Forum Discussion
Jean-Philippe Breton
Nov 26, 2021Iron Contributor
Question about testing SpyShelter
We are currently building a PoC for a customer. We are about 100 Windows 10 onboard into MDE. Customer is in healthcare thus many users have local Admin privilege. During a test phase, custo...
mas18
Nov 26, 2021Brass Contributor
Do you have any other endpoint protection solution also running in the Machine ? If you have other endpoint protection running as primary then you may need to enable EDR in Block mode but you will have limited edr capabilities while running defender in passive mode.
Jean-Philippe Breton
Nov 27, 2021Iron Contributor
No other Endpoint, except the MDE stack (Defender AV/ SmartScreen)
Pure Microsoft
No passive mode.
EDR in Block Mode is also enable.
Pure Microsoft
No passive mode.
EDR in Block Mode is also enable.
- mas18Nov 28, 2021Brass ContributorDoes events are coming in device timeline ?does mde client analyser tool results shows any connectivity issue between client and mde cloud?
- Jean-Philippe BretonNov 29, 2021Iron ContributorThere is no issue between MDE client and cloud. Have you tried https://www.spyshelter.com/security-test-tool/ ?
- Jean-Philippe BretonNov 29, 2021Iron ContributorSo customer has EDR block mode = OFF. Even thought there is no third party, I set it to ON. And boom re-running again SpyShelter did triigger all the Alerts 🙂
After some digging. many person did mention that setting EDR in block mode to ON did help to have more granular alert.