Forum Discussion
Deleted
Aug 21, 2023How to bock 365 Defender defaulting to passive mode?
365 Defender managed by InTune and GPO. How to block 365 Defender defaulting to passive mode due to a third party AV install? In passive mode, Microsoft Defender Antivirus is not used as the pr...
eliekarkafy
Aug 21, 2023MVP
Deleted you need to use the endpoint detection and response in block mode when Defender is not your primary antivirus product and its running in passive mode. artifacts might have been missed by the primary, non-Microsoft antivirus product. EDR in block mode allows Microsoft Defender Antivirus to take actions on post-breach, behavioral EDR detections.
Refer to the below link for more details
Endpoint detection and response in block mode | Microsoft Learn