Forum Discussion

Robdog24's avatar
Robdog24
Copper Contributor
Oct 30, 2022

AIR vs Block Mode vs AV

What is the actual difference between those 3?

 

https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/edr-in-block-mode?view=o365-worldwide#do-i-need-to-turn-edr-in-block-mode-on-if-i-have-microsoft-defender-antivirus-running-on-devices FAQ answer suggests Block mode uses the AV capability, as it states:
There is minimal benefit in enabling EDR in block mode when Microsoft Defender Antivirus is in active mode, because real-time protection is expected to catch and remediate detections first. 

 

The video on the same page shows the below illustration and explains blocking is applied to EDR detections after they have detected a malicious artifact.

If this is true, and assuming block mode applies to all EDR detections:

  1. How is the EDR block different to AIR threat remediation?
  2. How do EDR differ from AV detections, since there is minimal benefit of block mode when Defender AV is enabled?

Much appreciate any help on clarifying this!

 

No RepliesBe the first to reply