Hi Handian,
Thank you for your query.
While third-party antivirus solutions can technically be installed on Azure Local nodes (such as Azure Stack HCI), Microsoft recommends using Microsoft Defender Antivirus as the preferred solution. Defender is natively integrated with the platform and validated to work seamlessly with system updates and cluster operations.
Using third-party antivirus or malware protection tools may introduce risks such as performance impact or interference with OS updates and critical services, especially if not configured with the appropriate exclusions.
If you choose to proceed with a third-party solution, it is important to follow Microsoft’s guidance on antivirus exclusions and best practices to avoid any disruption to workloads or cluster stability.
For more details, please refer to the following documentation:
- Azure Local security and compliance guidance: https://learn.microsoft.com/en-us/azure/azure-local/assurance/azure-stack-iso27001-guidance?view=azloc-2603
- Security features for Azure Local (Microsoft Defender Antivirus) https://learn.microsoft.com/azure/azure-local/concepts/security-features?view=azloc-2603#microsoft-defender-antivirus
- Microsoft Defender Antivirus compatibility with other security products https://learn.microsoft.com/defender-endpoint/microsoft-defender-antivirus-compatibility
- Microsoft Defender Antivirus and non-Microsoft antivirus solutions without Defender for Endpoint https://learn.microsoft.com/defender-endpoint/defender-antivirus-compatibility-without-mde
Hope this helps! If it helpful! Could you please accept the answer and upvote it. Please let me know if you have any queries in comments.