Forum Discussion

PeDe's avatar
PeDe
Brass Contributor
Jul 27, 2021

2012R2 not Reporting Test Alerts (Eicar/Powershell)

Hi,
im currently running a POC for MS Defender for Endpoint on Servers
* Windows Server 2012R2, 2016,2019
* Outbound Communications
   2019 uses a special proxy for Telemetry-Data
   2012R2 and 2016 use an OMS gateway (no telemetry)
* 2012R2 have SCEP installed
* Updates are applied by WSUS

ISSUE:
When i create an eicar on a 2012R2 it´s detected and quarantined. I see the Filecreation in the timeline in the Security.microsoft.com but i get no alert and that it´s an Eicar.

With 2016 and 2019 it works as expected.
Any ideas why?

  • Had a MS Technical Specialists and a PFE on the phone today discusing the situation with our 2012R2 Servers. Thanks to you 2 😉
    MAPS does not use Monitoring Agent over the OMS-Gateway to the securitycenter.
    you definetly need a proxy to be configured in order to get MAPS working with security.microsoft.com.

     

    Sum Up:

  • PeDe's avatar
    PeDe
    Brass Contributor

    Had a MS Technical Specialists and a PFE on the phone today discusing the situation with our 2012R2 Servers. Thanks to you 2 😉
    MAPS does not use Monitoring Agent over the OMS-Gateway to the securitycenter.
    you definetly need a proxy to be configured in order to get MAPS working with security.microsoft.com.

     

    Sum Up:

Resources