Skip to content

Latest commit

 

History

History
77 lines (62 loc) · 6.56 KB

supported-capabilities-by-platform.md

File metadata and controls

77 lines (62 loc) · 6.56 KB
title description ms.service ms.author author ms.localizationpriority manager audience ms.collection ms.topic ms.subservice search.appverid ms.date
Supported Microsoft Defender for Endpoint capabilities by platform
Get to know the Microsoft Defender for Endpoint capabilities supported for Windows 10 devices, servers, and non-Windows devices.
defender-endpoint
siosulli
siosulli
medium
deniseb
ITPro
m365-security
tier2
conceptual
onboard
met150
07/17/2024

Supported Microsoft Defender for Endpoint capabilities by platform

[!INCLUDE Microsoft Defender XDR rebranding]

Applies to:

Want to experience Defender for Endpoint? Sign up for a free trial.

Learn how to Onboard devices and configure Microsoft Defender for Endpoint capabilities.

The following table gives information about the supported Microsoft Defender for Endpoint capabilities by platform.

Operating System Windows 10 & 11 Windows Server 2012 R2 [1],
2016 [1],
2019 & 2022,
1803+
macOS Linux
Prevention
Attack Surface Reduction Yes. Yes. No No
Device Control Yes. No Yes. No
Firewall Yes. Yes. No No
Network Protection Yes. Yes. Yes. Yes. [2]
Next-generation protection Yes. Yes. Yes. Yes.
Tamper Protection Yes. Yes. Yes. No
Web Protection Yes. Yes. Yes. Yes. [2]
Detection
Advanced Hunting Yes. Yes. Yes. Yes.
Custom file indicators Yes. Yes. Yes. Yes.
Custom network indicators Yes. Yes. Yes. Yes. [2]
EDR Block Yes. Yes. No No
Passive Mode Yes. Yes. Yes. Yes.
Sense detection sensor Yes. Yes. Yes. Yes.
Endpoint & network device discovery Yes. Yes. [5] No No
Vulnerability management Yes. Yes. Yes. Yes.
Response
Automated Investigation & Response (AIR) Yes. Yes. No No
Device response capabilities: collect investigation package Yes. Yes. Yes. [3] Yes. [3]
Device response capabilities: run antivirus scan Yes. Yes. Yes. Yes.
Device isolation Yes. Yes. Yes. Yes.
File response capabilities: collect file, deep analysis, block file, stop, and quarantine processes Yes. Yes. No No
Live Response Yes. Yes. Yes. Yes.

[1] Refers to the modern, unified solution for Windows Server 2012 R2 and Windows Server 2016. For more information, see Onboard Windows Servers to the Defender for Endpoint service.

[2] Feature is currently in preview (Microsoft Defender for Endpoint preview features)

[3] Response capabilities using Live Response [2]

[4] Collect file only, using Live Response [2]

[5] Endpoint & network device discovery is supported on Windows Server 2019 or later, Windows 10, and Windows 11

Note

Windows 7, 8.1, Windows Server 2008 R2 include support for the EDR sensor, and antivirus using System Center Endpoint Protection (SCEP).

[!INCLUDE Microsoft Defender for Endpoint Tech Community]