MS Defender Logging and Reporting

BR0KK 641 Reputation points
2021-05-14T09:28:43.087+00:00

I'm in search of a tool that can manage MS Defender on Clients and Servers. I have not found one yet

My current RMM (Solarwinds) can only check if the AV Signatures are up to date, but not if something was found on a client nor what action was taken.

There mus be a tool out there to do that

Thank you

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,765 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,732 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Reza-Ameri 16,836 Reputation points
    2021-05-14T14:40:16.547+00:00

    There are number of ways to manage Microsoft Defender and depending on your requirement you may try Configuration Manager or Microsoft Intune. In case you want to do on-premise management you may go for Configuration Manager and for Cloud Manager go for Microsoft Intune. To see how to manage Microsoft Defender, take a look at:
    https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configuration-management-reference-microsoft-defender-antivirus?view=o365-worldwide

    0 comments No comments

  2. Miles 1,251 Reputation points
    2021-05-17T02:46:18.807+00:00

    Hi

    To meet your requirements , we could try to use live response to collect support logs in Microsoft defender .
    We could download this tool from https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/troubleshoot-collect-support-log?view=o365-worldwide.
    Please refer to the article and run the tool via live response.

    Also , we can deploy , manage , and report on Microsoft defender antivirus in a number of ways.
    For example , Microsoft intune , Microsoft endpoint manager, group policy and active directory , powershell , windows management instrumentation and Microsoft azure. The specific information please scan the website https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/deploy-manage-report-microsoft-defender-antivirus?view=o365-worldwide .

    Best regards
    Miles

    0 comments No comments