Edit

Detecting endpoint detection and response solutions

This article explains how to check whether machines use a supported endpoint detection and response (EDR) solution.

Defender for Cloud includes EDR features for supported machines. It can:

Check for an EDR solution

Defender for Cloud uses agentless scanning to check whether Azure VMs and AWS/GCP machines connect to an EDR solution.

Agentless scanning for EDR settings is available when you enable Defender for Servers Plan 2 or the Defender CSPM plan in your Azure subscription.

Based on the findings, Defender for Cloud provides recommendations to help you find and fix machines that don't have an EDR solution running:

  • EDR solution should be installed on virtual machines
  • EDR solution should be installed on EC2 instances
  • EDR solution should be installed on virtual machines in GCP

Supported EDR solutions

The following table lists the EDR solutions supported by Defender for Cloud:

Solution Supported platform
Microsoft Defender for Endpoint Windows
Microsoft Defender for Endpoint Linux
Microsoft Defender for Endpoint Unified Solution Windows Server 2012/2012 R2
CrowdStrike (Falcon) Windows and Linux
Trellix Windows and Linux
Symantec Windows and Linux
Sophos Windows and Linux
Singularity Platform by SentinelOne Windows and Linux
Cortex XDR Windows and Linux (Supported only when installed via package manager on Linux)

Next steps

Review and remediate the "EDR solution should be installed" recommendations for virtual machines, EC2 instances, and GCP VMs.