Golden Image & Microsoft Defender for Endpoint

Brass Contributor

Dear Microsoft Community,

What are the best practices when creating Golden Image (using Packer) and we want to deploy the Microsoft Defender for Endpoint agent on it.


Here is the current process:

  1. We launch the adequate onboarding script, that matches the Windows Server version.
  2. We restart the server.
  3. We launch a script which:
    1. Configure the ASR rules
    2. Configure the different settings (Network Protection, Cloud Protection, ...)
    3. ...

The issue is that once the image is being used, we see within the Microsoft 365 Defender Portal, the asset with the status "Can be onboarded".
All required network flows are opened.

Thomas

0 Replies