{"items":[{"children":[{"children":[{"href":"microsoft-defender-endpoint","toc_title":"Defender for Endpoint"},{"href":"microsoft-defender-endpoint-windows","toc_title":"Defender for Endpoint on Windows"},{"href":"microsoft-defender-endpoint-linux","toc_title":"Defender for Endpoint on Linux"},{"href":"microsoft-defender-endpoint-mac","toc_title":"Defender for Endpoint on macOS"},{"href":"gov","toc_title":"Defender for Endpoint for US Government customers"},{"children":[{"href":"defender-endpoint-plan-1","toc_title":"Overview of Defender for Endpoint Plan 1"},{"href":"mde-p1-setup-configuration","toc_title":"Setup and configuration"},{"href":"mde-plan1-getting-started","toc_title":"Get started"}],"toc_title":"Defender for Endpoint Plan 1"},{"children":[{"displayName":"What\u0027s new in Microsoft Defender for Endpoint","href":"whats-new-in-microsoft-defender-endpoint","toc_title":"New features"},{"href":"microsoft-defender-endpoint-releases","toc_title":"Release notes"}],"toc_title":"What\u0027s new"},{"href":"defender-endpoint-trial-user-guide","toc_title":"Trial user guide - Defender for Endpoint"},{"href":"data-storage-privacy","toc_title":"Data storage and privacy"}],"toc_title":"Overview"},{"children":[{"children":[{"href":"evaluate-microsoft-defender-antivirus","toc_title":"Evaluate Microsoft Defender Antivirus"},{"href":"guidance-for-pen-testing-and-bas","toc_title":"Guidance for pen testing and BAS scenarios"},{"href":"guidance-pen-testing-bas-linux","toc_title":"Guidance for pen testing and BAS scenarios on Linux"},{"href":"microsoft-defender-antivirus-using-powershell","toc_title":"Evaluate Microsoft Defender Antivirus using PowerShell"},{"href":"evaluate-mda-using-mde-security-settings-management","toc_title":"Evaluate Microsoft Defender Antivirus using Microsoft Defender Endpoint Security Settings Management"},{"href":"evaluate-mdav-using-gp","toc_title":"Evaluate Microsoft Defender Antivirus using Group Policy"}],"toc_title":"Evaluate Microsoft Defender"},{"children":[{"href":"defender-endpoint-demonstration-ai-agent-runtime-protection","toc_title":"AI agent runtime protection demonstration"},{"href":"mde-demonstration-amsi","toc_title":"AMSI demonstrations"},{"href":"validate-antimalware","toc_title":"Antimalware validation demonstration"},{"href":"defender-endpoint-demonstration-attack-surface-reduction-rules","toc_title":"ASR rules demonstration"},{"href":"defender-endpoint-demonstration-app-reputation","toc_title":"App reputation demonstration"},{"href":"demonstration-behavior-monitoring","toc_title":"Behavior monitoring demonstration"},{"href":"defender-endpoint-demonstration-cloud-delivered-protection","toc_title":"Cloud-delivered protection"},{"href":"defender-endpoint-demonstration-controlled-folder-access-block-app","toc_title":"Controlled folder access (block an untrusted app) demonstration"},{"href":"defender-endpoint-demonstration-controlled-folder-access-ransomware","toc_title":"Controlled folder access (block ransomware) demonstration"},{"href":"edr-detection","toc_title":"EDR detections demonstration"},{"href":"defender-endpoint-demonstration-exploit-protection","toc_title":"Exploit protection demonstration"},{"href":"defender-endpoint-demonstration-network-protection","toc_title":"Network protection demonstration"},{"href":"defender-endpoint-demonstration-potentially-unwanted-applications","toc_title":"Potentially unwanted applications demonstration"},{"href":"defender-endpoint-demonstration-smartscreen-url-reputation","toc_title":"URL reputation demonstrations"}],"href":"defender-endpoint-demonstrations","toc_title":"Demonstration scenarios"}],"toc_title":"Microsoft Defender for Endpoint demonstrations and evaluation"},{"children":[{"children":[{"href":"mde-planning-guide","toc_title":"Overview"},{"href":"production-deployment","toc_title":"Step 1 - Prepare for deployment"},{"href":"prepare-deployment","toc_title":"Step 2 - Assign roles and permissions"},{"href":"deployment-strategy","toc_title":"Step 3 - Identify your architecture and select a deployment method"},{"href":"onboarding","toc_title":"Step 4 - Onboard devices to Defender for Endpoint"},{"href":"onboard-configure","toc_title":"Step 5 - Configure Defender for Endpoint capabilities"}],"toc_title":"Plan your deployment"},{"children":[{"children":[{"href":"configure-environment","toc_title":"Step 1 - Configure your network environment"},{"href":"configure-proxy-internet","toc_title":"Step 2 - Configure device proxy and Internet settings"},{"href":"verify-connectivity","toc_title":"Step 3 - Verify client connectivity to service URLs"}],"toc_title":"Configure service connections"},{"children":[{"href":"configure-device-connectivity","toc_title":"Onboard devices using streamlined method"},{"href":"migrate-devices-streamlined","toc_title":"Migrate devices to streamlined method"}],"toc_title":"Configure streamlined connectivity"},{"children":[{"href":"streamlined-device-connectivity-urls-commercial","toc_title":"Streamlined device connectivity URLs (commercial)"},{"href":"streamlined-device-connectivity-urls-gov","toc_title":"Streamlined device connectivity URLs (US government)"},{"children":[{"href":"standard-device-connectivity-urls-commercial","toc_title":"Standard device connectivity URLs (commercial)"},{"href":"standard-device-connectivity-urls-gov","toc_title":"Standard device connectivity URLs (US government)"}],"toc_title":"Standard device connectivity URLs"}],"toc_title":"Enable access to service URLs"},{"children":[{"children":[{"href":"defender-deployment-tool-windows","toc_title":"Onboard Windows devices using the Defender deployment tool"},{"href":"onboard-client","toc_title":"Onboard client devices running Windows or macOS"},{"href":"mde-plugin-wsl","toc_title":"Defender for Endpoint plug-in for WSL"},{"href":"configure-endpoints-mdm","toc_title":"Onboard Windows devices to Defender for Endpoint using Intune"},{"href":"configure-endpoints-sccm","toc_title":"Onboard Windows devices to Defender for Endpoint using Microsoft Configuration Manager"},{"href":"configure-endpoints-gp","toc_title":"Onboard Windows devices to Defender for Endpoint using Group Policy"},{"href":"configure-endpoints-script","toc_title":"Onboard Windows devices to Defender for Endpoint using a local script"},{"href":"configure-endpoints-vdi","toc_title":"Onboard non-persistent virtual desktop infrastructure (VDI) devices"},{"href":"onboard-windows-multi-session-device","toc_title":"Onboard Windows 10 multi-session devices in Azure Virtual Desktop"},{"href":"onboard-downlevel","toc_title":"Onboard previous versions of Windows"}],"toc_title":"Onboard client devices"},{"children":[{"href":"onboard-server","toc_title":"Onboard servers through Defender for Endpoint\u0027s experience"},{"href":"configure-endpoints-sccm","toc_title":"Onboard Windows devices using Configuration Manager"},{"href":"configure-endpoints-gp","toc_title":"Onboard Windows devices using Group Policy"},{"href":"configure-endpoints-script","toc_title":"Onboard Windows devices using a local script"},{"href":"configure-endpoints-vdi","toc_title":"Onboard non-persistent virtual desktop infrastructure (VDI) devices"},{"href":"/azure/defender-for-cloud/onboard-machines-with-defender-for-endpoint?toc=/defender-endpoint/toc.json\u0026bc=/defender-endpoint/breadcrumb/toc.json","toc_title":"Direct onboarding with Defender for Cloud"},{"href":"mde-sap-windows-server","toc_title":"Defender for Endpoint on Windows Server with SAP"},{"href":"mde-linux-deployment-on-sap","toc_title":"Deployment guidance for Defender for Endpoint on Linux for SAP"},{"href":"mde-sap-custom-detection-rules","toc_title":"Use custom detection rules to protect SAPXPG"}],"toc_title":"Onboard server devices"}],"toc_title":"Defender for Endpoint on Windows"},{"children":[{"children":[{"href":"microsoft-defender-endpoint-mac-prerequisites","toc_title":"Microsoft Defender for Endpoint Prerequisites on macOS"},{"href":"mac-install-with-intune","toc_title":"Deployment with Microsoft Intune"},{"children":[{"href":"mac-install-with-jamf","toc_title":"Deploy Microsoft Defender for Endpoint on macOS using Jamf Pro"},{"href":"mac-jamfpro-device-groups","toc_title":"Set up device groups"},{"href":"mac-jamfpro-policies","toc_title":"Set up policies"},{"href":"mac-jamfpro-enroll-devices","toc_title":"Enroll devices"}],"toc_title":"Jamf Pro-based deployment"},{"href":"mac-install-with-other-mdm","toc_title":"Another mobile device management (MDM) solution"},{"href":"mac-install-manually","toc_title":"Manual deployment"}],"toc_title":"Deploy Defender for Endpoint on macOS"},{"children":[{"href":"mac-exclusions","toc_title":"Configure and validate exclusions on Mac"},{"href":"mac-preferences","toc_title":"Set preferences on Mac"},{"href":"mac-pua","toc_title":"Detect and block potentially unwanted applications on Mac"},{"href":"tamper-protection-macos-configure","toc_title":"Protect macOS security settings using tamper protection"},{"href":"mac-support-offline-security-intelligence-update","toc_title":"Configure offline security intelligence updates on Mac"},{"children":[{"href":"mac-device-control-overview","toc_title":"Device control overview on Mac"},{"href":"mac-device-control-configure","toc_title":"Configure Device Control on Mac"}],"toc_title":"Device control"},{"href":"mac-schedule-scan","toc_title":"Schedule scans on Mac"}],"toc_title":"Configure Defender for Endpoint on macOS"},{"href":"mac-updates","toc_title":"Update Defender for Endpoint on macOS"},{"href":"mac-privacy","toc_title":"Privacy for Microsoft Defender for Endpoint on macOS"},{"href":"mac-resources","toc_title":"Resources for Microsoft Defender for Endpoint on macOS"},{"children":[{"href":"mac-health-status","toc_title":"Troubleshoot agent health issues"},{"href":"mac-troubleshoot-mode","toc_title":"Troubleshooting mode on macOS"},{"href":"mac-support-install","toc_title":"Troubleshoot macOS installation issues"},{"href":"mac-support-configuration","toc_title":"Troubleshoot macOS configuration"},{"displayName":"Troubleshoot performance issues for Microsoft Defender for Endpoint on macOS","href":"mac-support-perf-overview","toc_title":"Troubleshoot macOS performance issues overview"},{"href":"mac-support-perf","toc_title":"Troubleshoot performance issues"},{"href":"troubleshoot-cloud-connect-mdemac","toc_title":"Troubleshoot cloud connectivity"},{"href":"mac-support-license","toc_title":"Troubleshoot license issues"},{"children":[{"href":"manage-profiles-approve-sys-extensions-intune","toc_title":"Approve extensions using Intune"},{"href":"manage-sys-extensions-using-jamf","toc_title":"Approve extensions using Jamf Pro"},{"href":"manage-sys-extensions-manual-deployment","toc_title":"Manual deployment"}],"href":"mac-support-sys-ext","toc_title":"Troubleshoot system extension issues"}],"toc_title":"Troubleshoot Microsoft Defender for Endpoint on macOS"}],"toc_title":"Defender for Endpoint on macOS"},{"children":[{"children":[{"href":"mde-linux-prerequisites","toc_title":"Prerequisites"},{"children":[{"href":"linux-custom-location-installation","toc_title":"Enabling deployment to a custom location"},{"href":"linux-install-with-defender-deployment-tool","toc_title":"Deployment tool based deployment"},{"href":"linux-installer-script","toc_title":"Installer script based deployment"},{"href":"linux-install-with-ansible","toc_title":"Ansible based deployment"},{"href":"linux-deploy-defender-for-endpoint-with-chef","toc_title":"Chef based deployment"},{"href":"linux-install-with-puppet","toc_title":"Puppet based deployment"},{"href":"linux-install-with-saltack","toc_title":"Saltstack based deployment"},{"href":"linux-install-manually","toc_title":"Manual deployment"},{"href":"linux-deploy-defender-for-endpoint-using-golden-images","toc_title":"Golden image based deployment"},{"href":"/azure/defender-for-cloud/onboard-machines-with-defender-for-endpoint?toc=/defender-endpoint/toc.json\u0026bc=/defender-endpoint/breadcrumb/toc.json","toc_title":"Direct onboarding with Defender for Cloud"},{"href":"mde-linux-deployment-on-sap","toc_title":"Deployment guidance for Defender for Endpoint on Linux for SAP"}],"toc_title":"Choose a deployment method"}],"toc_title":"Deploy Defender for Endpoint on Linux"},{"children":[{"href":"linux-preferences","toc_title":"Configure security policies and settings"},{"href":"linux-static-proxy-configuration","toc_title":"Static proxy configuration"},{"children":[{"href":"configure-anti-virus-scans-linux","toc_title":"Configure Defender Antivirus scans on Linux"},{"href":"schedule-antivirus-scans-linux","toc_title":"Schedule Defender Antivirus scans on Linux"},{"href":"schedule-antivirus-scan-anacron","toc_title":"Schedule antivirus scans using Anacron"},{"href":"schedule-antivirus-scan-crontab","toc_title":"Schedule antivirus scans using Crontab"}],"toc_title":"Configure antivirus scans"},{"href":"network-protection-linux","toc_title":"Network protection for Linux"},{"href":"linux-exclusions","toc_title":"Configure and validate exclusions on Linux"},{"href":"linux-support-ebpf","toc_title":"Configure eBPF-based sensor"},{"href":"tamper-protection-linux-audit-mode","toc_title":"Use tamper protection in audit mode"},{"href":"linux-pua","toc_title":"Detect and block Potentially Unwanted Applications"},{"href":"linux-support-offline-security-intelligence-update","toc_title":"Configure Offline Security Intelligence Update"}],"toc_title":"Configure Defender for Endpoint on Linux"},{"children":[{"href":"linux-updates","toc_title":"Update Defender for Endpoint on Linux"},{"href":"linux-update-mde-linux","toc_title":"Schedule an update for Defender for Endpoint on Linux"}],"toc_title":"Update Defender for Endpoint on Linux"},{"href":"linux-off-board-endpoints","toc_title":"Offboard Defender for Endpoint on Linux"},{"href":"linux-privacy","toc_title":"Privacy for Defender for Endpoint on Linux"},{"href":"linux-resources","toc_title":"Additional resources for Defender for Endpoint on Linux"}],"toc_title":"Defender for Endpoint on Linux"},{"children":[{"href":"mtd","toc_title":"Mobile threat defense overview"},{"children":[{"href":"/intune/intune-service/protect/microsoft-defender-deploy-android?toc=/defender-endpoint/toc.json\u0026bc=/defender-endpoint/breadcrumb/toc.json","toc_title":"Deployment on Android with Microsoft Intune"},{"href":"ios-install","toc_title":"Deployment on iOS via Microsoft Intune"},{"href":"ios-install-unmanaged","toc_title":"Deployment on iOS with Mobile Application Manager"}],"toc_title":"Deploy"},{"children":[{"href":"android-new-ux","toc_title":"User experiences in Defender for Endpoint on Android"},{"href":"ios-new-ux","toc_title":"User experiences in Defender for Endpoint on iOS"},{"href":"mobile-resources-defender-endpoint","toc_title":"Mobile device resources for Defender for Endpoint"},{"href":"mobile-dynamic-preview-rings-configure","toc_title":"Configure Dynamic Preview Rings for Microsoft Defender on mobile"},{"href":"android-configure","toc_title":"Configure Defender for Endpoint on Android features"},{"href":"android-configure-mam","toc_title":"Configure Defender for Endpoint on Android using mobile application management"},{"href":"android-mobile-threat-defense-role","toc_title":"Android Mobile Threat Defense (MTD) Role"},{"href":"android-privacy","toc_title":"Privacy for Defender for Endpoint on Android"},{"href":"ios-configure-features","toc_title":"Configure Defender for Endpoint on iOS features"},{"href":"ios-privacy","toc_title":"Privacy for Defender for Endpoint on iOS"}],"toc_title":"Configure Mobile Threat Defense"}],"toc_title":"Defender for Endpoint on Android and iOS"},{"href":"run-detection-test","toc_title":"Run a detection test on a newly onboarded Microsoft Defender for Endpoint"},{"children":[{"href":"preferences-setup","toc_title":"Configure general Defender for Endpoint settings"},{"children":[{"href":"/defender-xdr/configure-email-notifications","toc_title":"Configure alert notifications"},{"href":"configure-vulnerability-email-notifications","toc_title":"Configure vulnerability email notifications"},{"href":"advanced-features","toc_title":"Configure advanced features"},{"href":"configure-libraries-live-response","toc_title":"Configure library management for live response"}],"toc_title":"General"},{"children":[{"href":"assign-portal-access","toc_title":"Overview of permissions management"},{"href":"basic-permissions","toc_title":"Use basic permissions to access the portal"},{"href":"rbac","toc_title":"Manage portal access using role-based access control"},{"href":"user-roles","toc_title":"Create and manage roles"},{"href":"machine-groups","toc_title":"Create and manage device groups"},{"href":"machine-tags","toc_title":"Create and manage device tags"}],"toc_title":"Permissions management"},{"children":[{"href":"defender-endpoint-exclusions-overview","toc_title":"Exclusions and indicators overview"},{"href":"manage-suppression-rules","toc_title":"Manage suppression rules"},{"children":[{"href":"indicators-overview","toc_title":"Overview of indicators"},{"href":"indicator-file","toc_title":"Create indicators for files"},{"href":"indicator-ip-domain","toc_title":"Create indicators for IPs and URLs/domains"},{"href":"indicator-certificates","toc_title":"Create indicators for certificates"},{"href":"indicator-manage","toc_title":"Manage indicators"},{"href":"manage-automation-file-uploads","toc_title":"Manage automation file uploads"},{"href":"automation-folder-exclusions-configure","toc_title":"Manage automation folder exclusions"}],"toc_title":"Indicators"}],"toc_title":"Rules and exclusions"},{"children":[{"href":"onboarding","toc_title":"Onboarding devices"},{"href":"offboard-machines","toc_title":"Offboarding devices"},{"href":"configure-machines","toc_title":"Review device configuration"},{"href":"configure-machines-onboarding","toc_title":"Monitor and increase device onboarding"},{"href":"update-agent-mma-windows","toc_title":"Updating MMA on Windows devices"}],"toc_title":"Device management"},{"href":"time-settings","toc_title":"Configure time zone settings"}],"toc_title":"Configure portal settings"},{"children":[{"href":"defender-endpoint-exclusions-configuration-reference","toc_title":"Exclusions reference"},{"href":"address-unwanted-behaviors-mde","toc_title":"Address unwanted behaviors with exclusions, indicators, and other techniques"},{"href":"mde-sdp-strategy","toc_title":"Safe deployment practices"}],"toc_title":"Safeguard and manage your environment"},{"children":[{"href":"troubleshoot-mdav-scan-issues","toc_title":"Troubleshoot antivirus scan issues"},{"children":[{"href":"troubleshoot-onboarding","toc_title":"Troubleshoot issues during onboarding"},{"href":"troubleshoot-onboarding-error-messages","toc_title":"Troubleshoot subscription and portal access issues"},{"href":"troubleshoot-security-config-mgt","toc_title":"Troubleshoot security configuration management onboarding issues"},{"href":"tamper-protection-troubleshoot","toc_title":"Troubleshoot problems with tamper protection"},{"href":"switch-to-mde-troubleshooting","toc_title":"Troubleshooting migration issues"}],"toc_title":"Troubleshoot onboarding issues"},{"children":[{"href":"check-sensor-status","toc_title":"Check sensor state"},{"href":"fix-unhealthy-sensors","toc_title":"Fix unhealthy sensors"},{"href":"fix-unhealthy-sensors#inactive-devices","toc_title":"Inactive devices"},{"href":"fix-unhealthy-sensors#misconfigured-devices","toc_title":"Misconfigured devices"},{"href":"event-error-codes","toc_title":"Review sensor events and errors on machines using Event Viewer"}],"toc_title":"Troubleshoot sensor state"},{"children":[{"href":"mac-troubleshoot-netext-mde","toc_title":"Troubleshoot NetExt issues with Defender for Endpoint on Mac"},{"href":"mac-troubleshoot-mode","toc_title":"Troubleshooting mode on macOS"},{"href":"mac-support-install","toc_title":"Troubleshoot macOS installation issues"},{"displayName":"Troubleshoot performance issues for Defender for Endpoint on macOS","href":"mac-support-perf-overview","toc_title":"Troubleshoot macOS performance issues overview"},{"href":"mac-support-perf","toc_title":"Troubleshoot performance issues"},{"href":"troubleshoot-cloud-connect-mdemac","toc_title":"Troubleshoot cloud connectivity"},{"href":"mac-support-license","toc_title":"Troubleshoot license issues"},{"children":[{"href":"manage-profiles-approve-sys-extensions-intune","toc_title":"Approve extensions using Intune"},{"href":"manage-sys-extensions-using-jamf","toc_title":"Approve extensions using Jamf Pro"},{"href":"manage-sys-extensions-manual-deployment","toc_title":"Manual deployment"}],"href":"mac-support-sys-ext","toc_title":"Troubleshoot system extension issues"}],"toc_title":"Troubleshoot Microsoft Defender for Endpoint on macOS"},{"children":[{"href":"linux-support-install","toc_title":"Troubleshoot Linux installation issues"},{"href":"health-status","toc_title":"Investigate agent health issues"},{"href":"linux-support-connectivity","toc_title":"Troubleshoot cloud connectivity issues"},{"href":"linux-support-perf","toc_title":"Troubleshoot performance issues"}],"toc_title":"Troubleshoot Microsoft Defender for Endpoint on Linux"},{"children":[{"href":"android-support-signin","toc_title":"Troubleshoot Microsoft Defender for Endpoint on Android issues"},{"href":"ios-troubleshoot","toc_title":"Troubleshoot Microsoft Defender for Endpoint on iOS issues"}],"toc_title":"Troubleshoot Mobile Threat Defense"},{"children":[{"href":"overview-client-analyzer","toc_title":"Client analyzer overview"},{"href":"run-analyzer-windows","toc_title":"Run the client analyzer on Windows"},{"href":"run-analyzer-linux","toc_title":"Run the client analyzer on Linux"},{"href":"run-analyzer-macos","toc_title":"Run the client analyzer on macOS"},{"href":"use-client-analyzer","toc_title":"Diagnose issues with Client Analyzer"},{"href":"data-collection-analyzer","toc_title":"Data collection for advanced troubleshooting on Windows"},{"href":"analyzer-report","toc_title":"Understand the analyzer HTML report"},{"href":"analyzer-feedback","toc_title":"Provide feedback on the client analyzer tool"}],"toc_title":"Troubleshoot sensor health issues using Client Analyzer"},{"children":[{"href":"troubleshoot-mdatp","toc_title":"Troubleshoot service issues"},{"href":"contact-support","toc_title":"Contact Microsoft Defender for Endpoint support"}],"toc_title":"Troubleshoot Microsoft Defender for Endpoint service issues"},{"href":"troubleshoot-live-response","toc_title":"Troubleshoot live response issues"},{"href":"troubleshoot-collect-support-log","toc_title":"Collect support logs using LiveAnalyzer"},{"href":"troubleshoot-remotely-with-client-analyzer","toc_title":"Run remote MDE Client Analyzer traces via live response"},{"href":"troubleshoot-settings","toc_title":"Troubleshoot Microsoft Defender Antivirus settings"},{"href":"troubleshoot-security-intelligence-not-updated","toc_title":"Troubleshoot Microsoft Defender Antivirus Security intelligence not getting updated"},{"displayName":"Troubleshooting Security Intelligence Updates from Microsoft Update source","href":"security-intelligence-update-tshoot","toc_title":"Troubleshooting Security Intelligence Updates from Microsoft Update source"},{"children":[{"href":"troubleshoot-np","toc_title":"Troubleshoot network protection"},{"href":"troubleshoot-asr","toc_title":"Troubleshoot ASR rules"},{"href":"migrating-asr-rules","toc_title":"Migrate to ASR rules"}],"toc_title":"Troubleshoot attack surface reduction issues"}],"toc_title":"Troubleshoot"}],"toc_title":"Onboard and configure devices"}],"toc_title":"Deployment, onboarding, and configuration"},{"href":"mde-sec-ops-guide","toc_title":"Defender for Endpoint Security Operations Guide"},{"children":[{"href":"azure-server-integration","toc_title":"Integration with Microsoft Defender for Cloud"},{"href":"onboarding-notification","toc_title":"Create an onboarding or offboarding notification rule"},{"href":"/intune/intune-service/protect/mde-security-integration","toc_title":"Manage Microsoft Defender for Endpoint configuration settings on devices with Microsoft Intune"},{"href":"defender-endpoint-subscription-settings","toc_title":"Manage Defender for Endpoint P1/P2 across devices"},{"href":"onboarding-endpoint-configuration-manager","toc_title":"Onboarding using Microsoft Configuration Manager"},{"href":"onboarding-endpoint-manager","toc_title":"Onboard Windows devices using Microsoft Intune"},{"href":"mobile-pretest-android","toc_title":"Deploy Microsoft Defender for Endpoint prerelease builds on Android devices"},{"href":"configure-wdac-script-enforcement-mde","toc_title":"Allow Defender for Endpoint scripts with WDAC script enforcement"}],"toc_title":"How to guides"},{"children":[{"href":"migration-guides","toc_title":"Migration guides overview"},{"href":"mde-side-by-side","toc_title":"Considerations for side-by-side deployment"},{"href":"migrating-mde-server-to-cloud","toc_title":"Migrate servers to Defender for Cloud"},{"children":[{"href":"switch-to-mde-overview","toc_title":"Overview"},{"href":"switch-to-mde-phase-1","toc_title":"Phase 1 - Prepare"},{"href":"switch-to-mde-phase-2","toc_title":"Phase 2 - Setup"},{"href":"switch-to-mde-phase-3","toc_title":"Phase 3 - Onboard"},{"children":[{"href":"server-migration","toc_title":"Overview"},{"href":"application-deployment-via-mecm","toc_title":"Migrating servers from Microsoft Monitoring Agent to the unified solution"}],"toc_title":"Server migration scenarios"}],"toc_title":"Migrate to Defender for Endpoint"}],"toc_title":"Migration guides"},{"children":[{"toc_title":"Detect vulnerabilities"},{"href":"/defender-vulnerability-management","toc_title":"Detect vulnerabilities"},{"children":[{"href":"device-discovery","toc_title":"Device discovery"},{"href":"configure-device-discovery","toc_title":"Manage device discovery"},{"href":"assess-devices","toc_title":"Review and assess devices"},{"children":[{"href":"troubleshoot-device-discovery-network-scans","toc_title":"Troubleshoot"}],"href":"network-devices","toc_title":"Configure network authenticated scans"},{"displayName":"devices, device inventory","href":"devices-overview","toc_title":"Device inventory"},{"children":[{"displayName":"device inventory","href":"machines-view-overview","toc_title":"Overview"},{"displayName":"device inventory fields, device inventory filters","href":"device-inventory-field-reference","toc_title":"Device inventory field and filter reference"}],"toc_title":"Explore devices in the device inventory"},{"displayName":"exclude devices, transient devices","href":"manage-device-scope-relevance","toc_title":"Manage device scope and relevance"},{"displayName":"target devices","href":"machine-tags","toc_title":"Manage device tags and target devices"},{"children":[{"displayName":"custom data collection, telemetry, threat hunting","href":"custom-data-collection","toc_title":"Overview"},{"href":"create-custom-data-collection-rules","toc_title":"Create custom data collection rules"}],"toc_title":"Collect custom device data"}],"toc_title":"Discover and manage devices"},{"href":"tamper-resiliency","toc_title":"Tamper resiliency"},{"children":[{"children":[{"displayName":"AI agent discovery overview","href":"local-agent-discovery-overview","toc_title":"Overview"},{"href":"discover-local-ai-agents","toc_title":"Discover local AI agents"}],"toc_title":"Discover local AI agents"},{"children":[{"displayName":"AI agent runtime protection overview","href":"ai-agent-runtime-protection-overview","toc_title":"Overview"},{"href":"configure-ai-agent-runtime-protection","toc_title":"Set up AI agent runtime protection"}],"toc_title":"Protect local AI agents with runtime protection"}],"toc_title":"Protect AI agents"},{"children":[{"href":"attack-surface-reduction-overview","toc_title":"Attack surface reduction overview"},{"href":"attack-surface-reduction-windows-events","toc_title":"Attack surface reduction Windows events"},{"href":"attack-surface-reduction-faq","toc_title":"Attack surface reduction FAQ"},{"children":[{"href":"attack-surface-reduction-rules-overview","toc_title":"About ASR rules"},{"children":[{"href":"attack-surface-reduction-rules-deployment","toc_title":"ASR rules deployment guide"},{"href":"attack-surface-reduction-rules-deployment-plan","toc_title":"Plan your ASR rules deployment"},{"href":"attack-surface-reduction-rules-deployment-test","toc_title":"Test your ASR rules deployment"},{"href":"attack-surface-reduction-rules-deployment-implement","toc_title":"Enable your ASR rules deployment"},{"href":"attack-surface-reduction-rules-deployment-operationalize","toc_title":"Manage and monitor your ASR rules deployment"}],"toc_title":"ASR rules deployment guide"},{"href":"attack-surface-reduction-rules-configure","toc_title":"Configure ASR rules and exclusions"},{"href":"attack-surface-reduction-rules-monitor","toc_title":"Monitor ASR rule activity"},{"href":"attack-surface-reduction-rules-report","toc_title":"ASR rules report"},{"href":"attack-surface-reduction-rules-reference","toc_title":"ASR rules reference"}],"toc_title":"ASR rules"},{"children":[{"href":"controlled-folder-access-overview","toc_title":"Controlled folder access overview"},{"href":"controlled-folder-access-configure","toc_title":"Configure controlled folder access"},{"href":"controlled-folder-access-monitor","toc_title":"Monitor controlled folder access"}],"toc_title":"Controlled folder access"},{"children":[{"href":"device-control-overview","toc_title":"Overview of device control"},{"href":"device-control-walkthroughs","toc_title":"Device control walkthroughs"},{"href":"device-control-policies","toc_title":"Understand device control policies"},{"href":"device-control-configure","toc_title":"Configure device control"},{"href":"device-control-faq","toc_title":"Device control frequently asked questions"}],"toc_title":"Device Control"},{"children":[{"href":"exploit-protection","toc_title":"Protect devices from exploits"},{"href":"evaluate-exploit-protection","toc_title":"Exploit protection evaluation"},{"href":"enable-exploit-protection","toc_title":"Enable exploit protection"},{"href":"customize-exploit-protection","toc_title":"Customize exploit protection"},{"href":"import-export-exploit-protection-emet-xml","toc_title":"Import, export, and deploy exploit protection configurations"},{"href":"troubleshoot-exploit-protection-mitigations","toc_title":"Troubleshoot exploit protection mitigations"},{"href":"exploit-protection-reference","toc_title":"Exploit protection reference"}],"toc_title":"Exploit protection"},{"children":[{"href":"network-protection","toc_title":"Protect your network"},{"href":"evaluate-network-protection","toc_title":"Evaluate network protection"},{"href":"enable-network-protection","toc_title":"Turn on network protection"},{"href":"network-protection-macos","toc_title":"Network protection for MacOS"}],"toc_title":"Network protection"},{"children":[{"href":"web-protection-overview","toc_title":"Web protection overview"},{"children":[{"href":"web-threat-protection","toc_title":"Web threat protection overview"},{"href":"web-protection-response","toc_title":"Respond to web threats"}],"toc_title":"Web threat protection"},{"href":"web-content-filtering","toc_title":"Web content filtering"}],"toc_title":"Web protection"}],"toc_title":"Attack surface reduction"},{"children":[{"children":[{"href":"microsoft-defender-antivirus-windows","toc_title":"Overview of Microsoft Defender Antivirus"},{"href":"microsoft-defender-antivirus-windows-server-configure","toc_title":"Configure Microsoft Defender Antivirus on Windows Server"},{"href":"enable-update-mdav-to-latest-ws","toc_title":"Enable and update Microsoft Defender Antivirus on Windows Server"},{"href":"microsoft-defender-security-center-antivirus","toc_title":"Microsoft Defender Antivirus in the Windows Security app"},{"href":"why-use-microsoft-defender-antivirus","toc_title":"Better together - Microsoft Defender Antivirus and Microsoft Defender for Endpoint"},{"href":"office-365-microsoft-defender-antivirus","toc_title":"Better together - Microsoft Defender Antivirus and Office 365"}],"href":"next-generation-protection","toc_title":"Next-generation protection overview"},{"href":"safety-scanner-download","toc_title":"Safety Scanner Download"},{"href":"configure-microsoft-defender-antivirus-features","toc_title":"Configure Microsoft Defender Antivirus features"},{"children":[{"href":"cloud-protection-configure","toc_title":"Configure cloud protection"},{"href":"configure-cloud-block-timeout-period-microsoft-defender-antivirus","toc_title":"Configure the cloud block timeout period"},{"href":"cloud-protection-microsoft-antivirus-sample-submission","toc_title":"Cloud protection and sample submission"}],"href":"cloud-protection-microsoft-defender-antivirus","toc_title":"Cloud protection and Microsoft Defender Antivirus"},{"href":"configure-network-connections-microsoft-defender-antivirus","toc_title":"Configure and validate Microsoft Defender Antivirus network connections"},{"children":[{"href":"tamper-protection-overview","toc_title":"Tamper protection overview"},{"href":"tamper-protection-windows-configure","toc_title":"Configure tamper protection on Windows devices"},{"href":"tamper-protection-antivirus-exclusions","toc_title":"Protect Microsoft Defender Antivirus exclusions"},{"href":"tamper-protection-faq","toc_title":"FAQs on tamper protection"}],"toc_title":"Tamper protection"},{"href":"secure-controlled-configuration","toc_title":"Controlled configuration"},{"href":"configure-block-at-first-sight-microsoft-defender-antivirus","toc_title":"Turn on block at first sight"},{"href":"amsi-on-mdav","toc_title":"Antimalware Scan Interface (AMSI) integration"},{"href":"configure-protection-features-microsoft-defender-antivirus","toc_title":"Configure behavioral, heuristic, and real-time protection"},{"href":"adv-tech-of-mdav","toc_title":"Advanced technologies at the core of Microsoft Defender Antivirus"},{"href":"behavior-monitor","toc_title":"Behavior monitoring with Microsoft Defender Antivirus"},{"href":"behavior-monitor-macos","toc_title":"Behavior monitoring with Microsoft Defender Antivirus on macOS"},{"href":"detect-block-potentially-unwanted-apps-microsoft-defender-antivirus","toc_title":"Detect and block potentially unwanted applications"},{"href":"configure-real-time-protection-microsoft-defender-antivirus","toc_title":"Enable and configure Microsoft Defender Antivirus always-on protection in Group Policy"},{"href":"configure-remediation-microsoft-defender-antivirus","toc_title":"Configure remediation for Microsoft Defender Antivirus detections"},{"children":[{"href":"schedule-antivirus-scans-group-policy","toc_title":"Schedule scans using Group Policy"},{"href":"schedule-antivirus-scans-powershell","toc_title":"Schedule scans using PowerShell"},{"href":"schedule-antivirus-scans-wmi","toc_title":"Schedule scans using WMI"},{"href":"mdav-scan-best-practices","toc_title":"Full scan best practices"}],"href":"schedule-antivirus-scans","toc_title":"About scheduled Microsoft Defender Antivirus scans"},{"href":"limited-periodic-scanning-microsoft-defender-antivirus","toc_title":"Use limited periodic scanning in Microsoft Defender Antivirus"},{"href":"microsoft-defender-endpoint-antivirus-performance-mode","toc_title":"Protect Dev Drive using performance mode"},{"href":"microsoft-defender-antivirus-compatibility","toc_title":"Compatibility with other security products"},{"href":"microsoft-defender-passive-mode","toc_title":"Defender for Endpoint passive mode"},{"displayName":"Microsoft Defender Antivirus and non-Microsoft antivirus/antimalware solutions, Antivirus protection without Defender for Endpoint","href":"defender-antivirus-compatibility-without-mde","toc_title":"Microsoft Defender Antivirus and third-party antivirus solutions without Defender for Endpoint"},{"href":"find-defender-malware-name","toc_title":"Find malware detection names for Microsoft Defender for Endpoint"},{"children":[{"href":"msda-updates-previous-versions-technical-upgrade-support","toc_title":"Previous versions for technical upgrade support only"},{"href":"manage-protection-updates-microsoft-defender-antivirus","toc_title":"Manage the sources for Microsoft Defender Antivirus protection updates"},{"href":"manage-protection-update-schedule-microsoft-defender-antivirus","toc_title":"Manage the schedule for when protection updates should be downloaded and applied"},{"href":"manage-gradual-rollout","toc_title":"Manage gradual rollout process for Microsoft Defender updates"},{"href":"configure-updates","toc_title":"Configure gradual rollout process for Microsoft Defender updates"},{"children":[{"href":"microsoft-defender-antivirus-ring-deployment","toc_title":"Overview"},{"href":"microsoft-defender-antivirus-ring-deployment-intune-microsoft-update","toc_title":"Intune and Microsoft Update"},{"href":"microsoft-defender-antivirus-ring-deployment-sscm-wsus","toc_title":"Configuration Manager and WSUS"},{"href":"microsoft-defender-antivirus-ring-deployment-group-policy-microsoft-update","toc_title":"Group Policy and Microsoft Update"},{"href":"microsoft-defender-antivirus-ring-deployment-group-policy-network-share","toc_title":"Group Policy and network share"},{"children":[{"href":"microsoft-defender-antivirus-pilot-ring-deployment-group-policy-wsus","toc_title":"Pilot ring"},{"href":"microsoft-defender-antivirus-production-ring-deployment-group-policy-wsus","toc_title":"Production ring"},{"href":"microsoft-defender-antivirus-ring-deployment-group-policy-wsus-appendices","toc_title":"Appendices for ring deployment using Group Policy and Windows Server Update Services (WSUS)"}],"toc_title":"Group Policy and WSUS"}],"toc_title":"Ring deployment"},{"href":"manage-outdated-endpoints-microsoft-defender-antivirus","toc_title":"Manage Microsoft Defender Antivirus updates and scans for endpoints that are out of date"},{"href":"manage-event-based-updates-microsoft-defender-antivirus","toc_title":"Manage event-based forced updates"},{"href":"manage-updates-mobile-devices-vms-microsoft-defender-antivirus","toc_title":"Manage updates for mobile devices and virtual machines (VMs)"}],"href":"microsoft-defender-antivirus-updates","toc_title":"Microsoft Defender Antivirus security intelligence and product updates"},{"children":[{"href":"use-intune-config-manager-microsoft-defender-antivirus","toc_title":"Use Microsoft Intune to manage Microsoft Defender Antivirus"},{"displayName":"Use Microsoft Defender for Endpoint Security Settings Management to manage Microsoft Defender Antivirus MDE Attach MDE Attach v2","href":"/intune/intune-service/protect/mde-security-integration?toc=/defender-endpoint/toc.json\u0026bc=/defender-endpoint/breadcrumb/toc.json","toc_title":"Use Microsoft Defender for Endpoint Security Settings Management to manage Microsoft Defender Antivirus"},{"href":"use-group-policy-microsoft-defender-antivirus","toc_title":"Use Group Policy settings to manage Microsoft Defender Antivirus"},{"href":"use-powershell-cmdlets-microsoft-defender-antivirus","toc_title":"Use PowerShell cmdlets to manage Microsoft Defender Antivirus"},{"href":"use-wmi-microsoft-defender-antivirus","toc_title":"Use Windows Management Instrumentation (WMI) to manage Microsoft Defender Antivirus"},{"href":"command-line-arguments-microsoft-defender-antivirus","toc_title":"Use the MpCmdRun command-line tool to manage Microsoft Defender Antivirus"},{"href":"configure-notifications-microsoft-defender-antivirus","toc_title":"Configure the notifications that appear on endpoints"},{"href":"configure-local-policy-overrides-microsoft-defender-antivirus","toc_title":"Specify whether users can locally modify Microsoft Defender Antivirus policy settings"},{"href":"prevent-end-user-interaction-microsoft-defender-antivirus","toc_title":"Specify whether users can see or interact with Microsoft Defender Antivirus user interface"}],"href":"configuration-management-reference-microsoft-defender-antivirus","toc_title":"Manage Microsoft Defender Antivirus for your organization"},{"children":[{"href":"deployment-vdi-microsoft-defender-antivirus","toc_title":"Configure Microsoft Defender Antivirus in a remote desktop or virtual desktop infrastructure environment"}],"href":"deploy-manage-report-microsoft-defender-antivirus","toc_title":"Deploy and report on Microsoft Defender Antivirus"},{"children":[{"href":"run-scan-microsoft-defender-antivirus","toc_title":"Configure and run on-demand Microsoft Defender Antivirus scans"},{"href":"microsoft-defender-offline","toc_title":"Run and review the results of a Microsoft Defender Offline scan"},{"href":"configure-advanced-scan-types-microsoft-defender-antivirus","toc_title":"Configure Microsoft Defender Antivirus scanning options"},{"href":"restore-quarantined-files-microsoft-defender-antivirus","toc_title":"Restore quarantined files in Microsoft Defender Antivirus"}],"href":"review-scan-results-microsoft-defender-antivirus","toc_title":"Scans and remediation"},{"children":[{"href":"microsoft-defender-antivirus-exclusions-overview","toc_title":"Exclusions overview"},{"href":"microsoft-defender-antivirus-exclusions-configure","toc_title":"Configure custom exclusions"},{"href":"microsoft-defender-antivirus-exclusions-windows-server","toc_title":"Exclusions for Windows Server"},{"href":"defender-endpoint-exclusions-common-mistakes","toc_title":"Exclusions to avoid"}],"toc_title":"Microsoft Defender Antivirus exclusions"},{"children":[{"href":"troubleshooting-mode-enable","toc_title":"Enable and use troubleshooting mode"},{"href":"troubleshooting-mode-scenarios","toc_title":"Troubleshooting mode scenarios"}],"toc_title":"Troubleshooting mode for Defender for Endpoint"},{"children":[{"href":"microsoft-defender-core-service-overview","toc_title":"Microsoft Defender Core service overview"},{"href":"microsoft-defender-core-service-configurations-and-experimentation","toc_title":"Microsoft Defender Core service configurations and experimentation"},{"href":"collect-diagnostic-data","toc_title":"Collect diagnostic data of Microsoft Defender Antivirus"}],"toc_title":"Diagnostics for Microsoft Defender Antivirus"},{"children":[{"children":[{"href":"tune-performance-defender-antivirus","toc_title":"Performance analyzer for Microsoft Defender Antivirus"},{"href":"performance-analyzer-reference","toc_title":"Performance analyzer reference"},{"href":"troubleshoot-av-performance-issues-with-procmon","toc_title":"Troubleshoot Microsoft Defender Antivirus performance issues with Process Monitor"},{"href":"troubleshoot-av-performance-issues-with-wprui","toc_title":"Troubleshoot Microsoft Defender Antivirus performance issues with WPRUI"}],"href":"troubleshoot-performance-issues","toc_title":"Troubleshoot performance issues related to real-time protection"},{"children":[{"href":"troubleshoot-microsoft-defender-antivirus","toc_title":"Review event logs and error codes to troubleshoot issues with Microsoft Defender Antivirus"},{"href":"troubleshoot-microsoft-defender-antivirus-when-migrating","toc_title":"Troubleshoot Microsoft Defender Antivirus while migrating from a third-party solution"}],"toc_title":"Troubleshoot Microsoft Defender Antivirus performance issues"}],"toc_title":"Troubleshooting Microsoft Defender Antivirus"},{"children":[{"href":"behavioral-blocking-containment","toc_title":"Behavioral blocking and containment"},{"href":"client-behavioral-blocking","toc_title":"Client behavioral blocking"},{"href":"feedback-loop-blocking","toc_title":"Feedback-loop blocking"}],"toc_title":"Behavioral blocking and containment"},{"href":"uefi-scanning-in-defender-for-endpoint","toc_title":"UEFI scanning in Defender for Endpoint"},{"href":"sandbox-mdav","toc_title":"Run Microsoft Defender Antivirus in a sandbox"},{"href":"elam-on-mdav","toc_title":"Early Launch Antimalware (ELAM) and Microsoft Defender Antivirus"}],"toc_title":"Next-generation protection"},{"href":"defender-endpoint-false-positives-negatives","toc_title":"Address false positives/negatives in Microsoft Defender for Endpoint"},{"children":[{"href":"endpoint-security-policies-configure","toc_title":"Manage endpoint security policies"},{"href":"/intune/intune-service/protect/mde-security-integration?toc=/defender-endpoint/toc.json\u0026bc=/defender-endpoint/breadcrumb/toc.json","toc_title":"Deploy endpoint security policies from Intune"},{"href":"configure-machines-security-baseline","toc_title":"Increase compliance with the security baseline"},{"href":"built-in-protection","toc_title":"Built-in protection"}],"toc_title":"Manage device configuration"}],"toc_title":"Detect threats and protect endpoints"},{"children":[{"children":[{"href":"overview-endpoint-detection-response","toc_title":"Endpoint detection and response overview"},{"href":"admin-submissions-mde","toc_title":"Submit files"},{"children":[{"href":"view-incidents-queue","toc_title":"View and organize the Incidents queue"},{"href":"manage-incidents","toc_title":"Manage incidents"},{"href":"investigate-incidents","toc_title":"Investigate incidents"}],"toc_title":"Incidents queue"},{"children":[{"href":"alerts-queue-endpoint-detection-response","toc_title":"Alerts queue in Microsoft Defender XDR"},{"href":"alerts-queue","toc_title":"View and organize the Alerts queue"},{"href":"review-alerts","toc_title":"Review alerts"},{"href":"/defender-xdr/investigate-alerts?toc=/defender-endpoint/TOC.json\u0026bc=/defender-endpoint/breadcrumb/toc.json","toc_title":"Manage alerts"},{"href":"investigate-alerts","toc_title":"Investigate alerts"},{"href":"review-detected-threats","toc_title":"Review and manage detected threats"},{"href":"investigate-files","toc_title":"Investigate files"},{"displayName":"device timeline, event flags, internet-facing devices","href":"investigate-machines","toc_title":"Investigate devices"},{"children":[{"href":"investigate-behind-proxy","toc_title":"Investigate connection events that occur behind forward proxies"}],"href":"investigate-ip","toc_title":"Investigate an IP address"},{"href":"investigate-user","toc_title":"Investigate a user account"}],"toc_title":"Alerts queue"},{"children":[{"children":[{"href":"respond-machine-alerts","toc_title":"Response actions on devices"},{"href":"respond-machine-alerts#manage-tags","toc_title":"Manage tags"},{"href":"respond-machine-alerts#initiate-automated-investigation","toc_title":"Start an automated investigation"},{"href":"respond-machine-alerts#initiate-live-response-session","toc_title":"Start a Live Response session"},{"href":"respond-machine-alerts#collect-investigation-package-from-devices","toc_title":"Collect investigation package"},{"href":"respond-machine-alerts#run-microsoft-defender-antivirus-scan-on-devices","toc_title":"Run antivirus scan"},{"href":"respond-machine-alerts#restrict-app-execution","toc_title":"Restrict app execution"},{"href":"respond-machine-alerts#isolate-devices-from-the-network","toc_title":"Isolate devices from the network"},{"href":"network-isolation-exclusions","toc_title":"Network isolation exclusions"},{"href":"respond-machine-alerts#contain-devices-from-the-network","toc_title":"Contain devices from the network"},{"href":"respond-machine-alerts#contain-user-from-the-network","toc_title":"Contain user from the network"},{"href":"respond-machine-alerts#gpo-hardening-preview","toc_title":"Automatically apply GPO hardening (predictive shielding)"},{"href":"respond-machine-alerts#safeboot-hardening-preview","toc_title":"Automatically apply Safeboot hardening (predictive shielding)"},{"href":"respond-machine-alerts#consult-a-threat-expert","toc_title":"Consult a threat expert"},{"href":"respond-machine-alerts#check-activity-details-and-status","toc_title":"Check activity details in Action center"},{"href":"restrict-response-actions-high-value-assets","toc_title":"Restrict response actions on high-value assets"}],"toc_title":"Take response actions on a device"},{"children":[{"href":"respond-file-alerts","toc_title":"Response actions on files"},{"href":"respond-file-alerts#stop-and-quarantine-files-in-your-network","toc_title":"Stop and quarantine files in your network"},{"href":"respond-file-alerts#restore-file-from-quarantine","toc_title":"Restore file from quarantine"},{"href":"respond-file-alerts#add-indicator-to-block-or-allow-a-file","toc_title":"Add indicators to block or allow a file"},{"href":"respond-file-alerts#check-activity-details-in-action-center","toc_title":"Check activity details in Action center"},{"href":"respond-file-alerts#download-or-collect-file","toc_title":"Download or collect file"},{"href":"respond-file-alerts#deep-analysis","toc_title":"Deep analysis"}],"toc_title":"Take response actions on a file"}],"toc_title":"Take response actions"},{"children":[{"href":"auto-investigation-action-center","toc_title":"View details and results of automated investigations"}],"href":"manage-auto-investigation","toc_title":"View and approve remediation actions"},{"children":[{"href":"live-response","toc_title":"Investigate entities on devices"},{"href":"live-response-command-examples","toc_title":"Live response command examples"}],"toc_title":"Investigate entities using Live response"},{"href":"information-protection-investigation","toc_title":"Use sensitivity labels to prioritize incident response"}],"toc_title":"Endpoint detection and response"},{"children":[{"href":"/defender-xdr/threat-analytics?toc=/defender-endpoint/toc.json\u0026bc=/defender-endpoint/breadcrumb/toc.json","toc_title":"Overview"},{"href":"/defender-xdr/threat-analytics-analyst-reports?toc=/defender-endpoint/toc.json\u0026bc=/defender-endpoint/breadcrumb/toc.json","toc_title":"Read the analyst report"}],"toc_title":"Threat analytics"},{"href":"edr-in-block-mode","toc_title":"EDR in block mode"},{"href":"edr-block-mode-faqs","toc_title":"EDR in block mode FAQ"},{"children":[{"href":"automated-investigations","toc_title":"Overview of AIR"},{"href":"automation-levels","toc_title":"Automation levels in AIR"},{"href":"configure-automated-investigations-remediation","toc_title":"Configure AIR capabilities"},{"href":"autoir-investigation-results","toc_title":"View the details and results of an automated investigation"}],"toc_title":"Automated investigation and response (AIR)"},{"href":"endpoint-attack-notifications","toc_title":"Endpoint Attack Notifications"},{"href":"customize-run-review-remediate-scans-microsoft-defender-antivirus","toc_title":"Run and customize scheduled and on-demand scans"}],"toc_title":"Investigate and respond to threats"},{"children":[{"href":"zero-trust-with-microsoft-defender-endpoint","toc_title":"Zero Trust with Defender for Endpoint"},{"children":[{"href":"threat-protection-reports","toc_title":"Microsoft Defender for Endpoint reports"},{"children":[{"href":"device-health-microsoft-defender-antivirus-health","toc_title":"Microsoft Defender Antivirus health report"},{"href":"device-health-sensor-health-os","toc_title":"Sensor health and OS report"}],"href":"device-health-reports","toc_title":"Device health reports"},{"href":"host-firewall-reporting","toc_title":"Host firewall reporting"},{"href":"web-protection-monitoring","toc_title":"Web protection and monitoring reports"},{"href":"device-control-report","toc_title":"Device control reports"},{"href":"attack-surface-reduction-rules-report","toc_title":"ASR rules report"},{"href":"aggregated-reporting","toc_title":"Aggregated reports"},{"href":"api/api-power-bi","toc_title":"Create custom reports using Power BI"}],"toc_title":"Reports"},{"children":[{"href":"configure-conditional-access","toc_title":"Configure Conditional Access"},{"href":"microsoft-cloud-app-security-config","toc_title":"Configure Microsoft Defender for Cloud Apps integration"}],"toc_title":"Configure integration with other Microsoft solutions"},{"children":[{"href":"api/management-apis","toc_title":"Overview of management and APIs"},{"href":"api/api-release-notes","toc_title":"API release notes"},{"children":[{"children":[{"href":"/legal/microsoft-365/api-terms-of-use","toc_title":"Microsoft Defender for Endpoint API license and terms"},{"href":"/defender-endpoint/api/apis-intro","toc_title":"Access the Microsoft Defender for Endpoint APIs"},{"href":"api/api-hello-world","toc_title":"Hello World"},{"href":"api/exposed-apis-create-app-webapp","toc_title":"Get access with application context"},{"href":"api/exposed-apis-create-app-nativeapp","toc_title":"Get access with user context"}],"toc_title":"Get started"},{"children":[{"href":"api/exposed-apis-list","toc_title":"Supported Microsoft Defender for Endpoint APIs"},{"href":"api/common-errors","toc_title":"Common REST API error codes"},{"href":"api/run-advanced-query-api","toc_title":"Advanced Hunting"},{"children":[{"href":"api/alerts","toc_title":"Alert properties"},{"href":"api/get-alerts","toc_title":"List alerts"},{"href":"api/create-alert-by-reference","toc_title":"Create alert"},{"href":"api/batch-update-alerts","toc_title":"Batch update alerts"},{"href":"api/update-alert","toc_title":"Update Alert"},{"href":"api/get-alert-info-by-id","toc_title":"Get alert information by ID"},{"href":"api/get-alert-related-domain-info","toc_title":"Get alert related domains information"},{"href":"api/get-alert-related-files-info","toc_title":"Get alert related file information"},{"href":"api/get-alert-related-ip-info","toc_title":"Get alert-related IPs information"},{"href":"api/get-alert-related-machine-info","toc_title":"Get alert-related device information"},{"href":"api/get-alert-related-user-info","toc_title":"Get alert-related user information"}],"toc_title":"Alert"},{"children":[{"href":"api/get-assessment-methods-properties","toc_title":"Export assessment methods and properties"},{"href":"api/get-assessment-secure-config","toc_title":"Export secure configuration assessment"},{"href":"api/get-assessment-software-inventory","toc_title":"Export software inventory assessment"},{"href":"api/get-assessment-non-cpe-software-inventory","toc_title":"Export non product code software inventory assessment"},{"href":"api/get-assessment-software-vulnerabilities","toc_title":"Export software vulnerabilities assessment"}],"toc_title":"Assessments of vulnerabilities and secure configurations"},{"children":[{"href":"api/get-authenticated-scan-properties","toc_title":"Authenticated scan properties"},{"href":"api/get-all-scan-definitions","toc_title":"Get all scan definitions"},{"href":"api/add-a-new-scan-definition","toc_title":"Add, delete or update a scan definition"},{"href":"api/get-all-scan-agents","toc_title":"Get all scan agents"},{"href":"api/get-agent-details","toc_title":"Get scan agent by Id"},{"href":"api/get-scan-history-by-definition","toc_title":"Get scan history by definition"},{"href":"api/get-scan-history-by-session","toc_title":"Get scan history by session"}],"toc_title":"Authenticated scan"},{"children":[{"href":"api/get-assessment-browser-extensions","toc_title":"Export browser extensions assessment"},{"href":"api/get-browser-extensions-permission-info","toc_title":"Get browser extensions permission information"}],"toc_title":"Browser extensions"},{"children":[{"href":"api/investigation","toc_title":"Investigation properties"},{"href":"api/get-investigation-collection","toc_title":"List Investigation"},{"href":"api/get-investigation-object","toc_title":"Get Investigation"},{"href":"api/initiate-autoir-investigation","toc_title":"Start Investigation"}],"toc_title":"Automated investigation"},{"children":[{"href":"api/device-health-api-methods-properties","toc_title":"Export device health methods and properties"},{"href":"api/device-health-export-antivirus-health-report-api","toc_title":"Export device antivirus health report"}],"toc_title":"Device Health"},{"children":[{"href":"api/export-certificate-inventory-assessment","toc_title":"Export certificate inventory assessment"}],"toc_title":"Certificate inventory"},{"children":[{"href":"api/get-domain-related-alerts","toc_title":"Get domain related alerts"},{"href":"api/get-domain-related-machines","toc_title":"Get domain related machines"},{"href":"api/get-domain-statistics","toc_title":"Get domain statistics"}],"toc_title":"Domain"},{"children":[{"href":"api/files","toc_title":"File properties"},{"href":"api/get-file-information","toc_title":"Get file information"},{"href":"api/get-file-related-alerts","toc_title":"Get file related alerts"},{"href":"api/get-file-related-machines","toc_title":"Get file related machines"},{"href":"api/get-file-statistics","toc_title":"Get file statistics"}],"toc_title":"File"},{"children":[{"href":"api/ti-indicator","toc_title":"Indicators properties"},{"href":"api/get-ti-indicators-collection","toc_title":"List Indicators"},{"href":"api/post-ti-indicator","toc_title":"Submit Indicator"},{"href":"api/import-ti-indicators","toc_title":"Import Indicator"},{"href":"api/delete-ti-indicator-by-id","toc_title":"Delete Indicator"},{"href":"api/batch-delete-ti-indicators","toc_title":"Batch Delete Indicators"}],"toc_title":"Indicators"},{"children":[{"href":"api/get-assessment-information-gathering","toc_title":"Export information gathering assessment"}],"toc_title":"Information gathering"},{"children":[{"href":"api/get-ip-related-alerts","toc_title":"Get IP related alerts"},{"href":"api/get-ip-statistics","toc_title":"Get IP statistics"}],"toc_title":"IP"},{"children":[{"href":"live-response-library-methods","toc_title":"Live response library properties"},{"href":"api/list-library-files","toc_title":"List library files"},{"href":"api/upload-library","toc_title":"Upload to live response library"},{"href":"api/delete-library","toc_title":"Delete from library"}],"toc_title":"Live response library"},{"children":[{"href":"api/machine","toc_title":"Machine properties"},{"href":"api/get-machines","toc_title":"List machines"},{"href":"api/get-machine-by-id","toc_title":"Get machine by ID"},{"href":"api/get-machine-log-on-users","toc_title":"Get machine log on users"},{"href":"api/get-machine-related-alerts","toc_title":"Get machine related alerts"},{"href":"api/get-installed-software","toc_title":"Get installed software"},{"href":"api/get-discovered-vulnerabilities","toc_title":"Get discovered vulnerabilities"},{"href":"api/get-security-recommendations","toc_title":"Get security recommendations"},{"href":"api/add-or-remove-machine-tags","toc_title":"Add or remove a machine tag"},{"href":"api/add-or-remove-multiple-machine-tags","toc_title":"Add or remove a tag from multiple machines"},{"href":"api/find-machines-by-ip","toc_title":"Find machines by IP"},{"href":"api/find-machine-info-by-ip","toc_title":"Find device information by internal IP"},{"href":"api/find-machines-by-tag","toc_title":"Find machines by tag"},{"href":"api/get-missing-kbs-machine","toc_title":"Get missing KBs"},{"href":"api/set-device-value","toc_title":"Set device value"},{"href":"api/update-machine-method","toc_title":"Update machine"}],"toc_title":"Machine"},{"children":[{"href":"api/machineaction","toc_title":"Machine Action properties"},{"href":"api/get-machineactions-collection","toc_title":"List Machine Actions"},{"href":"api/get-machineaction-object","toc_title":"Get Machine Action"},{"href":"api/collect-investigation-package","toc_title":"Collect investigation package"},{"href":"api/get-package-sas-uri","toc_title":"Get investigation package SAS URI"},{"href":"api/get-live-response-result","toc_title":"Get live response result"},{"href":"api/isolate-machine","toc_title":"Isolate machine"},{"href":"api/unisolate-machine","toc_title":"Release machine from isolation"},{"href":"api/restrict-code-execution","toc_title":"Restrict app execution"},{"href":"api/unrestrict-code-execution","toc_title":"Remove app restriction"},{"href":"api/run-av-scan","toc_title":"Run antivirus scan"},{"href":"api/run-live-response","toc_title":"Run live response"},{"href":"api/offboard-machine-api","toc_title":"Offboard machine"},{"href":"api/stop-and-quarantine-file","toc_title":"Stop and quarantine file"},{"href":"api/cancel-machine-action","toc_title":"Cancel machine action"}],"toc_title":"Machine Action"},{"children":[{"href":"api/recommendation","toc_title":"Recommendation properties"},{"href":"api/get-all-recommendations","toc_title":"List all recommendations"},{"href":"api/get-recommendation-by-id","toc_title":"Get recommendation by ID"},{"href":"api/list-recommendation-software","toc_title":"Get recommendation by software"},{"href":"api/get-recommendation-machines","toc_title":"List machines by recommendation"},{"href":"api/get-recommendation-vulnerabilities","toc_title":"List vulnerabilities by recommendation"}],"toc_title":"Recommendation"},{"children":[{"href":"api/get-remediation-methods-properties","toc_title":"Remediation activity properties"},{"href":"api/get-remediation-one-activity","toc_title":"Get one remediation activity by ID"},{"href":"api/get-remediation-all-activities","toc_title":"List all remediation activities"},{"href":"api/get-remediation-exposed-devices-activities","toc_title":"List exposed devices of one remediation activity"}],"toc_title":"Remediation activity"},{"children":[{"href":"api/score","toc_title":"Score properties"},{"href":"api/get-machine-group-exposure-score","toc_title":"List exposure score by machine group"},{"href":"api/get-exposure-score","toc_title":"Get exposure score"},{"href":"api/get-device-secure-score","toc_title":"Get device secure score"}],"toc_title":"Score"},{"children":[{"href":"api/export-security-baseline-assessment","toc_title":"Export security baselines assessment"},{"href":"api/get-security-baselines-assessment-profiles","toc_title":"List security baselines assessment profiles"},{"href":"api/get-security-baselines-assessment-configurations","toc_title":"Get baseline profile configurations"}],"toc_title":"Security baselines"},{"children":[{"href":"api/software","toc_title":"Software properties"},{"href":"api/get-software","toc_title":"List software"},{"href":"api/get-software-by-id","toc_title":"Get software by ID"},{"href":"api/get-software-ver-distribution","toc_title":"List software version distribution"},{"href":"api/get-machines-by-software","toc_title":"List machines by software"},{"href":"api/get-vuln-by-software","toc_title":"List vulnerabilities by software"},{"href":"api/get-missing-kbs-software","toc_title":"Get missing KBs"}],"toc_title":"Software"},{"children":[{"href":"api/get-user-related-alerts","toc_title":"Get user related alerts"},{"href":"api/get-user-related-machines","toc_title":"Get user related machines"}],"toc_title":"User"},{"children":[{"href":"api/vulnerability","toc_title":"Vulnerability properties"},{"href":"api/get-all-vulnerabilities","toc_title":"List vulnerabilities"},{"href":"api/get-all-vulnerabilities-by-machines","toc_title":"List vulnerabilities by machine and software"},{"href":"api/get-vulnerability-by-id","toc_title":"Get vulnerability by ID"},{"href":"api/get-machines-by-vulnerability","toc_title":"List machines by vulnerability"}],"toc_title":"Vulnerability"}],"toc_title":"Microsoft Defender for Endpoint APIs Schema"},{"children":[{"href":"api-microsoft-flow","toc_title":"Power Automate"},{"href":"api/api-power-bi","toc_title":"Power BI"},{"href":"api/run-advanced-query-sample-python","toc_title":"Advanced Hunting using Python"},{"href":"api/run-advanced-query-sample-powershell","toc_title":"Advanced Hunting using PowerShell"},{"href":"api/exposed-apis-odata-samples","toc_title":"Using OData Queries"},{"href":"api/exposed-apis-full-sample-powershell","toc_title":"Advanced Hunting with PowerShell API Guide"}],"toc_title":"How to use APIs - Samples"}],"toc_title":"Microsoft Defender for Endpoint API"},{"children":[{"href":"api/raw-data-export","toc_title":"Raw data streaming"},{"href":"api/raw-data-export-event-hub","toc_title":"Stream advanced hunting events to Azure Events hub"},{"href":"api/raw-data-export-storage","toc_title":"Stream advanced hunting events to your storage account"}],"toc_title":"Raw data streaming API"},{"children":[{"href":"configure-siem","toc_title":"Migrate from the MDE SIEM API to the Microsoft Defender XDR alerts API"},{"href":"troubleshoot-siem","toc_title":"Troubleshoot SIEM tool integration issues"}],"toc_title":"SIEM integration"},{"children":[{"href":"partner-applications","toc_title":"Partner applications"},{"href":"connected-applications","toc_title":"Connected applications"},{"href":"api/api-explorer","toc_title":"API explorer"}],"toc_title":"Partners \u0026 APIs"}],"toc_title":"Management and APIs"},{"children":[{"href":"configure-mssp-support","toc_title":"Configure managed security service provider integration"},{"href":"grant-mssp-access","toc_title":"Grant MSSP access to the portal"},{"href":"access-mssp-portal","toc_title":"Access the MSSP customer portal"},{"href":"configure-mssp-notifications","toc_title":"Configure alert notifications"},{"href":"api/exposed-apis-create-app-partners","toc_title":"Get partner application access"},{"href":"api/fetch-alerts-mssp","toc_title":"Fetch alerts from customer tenant"}],"toc_title":"Managed security service provider (MSSP) integration"},{"children":[{"href":"partner-integration","toc_title":"Technical partner opportunities"}],"toc_title":"Partner integration scenarios"},{"children":[{"href":"threat-protection-integration","toc_title":"Microsoft Defender for Endpoint integrations"},{"href":"conditional-access","toc_title":"Protect users, data, and devices with Conditional Access"},{"href":"microsoft-cloud-app-security-integration","toc_title":"Microsoft Defender for Cloud Apps integration overview"}],"toc_title":"Integrations"},{"children":[{"href":"/defender-xdr/microsoft-threat-actor-naming","toc_title":"Threat actor naming"},{"href":"/defender-xdr/malware-naming","toc_title":"Malware names"},{"href":"/defender-xdr/criteria","toc_title":"How Microsoft identifies malware and PUA"},{"href":"/defender-xdr/submission-guide","toc_title":"Submit files for analysis"},{"href":"/defender-xdr/portal-submission-troubleshooting","toc_title":"Troubleshoot MSI portal errors caused by admin block"},{"href":"/defender-xdr/virus-initiative-criteria","toc_title":"Microsoft virus initiative"},{"href":"/defender-xdr/developer-faq","toc_title":"Software developer FAQ"}],"toc_title":"Microsoft Security Resources"},{"children":[{"href":"malware/understanding-malware","toc_title":"Understanding malware"},{"href":"malware/coinminer-malware","toc_title":"Coinminers"},{"href":"malware/exploits-malware","toc_title":"Exploits and Exploit Kits"},{"href":"malware/fileless-threats","toc_title":"Fileless threats"},{"href":"malware/macro-malware","toc_title":"Macro threats"},{"href":"malware/phishing-trends","toc_title":"Phishing trends"},{"href":"malware/phishing","toc_title":"Phishing"},{"href":"malware/prevent-malware-infection","toc_title":"Prevent malware infection"},{"href":"malware/rootkits-malware","toc_title":"Rootkits"},{"href":"malware/supply-chain-malware","toc_title":"Supply chain malware"},{"href":"malware/support-scams","toc_title":"Support scams"},{"href":"malware/trojans-malware","toc_title":"Trojans"},{"href":"malware/unwanted-software","toc_title":"Unwanted software"},{"href":"malware/worms-malware","toc_title":"Worms"}],"toc_title":"Malware information"},{"href":"threat-indicator-concepts","toc_title":"Understand threat intelligence concepts"},{"children":[{"href":"whats-new-mde-archive","toc_title":"What\u0027s new archive"},{"href":"release-notes-mde-archive","toc_title":"Release notes archive"}],"toc_title":"Release notes archive"}],"toc_title":"Reference"},{"children":[{"href":"/defender","toc_title":"Microsoft Defender XDR"},{"href":"/defender-office-365","toc_title":"Defender for Office 365"},{"href":"/defender-for-identity/","toc_title":"Defender for Identity"},{"href":"/cloud-app-security/","toc_title":"Defender for Cloud Apps"},{"href":"/defender-business","toc_title":"Defender for Business"},{"href":"/defender-vulnerability-management","toc_title":"Defender Vulnerability Management"}],"toc_title":"Microsoft Defender XDR docs"}],"expanded":true,"href":"./","toc_title":"Microsoft Defender for Endpoint"}],"metadata":{"breadcrumb_path":"/defender-endpoint/breadcrumb/toc.json","count_of_node_with_href":637,"feedback_product_url":"https://techcommunity.microsoft.com/t5/security-compliance-and-identity/ct-p/MicrosoftSecurityandCompliance","feedback_system":"Standard","manager":"bagol","open_to_public_contributors":true,"permissioned-type":"public","searchScope":["Microsoft Defender Endpoint"],"titleSuffix":"Microsoft Defender for Endpoint","uhfHeaderId":"MSDocsHeader-MicrosoftDefender"}}