Microsoft Defender for Endpoint
Endpoint protection

Set up authenticated network scans in Microsoft Defender for Endpoint

In brief

The article now includes an Overview section, clearer setup guidance, an updated Windows support link, and clarifies that the displayed results are from a test scan. Metadata and the publication date were also updated.

What Defender admins need to know

Administrators can use the revised article for prerequisites, scanner setup, registration, and configuration. No action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Set up authenticated network scans in Microsoft Defender for Endpoint

Overview

Authenticated network scans provide an agentless way to discover and assess network infrastructure devices, such as switches, routers, WLAN controllers, firewalls, and VPN gateways. This article walks you through the prerequisites, scanner installation and registration, and configuration steps needed to set up authenticated network scans and view discovered devices in the device inventory.

For more information, see Authenticated network scans.

Supported Windows versions for the scanner

The scanner is supported on Windows 10, version 1903 and Windows Server, version 1903 and later. For more information, see Windows 10, version 1903 and Windows Server, version 1903Windows 10, version 1903 and Windows Server, version 1903

If there are multiple IP address ranges/subnets to scan, the test scan results take several minutes to show up. A test scan is available for up to 1,024 addresses.

When the test scan results are displayed, you can choose which devices to include in the periodic scan. If you skip viewing the scan results, all configured IP addresses are added to the network device authenticated scan (regardless of the device's response). The scan results can also be exported.

View network devices in the device inventory