Review & Remediate Endpoint Detection and Response Recommendations
Implementation Effort: Medium
Security and IT teams must review EDR-related recommendations, validate agent presence, and take remediation actions across Azure, AWS, and GCP workloads.
User Impact: Low
EDR remediation is handled by administrators; end users are not directly involved.
Overview
Microsoft Defender for Servers integrates with Microsoft Defender for Endpoint (MDE) to provide Endpoint Detection and Response (EDR) capabilities. Defender for Cloud continuously assesses whether supported machines have a valid EDR solution installed and running. If gaps are found, it generates recommendations to help security teams remediate them.
Key Capabilities
- Agentless scanning is used to detect EDR presence on Azure VMs, AWS EC2, and GCP Compute Engine instances.
- Recommendations are generated when:
- No EDR solution is detected.
- A non-Microsoft EDR is unsupported.
- Defender for Endpoint is not properly configured 1.