A cloud-based identity and access management service for securing user authentication and resource access
Facing same issue even though the devices have defender installed in them .Is this known Bug ?
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
We have defender as the antivirus software which is already installed on the virtual machines, but why does Azure Advisor - Security states that we need to "Install endpoint protection solution on virtual machines " ?
A cloud-based identity and access management service for securing user authentication and resource access
Facing same issue even though the devices have defender installed in them .Is this known Bug ?
Hi,
This problem persists. I have a subscription where this ("Install endpoint protection solution on virtual machines") is currently highlighted as an issue in the Microsoft Defender for Cloud Recommendations.
When you try to investigate, it tells you that it has been replaced by the new policy "Endpoint Protection not installed on Azure VMs" but this one policy still remains.
It is also not possible to disable it from the security policy-initiative parameters.
Has anyone been able to resolve this issue?
Advisor says "Install endpoint protection solution on virtual machines" however there is a following Note: There’s an updated version of this recommendation. See ‘Endpoint protection should be installed on your machines’. When I click on updated version of the recommendation it doesn't show a single VM.
So, if this genuine recommendation why the new version doesn't show a single machine. If this is not false positive, why this is not fixed?
Apologies for the delay in responding to your query. Do you see this alert for all the machines where defender is installed ?
Following are the settings checked when Azure security advisor reports this alert.
Defender for Cloud recommends Endpoint protection should be installed on your machines when Get-MpComputerStatus runs and the result is AMServiceEnabled: False
Defender for Cloud recommends Endpoint protection health issues should be resolved on your machines when Get-MpComputerStatus runs and any of the following occurs:
Any of the following properties are false:
AMServiceEnabled
AntispywareEnabled
RealTimeProtectionEnabled
BehaviorMonitorEnabled
IoavProtectionEnabled
OnAccessProtectionEnabled
If one or both of the following properties are 7 or more:
AntispywareSignatureAge
AntivirusSignatureAge
Deployment Guide for Microsoft Defender for Endpoint - https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/deployment-strategy?view=o365-worldwide
If you have any other questions, please let me know.
Thank you for your time and patience throughout this issue.
----------
Please remember to "Accept Answer" if my answer helped, so that others in the community facing similar issues can easily find the solution.