Three months after the last big refresh, I’ve worked through Microsoft’s Defender documentation again and updated my cross-platform comparison of Microsoft Defender for Endpoint features by operating system.

The big changes relate to AI agent security, ASR minimum version changes, and the Defender deployment tool (DDT).

You can find the updated comparison here:

Quick plug

If the comparison is useful and you want to go much deeper, MDE In Depth, 2nd Edition is available now. Paul, Ian, and I cover the architecture, deployment, configuration, investigation, hunting, response, and day-to-day operation of Defender for Endpoint in considerably more detail than I can fit into one comparison table.

MDE In Depth 2nd Edition cover

Notes

As usual, this is a best-efforts comparison. Microsoft’s documentation is spread across several doc sets, sometimes conflicts with itself, and doesn’t always make the distinction between product licensing, operating-system support, agent requirements, preview status, and portal availability especially obvious. The fun never stops.

Where the documentation conflicts, I’ve tried to be explicit about the limitation rather than picking the most generous interpretation. Feedback is very welcome if you spot something I’ve missed or think I’ve interpreted something incorrectly.

Changelog

  • Updated the for the current Defender deployment tool solution on Windows 7 SP1 and Windows Server 2008 R2.
  • Corrected the Android minimum from Android 11 to Android 10.
  • Corrected several ASR rule minimum-version entries and clarified Windows Server support wording for vulnerable-driver blocking and WMI persistence blocking.
  • Expanded the Network Protection notes with the Windows Server opt-in settings and Microsoft’s datagram-processing recommendation for high-volume server roles.
  • Updated down-level antivirus coverage to reflect the Defender deployment tool, while separating that from the older MMA/SCEP path.
  • Added Controlled configuration, currently in preview.
  • Added scheduled antivirus scans due to the preview Linux management experience and its agent requirement.
  • Updated offline security-intelligence management and changed custom data collection from preview to generally available.
  • Added the new AI agent security section, covering preview discovery of local AI agents and preview runtime protection.
  • Expanded Windows 7 SP1 and Windows Server 2008 R2 response-action coverage for antivirus scans, full isolation, and investigation-package collection.
  • Updated device response action licensing. This added P1 to forcible release from isolation and live response library management, and added Defender for Business to device containment.
  • Clarified where Windows Server 2008 R2 vulnerability-management capabilities are documented only for the legacy agent rather than the current Defender deployment tool solution.
  • Updated Android root detection to GA and clarified system-app scanning (and the Trust this network limitations in mobile network protection).
  • Updated onboarding and management for the generally available Defender deployment tool, e.g. Linux support.
  • Added the new Selective Response Actions capability.