Microsoft Defender for Endpoint | Onboarding Windows Server 2012 R2

แชร์
ฝัง
  • เผยแพร่เมื่อ 23 เม.ย. 2022
  • #microsoft #securityoperations #cybersecurity #security #datasecurity #infosec #databreach #cyber #cloudsecurity #computersecurity #defender #microsoftdefender #defenderforendpoint #endpointsecurity #edr #antivirus
    Microsoft Defender for Endpoint for Windows Server 2012 R2
    Onboarding Windows Server 2012 R2 to MDE
    Microsoft Article - docs.microsoft.com/en-us/micr...
    Network URLs for Commercial Customers - download.microsoft.com/downlo...
    All URLs - docs.microsoft.com/en-us/micr...
    What is Microsoft Defender for Endpoint? • Microsoft Defender - W...
    Getting Started with Microsoft Defender for Endpoint? • Microsoft Defender for...
    Microsoft Defender for Endpoint - Role Based Access Control • Microsoft Defender for...
    Microsoft Defender for Endpoint - Role Based Access Control - Portal Configuration • Microsoft Defender for...
    Onboard Windows 10 Devices | Microsoft Defender for Endpoints | MDATP | Local Script • Onboard Windows 10 Dev...
    Onboard Windows 10 Devices from GPO | Microsoft Defender for Endpoint • Onboard Windows 10 Dev...
    Microsoft Defender for Endpoint | Onboarding Linux Machine • Microsoft Defender for...
    Microsoft Defender for Endpoint for Linux • Microsoft Defender for...
    Microsoft Defender For Endpoint Deployment Guide • Detailed Deployment Vi...
    Microsoft Defender for Endpoint - Threat and Vulnerability Management • Microsoft Defender for...
    Threat and Vulnerability Management - Software Inventory | Microsoft Defender for Endpoint • Threat and Vulnerabili...
    Getting Started with Threat and Vulnerability Management | Microsoft defender for Endpoints • Getting Started with T...
    Security Recommendation and Remediation | Microsoft Defender for Endpoint • Security Recommendatio...
    Threat and Vulnerability Management - Weaknesses | Microsoft Defender for Endpoint • Threat and Vulnerabili...
    Threat and Vulnerability Management - Dashboard | Microsoft Defender for Endpoint • Threat and Vulnerabili...
    Regards,
    ConceptsWork
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 23

  • @gocrow23
    @gocrow23 2 ปีที่แล้ว +1

    Wonderfully explained in depth for given agenda. May I request you to cover some more areas mentioned below per Azure Arc enabled servers as one end to end video:
    1. Fresh install and onboarding of Azure arc agent using local using local script and group policy & off boarding if something was already on boarded it from previous tenants.
    2. This you already covered - MDE for Server 2012R2.
    3. Kms thru local script or Gpo
    4. Enabling all Azure Arc dependent native services, e.g. Update mgmt, log analytics (pre-req), Azure monitor etc.
    Common -
    1. verifying all these installations just like you did for mde.
    2. Including URL whitelising for smooth process.
    3. Pls include active passive mode in case where other non Microsoft software is being used as AV.
    4. SSCM
    5. Challenge: when onboarding multiple non native server thru Azure arc, we can use script for multiple servers but it needs Service principal and it is laid as bare text if doing using GPO then poses a security risk even though in own OU. There is MS doc. which is not too clear. Pls share if know a more secure way where we can mask/hide sp secret maybe using it in blob but how would it be read in script is Q.

  • @FearsomeGibbonofDoom
    @FearsomeGibbonofDoom ปีที่แล้ว

    This Defender for Endpoint series has been great, really clear and concise information. Thank you and well done.

  • @TastelessVanilla
    @TastelessVanilla ปีที่แล้ว +1

    Brilliant video, very clear and straight forward - Good job.

  • @networkn
    @networkn ปีที่แล้ว

    You did an excellent job with this video. Very clear.

  • @ibrahimabdeltawab6418
    @ibrahimabdeltawab6418 ปีที่แล้ว

    So helpful! Thanks so much

  • @BxN88
    @BxN88 ปีที่แล้ว

    In the process to standardize all devices from MMA legacy to MDE with SCCM client settings. This video really help. Do we have to uninstall the SCEP if it's already installed prior to use the MDE solution ? (Forget it... it must be Uninstall ... md4ws cant be installed if SCEP is still there)

  • @ro_surya
    @ro_surya 2 ปีที่แล้ว

    How to implement with group policy for multiple 2012 R2 & 2016 servers using 2019 as DC.. Please explain.. 🙏🙏

  • @user-kl1bm2gt4e
    @user-kl1bm2gt4e 5 หลายเดือนก่อน

    i am getting error on 2012R2 servers while installing the agent (2012 R2 - MpAsDesc.dll 310
    ). which KBA is required ?

  • @Lazielad
    @Lazielad 9 หลายเดือนก่อน

    Super videos , Is there a video for Onboarding non-persistent VDI as well

  • @mystudy1512
    @mystudy1512 2 ปีที่แล้ว +1

    thankyou for the wonderful presentation, but I have one doubt. How do we manage the server devices in endpoint security, need different AV configuration settings for the server
    should we manage via the SCCM

    • @ConceptsWork
      @ConceptsWork  2 ปีที่แล้ว

      It will be there in next two weeks.

  • @lees3692
    @lees3692 11 หลายเดือนก่อน

    I came here hoping to find out why one of my 2012R2 systems says it onboards successfully after running the onboarding .cmd file. Yet still shows "Can be Onboarded" in the M365 Defender portal. The Defender ATP service shows running and automatic (delayed start). None of the tips provided in the video seem to work for this server. I've deployed to dozens of other 2012R2 systems with minimal issues.

    • @ConceptsWork
      @ConceptsWork  11 หลายเดือนก่อน

      You must use client analyzer tool to get more insights, usually it is endpoints but as you have mentioned other servers are working, I am assuming it has to be something specific with the machine.

    • @lees3692
      @lees3692 11 หลายเดือนก่อน

      @@ConceptsWork I tried that already. The results aren't helpful. The provide the same results as a system that has successfully onboarded.

  • @storm_rder2345
    @storm_rder2345 ปีที่แล้ว +1

    Hi, when I am installing the installation package it is getting rolled back without giving any error, it just says
    "Microsoft defender for endpoint setup wizard ended prematurely because of an error. Your system has not been modified, to install this program at a later time run setup wizard again click the finish button to exit the setup wizard"

    • @ConceptsWork
      @ConceptsWork  ปีที่แล้ว

      Which version of windows server ??

    • @storm_rder2345
      @storm_rder2345 ปีที่แล้ว

      @@ConceptsWork Windows server 2012r2

    • @HannielGondim
      @HannielGondim ปีที่แล้ว

      The same problem here!
      I tried some processes but without success in the installation.

  • @amitbahuguna3270
    @amitbahuguna3270 2 ปีที่แล้ว

    How can i get presentation of this video

    • @ConceptsWork
      @ConceptsWork  2 ปีที่แล้ว

      Please send an email to learconceptswork@gmail.com

  • @AD-pb5mh
    @AD-pb5mh ปีที่แล้ว

    The entire onboarding process for Windows Servers is a total shit show thanks to Microsoft. I work in an environment with approx. 4,000 servers ranging from Server 2012 R2, 2016, 2019 etc. We use SCCM to patch all of these servers and it should have the capability to deploy required installation packages and perform the onboarding. Right now we are using custom task sequences to perform this action and its been a mess. Any other AV solution out there, would have been a lot less troublesome.....

    • @ConceptsWork
      @ConceptsWork  ปีที่แล้ว +1

      I agree, it is complicated, but most of the issues are related to either server not patched before onboarding getting started or disableantivirus or disableantispyware registery being created in policies section.

    • @AD-pb5mh
      @AD-pb5mh ปีที่แล้ว

      @@ConceptsWork Are there any guides on how to do this via Microsoft Endpoint Configuration Manager (SCCM)?