Windows 10: New capabilities of Windows Defender ATP maximizing endpoint security

Discus and support New capabilities of Windows Defender ATP maximizing endpoint security in Windows 10 News to solve the problem; Our mission is to empower every person and every organization on the planet to achieve more. A trusted and secure computing environment is a critical... Discussion in 'Windows 10 News' started by Brink, Apr 16, 2018.

  1. Brink
    Brink New Member

    New capabilities of Windows Defender ATP maximizing endpoint security


    Source: New capabilities of Windows Defender ATP further maximizing the effectiveness and robustness of endpoint security - Windows For Your Business

    :)
     
    Brink, Apr 16, 2018
    #1
  2. Rob Koch Win User

    Windows Defender ATP.

    Though it's possible that some form of "ATP Lite" might eventually become available for small business use, I believe it's unlikely we'll ever see the current product available to the wider consumer audience.

    I say this because as you should have experienced during the trials, the ATP logging functions can require not only significant quantities of storage for the forensic data, but also the technical ability to manage and understand the information that ATP
    provides.

    Though there have always been some technical users of Windows within the larger consumer population, the number who truly understand such deeper functions are small and the consumer can't really be properly served by the ATP product as it currently exists.

    The core forensics function that ATP provides to both Microsoft and its enterprise customers, allows them not only to leverage each other's expertise, but also to more quickly understand the methods and behaviors behind any new malware attack. This information
    is then used to provide new definitions for Windows Defender, any additional behavioral detections and if necessary, security updates to Windows for all of Microsoft's customers.

    The following blog article discusses how this capability was used in the most recent ransomeware attacks by a new variant of

    Ransom:Win32/Petya
    over the last few days.

    New ransomware, old techniques: Petya adds worm capabilities

    This is how the Defender ATP product actually helps the consumer and small business customer today, by increasing the speed at which Microsoft understands and so can respond to a new attack profile via the existing security products in place on all current platforms.

    So though eventually it wouldn't surprise me to see some form of "this is how your system was compromised" type of feature added to Windows Defender in order to inform the PC owner what they need to do to protect themselves now and in the future, I don't
    truly see any valid reason for the full ATP product as it currently exists to be provided to the wider consumer audience.

    Rob
     
    Rob Koch, Apr 16, 2018
    #2
  3. Managing Windows Defender with SCCM

    Hi everyone,

    We are looking into testing Windows Defender to replace our current AV solution. Our environment is Windows 10 (1703) and SCCM Current branch (1702 - build 8498)

    From reading the various documents (Deploy, manage, and report on Windows Defender Antivirus) it seems that Windows Defender is managed via installing the SCCM Endpoint protection
    point site role. where I am confused is that I was under the impression that endpoint protection referred to the discontinued System Center Endpoint Protection client however it seems that this is what MS uses as a generic label for the AV / malware tools
    nowadayas.

    I just wanted to check whether this is still the correct way to do this in order to manage the inbuilt Windows Defender client on Win 10 (1703) machines. Are there any pitfalls to be aware of? I intend to test this on a small subset of machines as a proof
    of concept.

    My other question is whether anyone here is using Windows Defender ATP and what their thoughts were on this, has it provided you with easier management / better reporting? I do like the look of "cloud" security center. However we are currently on E3 licenses
    and ATP requires E5.

    Many thanks in advance.

    A
     
    AntonyPaul, Apr 16, 2018
    #3
Thema:

New capabilities of Windows Defender ATP maximizing endpoint security

Loading...
  1. New capabilities of Windows Defender ATP maximizing endpoint security - Similar Threads - capabilities Defender ATP

  2. Windows Defender ATP service

    in Windows 10 Customization
    Windows Defender ATP service: Favor de ver este error cuando intento hacer un onboarding del WATPC:\WINDOWS\system32>%userprofile%\Desktop\WindowsDefenderATPLocalOnboardingScript This script will onboard this machine to the Windows Defender ATP service. Once completed, the machine should light up in the...
  3. Defender ATP Analysis

    in AntiVirus, Firewalls and System Security
    Defender ATP Analysis: Is the analysis ie alerting and blocking happening on the endpoints laptops, desktops or in the ATP Cloud console? If the analysis is occurring on the endpoints, will it cause performance issues on all endpoints if it is deployed across ~15,000 devices? If that's the case,...
  4. Microsoft Defender ATP gets new UEFI scanner

    in Windows 10 Ask Insider
    Microsoft Defender ATP gets new UEFI scanner: Microsoft has announced that it’s expanding the protection capabilities of Microsoft Defender ATP to the firmware level by introducing a new Unified Extensible Firmware Interface (UEFI) scanner. https://www.onmsft.com/news/microsoft-defender-atp-gets-new-uefi-scanner...
  5. Windows Defender ATP Reboot

    in AntiVirus, Firewalls and System Security
    Windows Defender ATP Reboot: I am having an issue with Windows Defender ATP on all my Windows 10, domain joined PCs. After running the on-boarding script, the registry is updated at HKLM\SYSTEM\CurrentControlSet\Control\SessionManager\PendingFileRenameOperations with a number of ATP files. After a...
  6. Windows Defender ATP Offboarding

    in AntiVirus, Firewalls and System Security
    Windows Defender ATP Offboarding: Need help with Offboarding 1000 Windows 10 devices from an old 2017 Trial ATP tenant no longer active. Any help would be grateful https://answers.microsoft.com/en-us/windows/forum/all/windows-defender-atp-offboarding/a3c0d30e-5c4a-4cd6-9947-6f0ee8e9311d"
  7. New Tamper protection in Microsoft Defender ATP for Windows 10

    in Windows 10 News
    New Tamper protection in Microsoft Defender ATP for Windows 10: We are committed to making our solutions resistant to attacks and continuously working towards raising the bar in security. In this blog we’re covering a key feature of our tampering protection strategies, which build on our previously announced Windows Defender Antivirus...
  8. Windows Defender ATP EDR capability for Windows 7 and Windows 8.1

    in Windows 10 News
    Windows Defender ATP EDR capability for Windows 7 and Windows 8.1: We’re announcing the general availability of Windows Defender ATP’s endpoint detection & response (EDR) capability for Windows 7 and Windows 8.1, helping customers achieve the best security possible while transitioning to Windows 10. With Windows 10 we’ve built the most...
  9. Defender ATP

    in AntiVirus, Firewalls and System Security
    Defender ATP: I tried to submit a question, but it would not let me submit it. What good does it do to have this system if it won't work. Why am I, as an individual home computer user, subject to the strict regulations of Defender ATP? I cannot connect to links that are provided in...
  10. Windows Defender ATP

    in AntiVirus, Firewalls and System Security
    Windows Defender ATP: What is Sandbox in Windows Defender ATP? https://answers.microsoft.com/en-us/protect/forum/all/windows-defender-atp/714d1096-97e9-49bb-b825-c2c732ccd642