Forum Discussion

drivesafely's avatar
drivesafely
Brass Contributor
Nov 20, 2024

MDE disable settings

Hello All,

As devices are onboarded to Microsoft Defender for Endpoint and policies are enforced, it’s crucial to establish prompt troubleshooting mechanisms. Kindly provide insights on the following steps:  

1. Disabling Tamper Protection and Real-Time Protection:  
   How can these settings, enforced by policy, be turned off on a device in the shortest time frame?  

2. Offboarding Devices and Policy Removal:  
   - Does offboarding a device immediately remove all applied policies?  
   - If not, how long does it typically take for policies to clear from the device after offboarding?  

3. Uninstalling Defender:  
   What is the recommended process for completely uninstalling Microsoft Defender from a device?  

Your guidance on executing these actions efficiently would be highly valuable.  

Regards,

  • TSaL's avatar
    TSaL
    Copper Contributor
    1. Disabling TP from security.microsoft is pretty fast at most just a few minutes.
    2. Yes, probably fast if you rebooted after.
    3. If this is for Windows Server. I would remove feature, and add GPO setting to disable windefend.

Resources