Hi, I know this is the Windows 10 security community, but couldn't spot a relevant Server 2016 community, and this is specifically Defender AV and Defender ATP related.


Essentially i would like to understand how the decision, as outlined here:

that Defender AV will remain in Active mode on Server 2016, even if enrolled in ATP, and that if third party AV is installed you should completely remove Defender AV, was made?


This seems to be counter-intuitive, completely against the point of Defender ATP and the entire point of the platform, especially where Servers are concerned, unless i'm really missing something?


Having Defender AV in either passive mode or active disabled mode on Servers with third party AV makes complete sense, if the third party AV is unable to perform its function, Defender AV steps in, if ATP requires protection intervention on the Server, Defender AV steps in. This approach loses all that functionality, with, as afar as i can tell, absolutely no benefits.


beyond this insanity above, it also turns out that you cannot get the WindowsUpdateLog without Defender AV feature installed (yes you can copy the dll over but come on, seriously?!) 


Beyond blinkered "MS AV is rubbish" rhetoric which just shows an inability to understand the current protection environment, there is no good reason to not have Defender installed on Windows 10 or Windows Server 2016, the current advice and behaviour of the AV client only helps to drive ignorance and potentially expose systems to more risk, along with reducing the functionality and value of Defender ATP.


I have raised a uservoice request to change this behaviour for anyone that agrees this is nuts:

This is just speculation, but the reason for this is likely because of the way WDATP is integrated in Windows 10 compared to Servers.

In Windows 10, WDATP is built-in to the operating system while in Windows Server they've patched the AV agent to provide the functionality for WDATP.