Forum Discussion
Windows Defender antivirus and Defender for Endpoint next-gen antivirus
- SteBeSecJun 03, 2021Iron ContributorI can recommend the following video to learn about the MDE features: https://www.youtube.com/watch?v=U7jWbXx_bmE
It's a bit older, but still give you great insights.- peterisJun 03, 2021Copper Contributor
SteBeSec still not clear for me. I perfectly understand that MDE adds additional features besides tradional antivirus.
But this link (https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/microsoft-defender-antivirus-in-windows-10?view=o365-worldwide) states that MDE includes "Next-generation protection".
I have read further and understood, that MDE includes PUA (potentially unwanted application) detection. As well as it includes BAFS (Block at first sight) feature. And also there is dynamic emergency updates feature (Cloud-delivered protection and Microsoft Defender Antivirus | Microsoft Docs).
Are these available without MDE?
- Shane CurtisOct 23, 2021Copper ContributorI have been struggling with this question lately myself, i.e., do you actually get something more out of Microsoft Defender Antivirus through MDE that you do not get when you simply manage Microsoft Defender AV with Intune on a Windows 10 machine. Is there a difference between Microsoft Defender Antivirus and Next Generation Protection? Microsoft needs to be a lot more clear about this. I have the same question about a lot of the Attack Surface Reduction technologies. They are mostly all built into Windows 10 and can be managed with Intune. So what does MDE give me really? It makes MDE Plan 1 a hard sell. The only benefit I can see is that they feed into the M365 Defender portal so you can see alerts.
- SteBeSecJun 03, 2021Iron Contributor
If you ask me: Yes. With MDE, you get the whole EDR/XDR part, post breach functionality, custom indicators, Advanced hunting, Reportingcapabilities via API and so on.
With only Defender AV built in Windows 10, you are missing all the features mentioned above and if you are also missing SCCM or Intune, you don't have the possibility to manage Defender , it updates and its detections. Only the Defender Settings can be distributed via GPO.
Hope this answers your question.