Replacing a third party AV with Defender for Cloud

Channing, Peter 0 Reputation points
2024-10-24T11:18:00.4433333+00:00

I'm in the process of rolling out Defender for Servers via Defender for Cloud subscription to onboarded ARC on-prem machines (Windows and Linux). The current solution uses a lot of file and folder exceptions. I've rolled out to a few test machines but i do not see anywhere to add any exceptions for these onboard machines.

I have found some MS instructions but they are not accurate - at least, I don't see the sections in the Cloud Portal that the instructions say I should see.

Is the only option for exceptions (we don't use Intune), GPOs in combination with the MDE sensor that is pushed to onboarded systems?

My concern is installing MDE via Defender for Cloud onboarding where an existing installation of McAfee is running which might impact performance. The instructions online to provide commands to confirm MDE is in passive mode (because there's already a scanning running) but those PS commands either do not work and error out or do not provide outage as described in the instructions.

Any assistance would be helpful!

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,421 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.