ATP need Defender or not?

Copper Contributor

Hello, my company is planning to deploy ATP for all servers.

While currently only Windows 2019 servers are using Windows Defender as antivirus.

Other Windows Servers and all Linux servers are using a 3rd party antivirus software.

 

Could any one help me for some questions.

Do I need enable defender on Windows 2012 and Windows 2016 servers?

Do I need install Defender on Linux servers?

If I need full function of ATP, do I need use Defender as antivirus software?

Or if I installed Defender, but didn't use it for antivirus, will ATP failed to work, or loss some function?

 

Thanks.

1 Reply
MDE minimum requirement section covers supported OS version https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/minimum-requirements?view=...
Do I need enable defender on Windows 2012 and Windows 2016 servers, install Defender on Linux servers? - Defender can be enabled on Windows Server 2012 R2(Not 2012). if you want to enable Endpoint protection for Windows 2012 then you can use system center endpoint protection as AV. There is new MDE onboarding method available for Windows Server 2012 R2 and 2016. Refer: https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/defending-windows-server-2012... . For Linux, you can refer the above (first) link for supported linux server distribution.
If I need full function of ATP, do I need use Defender as antivirus software? Or if I installed Defender, but didn't use it for antivirus, will ATP failed to work, or loss some function? - MDE, Defender AV provides EDR and AV capabilities. If you are availing only EDR then you may miss some feature that Defender AV is offering. Microsoft Defender Antivirus is built into Windows, and it works with Microsoft Defender for Endpoint to provide protection on device and in the cloud.
Defender can co-exist with your existing endpoint protection meaning third-party AV can run in active mode and Defender can run in passive mode. Refer https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/edr-in-block-mode?view=o36...