Remediate EDR solution recommendations
In brief
The page now explicitly requires agentless scanning and Defender for Servers Plan 2 or Defender CSPM for EDR recommendation investigation and remediation. It also clarifies supported machine coverage and when Defender for Endpoint integration is available.
What Defender admins need to know
Before reviewing or fixing EDR recommendations, verify that agentless scanning is enabled and the required Defender plan is turned on.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Remediate EDR solution recommendations
Microsoft Defender for Cloud includeshelps improve security posture for supported machines with endpoint detection and response (EDR) capabilities to improve security posture for supported machines.. Defender for Cloud:
Integrates nativelyWorks with Microsoft Defender for Endpoint asana built-in EDRsolution for machine protection.solution.- Scans
connected machines, includingAzure virtual machines (VMs), AWS machines, andAWS orGCPmachines,machines to check whether an EDR solution is installed and running. The EDR solution can beMicrosoftDefender for Endpoint or a supported non-Microsoft solution.
Based on EDR solution findings,scan results, Defender for Cloud provides recommendations to ensure thathelp you install and run EDR solutions are installed and running correctly on machines.correctly. This article describes how to remediatefix those recommendations.
Prerequisites
Before you investigate or remediate EDR solution recommendations, make sure you meet these requirements.
| Requirement | Details |
|---|---|
| Plan | Defender for Cloud must be available in the Azure subscription and one of these plans must be enabled: - Defender for Servers Plan 2 - Defender cloud security posture management (Defender CSPM) |
| Agentless scanning | Agentless scanning for machines must be turned on. |
Investigate EDR solution recommendations
To investigatereview EDR solution recommendations for your machines:
In Defender for Cloud,
go toopen Recommendations.Search for and select one of
the followingthese recommendations:EDR solution should be installed on Virtual MachinesEDR solution should be installed on EC2s
In the recommendation details, select the Healthy resources tab.
TheFind the EDR solutiondeployed on thefor each machineis displayedin the Discovered EDRs column.:::image type="content" source="media/endpoint-detection-response/discovered-solutions.png" alt-text="Screenshot of the Healthy resources tab, which shows where you can see which endpoint detection and response solution is enabled on your machine." lightbox="media/endpoint-detection-response/discovered-solutions.png":::
:::image type="content" source="media/endpoint-detection-response/identify-recommendations.png" alt-text="Screenshot of the recommendations page showing the identified endpoint solution recommendations." lightbox="media/endpoint-detection-response/identify-recommendations.png":::
Select one of the listed recommended actions to see the remediation
steps.steps for that action.
Enable Defender for Endpoint integration
The Enable Microsoft Defender for Endpoint integration action is availableappears when Defender for Endpoint can be installed on a machine and amachine. This action is available only when no supported non-Microsoft EDR solution isn'tis detected on the machine.
Enable Defender for Endpoint on the machine as follows:
:::image type="content" source="media/endpoint-detection-response/enable-fix.png" alt-text="Screenshot that shows where the fix button is located." lightbox="media/endpoint-detection-response/enable-fix.png":::
In Enable EDR solution, select Enable. This
settinginstalls the Defender for Endpoint sensorautomaticallyon all Windows and Linux servers in the subscription.After the process completes, it can take up to 24 hours for your machine to appear in the Healthy resources tab.
:::image type="content" source="media/endpoint-detection-response/enable-endpoint.png" alt-text="Screenshot that shows the pop-up window from which to enable the Defender for Endpoint integration on.":::
Turn on athe required Defender plan
The Upgrade Defender plan action is available when:
- A supported non-Microsoft EDR solution isn't detected on the machine.
- A required
Defender for Cloudplan (Defender for Servers Plan 2 or Defender CSPM) isn'tenabledturned on for the machine.
Fix the recommendation as follows:
Troubleshoot Defender for Endpoint onboarding
The Troubleshoot onboarding action is availableappears when Defender for Endpoint is detectedfound on a machine but wasndidn't onboarded properly.onboard correctly.
Select the affected VM.
:::image type="content" source="media/endpoint-detection-response/remediation-steps.png" alt-text="Screenshot that shows where the remediation steps are located in the recommendation." lightbox="media/endpoint-detection-response/remediation-steps.png":::
TroubleshootFix onboarding issuesbyfor your platform:
After the process completes,you finish, it can take up to 24 hours for your machine to appear inshow on the Healthy resources tab.
@@ -2,19 +2,20 @@ title: Remediate EDR solution recommendations description: Identify and remediate security gaps in endpoint detection and response solutions on your virtual machine with Defender for Cloud recommendations. ms.topic: how-to-ms.date: 06/02/2026+ms.date: 07/03/2026 ai-usage: ai-assisted+ms.custom: msecd-doc-authoring-1013 #customer intent: As a user, I want to learn how to review and remediate endpoint detection and response recommendations in order to ensure the security of my virtual machine. --- # Remediate EDR solution recommendations -Microsoft Defender for Cloud includes endpoint detection and response (EDR) capabilities to improve security posture for supported machines. Defender for Cloud:+Microsoft Defender for Cloud helps improve security posture for supported machines with endpoint detection and response (EDR). Defender for Cloud: -- Integrates natively with [Microsoft Defender for Endpoint](integration-defender-for-endpoint.md) as an EDR solution for machine protection.-- Scans connected machines, including Azure virtual machines (VMs) and AWS or GCP machines, to check whether an EDR solution is installed and running. The EDR solution can be Microsoft Defender for Endpoint or a [supported non-Microsoft solution](detect-endpoint-detection-response-solutions.md#supported-edr-solutions).+- Works with [Microsoft Defender for Endpoint](integration-defender-for-endpoint.md) as a built-in EDR solution.+- Scans Azure virtual machines (VMs), AWS machines, and GCP machines to check whether an EDR solution is installed and running. The EDR solution can be Defender for Endpoint or a [supported non-Microsoft solution](detect-endpoint-detection-response-solutions.md#supported-edr-solutions). -Based on EDR solution findings, Defender for Cloud provides [recommendations](detect-endpoint-detection-response-solutions.md) to ensure that EDR solutions are installed and running correctly on machines. This article describes how to remediate those recommendations.+Based on scan results, Defender for Cloud provides [recommendations](detect-endpoint-detection-response-solutions.md) to help you install and run EDR solutions correctly. This article describes how to fix those recommendations. > [!NOTE] >@@ -25,18 +26,20 @@ Based on EDR solution findings, Defender for Cloud provides [recommendations](de ## Prerequisites +Before you investigate or remediate EDR solution recommendations, make sure you meet these requirements.+ **Requirement** | **Details** --- | --- **Plan** | [Defender for Cloud](connect-azure-subscription.md) must be available in the Azure subscription and one of these plans must be enabled:<br/><br/>- [Defender for Servers Plan 2](tutorial-enable-servers-plan.md)<br/>- [Defender cloud security posture management (Defender CSPM)](tutorial-enable-cspm-plan.md)-**Agentless scanning** | [Agentless scanning for machines](concept-agentless-data-collection.md) must be turned on. It's enabled by default in the plans. If you need to turn it on manually, see [Enable agentless scanning for VMs](enable-agentless-scanning-vms.md).+**Agentless scanning** | [Agentless scanning for machines](concept-agentless-data-collection.md) must be turned on. Agentless scanning is enabled by default in both Defender for Servers Plan 2 and Defender CSPM. If you need to turn it on manually, see [Enable agentless scanning for VMs](enable-agentless-scanning-vms.md). ## Investigate EDR solution recommendations -To investigate EDR solution recommendations for your machines:+To review EDR recommendations for your machines: -1. In **Defender for Cloud**, go to **Recommendations**.+1. In **Defender for Cloud**, open **Recommendations**. -1. Search for and select one of the following recommendations:+1. Search for and select one of these recommendations: - `EDR solution should be installed on Virtual Machines` - `EDR solution should be installed on EC2s`@@ -44,7 +47,7 @@ To investigate EDR solution recommendations for your machines: 1. In the recommendation details, select the **Healthy resources** tab. -1. The EDR solution deployed on the machine is displayed in the **Discovered EDRs** column.+1. Find the EDR solution for each machine in the **Discovered EDRs** column. :::image type="content" source="media/endpoint-detection-response/discovered-solutions.png" alt-text="Screenshot of the Healthy resources tab, which shows where you can see which endpoint detection and response solution is enabled on your machine." lightbox="media/endpoint-detection-response/discovered-solutions.png"::: @@ -56,11 +59,11 @@ To remediate EDR solution recommendations: :::image type="content" source="media/endpoint-detection-response/identify-recommendations.png" alt-text="Screenshot of the recommendations page showing the identified endpoint solution recommendations." lightbox="media/endpoint-detection-response/identify-recommendations.png"::: -1. Select one of the listed recommended actions to see the remediation steps.+1. Select one of the listed recommended actions to see the remediation steps for that action. ## Enable Defender for Endpoint integration -The **Enable Microsoft Defender for Endpoint integration** action is available when Defender for Endpoint can be installed on a machine and a [supported non-Microsoft EDR solution](detect-endpoint-detection-response-solutions.md) isn't detected on the machine.+The **Enable Microsoft Defender for Endpoint integration** action appears when Defender for Endpoint can be installed on a machine. This action is available only when no [supported non-Microsoft EDR solution](detect-endpoint-detection-response-solutions.md) is detected on the machine. Enable Defender for Endpoint on the machine as follows: @@ -70,18 +73,19 @@ Enable Defender for Endpoint on the machine as follows: :::image type="content" source="media/endpoint-detection-response/enable-fix.png" alt-text="Screenshot that shows where the fix button is located." lightbox="media/endpoint-detection-response/enable-fix.png"::: -1. In **Enable EDR solution**, select **Enable**. This setting installs the Defender for Endpoint sensor automatically on all Windows and Linux servers in the subscription.+1. In **Enable EDR solution**, select **Enable**. This installs the Defender for Endpoint sensor on all Windows and Linux servers in the subscription. After the process completes, it can take up to 24 hours for your machine to appear in the **Healthy resources** tab. :::image type="content" source="media/endpoint-detection-response/enable-endpoint.png" alt-text="Screenshot that shows the pop-up window from which to enable the Defender for Endpoint integration on."::: -## Turn on a plan+<a name="turn-on-a-plan"></a>+## Turn on the required Defender plan The **Upgrade Defender plan** action is available when: - A [supported non-Microsoft EDR solution](detect-endpoint-detection-response-solutions.md) isn't detected on the machine.-- A required Defender for Cloud plan (Defender for Servers Plan 2 or Defender CSPM) isn't enabled for the machine.+- A required plan (Defender for Servers Plan 2 or Defender CSPM) isn't turned on for the machine. Fix the recommendation as follows: @@ -101,7 +105,7 @@ After the process completes, it can take up to 24 hours for your machine to appe ## Troubleshoot Defender for Endpoint onboarding -The **Troubleshoot onboarding** action is available when Defender for Endpoint is detected on a machine but wasn't onboarded properly.+The **Troubleshoot onboarding** action appears when Defender for Endpoint is found on a machine but didn't onboard correctly. 1. Select the affected VM. @@ -109,9 +113,9 @@ The **Troubleshoot onboarding** action is available when Defender for Endpoint i :::image type="content" source="media/endpoint-detection-response/remediation-steps.png" alt-text="Screenshot that shows where the remediation steps are located in the recommendation." lightbox="media/endpoint-detection-response/remediation-steps.png"::: -1. Troubleshoot onboarding issues by platform:+1. Fix onboarding issues for your platform: - [Troubleshoot onboarding for Windows](/defender-endpoint/troubleshoot-onboarding) - [Troubleshoot onboarding for Linux](/defender-endpoint/microsoft-defender-endpoint-linux) -After the process completes, it can take up to 24 hours for your machine to appear in the **Healthy resources** tab.+After you finish, it can take up to 24 hours for your machine to show on the **Healthy resources** tab. 