Detecting endpoint detection and response solutions
In brief
The article now uses clearer wording for checking supported EDR connections, agentless scanning, plan prerequisites, recommendations, and related content.
What Defender admins need to know
Administrators have clearer guidance on EDR assessment prerequisites and remediation recommendations. No action is required.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Detecting endpoint detection and response solutions
This article explains how to check whether machines are connected touse a supported endpoint detection and response (EDR) solution in Microsoft Defender for Cloud.solution.
Microsoft Defender for Cloud includes endpoint detection and response (EDR) capabilitiesEDR features for supported machines. Defender for Cloud:It can:
DetectsDetect whether a machine connects to a supported EDR solution.- Integrate natively with Microsoft Defender for Endpoint as an EDR solution.
Check for an EDR solution
Defender for Cloud uses agentless scanning to assesscheck whether Azure VMs and AWS/GCP machines are connectedconnect to an EDR solution.
Agentless scanning for EDR solution settings is available when Defender for Cloud is running in your Azure subscription and eitheryou enable Defender for Servers Plan 2 or the Defender CSPM plan is enabled.in your Azure subscription.
Based on EDR solutionthe findings, Defender for Cloud provides the following recommendations to help you identifyfind and remediatefix machines that don't have an EDR solution running. EDR solution recommendations are as follows:running:
EDR solution should be installed on virtual machinesEDR solution should be installed on EC2 instancesThe following table lists the EDR solutions supported by Defender for Cloud:
|
| Solution | Supported platform
|
|---|---|
| Microsoft Defender for Endpoint | Windows |
| Microsoft Defender for Endpoint | Linux |
| Singularity Platform by SentinelOne | Windows and |
| Cortex XDR | Windows and Linux (Supported only when installed via package manager on Linux) |
Next steps
[!div class="nextstepaction"] Enable Defender for Servers Plan 2
Related content
@@ -1,28 +1,29 @@ --- title: Detecting endpoint detection and response solutions-description: Learn about detection for endpoint detection and response solutions in Microsoft Defender for Cloud+description: Check whether your machines are connected to a supported endpoint detection and response (EDR) solution in Microsoft Defender for Cloud. ms.topic: how-to-ms.date: 05/28/2026+ms.date: 07/03/2026 ai-usage: ai-assisted+ms.custom: msecd-doc-authoring-1013 #customer intent: As a user, I want to learn how Microsoft Defender for Cloud can help me to protect enterprise endpoints, improve endpoint posture, and respond to security threats. --- # Detecting endpoint detection and response solutions -This article explains how to check whether machines are connected to a supported endpoint detection and response (EDR) solution in Microsoft Defender for Cloud.+This article explains how to check whether machines use a supported endpoint detection and response (EDR) solution. -Microsoft Defender for Cloud includes endpoint detection and response (EDR) capabilities for supported machines. Defender for Cloud:+Defender for Cloud includes EDR features for supported machines. It can: -- Detects whether a machine connects to a supported EDR solution.-- [Integrates natively with Microsoft Defender for Endpoint as an EDR solution](integration-defender-for-endpoint.md).+- Detect whether a machine connects to a supported EDR solution.+- [Integrate natively with Microsoft Defender for Endpoint as an EDR solution](integration-defender-for-endpoint.md). ## Check for an EDR solution -Defender for Cloud uses [agentless scanning](concept-agentless-data-collection.md) to assess whether Azure VMs and AWS/GCP machines are connected to an EDR solution.+Defender for Cloud uses [agentless scanning](concept-agentless-data-collection.md) to check whether Azure VMs and AWS/GCP machines connect to an EDR solution. -Agentless scanning for EDR solution settings is available when Defender for Cloud is running in your Azure subscription and either [Defender for Servers Plan 2](tutorial-enable-servers-plan.md) or the [Defender cloud security posture management (Defender CSPM) plan](tutorial-enable-cspm-plan.md) is enabled.+Agentless scanning for EDR settings is available when you enable [Defender for Servers Plan 2](tutorial-enable-servers-plan.md) or the [Defender CSPM plan](tutorial-enable-cspm-plan.md) in your Azure subscription. -Based on EDR solution findings, Defender for Cloud provides the following recommendations to help you identify and remediate machines that don't have an EDR solution running. EDR solution recommendations are as follows:+Based on the findings, Defender for Cloud provides recommendations to help you find and fix machines that don't have an EDR solution running: - `EDR solution should be installed on virtual machines` - `EDR solution should be installed on EC2 instances`@@ -33,11 +34,6 @@ Based on EDR solution findings, Defender for Cloud provides the following recomm The following table lists the EDR solutions supported by Defender for Cloud: |**Solution** | **Supported platform**|--## Next step--> [!div class="nextstepaction"]-> [Enable Defender for Servers Plan 2](tutorial-enable-servers-plan.md) |--- | ---| |Microsoft Defender for Endpoint | Windows| |Microsoft Defender for Endpoint | Linux|@@ -49,7 +45,13 @@ The following table lists the EDR solutions supported by Defender for Cloud: |Singularity Platform by SentinelOne | Windows and Linux| |Cortex XDR | Windows and Linux (Supported only when installed via package manager on Linux)| +<a name="next-step"></a> ## Next steps -[Review and remediate EDR solution recommendations](endpoint-detection-response-solution-recommendations.md).+> [!div class="nextstepaction"]+> [Enable Defender for Servers Plan 2](tutorial-enable-servers-plan.md)+++## Related content +[Review and remediate the "EDR solution should be installed" recommendations for virtual machines, EC2 instances, and GCP VMs](endpoint-detection-response-solution-recommendations.md). 