Forum Discussion
Asheeshonroute
Jan 13, 2024Copper Contributor
Microsoft Defender for endpoint - device running in EDR block mode
Good day Team On Microsoft Defender for endpoints - one of my device is running EDR in block mode in. We want to move out the device to make running in active mode. what are the steps to exit the de...
Asheeshonroute
Jan 16, 2024Copper Contributor
"On the device, Sysmantec was initially installed but later uninstalled, and Defender Antivirus took over. However, a week later, the server status transitioned to EDR in block mode. I am seeking advice on troubleshooting the issue.
HeikeRitter
Microsoft
Jan 17, 2024Can you please run this command and share the results? https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/edr-block-mode-faqs?view=o365-worldwide#how-do-i-confirm-microsoft-defender-antivirus-is-in-active-or-passive-mode-
I am suspecting, that Defender AV did not register properly as the primary AV (for whatever reason)
I am suspecting, that Defender AV did not register properly as the primary AV (for whatever reason)
- AsheeshonrouteFeb 07, 2024Copper ContributorHere is the output:
PS C:\WINDOWS\system32> Get-MpComputerStatus
AMEngineVersion : 1.1.23110.2
AMProductVersion : 4.18.23110.3
AMRunningMode : Normal
AMServiceEnabled : True
AMServiceVersion : 4.18.23110.3
AntispywareEnabled : True
AntispywareSignatureAge : 0
AntispywareSignatureLastUpdated : 2024-02-07 05:23:14 AM
AntispywareSignatureVersion : 1.403.3357.0
AntivirusEnabled : True
AntivirusSignatureAge : 0
AntivirusSignatureLastUpdated : 2024-02-07 05:23:13 AM
AntivirusSignatureVersion : 1.403.3357.0
BehaviorMonitorEnabled : True
ComputerID : XXXXXXXXXXXXXXXXXXXXXXXX
ComputerState : 0
DefenderSignaturesOutOfDate : False
DeviceControlDefaultEnforcement :
DeviceControlPoliciesLastUpdated : 2023-03-03 08:07:12 AM
DeviceControlState : Disabled
FullScanAge : 29
FullScanEndTime : 2024-01-08 04:05:21 PM
FullScanOverdue : False
FullScanRequired : False
FullScanSignatureVersion : 1.403.1830.0
FullScanStartTime : 2024-01-08 03:31:09 PM
InitializationProgress : ServiceStartedSuccessfully
IoavProtectionEnabled : True
IsTamperProtected : False
IsVirtualMachine : True
LastFullScanSource : 1
LastQuickScanSource : 1
NISEnabled : True
NISEngineVersion : 1.1.23110.2
NISSignatureAge : 0
NISSignatureLastUpdated : 2024-02-07 05:23:13 AM
NISSignatureVersion : 1.403.3357.0
OnAccessProtectionEnabled : True
ProductStatus : 524416
QuickScanAge : 57
QuickScanEndTime : 2023-12-11 02:43:22 PM
QuickScanOverdue : True
QuickScanSignatureVersion : 1.403.317.0
QuickScanStartTime : 2023-12-11 02:42:12 PM
RealTimeProtectionEnabled : True
RealTimeScanDirection : 0
RebootRequired : False
SmartAppControlExpiration :
SmartAppControlState : Off
TamperProtectionSource : Signatures
TDTMode : N/A
TDTSiloType : N/A
TDTStatus : N/A
TDTTelemetry : N/A
TroubleShootingDailyMaxQuota : 480
TroubleShootingDailyQuotaLeft : 480
TroubleShootingEndTime : INFINITE
TroubleShootingExpirationLeft : INFINITE
TroubleShootingMode : Disabled
TroubleShootingModeSource : Service
TroubleShootingQuotaResetTime : N/A
TroubleShootingStartTime : N/A
PSComputerName : - AsheeshonrouteFeb 07, 2024Copper ContributorHey Heike
Here is the result / output ---
PS C:\WINDOWS\system32> Get-MpComputerStatus
AMEngineVersion : 1.1.23110.2
AMProductVersion : 4.18.23110.3
AMRunningMode : Normal
AMServiceEnabled : True
AMServiceVersion : 4.18.23110.3
AntispywareEnabled : True
AntispywareSignatureAge : 0
AntispywareSignatureLastUpdated : 2024-02-07 05:23:14 AM
AntispywareSignatureVersion : 1.403.3357.0
AntivirusEnabled : True
AntivirusSignatureAge : 0
AntivirusSignatureLastUpdated : 2024-02-07 05:23:13 AM
AntivirusSignatureVersion : 1.403.3357.0
BehaviorMonitorEnabled : True
ComputerID : XXXXXXXXXXXXXXXXXXXXXXXX
ComputerState : 0
DefenderSignaturesOutOfDate : False
DeviceControlDefaultEnforcement :
DeviceControlPoliciesLastUpdated : 2023-03-03 08:07:12 AM
DeviceControlState : Disabled
FullScanAge : 29
FullScanEndTime : 2024-01-08 04:05:21 PM
FullScanOverdue : False
FullScanRequired : False
FullScanSignatureVersion : 1.403.1830.0
FullScanStartTime : 2024-01-08 03:31:09 PM
InitializationProgress : ServiceStartedSuccessfully
IoavProtectionEnabled : True
IsTamperProtected : False
IsVirtualMachine : True
LastFullScanSource : 1
LastQuickScanSource : 1
NISEnabled : True
NISEngineVersion : 1.1.23110.2
NISSignatureAge : 0
NISSignatureLastUpdated : 2024-02-07 05:23:13 AM
NISSignatureVersion : 1.403.3357.0
OnAccessProtectionEnabled : True
ProductStatus : 524416
QuickScanAge : 57
QuickScanEndTime : 2023-12-11 02:43:22 PM
QuickScanOverdue : True
QuickScanSignatureVersion : 1.403.317.0
QuickScanStartTime : 2023-12-11 02:42:12 PM
RealTimeProtectionEnabled : True
RealTimeScanDirection : 0
RebootRequired : False
SmartAppControlExpiration :
SmartAppControlState : Off
TamperProtectionSource : Signatures
TDTMode : N/A
TDTSiloType : N/A
TDTStatus : N/A
TDTTelemetry : N/A
TroubleShootingDailyMaxQuota : 480
TroubleShootingDailyQuotaLeft : 480
TroubleShootingEndTime : INFINITE
TroubleShootingExpirationLeft : INFINITE
TroubleShootingMode : Disabled
TroubleShootingModeSource : Service
TroubleShootingQuotaResetTime : N/A
TroubleShootingStartTime : N/A
PSComputerName :