Reader small image

You're reading from  Mastering Microsoft 365 Defender

Product typeBook
Published inJul 2023
PublisherPackt
ISBN-139781803241708
Edition1st Edition
Right arrow
Authors (2):
Ru Campbell
Ru Campbell
author image
Ru Campbell

Ruairidh (Ru) Campbell is a Microsoft Security MVP and leads Microsoft consultancy at Threatscape. At Threatscape, Ru develops, delivers, and manages offerings and professional services for cybersecurity, compliance, identity, and management. In the cybersecurity community, Ru runs the Microsoft 365 Security & Compliance user group and his blog (campbell.scot), regularly speaks at other user groups and conferences, and contributes to well-known industry publications such as Practical 365. Ru holds 14 Microsoft certifications and a B.Sc. (Distinction) in computer networking from the University of the West of Scotland. Away from cybersecurity, he is a petrolhead who enjoys heavy metal and hiking around Scotland with his wife.
Read more about Ru Campbell

Viktor Hedberg
Viktor Hedberg
author image
Viktor Hedberg

Viktor Hedberg is a Microsoft Security MVP and senior consultant at Truesec. At Truesec, Viktor works with proactive security measures within the Microsoft sphere of technologies, by delivering workshops on best practices and by his deep technical expertise in these areas. In the cybersecurity community, Viktor runs his blogs at Truesec (Experts – viktor-hedberg). Alongside this, he is one of the hosts of the Swedish Windows Security user group, as well as a co-host of the Swedish podcast The Nerd Herd. He is a frequent speaker at both conferences and user groups around the world, focusing on matters of Microsoft Security. Viktor holds numerous Microsoft certifications, as well as being a Microsoft Certified Trainer. Away from cybersecurity, Viktor is a family man, spending most of his time with his wife and three kids, as well as enjoying football, both as a practitioner and as a fan. Heavy metal has been part of his life since his early teens.
Read more about Viktor Hedberg

View More author details
Right arrow

Onboarding and Managing Linux Servers

In this chapter, you will learn about extending Microsoft Defender for Endpoint (MDE) to Linux, the most popular server OS type. You are indeed reading this correctly: you can now get antimalware protection from Microsoft for Linux servers. You’ve already explored how to onboard other desktop and server OSs to MDE, so by extending this to your Linux server estate, you’ll reap the benefits of a central endpoint detection and response (EDR) and antimalware system to defend against threats and respond to incidents.

The process for Linux servers is similar to macOS but has differences you’ll need to be aware of due to the nature of how Linux server distributions operate and are managed. Therefore, in this chapter, to help you master onboarding and managing Linux servers, we’ll explore the following:

  • Options available for onboarding
  • How to customize the protection settings for your Linux servers, including...

Onboarding Linux

If your servers are in Azure or managed with Azure Arc, Microsoft Defender for Cloud is an onboarding option, just as with Windows Server. When you onboard devices using Microsoft Defender for Cloud, it is branded as Microsoft Defender for Servers. Deployment of the client and onboarding to your specific MDE instance is configured automatically this way.

Configuration management tools such as Ansible, Chef, and Puppet can be used to deploy and onboard but are not mandatory: an onboarding script is also available. In this chapter, we will focus on using the script and Microsoft Defender for Cloud.

Script onboarding

The process for onboarding MDE on Linux differs by Linux variation. We can group them into three groups:

  • Amazon Linux 2, CentOS, Fedora, and Oracle Linux all follow the RHEL path
  • Ubuntu and Debian Linux use the same process
  • SLES 12+ sits on its own

Among other things, the commands executed by the shell differ due to the different...

Managing Linux protection settings

With MDE now deployed to your Linux servers, it’s time to focus on customizing its protection settings. This section will educate you on the fundamentals of how Linux settings are deployed, how to manage scanning and remediation, exclusion control, and how updates can be scheduled.

As in other chapters, our focus here is enterprise deployment. While the sudo mdatp config command is available for individual hands-on keyboard servers, just as it was for macOS, we’re going to focus on the configuration profile file. This file is how settings are controlled centrally.

Understanding MDE configuration profile files

Settings are deployed to Linux servers with a configuration profile, like the type of profile you learned about for macOS in the previous chapter. The difference for Linux is the format: JSON.

The good news is that JSON files are easier to read than macOS’s XML files but maintain a similar structure, so you’...

Summary

This chapter taught you how to onboard Linux servers into MDE. You learned that client OSs are unsupported but that many server distributions are supported. We explored the use of a Microsoft-provided script to onboard them, including its various options for customized deployments. You also found out that Microsoft Defender for Servers, part of Microsoft Defender for Cloud, provides automatic onboarding for Linux servers, and that you can extend this to on-premises or third-party clouds using Azure Arc.

In the next chapter, we explore leaving the server world and focus on the most portable devices: iOS and Android.

Questions

Now that you understand the onboarding processes for MDE, you can test your knowledge with the following questions:

  1. Which of the following Linux distributions are supported? Choose all that apply.
    1. Oracle Linux 6.7
    2. Oracle Linux 7.2
    3. Oracle Linux 8
    4. Amazon Linux 2
  2. Which of these should you expect to see on an Ubuntu server onboarded using Microsoft Defender for Cloud? Choose all that apply.
    1. MicrosoftMonitoringAgent
    2. MDE.Cloud
    3. MDE.Linux
    4. OMSAgentForLinux
  3. You want to pilot MDE on some Linux servers purely for endpoint telemetry information and not antimalware. To achieve this, which of the following options can be passed to the script when onboarding devices?
    1. --pilot
    2. --pilot-mode
    3. --passive-mode
    4. --passive
  4. True or false: There is a GUI version of MDE available for client Linux distributions such as Ubuntu.
    1. True
    2. False
  5. Which of the following would you be required to process if adding an individual Linux server to Azure Arc with the generated script? Choose all that apply.
    1. An...

Further reading

There may be some specific scenarios and news regarding MDE for Linux that this book has not discussed. You can find useful information on examples of these with the following links:

lock icon
The rest of the chapter is locked
You have been reading a chapter from
Mastering Microsoft 365 Defender
Published in: Jul 2023Publisher: PacktISBN-13: 9781803241708
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
undefined
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at £13.99/month. Cancel anytime

Authors (2)

author image
Ru Campbell

Ruairidh (Ru) Campbell is a Microsoft Security MVP and leads Microsoft consultancy at Threatscape. At Threatscape, Ru develops, delivers, and manages offerings and professional services for cybersecurity, compliance, identity, and management. In the cybersecurity community, Ru runs the Microsoft 365 Security & Compliance user group and his blog (campbell.scot), regularly speaks at other user groups and conferences, and contributes to well-known industry publications such as Practical 365. Ru holds 14 Microsoft certifications and a B.Sc. (Distinction) in computer networking from the University of the West of Scotland. Away from cybersecurity, he is a petrolhead who enjoys heavy metal and hiking around Scotland with his wife.
Read more about Ru Campbell

author image
Viktor Hedberg

Viktor Hedberg is a Microsoft Security MVP and senior consultant at Truesec. At Truesec, Viktor works with proactive security measures within the Microsoft sphere of technologies, by delivering workshops on best practices and by his deep technical expertise in these areas. In the cybersecurity community, Viktor runs his blogs at Truesec (Experts – viktor-hedberg). Alongside this, he is one of the hosts of the Swedish Windows Security user group, as well as a co-host of the Swedish podcast The Nerd Herd. He is a frequent speaker at both conferences and user groups around the world, focusing on matters of Microsoft Security. Viktor holds numerous Microsoft certifications, as well as being a Microsoft Certified Trainer. Away from cybersecurity, Viktor is a family man, spending most of his time with his wife and three kids, as well as enjoying football, both as a practitioner and as a fan. Heavy metal has been part of his life since his early teens.
Read more about Viktor Hedberg