Skip to content

Commit

Permalink
Update microsoft-defender-antivirus-compatibility.md
Browse files Browse the repository at this point in the history
Added info about the EDR response actions.
YongRhee-MSFT authored Jan 21, 2025
1 parent 4fa5186 commit 09d6f14
Showing 1 changed file with 1 addition and 0 deletions.
Original file line number Diff line number Diff line change
@@ -213,6 +213,7 @@ You can use one of several methods to confirm the state of Microsoft Defender An
> - To switch Microsoft Defender Antivirus to passive mode, even if it was disabled before onboarding, you can apply the [ForceDefenderPassiveMode configuration](switch-to-mde-phase-2.md#set-microsoft-defender-antivirus-to-passive-mode-on-windows-server) with a value of `1`. To place it into active mode, switch this value to `0` instead.
>
> Note the modified logic for `ForceDefenderPassiveMode` when tamper protection is enabled: Once Microsoft Defender Antivirus is toggled to active mode, tamper protection prevents it from going back into passive mode even when `ForceDefenderPassiveMode` is set to `1`.
> All Microsoft Defender for Endpoint – EDR response actions work in Passive mode whether or not in EDR in block mode.
### Use the Windows Security app to identify your antivirus app

0 comments on commit 09d6f14

Please sign in to comment.