Microsoft Defender for Endpoint
Architecture and deployment

Deploy Microsoft Defender endpoint security to Linux devices using the Defender deployment tool

In brief

The page heading no longer includes “(preview),” note formatting was updated, and a screenshot showing successful deployment tool events was added.

What Defender admins need to know

Administrators have a visual reference for verifying successful Linux deployments; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  • Microsoft Defender for Endpoint Plan 2

Deploy Microsoft Defender endpoint security to Linux devices using the Defender deployment tool (preview)

The Defender deployment tool provides an efficient, user-friendly onboarding process for Microsoft Defender for Endpoint on Linux devices. It allows users to install and onboard Microsoft Defender for Endpoint using a single package that can be downloaded from the Microsoft Defender portal. This eliminates the need to install Defender using installer script/cli commands and then, separately, to onboard the device using the onboarding package from the portal.

1. Under **Download and apply onboarding packages or files**, select the **Download package** button under **Defender deployment tool**.
  :::image type="content" source="./media/linux-install-with-defender-deployment-tool/deployment-tool-download-package.png" alt-text="Screenshot showing the download package button." lightbox="./media/linux-install-with-defender-deployment-tool/deployment-tool-download-package.png":::

To filter deployment events on the timeline, enter DefenderDeployment in the timeline search box. Each event reads Defender deployment tool: <step> succeeded or Defender deployment tool: <step> failed, and includes any extra details the tool reports for that step. The following screenshot shows a successful install run.

:::image type="content" source="./media/linux-install-with-defender-deployment-tool/deployment-tool-successful-install-timeline.png" alt-text="Screenshot of the device timeline filtered to show successful Defender deployment tool events." lightbox="./media/linux-install-with-defender-deployment-tool/deployment-tool-successful-install-timeline.png":::

Deployment timeline

A successful install-and-onboard run produces the following sequence of events: