Windows 10: Defender ATP, Storage Servers, $Home Drives

Discus and support Defender ATP, Storage Servers, $Home Drives in AntiVirus, Firewalls and System Security to solve the problem; In an enterprise, users can have $Home drives, Roaming Profiles, and/or Shell folders like Desktop/Documents located on a storage server. Is anyone... Discussion in 'AntiVirus, Firewalls and System Security' started by AlHoff25, Feb 4, 2021.

  1. AlHoff25 Win User

    Defender ATP, Storage Servers, $Home Drives


    In an enterprise, users can have $Home drives, Roaming Profiles, and/or Shell folders like Desktop/Documents located on a storage server.

    Is anyone seeing DATP quarantining the same file non-malicious file, creating the same alert, because it doesn't get removed? How is the false-positive file returning if it says it was quarantined??


    --

    I know it should be deleted in both places.

    So, there's a couple of ways to ask this question.


    Can there be a situation where Defender ATP quarantines a file on a computer, but the storage server puts it back and creates a loop of alerts?

    Is there ever a case where DATP removes something, but doesn't sync to storage and delete that copy?

    Could the large enterprise have a setup where the file has to be removed on a computer and specific from the server's drive itself?


    You might have seen when DATP keeps quarantining the same file over and over, creating the same alert. I'm not truly concerned with malware persistence or the Registry/bigger concerns/types of malware/etc, but instead quarantining any file and continuously creating an alert because of how infrastructure is set up.


    Technically, DATP should delete your file and it's gone everywhere, but Microsoft can create unexpected, variable situations where its not fixed by definition. I had a situation like this with OneDrive syncing to my personal computer after a reimage. The file name was in a .tmp state, so AV>OneDrive>AV>OneDrive, and I couldn't go and just delete it.

    :)
     
    AlHoff25, Feb 4, 2021
    #1
  2. Naresh_K Win User

    Defender ATP

    Hi,



    Thank you for writing to Microsoft Community Forums.



    Usually we do not suggest to disable Windows Defender feature, Windows Defender ATP protects endpoints from cyber threats; detects advanced attacks and data breaches, automates security incidents, and improves security posture. However, if you
    still wish to disable it, please follow the steps mentioned below and check if it helps:

    1. Open Windows Settings (Windows key + I).
    2. Then click on Updates & Settings.
    3. Then click on Windows Security.
    4. You can disable Cloud based and automatic submissions.

    If you need any additional assistance, then please write back with the following information:

    1. What is the exact error message which you are getting?
    2. Is the issue specific to an application?
    3. Could you please
      post a screenshot for a better understanding?


    Regards,
     
    Naresh_K, Feb 4, 2021
    #2
  3. How to setup window defender ATP?

    I would like to know on how to setup window defender ATP

    Does anyone have any suggestions?

    Thanks in advance for any suggestions
     
    PublicMicro, Feb 4, 2021
    #3
  4. Defender ATP, Storage Servers, $Home Drives

    Windows Defender ATP.

    Why isn't the Windows Defender ATP platform available with Windows 10 Pro for free? What's the difference between Windows Defender and Windows Defender ATP? If you're going to make Windows 10 the best operating system ever, the virus and malware protection
    has to be the best too. So having one Windows Defender ATP across the whole Windows 10 ecosystem for free is better then having two different virus and malware platforms?
     
    AnthonyPosi, Feb 4, 2021
    #4
Thema:

Defender ATP, Storage Servers, $Home Drives

Loading...
  1. Defender ATP, Storage Servers, $Home Drives - Similar Threads - Defender ATP Storage

  2. Disabling Defender ATP

    in Windows 10 Software and Apps
    Disabling Defender ATP: Hi, I am struggling with disabling Windows Defender ATP, once I try to disable it from the settings turn off real-time protection, I am unable to do so because of tamper protection, it says that this setting is managed by your administrator, and I am not able to turn off...
  3. Disabling Defender ATP

    in Windows 10 Gaming
    Disabling Defender ATP: Hi, I am struggling with disabling Windows Defender ATP, once I try to disable it from the settings turn off real-time protection, I am unable to do so because of tamper protection, it says that this setting is managed by your administrator, and I am not able to turn off...
  4. Duplicate entries in Defender ATP

    in AntiVirus, Firewalls and System Security
    Duplicate entries in Defender ATP: Hello,Thanks in advance for any information on this issue.As you can see we have duplicate entries in the Security Center showing up. In the below example, there are 4 total entries for this VM. These VMs are deployed through a pipeline. For some reason some are showing up in...
  5. Defender ATP for On-Prem Server

    in AntiVirus, Firewalls and System Security
    Defender ATP for On-Prem Server: Hi,Our company is conducting a POC for multiple EDR solutions for all endpoints including the On-Prem Windows servers and Linux boxes. There is crystal clear information on how to onboard the endpoints to Microsoft Security Center and what kind of licensing is required. An...
  6. Defender ATP Analysis

    in AntiVirus, Firewalls and System Security
    Defender ATP Analysis: Is the analysis ie alerting and blocking happening on the endpoints laptops, desktops or in the ATP Cloud console? If the analysis is occurring on the endpoints, will it cause performance issues on all endpoints if it is deployed across ~15,000 devices? If that's the case,...
  7. onboarding windows server 2016 Windows Defender ATP

    in AntiVirus, Firewalls and System Security
    onboarding windows server 2016 Windows Defender ATP: Hello, I have managed to onboard windows server 2019 and we can see Exposure level and risk lvl. We have also configure Azure Security center to deploy win 2008 r2, 2012 and 2016 machines and enabled integration with ATP which means all devices that are enrolled in azure...
  8. Windows Defender ATP Offboarding

    in AntiVirus, Firewalls and System Security
    Windows Defender ATP Offboarding: Need help with Offboarding 1000 Windows 10 devices from an old 2017 Trial ATP tenant no longer active. Any help would be grateful https://answers.microsoft.com/en-us/windows/forum/all/windows-defender-atp-offboarding/a3c0d30e-5c4a-4cd6-9947-6f0ee8e9311d"
  9. Defender ATP

    in AntiVirus, Firewalls and System Security
    Defender ATP: I tried to submit a question, but it would not let me submit it. What good does it do to have this system if it won't work. Why am I, as an individual home computer user, subject to the strict regulations of Defender ATP? I cannot connect to links that are provided in...
  10. Windows Defender ATP

    in AntiVirus, Firewalls and System Security
    Windows Defender ATP: What is Sandbox in Windows Defender ATP? https://answers.microsoft.com/en-us/protect/forum/all/windows-defender-atp/714d1096-97e9-49bb-b825-c2c732ccd642