Notatka
Dostęp do tej strony wymaga autoryzacji. Może spróbować zalogować się lub zmienić katalogi.
Dostęp do tej strony wymaga autoryzacji. Możesz spróbować zmienić katalogi.
Ten artykuł zawiera przykłady kodu programu PowerShell umożliwiające włączanie i konfigurowanie ochrony przed złośliwym kodem firmy Microsoft dla różnych usług Azure, w tym:
- Maszyny wirtualne Azure Resource Manager
- Klastry Azure Service Fabric
- Azure Cloud Services (rozszerzona pomoc techniczna)
- serwery z obsługą Azure Arc
Wykorzystaj te przykłady do wdrożenia i skonfigurowania rozszerzenia Microsoft Antimalware w środowiskach Azure.
Wdrażanie oprogramowania firmy Microsoft chroniącego przed złośliwym kodem na maszynach wirtualnych Azure Resource Manager
Uwaga / Notatka
Zanim uruchomisz ten przykładowy fragment kodu, odkomentuj zmienne i podaj odpowiednie wartości.
Ostrzeżenie
Wdrażanie lub aktualizowanie tego rozszerzenia zastępuje istniejące ustawienia programu antywirusowego Microsoft Defender, w tym wykluczenia. Aby zachować ustawienia, określ je w konfiguracji rozszerzenia. Aby uzyskać więcej informacji, zobacz Domyślna i Niestandardowa konfiguracja ochrony przed złośliwym kodem.
# Script to add Microsoft Antimalware extension to Azure Resource Manager VMs
# Specify your subscription ID
$subscriptionId= " SUBSCRIPTION ID HERE "
# Specify location, resource group, and VM for the extension
$location = " LOCATION HERE " # For example, "Southeast Asia" or "Central US"
$resourceGroupName = " RESOURCE GROUP NAME HERE "
$vmName = " VM NAME HERE "
# Enable Antimalware with default policies
$settingString = '{"AntimalwareEnabled": true}'
# Enable Antimalware with custom policies
# $settingString = '{
# "AntimalwareEnabled": true,
# "RealtimeProtectionEnabled": true,
# "ScheduledScanSettings": {
# "isEnabled": true,
# "day": 0,
# "time": 120,
# "scanType": "Quick"
# },
# "Exclusions": {
# "Extensions": ".ext1,.ext2",
# "Paths":"",
# "Processes":"sampl1e1.exe, sample2.exe"
# },
# "SignatureUpdates": {
# "FileSharesSources": "",
# "FallbackOrder": "",
# "ScheduleDay": 0,
# "UpdateInterval": 0,
# },
# "CloudProtection": true
#
# }'
# Sign in to Azure and select the subscription to use
Connect-AzAccount
Set-AzContext -SubscriptionId $subscriptionId
# Retrieve the most recent version number of the extension
$allVersions = (Get-AzVMExtensionImage -Location $location -PublisherName "Microsoft.Azure.Security" -Type "IaaSAntimalware").Version
$versionString = $allVersions[($allVersions.Count)-1].Split(".")[0] + "." + $allVersions[($allVersions.Count)-1].Split(".")[1]
# Set the extension by using prepared values
Set-AzVMExtension -ResourceGroupName $resourceGroupName -Location $location -VMName $vmName -Name "IaaSAntimalware" -Publisher "Microsoft.Azure.Security" -ExtensionType "IaaSAntimalware" -TypeHandlerVersion $versionString -SettingString $settingString
Dodaj Microsoft Antimalware do klastrów Azure Service Fabric
Azure Service Fabric wykorzystuje zestawy skalowania maszyn wirtualnych Azure do tworzenia klastrów Service Fabric. Szablon zestawów skalowania maszyn wirtualnych, który tworzy klastry Service Fabric, nie jest aktywowany w rozszerzeniu Antimalware. Włącz osobno ochronę przed złośliwym oprogramowaniem w zestawach skalowania. Po włączeniu tej opcji dla zestawów skalowania wszystkie węzły utworzone w zestawach skalowania maszyn wirtualnych automatycznie dziedziczą to rozszerzenie.
Poniższy przykład kodu pokazuje, jak włączyć rozszerzenie IaaS Antimalware za pomocą cmdletów PowerShell Az.Compute.
Uwaga / Notatka
Przed uruchomieniem tego przykładowego fragmentu kodu odkomentuj zmienne i podaj odpowiednie wartości.
Ostrzeżenie
Wdrażanie lub aktualizowanie tego rozszerzenia zastępuje istniejące ustawienia programu antywirusowego Microsoft Defender, w tym wykluczenia. Aby zachować ustawienia, określ je w konfiguracji rozszerzenia. Aby uzyskać więcej informacji, zobacz Domyślna i Niestandardowa konfiguracja ochrony przed złośliwym kodem.
# Script to add Microsoft Antimalware extension to a virtual machine scale set (VMSS) and Service Fabric cluster
# Sign in to Azure and select the subscription to use
Connect-AzAccount
# Specify your subscription ID
$subscriptionId="SUBSCRIPTION ID HERE"
Set-AzContext -SubscriptionId $subscriptionId
# Specify location, resource group, and VMSS for the extension
$location = "LOCATION HERE" # For example, "West US", "Southeast Asia", or "Central US"
$resourceGroupName = "RESOURCE GROUP NAME HERE"
$vmScaleSetName = "YOUR VM SCALE SET NAME"
# Customize the configuration.json configuration file according to the documentation: https://msdn.microsoft.com/library/dn771716.aspx
$settingString = '{"AntimalwareEnabled": true}'
# Enable Antimalware with custom policies
# $settingString = '{
# "AntimalwareEnabled": true,
# "RealtimeProtectionEnabled": true,
# "ScheduledScanSettings": {
# "isEnabled": true,
# "day": 0,
# "time": 120,
# "scanType": "Quick"
# },
# "Exclusions": {
# "Extensions": ".ext1,.ext2",
# "Paths":"",
# "Processes":"sampl1e1.exe, sample2.exe"
# } ,
# "SignatureUpdates": {
# "FileSharesSources": "",
# "FallbackOrder": "",
# "ScheduleDay": 0,
# "UpdateInterval": 0,
# },
# "CloudProtection": true
# }'
# Retrieve the most recent version number of the extension
$allVersions = (Get-AzVMExtensionImage -Location $location -PublisherName "Microsoft.Azure.Security" -Type "IaaSAntimalware").Version
$versionString = $allVersions[($allVersions.Count)-1].Split(".")[0] + "." + $allVersions[($allVersions.Count)-1].Split(".")[1]
$vmss = Get-AzVmss -ResourceGroupName $resourceGroupName -VMScaleSetName $vmScaleSetName
Add-AzVmssExtension -VirtualMachineScaleSet $vmss -Name "IaaSAntimalware" -Publisher "Microsoft.Azure.Security" -Type "IaaSAntimalware" -TypeHandlerVersion $versionString -Setting $settingString
Update-AzVmss -ResourceGroupName $resourceGroupName -VMScaleSetName $vmScaleSetName -VirtualMachineScaleSet $vmss
Dodaj Microsoft Antimalware do Azure Cloud Services, korzystając z rozszerzonego wsparcia
Poniższy przykład kodu pokazuje, jak dodać lub skonfigurować Microsoft Antimalware do Azure Cloud Services, korzystając z rozszerzonego wsparcia za pomocą cmdletów PowerShell.
Uwaga / Notatka
Zanim uruchomisz ten przykładowy fragment kodu, odkomentuj zmienne i podaj odpowiednie wartości.
Ostrzeżenie
Wdrażanie lub aktualizowanie tego rozszerzenia zastępuje istniejące ustawienia programu antywirusowego Microsoft Defender, w tym wykluczenia. Aby zachować ustawienia, określ je w konfiguracji rozszerzenia. Aby uzyskać więcej informacji, zobacz Domyślna i Niestandardowa konfiguracja ochrony przed złośliwym kodem.
# Create an Antimalware extension object, where file is AntimalwareSettings
$xmlconfig = [IO.File]::ReadAllText("C:\path\to\file.xml")
$extension = New-AzCloudServiceExtensionObject -Name "AntimalwareExtension" -Type "PaaSAntimalware" -Publisher "Microsoft.Azure.Security" -Setting $xmlconfig -TypeHandlerVersion "1.5" -AutoUpgradeMinorVersion $true
# Get existing Cloud Service
$cloudService = Get-AzCloudService -ResourceGroup "ContosOrg" -CloudServiceName "ContosoCS"
# Add Antimalware extension to existing Cloud Service extension object
$cloudService.ExtensionProfile.Extension = $cloudService.ExtensionProfile.Extension + $extension
# Update Cloud Service
$cloudService | Update-AzCloudService
Oto przykład prywatnego pliku XML konfiguracyjnego:
<?xml version="1.0" encoding="utf-8"?>
<AntimalwareConfig
xmlns:i="http://www.w3.org/2001/XMLSchema-instance">
<AntimalwareEnabled>true</AntimalwareEnabled>
<RealtimeProtectionEnabled>true</RealtimeProtectionEnabled>
<ScheduledScanSettings isEnabled="true" day="1" time="120" scanType="Full" />
<Exclusions>
<Extensions>
<Extension>.ext1</Extension>
<Extension>.ext2</Extension>
</Extensions>
<Paths>
<Path>c:\excluded-path-1</Path>
<Path>c:\excluded-path-2</Path>
</Paths>
<Processes>
<Process>excludedproc1.exe</Process>
<Process>excludedproc2.exe</Process>
</Processes>
</Exclusions>
</AntimalwareConfig>
Dodawanie oprogramowania firmy Microsoft chroniącego przed złośliwym kodem dla serwerów z obsługą Azure Arc
Poniższy przykładowy kod pokazuje, jak dodać Microsoft Antimalware dla serwerów obsługujących Azure Arc za pomocą cmdletów PowerShell.
Uwaga / Notatka
Przed uruchomieniem tego przykładowego fragmentu kodu odkomentuj zmienne i podaj odpowiednie wartości.
# Before you use Azure PowerShell to manage VM extensions on your hybrid server managed by Azure Arc-enabled servers, install the Az.ConnectedMachine module. Run the following command on your Azure Arc-enabled server:
# If Az.ConnectedMachine is installed, ensure the version is at least 0.4.0
Install-Module -Name Az.ConnectedMachine
Import-Module -Name Az.ConnectedMachine
# Specify location, resource group, and machine for the extension
$subscriptionid =" SUBSCRIPTION ID HERE "
$location = " LOCATION HERE " # For example, "Southeast Asia" or "Central US"
$resourceGroupName = " RESOURCE GROUP NAME HERE "
$machineName = "MACHINE NAME HERE "
# Enable Antimalware with default policies
$setting = @{"AntimalwareEnabled"=$true}
# Enable Antimalware with custom policies
$setting2 = @{
"AntimalwareEnabled"=$true;
"RealtimeProtectionEnabled"=$true;
"ScheduledScanSettings"= @{
"isEnabled"=$true;
"day"=0;
"time"=120;
"scanType"="Quick"
};
"Exclusions"= @{
"Extensions"=".ext1, .ext2";
"Paths"="";
"Processes"="sampl1e1.exe, sample2.exe"
};
"SignatureUpdates"= @{
"FileSharesSources"="";
"FallbackOrder"="";
"ScheduleDay"=0;
"UpdateInterval"=0;
};
"CloudProtection"=$true
}
# Sign in to Azure
Connect-AzAccount
# Enable Antimalware with the policies
New-AzConnectedMachineExtension -Name "IaaSAntimalware" -ResourceGroupName $resourceGroupName -MachineName $machineName -Location $location -SubscriptionId $subscriptionid -Publisher "Microsoft.Azure.Security" -Settings $setting -ExtensionType "IaaSAntimalware"