Forum Discussion

Asheeshonroute's avatar
Asheeshonroute
Copper Contributor
Jan 13, 2024

Microsoft Defender for endpoint - device running in EDR block mode

Good day Team

On Microsoft Defender for endpoints - one of my device is running EDR in block mode in. We want to move out the device to make running in active mode. what are the steps to exit the device EDR from block mode to active mode. OS running on the device is Windows server 2019.

 

11 Replies

  • Asheeshonroute's avatar
    Asheeshonroute
    Copper Contributor
    As I looked over my MDE device's health status, I noticed that one of the device showing 'Defender Antivirus mode as EDR in block mode,' while the other devices are showing 'Defender Antivirus mode - active.' I would like assistance in enabling Defender Antivirus mode - active on the device.
    • HeikeRitter's avatar
      HeikeRitter
      Icon for Microsoft rankMicrosoft
      Looks like on the one device showing EDR block mode, there is 3rd party AV installed.
      Here is what the different modes mean:
      Active = Defender Antivirus is the primary AV - EDR block isn't relevant, as Defender Antivirus is active.
      Passive = Defender Antivirus isn't the primary and a 3rd party AV is
      EDR Block = the same as Passive but with EDR Block mode enabled, which means Defender Antivirus can 'wake up' and stop a threat if the 3rd party AV missed it.

      So you will either uninstall your 3rd party AV on that device, or leave it with EDR block enabled.
      • Asheeshonroute's avatar
        Asheeshonroute
        Copper Contributor

        "On the device, Sysmantec was initially installed but later uninstalled, and Defender Antivirus took over. However, a week later, the server status transitioned to EDR in block mode. I am seeking advice on troubleshooting the issue.

         

         

  • Hello, EDR in block mode is either set on the tenant level (all devices will have it enabled) or via a custom policy (CSPs) in Intune. What do you mean by saying "exit block mode to active mode"?

Resources