Jul 31 2024 09:56 PM
Hi All,
I don't want to expose my servers to internet using a proxy or any other mechanism.
Is there any possibility to deploy & manage Defender for both Windows & Linux servers?
If yes, what are the risks and challenges?
All servers are Windows 2022 servers. For definition updates, can i use either SCCM or any other product?
Aug 04 2024 03:57 AM
Hi @Sankaperera
Defender for Server/Endpoint is a cloud service that requires internet connectivity, whether directly or through a proxy. You now have the option to utilize the new streamlined connectivity, which requires opening traffic only to *.endpoint.security.microsoft.com. I recommend checking out this article for more details > Onboarding devices using streamlined connectivity for Microsoft Defender for Endpoint - Microsoft De...
Aug 04 2024 04:19 AM
Aug 04 2024 05:17 AM
Aug 05 2024 06:26 AM
Solution@Sankaperera
Defender Antivirus
Without internet access you can use Defender Antivirus, which is a traditional Antivirus solution available on windows servers 2016 and up.
(note, the antivirus in 2016 does not have all the functionality that is available 2019 and up.
You have the option of distributing updates via a share folder, WSUS or MEC, which will not require direct internet access from the protected servers.
Defender Antivirus is integrated in the OS so it does not require Defender for Servers licensing.
Defender for Endpoint(Defender for Servers)
The EDR solution Defender for Endpoint runs all analytics in the cloud, and will require internet access, either direct or through a proxy.
Aug 16 2024 03:06 AM - edited Aug 16 2024 03:11 AM
For an offline environment, consider using Microsoft Defender Antivirus (Windows only) with on-premises management via Group Policy or MECM, but this won't provide full MDE capabilities. Linux servers would require a different solution.
You cannot deploy and manage Microsoft Defender for Endpoint on both Windows and Linux servers without internet access. Defender for Endpoint requires internet connectivity for management, updates, and threat intelligence. Microsoft Defender cannot manage Linux servers without internet access.
Consider using ClamAV or Symantec Endpoint Protection for offline antivirus management on Linux servers.
Aug 05 2024 06:26 AM
Solution@Sankaperera
Defender Antivirus
Without internet access you can use Defender Antivirus, which is a traditional Antivirus solution available on windows servers 2016 and up.
(note, the antivirus in 2016 does not have all the functionality that is available 2019 and up.
You have the option of distributing updates via a share folder, WSUS or MEC, which will not require direct internet access from the protected servers.
Defender Antivirus is integrated in the OS so it does not require Defender for Servers licensing.
Defender for Endpoint(Defender for Servers)
The EDR solution Defender for Endpoint runs all analytics in the cloud, and will require internet access, either direct or through a proxy.