Reader small image

You're reading from  Mastering Microsoft 365 Defender

Product typeBook
Published inJul 2023
PublisherPackt
ISBN-139781803241708
Edition1st Edition
Right arrow
Authors (2):
Ru Campbell
Ru Campbell
author image
Ru Campbell

Ruairidh (Ru) Campbell is a Microsoft Security MVP and leads Microsoft consultancy at Threatscape. At Threatscape, Ru develops, delivers, and manages offerings and professional services for cybersecurity, compliance, identity, and management. In the cybersecurity community, Ru runs the Microsoft 365 Security & Compliance user group and his blog (campbell.scot), regularly speaks at other user groups and conferences, and contributes to well-known industry publications such as Practical 365. Ru holds 14 Microsoft certifications and a B.Sc. (Distinction) in computer networking from the University of the West of Scotland. Away from cybersecurity, he is a petrolhead who enjoys heavy metal and hiking around Scotland with his wife.
Read more about Ru Campbell

Viktor Hedberg
Viktor Hedberg
author image
Viktor Hedberg

Viktor Hedberg is a Microsoft Security MVP and senior consultant at Truesec. At Truesec, Viktor works with proactive security measures within the Microsoft sphere of technologies, by delivering workshops on best practices and by his deep technical expertise in these areas. In the cybersecurity community, Viktor runs his blogs at Truesec (Experts – viktor-hedberg). Alongside this, he is one of the hosts of the Swedish Windows Security user group, as well as a co-host of the Swedish podcast The Nerd Herd. He is a frequent speaker at both conferences and user groups around the world, focusing on matters of Microsoft Security. Viktor holds numerous Microsoft certifications, as well as being a Microsoft Certified Trainer. Away from cybersecurity, Viktor is a family man, spending most of his time with his wife and three kids, as well as enjoying football, both as a practitioner and as a fan. Heavy metal has been part of his life since his early teens.
Read more about Viktor Hedberg

View More author details
Right arrow

Onboarding Windows Clients and Servers

In this chapter, you will learn how Windows clients and servers are onboarded to MDE. As established in the last chapter, MDE supports a diverse arrangement of operating systems and devices. For Windows, this list is as follows:

  • Windows 7 SP1 and 8.1 Pro/Enterprise
  • Windows 10 and 11 Pro, Education, Pro Education, and Enterprise (including IoT and LTSC 2016+)
  • Windows Server 2008 R2 SP1, 2012 R2, 2016, SAC 1803+, 2019, and 2022
  • Azure Virtual Desktop and Windows 365

In the last chapter, you learned what onboarding is (insofar as it relates to EDR capabilities and not necessarily full endpoint protection) and the prerequisites such as internet connectivity. In this chapter, we’ll explore onboarding further by looking into details about how you can use each available option and the differences between them.

Be warned: there are a lot of options. For example, Windows Server alone can be onboarded in at least six...

Onboarding Windows clients

Different options are available, depending on the age of the Windows version. Windows 10 and 11 both have capabilities built-in that Windows 7 SP1 and Windows 8.1 do not. Even after onboarding, their support of MDE features varies.

Figure 4.1 – Deciding which management tool to use for onboarding Windows clients

Figure 4.1 – Deciding which management tool to use for onboarding Windows clients

Detection tests for Windows

You can confirm whether Windows clients and servers are onboarded and successfully transmitting EDR sensor data by executing the following command prompt, which is also found within the Microsoft 365 Defender portal’s onboarding settings:

powershell.exe -NoExit -ExecutionPolicy Bypass -WindowStyle Hidden $ErrorActionPreference = 'silentlycontinue';(New-Object System.Net.WebClient).DownloadFile('http://127.0.0.1/1.exe', 'invoice.exe');Start-Process 'invoice.exe'

In the sections that follow, you will learn how to onboard all supported...

Onboarding Windows Server

So far, you’ve learned how to onboard Windows clients. Now, we’ll explore the server options. As with clients, how we onboard differs by OS due to support reasons and out-of-the-box feature availability.

Supported platforms are the first thing to note. You can onboard Windows Server 2008 R2, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, and Windows Server 2022. This includes the Semi-Annual Channel (SAC) releases from 1803, for which you should follow the processes for Windows Server 2019.

Although onboarding methods for servers are largely like their client sibling versions —with manual scripts, Group Policy, and Configuration Manager still present — you will learn about the significant advantages Windows Server 2012 R2 now has over Windows 8.1, and how Windows Server 2016 follows the same onboarding method as Windows Server 2012 R2, despite having Microsoft Defender Antivirus built in.

There are also...

Summary

In this chapter, you learned that onboarding Windows clients and servers to MDE means that the device is available for EDR functionality, and how to perform onboarding in various ways depending on the tools you have available. You learned about the support for down-level and modern systems, across Azure and on-premises, with the ability to now make informed decisions about the most appropriate way for your scenario.

As you begin your journey with MDE, you want to approach onboarding with the long-term in mind, utilizing Intune. To begin with testing or very small-scale deployments, you can manually onboard devices with scripts. If Intune-only onboarding is not an option, due to time constraints or technical limitations in your organization, you can centrally control deployments with other tools, such as Group Policy or Configuration Manager. For servers, you can license Defender for Servers as part of Defender for Cloud, while also benefiting from automatic onboarding. Azure...

Questions

Now that you understand the onboarding processes for MDE, you can test your knowledge with the following questions:

  1. If you require anti-malware protection on down-level Windows, which of the following would be an appropriate suggestion? Choose all that apply:
    1. Third-party software
    2. Microsoft Defender Antivirus
    3. System Center Endpoint Protection
    4. Microsoft Intune
  2. You are comparing options for onboarding Windows 11 for your business, which has a cloud-first IT strategy and a fully remote workforce. Which of the following could be an appropriate method to adopt for production onboarding, considering the long-term strategy? Choose all that apply:
    1. Group Policy
    2. Microsoft Intune
    3. Interactively starting a script
    4. Co-management
  3. What is the relationship between Microsoft Defender for Servers and MDE? Choose all that apply:
    1. Microsoft Defender for Servers is included in Microsoft 365 E5
    2. Microsoft Defender for Servers is part of Microsoft Defender for Cloud
    3. MDE is included with Microsoft...

Further reading

There may be some specific scenarios regarding onboarding that this book has not discussed. You can find useful information on examples of these with the following links:

  • If your Windows 10 (or server equivalent) devices are not granted internet access, you may use a network proxy to onboard them: campbell.scot/mdeofflinewindows.
  • If decommissioning devices, you can go through the opposite of onboarding: offboarding. The process varies by OS, with official documentation available here: learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/offboard-machines.
  • Alex Verboon’s Microsoft Defender for Endpoint PowerShell module contains, amongst other great tools, cmdlets such as Get-MDATPDevice to monitor onboarding using PowerShell: github.com/alexverboon/PSMDATP.
  • Completely air-gapped networks with no internet connectivity, including by proxy, are not supported for EDR capabilities, due to the cloud-based nature of MDE. Microsoft has...
lock icon
The rest of the chapter is locked
You have been reading a chapter from
Mastering Microsoft 365 Defender
Published in: Jul 2023Publisher: PacktISBN-13: 9781803241708
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
undefined
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at €14.99/month. Cancel anytime

Authors (2)

author image
Ru Campbell

Ruairidh (Ru) Campbell is a Microsoft Security MVP and leads Microsoft consultancy at Threatscape. At Threatscape, Ru develops, delivers, and manages offerings and professional services for cybersecurity, compliance, identity, and management. In the cybersecurity community, Ru runs the Microsoft 365 Security & Compliance user group and his blog (campbell.scot), regularly speaks at other user groups and conferences, and contributes to well-known industry publications such as Practical 365. Ru holds 14 Microsoft certifications and a B.Sc. (Distinction) in computer networking from the University of the West of Scotland. Away from cybersecurity, he is a petrolhead who enjoys heavy metal and hiking around Scotland with his wife.
Read more about Ru Campbell

author image
Viktor Hedberg

Viktor Hedberg is a Microsoft Security MVP and senior consultant at Truesec. At Truesec, Viktor works with proactive security measures within the Microsoft sphere of technologies, by delivering workshops on best practices and by his deep technical expertise in these areas. In the cybersecurity community, Viktor runs his blogs at Truesec (Experts – viktor-hedberg). Alongside this, he is one of the hosts of the Swedish Windows Security user group, as well as a co-host of the Swedish podcast The Nerd Herd. He is a frequent speaker at both conferences and user groups around the world, focusing on matters of Microsoft Security. Viktor holds numerous Microsoft certifications, as well as being a Microsoft Certified Trainer. Away from cybersecurity, Viktor is a family man, spending most of his time with his wife and three kids, as well as enjoying football, both as a practitioner and as a fan. Heavy metal has been part of his life since his early teens.
Read more about Viktor Hedberg