Cortex XDR Agent & MDE

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Cortex XDR Agent & MDE

L0 Member

I am trying to install Cortex Agent and MS Defender for Endpoint on a Windows Server. We have managed to get them to run in parallel on Windows 10, but are failing to get it work properly on Windows. The bit that is not working is pulling down the AV settings from the MDE console. I have been told to add exclusions into Cortex, and I have added some in there, but it is still not working. Does anyone have some secret sauce that will get them to work happily together?

1 REPLY 1

L0 Member

Getting Cortex XDR Agent and Microsoft Defender for Endpoint (MDE) to coexist on Windows Server is possible, but it is significantly more fragile than on Windows 10. On Server SKUs, Defender’s behavior is much more sensitive to real-time antivirus contention and platform mode mismatches. When another EDR or AV product takes partial control of real-time protection, Defender may silently fall out of its expected operating mode. A common side effect of this condition is that Defender stops pulling or applying AV policies from MDE, even though the MDE sensor itself remains onboarded and healthy. This issue is well-known in environments running dual EDR solutions on Windows Server and typically requires careful coor   transunion credit

  • 1805 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!