Microsoft Defender for Endpoint
Endpoint protection

Defender Deployment Tool Windows

In brief

The Windows deployment-tool page now includes the streamlined connectivity SSL inspection requirement and replaces DefenderDTconfig.txt with MdeConfig.txt/MDEConfig.txt in its instructions. Prerequisite links were also refreshed.

What Defender admins need to know

Review deployment procedures for the updated configuration filename and the added SSL inspection requirement.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  • m365-security

  • tier3 ms.subservice: onboard ms.date: 06/15/07/28/2026 appliesto:

    • Microsoft Defender for Endpoint Plan 1
    • Microsoft Defender for Endpoint Plan 2
  • While the tool checks for connectivity against your specific tenant before proceeding, other connectivity requirements, such as access to the consolidated *.endpoint.security.microsoft.com/*, apply to (additional) functionality you might want to use with the product. See Configure your network environment to ensure connectivity with the Defender for Endpoint service.

[!INCLUDE Streamlined connectivity SSL inspection requirement]

Additional prerequisites for Windows 7 SP1 and Windows Server 2008 R2 SP1

  • Devices must be running an x64 version of Windows 7 SP1 or Windows Server 2008 R2 SP1. We recommend having the latest updates installed to avoid reboots and to significantly reduce required installation time.

  • For the Defender deployment tool to run on Windows 7 SP1 or Windows Server 2008 R2 SP1, at a minimum, the update KB4474419 for SHA2 code signingSHA2 code signing must be installed.

    • Servicing stack update (SSU) (KB4490628KB4490628). If you use Windows Update, the required SSU is offered to you automatically.

    • SHA-2 update (KB4474419KB4474419) released September 10, 2019. If you use Windows Update, the required SHA-2 update is offered to you automatically.

  • On Server 2008 R2 SP1 devices, .NET 3.5 or a higher version of the .NET framework must also be installed.

    DefenderDT.exe -MakeConfig
    ```
    
    1. Use Notepad to open the DefenderDTconfig.MdeConfig.txt file that was created in the directory. Specify parameters you want to use.

      For example:

      DefenderDT.exe -File:\server\DDT\Defenderconfig.txt

      
      If the *DefenderDTconfig.*MdeConfig.txt* file is stored in the same directory as the tool, you don't need to specify a path.
      

Using Group Policy for deployment

The following steps show how to create a scheduled task to run the tool using Group Policy:

  1. Place the files DefenderDT.exe and WindowsDefenderATP.onboarding on a shared location that can be accessed by the device. If you've previously created an DefenderDTconfig.MDEConfig.txt configuration file, place it in the same location.

  2. To create a new Group Policy Object (GPO), open the Group Policy Management Console (GPMC), right-click Group Policy Objects you want to configure and select New. Enter the name of the new GPO in the dialogue box that is displayed and select OK.