[Updated Feb 2024] Ultimate Comparison of Defender for Endpoint Features by OS

[Updated Feb 2024] Ultimate Comparison of Defender for Endpoint Features by OS

Finally, it's time for a refresh.  It's been a while!  Due to personal circumstances, I haven't been able to keep the Ultimate Comparison of MDE by OS updated.  I've had time to dive into the changes since v5 and it's really been amazing to see MDE grow in scope.  What is MDE and why do we need an 'ultimate comparison'? Microsoft Defender for Endpoint (MDE) is a massive stack of endpoint protection and endpoint…
[Feb 2023] Ultimate Comparison of Defender for Endpoint Features by OS

[Feb 2023] Ultimate Comparison of Defender for Endpoint Features by OS

Microsoft Defender for Endpoint (MDE) is a massive stack of endpoint protection and endpoint detection and response (EDR) capabilities.  It integrates with Microsoft 365 Defender (the broader XDR platform) and is available for almost any OS you'll find in an enterprise.  This cross-platform nature of MDE makes it difficult to understand and track what features and capabilities are available on each OS.  It's not always intuitive, and you may be in for some surprises. …
Ultimate Comparison of Defender for Endpoint Features by OS [Updated August 2022]

Ultimate Comparison of Defender for Endpoint Features by OS [Updated August 2022]

This is the updated "matrix" of OS supported for the almost 80 features, services, and important components that make up Microsoft Defender for Endpoint. This follows up on my March 2022 release of the comparison. What's new? Now available in Excel format, which was the biggest request :) Added the new Microsoft Defender Vulnerability Management capabilities (add-on license required) Added macOS tamper protection support Added macOS network and web protection Added iOS and Android's…
Updated March 2022: Ultimate Comparison of Defender for Endpoint Features by Operating System

Updated March 2022: Ultimate Comparison of Defender for Endpoint Features by Operating System

It's been about 5 months since I last updated my comparison of Defender for Endpoint features by OS.  This is a "matrix" of the tons of features, services, and important components that make up Microsoft Defender for Endpoint. Three months later, it's overdue an update.  So here it is :)  I've also decided to rename it to The Ultimate Comparison of MDE Features by OS... because renaming's what we do, right? Changes include but…
Updated October 2021: Availability of Defender for Endpoint Features by Operating System

Updated October 2021: Availability of Defender for Endpoint Features by Operating System

In July, I released v1 of The Big Comparison of Defender for Endpoint Features by Operating System (or, what I think is much catchier, TBCMDEFOS).  This was a "matrix" of the tons of features, services, and important components that make up Microsoft Defender for Endpoint. Three months later, it's overdue an update.  So here it is :) The headline news is that, in preview anyway, there's a bunch of additions to Windows Server 2012…
The Big Comparison of Defender for Endpoint Features by Operating System

The Big Comparison of Defender for Endpoint Features by Operating System

Microsoft Defender for Endpoint (MDE) is a massive platform.  It's not a single product, and it's more than just a service.  It's a platform of tons of security features, portals, services, and controls.  The more you dig in, the more elements of general Microsoft security have been included in the MDE "branding".  It's not only endpoint detection and response (EDR), but also Windows 10 security settings.  It's not just the security software on the…
Microsoft Defender Antivirus – Schedule & Install Updates via Network Shares

Microsoft Defender Antivirus – Schedule & Install Updates via Network Shares

Although not common, there are scenarios out where you will have LAN-only devices onboarded in Microsoft Defender for Endpoint (MDE), or at least using Microsoft Defender Antivirus (MDAV).  With no line of sight to the internet, you can use options such as WSUS, but in this blog, I'll explore using a network share, as WSUS isn't always an option. Set up the network share for updates 1. Create a directory on your file server…
Microsoft Defender for Endpoint – Offline Onboarding for Windows 10 via a Proxy

Microsoft Defender for Endpoint – Offline Onboarding for Windows 10 via a Proxy

Getting your devices into Defender for Endpoint is referred to as onboarding and can be done in lots of different ways, depending on the scenario.  The tools you use for Windows Server 2008 R2, for example, are different from the tools you use for Windows Server 2019, which are different from the tools you use for Windows 10, and so on. The common denominator behind most onboarding methods is internet connectivity.  Your device connects…
Microsoft Defender for Endpoint Web Content Filtering – Migrate Rules from Existing Security Software

Microsoft Defender for Endpoint Web Content Filtering – Migrate Rules from Existing Security Software

In my last blog, I wrote about web content filtering in MDATP and how it now allows you to block website categories on the client across all apps.  Category blockers are great because, with one easy checkbox, you ban hundreds of thousands of dangerous on inappropriate websites.  Nothing is perfect, though, and anyone who's ever worked a helpdesk or SOC will attest that false positives and false negatives are common. The engine for MDATP…
Microsoft Defender for Endpoint Web Content Filtering – Administration, Limitations, and User Experience

Microsoft Defender for Endpoint Web Content Filtering – Administration, Limitations, and User Experience

Historically, one of the big features missing "out of the box" with MDATP was web content filtering.  Customers typically look at MDATP as an option when their existing endpoint security is due for license renewal, and compare their existing solution against it.  They would be moving from one of the big security vendors such as Sophos, Norton, and McAfee, which all supported web content filtering.  Higher lever stakeholders often listed the ability to block…