Forum Discussion
Defender for Endpoint on Linux
I'm using the Linux version of the defender agent on RHEL 8.
The intended setup is, The agents are registered to the Defender cloud. And we have enabled the InTune to Defender connector. So when you register your endpoint, it should also create a skeleton registration in Intune so it can manage the Linux policy.
I've got that setup. However, If you need to make quick, perhaps unscheduled changes to your Linux MDATP profile. How do you do it? As it seems to be based on when the endpoint checks in with Intune. Which Intune does between 4-6 hours.
Some of the docs I read, said just make the change to the .json config on the client. Then Intune will reapply the update policy when it checks the agent in.
Ok, but if you have enabled the anti tamper feature on the agents. How do you then update the .json file? It's just going to block you from doing that