Forum Discussion

gilblumberg's avatar
gilblumberg
Iron Contributor
May 21, 2023

Updating the MDE.Windows extension

We have multiple servers running in Azure Arc onboarded into MDE using the MDE.Windows extension.

 

Just our luck to discover that Microsoft's documentation shows that that automatic extension upgrades are not available for this particular extension - https://learn.microsoft.com/en-gb/azure/azure-arc/servers/manage-automatic-vm-extension-upgrade?tabs=azure-portal#supported-extensions

 

Disappointing that this has to be performed manually. What method are others using to be alerted when an update is available and how are you updating it?

 

Assuming Azure Monitor for alerts and Powershell/Runbook for updating?

  • gilblumberg's avatar
    gilblumberg
    Iron Contributor

    UPDATE:

    It's taken quite a bit of back and forth with Microsoft support, and this is basically a summary:

    • Once on-boarded, the extension is not used or required to maintain MDE functionalities

    • Updating the extension in Azure Arc serves no purpose

    • When deleting the MDE.Windows/MDE.Linux extension, there is no impact to the Sensor software on the server

    • If integration with Microsoft Defender for Endpoint is enabled, and the extension is deleted, it will be promptly installed again.

    This last point I thought is particularly relevant (but not documented), as for for many organisations which have strict change-control procedures. The re-installation of the Sensor is effectively making a change on the server.

    In my case, not taking any action. If not for any other reason, keeping the integration enabled.

    (I submitted the bullet points above as feedback on the product page, so with any luck they'll agree it needs this key information)

Resources