Microsoft Defender for Cloud
Cloud and workloads

Assess Defender for Endpoint EDR settings

In brief

The article now more clearly explains how Defender for Cloud uses agentless scanning to assess Defender for Endpoint EDR settings, identify misconfigurations, and provide actionable recommendations. Prerequisite and remediation links were also refreshed, along with metadata and the publication date.

What Defender admins need to know

Administrators have clearer guidance for understanding EDR assessments and following the documented recommendation and remediation steps. No action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Assess Defender for Endpoint EDR settings

Microsoft Defender for Cloud integrates natively with Microsoft Defender for Endpoint as an endpoint detection and response (EDR) solution. This article explains how Defender for Cloud uses agentless scanning to assess EDR settings, detect misconfigurations, and surface actionable recommendations to help you remediate them.

Understand EDR capabilities in Defender for Endpoint

EDR capabilities in Defender for Endpoint detect, investigate, and respond to advanced threats. These capabilities include advanced threat hunting (see Advanced threat hunting overview) and automatic investigation and remediation (see Automatic investigation and remediation).

Assess Defender for Endpoint settings

  • Anti-Virus component in your EDR is off or partially configured
  • Anti-Virus component of your EDR uses outdated signatures

Once you locate these recommendations (Review security recommendations), you can remediate them (Implement security recommendations).

Next step