SOC experience Hybrid identities Endpoints and IoT Email and collaboration Cloud apps Data Prevent Reduce attack surface with threat-based configuration recommendations and built-in vulnerability management Protect Automatically contain and remediate compromised assets Detect and respond Use incidents to respond to cross-workload threats from a single portal Speed up response with an experience designed for SOC efficiency Extend Unified APIs and connectors
encrypted on additional hosts Browse to a website Phishing mail Open attachment Click a URL Command & Control User account is compromised Brute force account or use stolen account credentials Attacker compromises a privileged account Domain compromised Attacker exfiltrates sensitive data Attacker collects reconnaissance & configuration data Email Endpoints Identities Workloads Exploitation & Installation External Threats Externally exposed vulnerabilities Microsoft Threat Intelligence Microsoft EASM Defender for Office 365 Defender for Endpoint Defender for IOT (&OT) Defender for Cloud Defender for Identity Defender for Cloud Apps Entra ID Microsoft Defender for Identity Sentinel Microsoft
Defender security settings • Enforced from the MDE cloud, even against local admins Why • Stops attackers from disabling protections after gaining local admin access • Prevents misconfigurations caused by scripts, GPOs, or manual actions • Ensures security posture consistency across all onboarded devices How • Enforced from the Microsoft Defender for Endpoint cloud • Overrides local changes made via registry, PowerShell, GPO, or third-party tools • Applies automatically to all supported devices once enabled at tenant level
attacks • Files submission for cloud analysis • Detonation • Big data analysis with Machine learning • Block at first sight (BAFS) • Integrations with MDE • Tamper protection • EDR block mode • IoC https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/enable-cloud-protection-microsoft-defender-antivirus?view=o365-worldwide
Administrative Templates > Windows Components > Data Collection and Preview Builds • Configure Authenticated Proxy usage for the Connected User Experience and Telemetry Service • Configure connected user experiences and telemetry Defender AV • Winhttp using NETSH • GPO Administrative Templates > Windows Components > Microsoft Defender Antivirus • Define proxy server for connecting to the network
Windows Server 2016 and later • Built-in exclusions for operating system files in all versions of Windows • Custom exclusions for files and folders that you specify, if necessary
(files open by a process) Exclusions for files, folders, and extensions will be skipped by scheduled scans, on-demand scans, real-time protection and some ASR Rules.
(files open by a process) Exclusions for process-opened files won't be scanned by real-time protection and Network Protection. Exclusions for process-opened files are still subject to quick, full, or on-demand antivirus scans.
multiple exclusions using different tools Using incorrect environment variables as wildcards Exclude known folder locations, file extensions and processes
Smart Screen filtering enabled • The website https://www.linkedin.com is blocked on Edge • The website https://www.linkedin.com is not blocked on Chrome
Available on third party OS IP is supported for all three protocols TCP, HTTP, and HTTPS (TLS) Audit or Block Mode Windows Defender SmartScreen Only for Microsoft browser Microsoft Defender Browser Protection Plug-in (optional)
enabled • Cloud-delivered protection is active • Platform Update version 4.18.2001.x.x or newer (Unified Agent) • Enabled via PowerShell/GPO/SCCM/Intune • For Windows Servers and Windows Multi-session, there are additional items that you must enable: • AllowNetworkProtectionDownLevel (dword) 1 (hex) • AllowNetworkProtectionOnWinServer (dword) 1 (hex) • EnableNetworkProtection (dword) 1 (hex)
Web Content Filtering Stops web threats without a web proxy Protect devices while they are away or on premises Web threats • SmartScreen Intel • Exchange Online Protection
and regulate access to websites based on their content categories. Support audit/block and device group assignment. Categories: • Adult websites • Legal Liability • High Bandwidth • Leisure • Uncategorized Web Content Filtering
I don’t need to update MDAV… Update KB Description Update for Defender antimalware platform (AmProductVersion) KB4052623 This update adds new features and fixes Security Intelligence updates KB2267602 Security Intelligence Updates/ Signature updates Update for EDR sensor (2012R2/ 2016) KB5005292 Updates and fixes to the EDR sensor that is used by MDE for 2012R2/ 2016 FALSE!!! MDAV must be updated!
and may be updated as needed. It has been prepared for educational and informational purposes only. In the event of any discrepancy between the content of this presentation and official documentation, the official documentation shall take precedence.