. Is this script part of the MDE integration with Azure Defender for Servers ?
2c. Does this script run automatically on a daily basis, as can see recurring entries in the event logs ?

  1. If Windows Defender has been removed from a server, will Microsoft Defender for Servers still provide threat protection on that server?
Microsoft Security | Microsoft Defender | Microsoft Defender for Office 365
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Catherine Kyalo 1,935 Reputation points Microsoft Employee
    2025-06-03T08:18:14.66+00:00

    Hi $@chin

    Microsoft recommends using the MDAV and MDE together in the Better together: Microsoft Defender Antivirus and Microsoft Defender for Endpoint. It also provides reasons why this is the preferred route.

    To your concerns:

    1. I did not find any explicit documentation stating that MDE will automatically reinstall MDAV when/if it was explicitly uninstalled
    2. HandlerUtilities.psm1 is part of the Microsoft Defender for Servers extension for Windows, specifically used during the deployment and configuration of Microsoft Defender for Endpoint (MDE) on Azure or Arc-enabled servers
    3. Without Windows Defender Antivirus, you will experience limited threat protection this is because the Microsoft Defender for Endpoint agent depends on Microsoft Defender Antivirus for some capabilities such as file scanning. Microsoft Defender for Servers plan 2 integrated MDE.

    For optimal protection, configure the Security intelligence updates and Platform updates, whether Microsoft Defender Antivirus is the active antimalware solution or not.

    Refer to: -Antivirus solution compatibility with Microsoft Defender for Endpoint

    If you find the answer above helpful, please "Accept the answer" to help anyone in the community who might have a similar question to quickly find the solution.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.