Assess Defender for Endpoint EDR settings
In brief
The article now more clearly explains how Defender for Cloud uses agentless scanning to assess Defender for Endpoint EDR settings, identify misconfigurations, and provide actionable recommendations. Prerequisite and remediation links were also refreshed, along with metadata and the publication date.
What Defender admins need to know
Administrators have clearer guidance for understanding EDR assessments and following the documented recommendation and remediation steps. No action is required.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Assess Defender for Endpoint EDR settings
Microsoft Defender for Cloud integrates natively with Microsoft Defender for Endpoint as an endpoint detection and response (EDR) solution. This article explains how Defender for Cloud uses agentless scanning to assess EDR settings, detect misconfigurations, and surface actionable recommendations to help you remediate them.
Understand EDR capabilities in Defender for Endpoint
EDR capabilities in Defender for Endpoint detect, investigate, and respond to advanced threats. These capabilities include advanced threat hunting (see Advanced threat hunting overview) and automatic investigation and remediation (see Automatic investigation and remediation).
- Defender for Cloud uses agentless scanning to assess EDR settings. See About agentless data collection.
- Agentless scanning for EDR settings is available when Defender for Cloud is running in your Azure subscription and either Defender for Servers Plan 2 (Enable Defender for Servers Plan 2) or the Defender cloud security posture management (Defender CSPM) plan (Enable Defender CSPM) is enabled.
Assess Defender for Endpoint settings
Anti-Virus component in your EDR is off or partially configuredAnti-Virus component of your EDR uses outdated signatures
Once you locate these recommendations (Review security recommendations), you can remediate them (Implement security recommendations).
Next step
@@ -1,23 +1,23 @@ --- title: Assess Defender for Endpoint EDR settings-description: Learn how Microsoft Defender for Cloud uses agentless scanning to assess Defender for Endpoint EDR settings on protected machines.+description: Learn how Microsoft Defender for Cloud integrates with Defender for Endpoint as an EDR solution and assesses EDR settings to detect and remediate misconfigurations. ms.topic: how-to-ms.date: 06/02/2026+ms.date: 07/03/2026 ai-usage: ai-assisted-ms.custom: sfi-image-nochange+ms.custom: sfi-image-nochange, msecd-doc-authoring-1013 #customer intent: As a user, I want to learn how Microsoft Defender for Cloud can help me to protect enterprise endpoints, improve endpoint posture, and respond to security threats. --- # Assess Defender for Endpoint EDR settings -Microsoft Defender for Cloud integrates natively with Microsoft Defender for Endpoint as an endpoint detection and response (EDR) solution.+Microsoft Defender for Cloud integrates natively with Microsoft Defender for Endpoint as an endpoint detection and response (EDR) solution. This article explains how Defender for Cloud uses agentless scanning to assess EDR settings, detect misconfigurations, and surface actionable recommendations to help you remediate them. ## Understand EDR capabilities in Defender for Endpoint EDR capabilities in Defender for Endpoint detect, investigate, and respond to advanced threats. These capabilities include advanced threat hunting (see [Advanced threat hunting overview](/defender-xdr/advanced-hunting-overview)) and automatic investigation and remediation (see [Automatic investigation and remediation](/defender-xdr/m365d-autoir)). - Defender for Cloud uses agentless scanning to assess EDR settings. See [About agentless data collection](concept-agentless-data-collection.md).-- Agentless scanning for EDR settings is available when Defender for Cloud is running in your Azure subscription and either Defender for Servers Plan 2 ([enable](tutorial-enable-servers-plan.md)) or the Defender cloud security posture management (Defender CSPM) plan ([enable](tutorial-enable-cspm-plan.md)) is enabled.+- Agentless scanning for EDR settings is available when Defender for Cloud is running in your Azure subscription and either Defender for Servers Plan 2 ([Enable Defender for Servers Plan 2](tutorial-enable-servers-plan.md)) or the Defender cloud security posture management (Defender CSPM) plan ([Enable Defender CSPM](tutorial-enable-cspm-plan.md)) is enabled. ## Assess Defender for Endpoint settings @@ -34,7 +34,7 @@ If misconfigurations are found, Defender for Cloud presents recommendations such - `Anti-Virus component in your EDR is off or partially configured` - `Anti-Virus component of your EDR uses outdated signatures` -Once you locate these recommendations ([learn how to review recommendations](review-security-recommendations.md)), you can remediate them ([learn how to remediate recommendations](implement-security-recommendations.md)).+Once you locate these recommendations ([Review security recommendations](review-security-recommendations.md)), you can remediate them ([Implement security recommendations](implement-security-recommendations.md)). ## Next step 