Update defender-csp.md

adding new EDR block CSP (PassiveRemediation) 
to be merged on date of next platform release & confirmed by Denise
This commit is contained in:
Marysia Kaminska 2022-02-28 11:25:01 -08:00 committed by GitHub
parent 3d41a80ebe
commit 51f19fe924
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -75,6 +75,7 @@ Defender
--------EngineUpdatesChannel (Added with the 4.18.2106.5 Defender platform release) --------EngineUpdatesChannel (Added with the 4.18.2106.5 Defender platform release)
--------SecurityIntelligenceUpdatesChannel (Added with the 4.18.2106.5 Defender platform release) --------SecurityIntelligenceUpdatesChannel (Added with the 4.18.2106.5 Defender platform release)
--------DisableGradualRelease (Added with the 4.18.2106.5 Defender platform release) --------DisableGradualRelease (Added with the 4.18.2106.5 Defender platform release)
--------PassiveRemediation (Added with the 4.18.2202.X Defender platform release)
----Scan ----Scan
----UpdateSignature ----UpdateSignature
----OfflineScan (Added in Windows 10 version 1803) ----OfflineScan (Added in Windows 10 version 1803)
@ -821,6 +822,16 @@ More details:
- [Manage the gradual rollout process for Microsoft Defender updates](/microsoft-365/security/defender-endpoint/manage-gradual-rollout) - [Manage the gradual rollout process for Microsoft Defender updates](/microsoft-365/security/defender-endpoint/manage-gradual-rollout)
- [Create a custom gradual rollout process for Microsoft Defender updates](/microsoft-365/security/defender-endpoint/configure-updates) - [Create a custom gradual rollout process for Microsoft Defender updates](/microsoft-365/security/defender-endpoint/configure-updates)
<a href="" id="configuration-passiveremediation"></a>**Configuration/PassiveRemediation**
This policy setting enables or disables EDR in block mode (recommended for devices running Microsoft Defender Antivirus in passive mode). For more information, see Endpoint detection and response in block mode | Microsoft Docs. Available with platform release: 4.18.2202.X
The data type is integer
Supported values:
- 1: Turn EDR in block mode on
- 0: Turn EDR in block mode off
<a href="" id="scan"></a>**Scan** <a href="" id="scan"></a>**Scan**
Node that can be used to start a Windows Defender scan on a device. Node that can be used to start a Windows Defender scan on a device.