Defender Antivirus and Microsoft Defender for Endpoint (ATP) for Servers

%3CLINGO-SUB%20id%3D%22lingo-sub-2158738%22%20slang%3D%22en-US%22%3EDefender%20Antivirus%20and%20Microsoft%20Defender%20for%20Endpoint%20(ATP)%20for%20Servers%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2158738%22%20slang%3D%22en-US%22%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHi%20All%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOur%20company%20is%20looking%20into%20migrating%20our%20antivirus%20solution%20for%20our%20server%20estate%20from%20Sophos%20to%20Microsoft%20Defender%20Antivirus%20and%20Microsoft%20Defender%20for%20Endpoint%20(ATP).%20Was%20hoping%20to%20get%20some%20advice%20on%20the%20best%20way%20to%20approach%20this.%20I%20have%20listed%20some%20points%20below%20which%20I%20was%20hoping%20to%20get%20some%20clarity%20on.%3C%2FP%3E%3CP%3E%3CBR%20%2F%3E-%20Servers%20that%20are%20considered%20as%20%E2%80%9Cdown-level%20devices%E2%80%9D%20that%20do%20not%20have%20MS%20Defender%20preinstalled%20by%20default%20i.e.%202008R2%2C%202012%20and%202012R2%20what%20would%20the%20best%20Microsoft%20solution%20to%20provide%20security.%20Have%20been%20looking%20at%20Microsoft%E2%80%99s%20System%20Center%20Endpoint%20Protection%20(SCEP)%20as%20a%20solution.%20Is%20there%20any%20services%20that%20can%20be%20used%20from%20Azure%20to%20protect%20on-prem%20servers%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E-%20We%20have%20a%20Hybrid%20Azure%20AD%20setup.%20None%20of%20our%20on-premise%20servers%20are%20HAADJ.%20Do%20we%20need%20to%20have%20server%20as%20a%20Azure%20resource%20for%20us%20to%20manage%20Defender%20AV%20and%20ATP%20(Server%202016%20%2B).%20We%20currently%20manage%20our%20W10%20workstation%20using%20the%20MEM%20-%20Microsoft%20Defender%20for%20Endpoint%20Baseline.%3CBR%20%2F%3E%3CBR%20%2F%3E-%20Majority%20of%20our%20servers%20do%20not%20have%20any%20internet%20access.%20To%20tighten%20the%20firewall%20rule%2C%20is%20there%20a%20list%20of%20IPs%20and%20URLs%20that%20are%20associated%20with%20Defender%20ATP%20so%20the%20servers%20can%20only%20communicate%20to%20these%20IPs%20etc.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E-%20Is%20there%20any%20pre-req%20work%20needed%20for%20servers%20such%20as%202008R2%2C%202012%20and%202012R2%20before%20on-boarding%20to%20ATP.%20Install%20updates%2C%20telemetry%20services%20updates%20etc%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E-%20Anyone%20that%20is%20using%20defender%20ATP%20for%20servers%20that%20are%20on-prem.%20What%20type%20of%20setup%20do%20you%20have%20and%20any%20recommendations.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%3C%2FP%3E%3CP%3EMo%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2158738%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EATP%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EDefender%20Antivirus%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EDefender%20for%20Endpoint%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EDown-Level%20Devices%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EServers%20Onboarding%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2241430%22%20slang%3D%22en-US%22%3ERe%3A%20Defender%20Antivirus%20and%20Microsoft%20Defender%20for%20Endpoint%20(ATP)%20for%20Servers%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2241430%22%20slang%3D%22en-US%22%3EIn%20regards%20to%20your%20first%20question%2C%20you%20can%20use%20Azure%20Arc%20to%20register%20your%20old%20servers%2C%20then%20use%20Azure%20Security%20Center%20to%20evaluate%20their%20security%20posture%2C%20When%20you%20do%20this%2C%20those%20machines%20get%20Defender%20for%20Endpoint%20automatically%2C%20see%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fdefender-for-servers-introduction%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fdefender-for-servers-introduction%3C%2FA%3E%20to%20get%20started%3C%2FLINGO-BODY%3E
Occasional Contributor

 

Hi All,

 

Our company is looking into migrating our antivirus solution for our server estate from Sophos to Microsoft Defender Antivirus and Microsoft Defender for Endpoint (ATP). Was hoping to get some advice on the best way to approach this. I have listed some points below which I was hoping to get some clarity on.


- Servers that are considered as “down-level devices” that do not have MS Defender preinstalled by default i.e. 2008R2, 2012 and 2012R2 what would the best Microsoft solution to provide security. Have been looking at Microsoft’s System Center Endpoint Protection (SCEP) as a solution. Is there any services that can be used from Azure to protect on-prem servers?

 

- We have a Hybrid Azure AD setup. None of our on-premise servers are HAADJ. Do we need to have server as a Azure resource for us to manage Defender AV and ATP (Server 2016 +). We currently manage our W10 workstation using the MEM - Microsoft Defender for Endpoint Baseline.

- Majority of our servers do not have any internet access. To tighten the firewall rule, is there a list of IPs and URLs that are associated with Defender ATP so the servers can only communicate to these IPs etc.

 

- Is there any pre-req work needed for servers such as 2008R2, 2012 and 2012R2 before on-boarding to ATP. Install updates, telemetry services updates etc

 

- Anyone that is using defender ATP for servers that are on-prem. What type of setup do you have and any recommendations.

 

Thank you

Mo

1 Reply
In regards to your first question, you can use Azure Arc to register your old servers, then use Azure Security Center to evaluate their security posture, When you do this, those machines get Defender for Endpoint automatically, see https://docs.microsoft.com/en-us/azure/security-center/defender-for-servers-introduction to get started