Defender for Endpoint for Linux - View Threat Telemetry

Taranjeet Malik 546 Reputation points
2024-08-03T22:21:11.3533333+00:00

Hi

We have a fleet of around 1000 RHEL 7.2 systems that we wish to onboard to Microsoft Defender. There are a mix of DEV, Pre-Prod, PROD and run Web, DB + enterprise Apps for the business. We want to ensure that we can simply onboard them in a passive mode, i.e., enable Anti-virus in "Passive" mode as described here--> https://learn.microsoft.com/en-us/defender-endpoint/linux-preferences#enforcement-level-for-antivirus-engine

Since these are all critical servers, we want to ensure there's least business interruption of on boarding these devices to Defender. Therefore, want to clarify the following:

  1. If we on board these devices with AV set to "Passive", the AV will catch the threats / malicious actions, but will not take any action - is that correct?
  2. When we publish a Linux configuration profile using to Linux systems that's detailed here--> https://learn.microsoft.com/en-us/defender-endpoint/linux-preferences and if they have the AV set to "passive" mode, will they start reporting the alerts raised by AV component to Defender portal?
  3. What's the significance of this particular setting "Report AV Suspicious Events to EDR". Will it enable the threat / malicious detection telemetry for Linux endpoints to Defender portal? If yes, is there a way to filter this telemetry just for Linux systems?
  4. Is it fair to say that reviewing this telemetry provides all the information to plan what configuration profile for Linux (for example, what files/paths/actions are currently raising alerts, so we can review them and create appropriate exceptions)?
  5. Is there any recommendation from Microsoft around safe / good start when planning the configuration profile for Linux systems to ensure minimum business disruption?
  6. Is the guidance here common to all OSes (including Linux) or specific to Windows OS--> https://learn.microsoft.com/en-us/defender-endpoint/edr-in-block-mode?view=o365-worldwide

Thanks

Taranjeet Singh

Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
40 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.