mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-12 21:37:22 +00:00
Merge remote-tracking branch 'refs/remotes/origin/rs4' into jdrs4
This commit is contained in:
commit
7d806e4b1c
@ -1,6 +1,436 @@
|
|||||||
{
|
{
|
||||||
"redirections": [
|
"redirections": [
|
||||||
{
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/add-rules-for-packaged-apps-to-existing-applocker-rule-set.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/add-rules-for-packaged-apps-to-existing-applocker-rule-set",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/administer-applocker-using-mdm.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/administer-applocker-using-mdm",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/administer-applocker.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/administer-applocker",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/applocker-architecture-and-components.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-architecture-and-components",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/applocker-functions.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-functions",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/applocker-overview.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-overview",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/applocker-policies-deployment-guide.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-policies-deployment-guide",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/applocker-policies-design-guide.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-policies-design-guide",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/applocker-policy-use-scenarios.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-policy-use-scenarios",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/applocker-processes-and-interactions.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-processes-and-interactions",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/applocker-settings.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-settings",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/applocker-technical-reference.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-technical-reference",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/configure-an-applocker-policy-for-audit-only.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/configure-an-applocker-policy-for-audit-only",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/configure-an-applocker-policy-for-enforce-rules.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/configure-an-applocker-policy-for-enforce-rules",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/configure-exceptions-for-an-applocker-rule.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/configure-exceptions-for-an-applocker-rule",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/configure-the-application-identity-service.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/configure-the-application-identity-service",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/configure-the-appLocker-reference-device.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/configure-the-appLocker-reference-device",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/create-a-rule-for-packaged-apps.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/create-a-rule-for-packaged-apps",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/create-a-rule-that-uses-a-file-hash-condition.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/create-a-rule-that-uses-a-file-hash-condition",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/create-a-rule-that-uses-a-path-condition.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/create-a-rule-that-uses-a-path-condition",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/create-a-rule-that-uses-a-publisher-condition.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/create-a-rule-that-uses-a-publisher-condition",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/create-applocker-default-rules.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/create-applocker-default-rules",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/create-list-of-applications-deployed-to-each-business-group.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/create-list-of-applications-deployed-to-each-business-group",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/create-your-applocker-policies.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/create-your-applocker-policies",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/create-your-applocker-rules.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/create-your-applocker-rules",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/delete-an-applocker-rule.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/delete-an-applocker-rule",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/deploy-applocker-policies-by-using-the-enforce-rules-setting.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/deploy-applocker-policies-by-using-the-enforce-rules-setting",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/deploy-the-applocker-policy-into-production.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/deploy-the-applocker-policy-into-production",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/determine-group-policy-structure-and-rule-enforcement.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/determine-group-policy-structure-and-rule-enforcement",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/determine-which-applications-are-digitally-signed-on-a-reference-computer.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/determine-which-applications-are-digitally-signed-on-a-reference-computer",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/determine-your-application-control-objectives.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/determine-your-application-control-objectives",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/display-a-custom-url-message-when-users-try-to-run-a-blocked-application.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/display-a-custom-url-message-when-users-try-to-run-a-blocked-application",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/dll-rules-in-applocker.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/dll-rules-in-applocker",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/document-group-policy-structure-and-applocker-rule-enforcement.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/document-group-policy-structure-and-applocker-rule-enforcement",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/document-your-application-list.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/document-your-application-list",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/document-your-applocker-rules.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/document-your-applocker-rules",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/edit-an-applocker-policy.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/edit-an-applocker-policy",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/edit-applocker-rules.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/edit-applocker-rules",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/enable-the-dll-rule-collection.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/enable-the-dll-rule-collection",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/enforce-applocker-rules.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/enforce-applocker-rules",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/executable-rules-in-applocker.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/executable-rules-in-applocker",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/export-an-applocker-policy-from-a-gpo.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/export-an-applocker-policy-from-a-gpo",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/export-an-applocker-policy-to-an-xml-file.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/export-an-applocker-policy-to-an-xml-file",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/how-applocker-works-techref.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/how-applocker-works-techref",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/import-an-applocker-policy-from-another-computer.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/import-an-applocker-policy-from-another-computer",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/import-an-applocker-policy-into-a-gpo.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/import-an-applocker-policy-into-a-gpo",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/maintain-applocker-policies.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/maintain-applocker-policies",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/manage-packaged-apps-with-applocker.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/manage-packaged-apps-with-applocker",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/merge-applocker-policies-by-using-set-applockerpolicy.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/merge-applocker-policies-by-using-set-applockerpolicy",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/merge-applocker-policies-manually.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/merge-applocker-policies-manually",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/monitor-application-usage-with-applocker.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/monitor-application-usage-with-applocker",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/optimize-applocker-performance.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/optimize-applocker-performance",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/packaged-apps-and-packaged-app-installer-rules-in-applocker.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/packaged-apps-and-packaged-app-installer-rules-in-applocker",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/plan-for-applocker-policy-management.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/plan-for-applocker-policy-management",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/refresh-an-applocker-policy.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/refresh-an-applocker-policy",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/requirements-for-deploying-applocker-policies.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/requirements-for-deploying-applocker-policies",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/requirements-to-use-applocker.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/requirements-to-use-applocker",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/run-the-automatically-generate-rules-wizard.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/run-the-automatically-generate-rules-wizard",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/script-rules-in-applocker.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/script-rules-in-applocker",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/security-considerations-for-applocker.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/security-considerations-for-applocker",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/select-types-of-rules-to-create.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/select-types-of-rules-to-create",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/test-an-applocker-policy-by-using-test-applockerpolicy.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/test-an-applocker-policy-by-using-test-applockerpolicy",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/test-and-update-an-applocker-policy.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/test-and-update-an-applocker-policy",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/tools-to-use-with-applocker.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/tools-to-use-with-applocker",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/understand-applocker-enforcement-settings.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/understand-applocker-enforcement-settings",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/understand-applocker-policy-design-decisions.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/understand-applocker-policy-design-decisions",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/understand-applocker-rules-and-enforcement-setting-inheritance-in-group-policy.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/understand-applocker-rules-and-enforcement-setting-inheritance-in-group-policy",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/understand-the-applocker-policy-deployment-process.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/understand-the-applocker-policy-deployment-process",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/understanding-applocker-allow-and-deny-actions-on-rules.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/understanding-applocker-allow-and-deny-actions-on-rules",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/understanding-applocker-default-rules.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/understanding-applocker-default-rules",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/understanding-applocker-rule-behavior.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/understanding-applocker-rule-behavior",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/understanding-applocker-rule-collections.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/understanding-applocker-rule-collections",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/understanding-applocker-rule-condition-types.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/understanding-applocker-rule-condition-types",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/understanding-applocker-rule-exceptions.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/understanding-applocker-rule-exceptions",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/understanding-the-file-hash-rule-condition-in-applocker.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/understanding-the-file-hash-rule-condition-in-applocker",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/understanding-the-path-rule-condition-in-applocker.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/understanding-the-path-rule-condition-in-applocker",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/understanding-the-publisher-rule-condition-in-applocker.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/understanding-the-publisher-rule-condition-in-applocker",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/use-a-reference-computer-to-create-and-maintain-applocker-policies.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/use-a-reference-computer-to-create-and-maintain-applocker-policies",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/use-applocker-and-software-restriction-policies-in-the-same-domain.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/use-applocker-and-software-restriction-policies-in-the-same-domain",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/use-the-applocker-windows-powershell-cmdlets.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/use-the-applocker-windows-powershell-cmdlets",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/using-event-viewer-with-applocker.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/using-event-viewer-with-applocker",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/using-software-restriction-policies-and-applocker-policies.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/using-software-restriction-policies-and-applocker-policies",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/what-is-applocker.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/what-is-applocker",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/windows-installer-rules-in-applocker.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/windows-installer-rules-in-applocker",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/working-with-applocker-policies.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/working-with-applocker-policies",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"source_path": "windows/security/threat-protection/applocker/working-with-applocker-rules.md",
|
||||||
|
"redirect_url": "/windows/security/threat-protection/windows-defender-application-control/applocker/working-with-applocker-rules",
|
||||||
|
"redirect_document_id": true
|
||||||
|
},
|
||||||
|
{
|
||||||
"source_path": "windows/security/threat-protection/device-guard/requirements-and-deployment-planning-guidelines-for-device-guard.md",
|
"source_path": "windows/security/threat-protection/device-guard/requirements-and-deployment-planning-guidelines-for-device-guard.md",
|
||||||
"redirect_url": "/windows/security/threat-protection/windows-defender-exploit-guard/requirements-and-deployment-planning-guidelines-for-virtualization-based-protection-of-code-integrity",
|
"redirect_url": "/windows/security/threat-protection/windows-defender-exploit-guard/requirements-and-deployment-planning-guidelines-for-virtualization-based-protection-of-code-integrity",
|
||||||
"redirect_document_id": true
|
"redirect_document_id": true
|
||||||
|
@ -509,7 +509,7 @@ If you set this policy, the GroupID policy will be ignored.
|
|||||||
|
|
||||||
The options set in this policy only apply to Group (2) download mode. If Group (2) isn't set as Download mode, this policy will be ignored.
|
The options set in this policy only apply to Group (2) download mode. If Group (2) isn't set as Download mode, this policy will be ignored.
|
||||||
|
|
||||||
For option 4 - DHCP Option ID, the client will query DHCP Option ID 234 and use the returned GUID value as the Group ID.
|
For option 3 - DHCP Option ID, the client will query DHCP Option ID 234 and use the returned GUID value as the Group ID.
|
||||||
|
|
||||||
<!--/Description-->
|
<!--/Description-->
|
||||||
<!--ADMXMapped-->
|
<!--ADMXMapped-->
|
||||||
|
@ -189,6 +189,7 @@
|
|||||||
##### [Enable and create Power BI reports using Windows Defender ATP data](windows-defender-atp\powerbi-reports-windows-defender-advanced-threat-protection.md)
|
##### [Enable and create Power BI reports using Windows Defender ATP data](windows-defender-atp\powerbi-reports-windows-defender-advanced-threat-protection.md)
|
||||||
##### [Enable Secure score security controls](windows-defender-atp\enable-secure-score-windows-defender-advanced-threat-protection.md)
|
##### [Enable Secure score security controls](windows-defender-atp\enable-secure-score-windows-defender-advanced-threat-protection.md)
|
||||||
##### [Configure advanced features](windows-defender-atp\advanced-features-windows-defender-advanced-threat-protection.md)
|
##### [Configure advanced features](windows-defender-atp\advanced-features-windows-defender-advanced-threat-protection.md)
|
||||||
|
##### [Protect data with conditional access](windows-defender-atp\conditional-access-windows-defender-advanced-threat-protection.md)
|
||||||
|
|
||||||
####Permissions
|
####Permissions
|
||||||
##### [Manage portal access using RBAC](windows-defender-atp\rbac-windows-defender-advanced-threat-protection.md)
|
##### [Manage portal access using RBAC](windows-defender-atp\rbac-windows-defender-advanced-threat-protection.md)
|
||||||
@ -294,6 +295,9 @@
|
|||||||
#### [Enable Exploit protection](windows-defender-exploit-guard\enable-exploit-protection.md)
|
#### [Enable Exploit protection](windows-defender-exploit-guard\enable-exploit-protection.md)
|
||||||
#### [Customize Exploit protection](windows-defender-exploit-guard\customize-exploit-protection.md)
|
#### [Customize Exploit protection](windows-defender-exploit-guard\customize-exploit-protection.md)
|
||||||
##### [Import, export, and deploy Exploit protection configurations](windows-defender-exploit-guard\import-export-exploit-protection-emet-xml.md)
|
##### [Import, export, and deploy Exploit protection configurations](windows-defender-exploit-guard\import-export-exploit-protection-emet-xml.md)
|
||||||
|
#### [Memory integrity](windows-defender-exploit-guard/memory-integrity.md)
|
||||||
|
##### [Requirements and deployment planning guidelines for virtualization-based protection of code integrity](windows-defender-exploit-guard/requirements-and-deployment-planning-guidelines-for-virtualization-based-protection-of-code-integrity.md)
|
||||||
|
##### [Enable virtualization-based protection of code integrity](windows-defender-exploit-guard/enable-virtualization-based-protection-of-code-integrity.md)
|
||||||
### [Attack surface reduction](windows-defender-exploit-guard\attack-surface-reduction-exploit-guard.md)
|
### [Attack surface reduction](windows-defender-exploit-guard\attack-surface-reduction-exploit-guard.md)
|
||||||
#### [Evaluate Attack surface reduction](windows-defender-exploit-guard\evaluate-attack-surface-reduction.md)
|
#### [Evaluate Attack surface reduction](windows-defender-exploit-guard\evaluate-attack-surface-reduction.md)
|
||||||
#### [Enable Attack surface reduction](windows-defender-exploit-guard\enable-attack-surface-reduction.md)
|
#### [Enable Attack surface reduction](windows-defender-exploit-guard\enable-attack-surface-reduction.md)
|
||||||
|
@ -38,13 +38,11 @@ But configurable CI carries no specific hardware or software requirements other
|
|||||||
Since the initial release of Windows 10, the world has witnessed numerous hacking and malware attacks where application control alone could have prevented the attack altogether. So we are promoting configurable CI within our security stack and giving it a name of its own: [Windows Defender Application Control](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-application-control).
|
Since the initial release of Windows 10, the world has witnessed numerous hacking and malware attacks where application control alone could have prevented the attack altogether. So we are promoting configurable CI within our security stack and giving it a name of its own: [Windows Defender Application Control](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-application-control).
|
||||||
We hope this branding change will help us better communicate options for adopting application control within an organization.
|
We hope this branding change will help us better communicate options for adopting application control within an organization.
|
||||||
|
|
||||||
Does this mean Windows Defender Device Guard is going away? Not at all. Device Guard will continue to exist as a way to describe the fully locked down state achieved through the use of Windows Defender Application Control (WDAC), [HVCI](https://docs.microsoft.com/windows/security/threat-protection/enable-virtualization-based-protection-of-code-integrity), and hardware and firmware security features. It also allows us to work with our OEM partners to identify specifications for devices that are “Device Guard capable” so that our joint customers can easily purchase devices that meet all of the hardware and firmware requirements of the original Device Guard scenario.
|
Does this mean Windows Defender Device Guard is going away? Not at all. Device Guard will continue to exist as a way to describe the fully locked down state achieved through the use of Windows Defender Application Control (WDAC), HVCI, and hardware and firmware security features. It also allows us to work with our OEM partners to identify specifications for devices that are “Device Guard capable” so that our joint customers can easily purchase devices that meet all of the hardware and firmware requirements of the original Device Guard scenario.
|
||||||
|
|
||||||
## Related topics
|
## Related topics
|
||||||
|
|
||||||
- [Windows Defender Application Control](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-application-control)
|
[Windows Defender Application Control](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-application-control)
|
||||||
|
|
||||||
- [HVCI](https://docs.microsoft.com/windows/security/threat-protection/enable-virtualization-based-protection-of-code-integrity)
|
|
||||||
|
|
||||||
[Dropping the Hammer Down on Malware Threats with Windows 10’s Windows Defender Device Guard](https://channel9.msdn.com/Events/Ignite/2015/BRK2336)
|
[Dropping the Hammer Down on Malware Threats with Windows 10’s Windows Defender Device Guard](https://channel9.msdn.com/Events/Ignite/2015/BRK2336)
|
||||||
|
|
||||||
|
@ -29,8 +29,6 @@
|
|||||||
#### [Signing WDAC policies with SignTool.exe](signing-policies-with-signtool.md)
|
#### [Signing WDAC policies with SignTool.exe](signing-policies-with-signtool.md)
|
||||||
### [Disable WDAC policies](disable-windows-defender-application-control-policies.md)
|
### [Disable WDAC policies](disable-windows-defender-application-control-policies.md)
|
||||||
|
|
||||||
## [Windows Defender Application Control and AppLocker](windows-defender-application-control-and-applocker.md)
|
|
||||||
|
|
||||||
## [AppLocker](applocker\applocker-overview.md)
|
## [AppLocker](applocker\applocker-overview.md)
|
||||||
### [Administer AppLocker](applocker\administer-applocker.md)
|
### [Administer AppLocker](applocker\administer-applocker.md)
|
||||||
#### [Maintain AppLocker policies](applocker\maintain-applocker-policies.md)
|
#### [Maintain AppLocker policies](applocker\maintain-applocker-policies.md)
|
||||||
|
@ -1,19 +0,0 @@
|
|||||||
---
|
|
||||||
title: Windows Defender Application Control and AppLocker (Windows 10)
|
|
||||||
description: Windows Defender Application Control and AppLocker.
|
|
||||||
ms.assetid: 8d6e0474-c475-411b-b095-1c61adb2bdbb
|
|
||||||
ms.prod: w10
|
|
||||||
ms.mktglfcycl: deploy
|
|
||||||
ms.sitesec: library
|
|
||||||
ms.pagetype: security
|
|
||||||
author: jsuther1974
|
|
||||||
ms.date: 01/24/2018
|
|
||||||
---
|
|
||||||
|
|
||||||
# Windows Defender Application Control and AppLocker
|
|
||||||
|
|
||||||
**Applies to:**
|
|
||||||
|
|
||||||
- Windows 10
|
|
||||||
- Windows Server 2016
|
|
||||||
|
|
@ -1,173 +1,200 @@
|
|||||||
# [Windows Defender Advanced Threat Protection](windows-defender-advanced-threat-protection.md)
|
# [Windows Defender Advanced Threat Protection](windows-defender-advanced-threat-protection.md)
|
||||||
|
|
||||||
##Get started
|
##Get started
|
||||||
## [Minimum requirements](minimum-requirements-windows-defender-advanced-threat-protection.md)
|
### [Minimum requirements](minimum-requirements-windows-defender-advanced-threat-protection.md)
|
||||||
## [Validate licensing and complete setup](licensing-windows-defender-advanced-threat-protection.md)
|
### [Validate licensing and complete setup](licensing-windows-defender-advanced-threat-protection.md)
|
||||||
## [Troubleshoot subscription and portal access issues](troubleshoot-onboarding-error-messages-windows-defender-advanced-threat-protection.md)
|
### [Troubleshoot subscription and portal access issues](troubleshoot-onboarding-error-messages-windows-defender-advanced-threat-protection.md)
|
||||||
## [Preview features](preview-windows-defender-advanced-threat-protection.md)
|
### [Preview features](preview-windows-defender-advanced-threat-protection.md)
|
||||||
## [Data storage and privacy](data-storage-privacy-windows-defender-advanced-threat-protection.md)
|
### [Data storage and privacy](data-storage-privacy-windows-defender-advanced-threat-protection.md)
|
||||||
## [Assign user access to the portal](assign-portal-access-windows-defender-advanced-threat-protection.md)
|
### [Assign user access to the portal](assign-portal-access-windows-defender-advanced-threat-protection.md)
|
||||||
## [Onboard endpoints and set up access](onboard-configure-windows-defender-advanced-threat-protection.md)
|
## [Onboard machines](onboard-configure-windows-defender-advanced-threat-protection.md)
|
||||||
## [Configure client endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md)
|
### [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md)
|
||||||
### [Configure endpoints using Group Policy](configure-endpoints-gp-windows-defender-advanced-threat-protection.md)
|
#### [Onboard machines using Group Policy](configure-endpoints-gp-windows-defender-advanced-threat-protection.md)
|
||||||
### [Configure endpoints using System Center Configuration Manager](configure-endpoints-sccm-windows-defender-advanced-threat-protection.md)
|
#### [Onboard machines using System Center Configuration Manager](configure-endpoints-sccm-windows-defender-advanced-threat-protection.md)
|
||||||
### [Configure endpoints using Mobile Device Management tools](configure-endpoints-mdm-windows-defender-advanced-threat-protection.md)
|
#### [Onboard machines using Mobile Device Management tools](configure-endpoints-mdm-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Configure endpoints using Microsoft Intune](configure-endpoints-mdm-windows-defender-advanced-threat-protection.md#configure-endpoints-using-microsoft-intune)
|
##### [Onboard machines using Microsoft Intune](configure-endpoints-mdm-windows-defender-advanced-threat-protection.md#onboard-windows-10-machines-using-microsoft-intune)
|
||||||
### [Configure endpoints using a local script](configure-endpoints-script-windows-defender-advanced-threat-protection.md)
|
#### [Onboard machines using a local script](configure-endpoints-script-windows-defender-advanced-threat-protection.md)
|
||||||
### [Configure non-persistent virtual desktop infrastructure (VDI) machines](configure-endpoints-vdi-windows-defender-advanced-threat-protection.md)
|
#### [Onboard non-persistent virtual desktop infrastructure (VDI) machines](configure-endpoints-vdi-windows-defender-advanced-threat-protection.md)
|
||||||
## [Configure server endpoints](configure-server-endpoints-windows-defender-advanced-threat-protection.md)
|
### [Onboard servers](configure-server-endpoints-windows-defender-advanced-threat-protection.md)
|
||||||
## [Configure non-Windows endpoints](configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md)
|
### [Onboard non-Windows machines](configure-endpoints-non-windows-windows-defender-advanced-threat-protection.md)
|
||||||
## [Run a detection test on a newly onboarded endpoint](run-detection-test-windows-defender-advanced-threat-protection.md)
|
### [Run a detection test on a newly onboarded machine](run-detection-test-windows-defender-advanced-threat-protection.md)
|
||||||
## [Configure proxy and Internet connectivity settings](configure-proxy-internet-windows-defender-advanced-threat-protection.md)
|
### [Run simulated attacks on machines](attack-simulations-windows-defender-advanced-threat-protection.md)
|
||||||
## [Troubleshoot onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md)
|
### [Configure proxy and Internet connectivity settings](configure-proxy-internet-windows-defender-advanced-threat-protection.md)
|
||||||
|
### [Troubleshoot onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md)
|
||||||
## [Understand the Windows Defender ATP portal](use-windows-defender-advanced-threat-protection.md)
|
## [Understand the Windows Defender ATP portal](use-windows-defender-advanced-threat-protection.md)
|
||||||
## [Portal overview](portal-overview-windows-defender-advanced-threat-protection.md)
|
### [Portal overview](portal-overview-windows-defender-advanced-threat-protection.md)
|
||||||
## [View the Security operations dashboard](dashboard-windows-defender-advanced-threat-protection.md)
|
### [View the Security operations dashboard](security-operations-dashboard-windows-defender-advanced-threat-protection.md)
|
||||||
## [View the Security analytics dashboard](security-analytics-dashboard-windows-defender-advanced-threat-protection.md)
|
### [View the Secure Score dashboard and improve your secure score](secure-score-dashboard-windows-defender-advanced-threat-protection.md)
|
||||||
|
### [View the Threat analytics dashboard and take recommended mitigation actions](threat-analytics-dashboard-windows-defender-advanced-threat-protection.md)
|
||||||
|
|
||||||
##Investigate and remediate threats
|
##Investigate and remediate threats
|
||||||
##Alerts queue
|
###Alerts queue
|
||||||
### [View and organize the Alerts queue](alerts-queue-windows-defender-advanced-threat-protection.md)
|
#### [View and organize the Alerts queue](alerts-queue-windows-defender-advanced-threat-protection.md)
|
||||||
### [Manage alerts](manage-alerts-windows-defender-advanced-threat-protection.md)
|
#### [Manage alerts](manage-alerts-windows-defender-advanced-threat-protection.md)
|
||||||
### [Investigate alerts](investigate-alerts-windows-defender-advanced-threat-protection.md)
|
#### [Investigate alerts](investigate-alerts-windows-defender-advanced-threat-protection.md)
|
||||||
### [Investigate files](investigate-files-windows-defender-advanced-threat-protection.md)
|
#### [Investigate files](investigate-files-windows-defender-advanced-threat-protection.md)
|
||||||
### [Investigate machines](investigate-machines-windows-defender-advanced-threat-protection.md)
|
#### [Investigate machines](investigate-machines-windows-defender-advanced-threat-protection.md)
|
||||||
### [Investigate an IP address](investigate-ip-windows-defender-advanced-threat-protection.md)
|
#### [Investigate an IP address](investigate-ip-windows-defender-advanced-threat-protection.md)
|
||||||
### [Investigate a domain](investigate-domain-windows-defender-advanced-threat-protection.md)
|
#### [Investigate a domain](investigate-domain-windows-defender-advanced-threat-protection.md)
|
||||||
### [Investigate a user account](investigate-user-windows-defender-advanced-threat-protection.md)
|
#### [Investigate a user account](investigate-user-windows-defender-advanced-threat-protection.md)
|
||||||
|
|
||||||
##Machines list
|
|
||||||
### [View and organize the Machines list](machines-view-overview-windows-defender-advanced-threat-protection.md)
|
|
||||||
### [Manage machine group and tags](investigate-machines-windows-defender-advanced-threat-protection.md#manage-machine-group-and-tags)
|
|
||||||
### [Alerts related to this machine](investigate-machines-windows-defender-advanced-threat-protection.md#alerts-related-to-this-machine)
|
|
||||||
### [Machine timeline](investigate-machines-windows-defender-advanced-threat-protection.md#machine-timeline)
|
|
||||||
#### [Search for specific events](investigate-machines-windows-defender-advanced-threat-protection.md#search-for-specific-events)
|
|
||||||
#### [Filter events from a specific date](investigate-machines-windows-defender-advanced-threat-protection.md#filter-events-from-a-specific-date)
|
|
||||||
#### [Export machine timeline events](investigate-machines-windows-defender-advanced-threat-protection.md#export-machine-timeline-events)
|
|
||||||
#### [Navigate between pages](investigate-machines-windows-defender-advanced-threat-protection.md#navigate-between-pages)
|
|
||||||
|
|
||||||
|
|
||||||
## [Take response actions](response-actions-windows-defender-advanced-threat-protection.md)
|
|
||||||
### [Take response actions on a machine](respond-machine-alerts-windows-defender-advanced-threat-protection.md)
|
|
||||||
#### [Collect investigation package](respond-machine-alerts-windows-defender-advanced-threat-protection.md#collect-investigation-package-from-machines)
|
###Machines list
|
||||||
### [Run antivirus scan](respond-machine-alerts-windows-defender-advanced-threat-protection.md#run-windows-defender-antivirus-scan-on-machines)
|
#### [View and organize the Machines list](machines-view-overview-windows-defender-advanced-threat-protection.md)
|
||||||
### [Restrict app execution](respond-machine-alerts-windows-defender-advanced-threat-protection.md#restrict-app-execution)
|
#### [Manage machine group and tags](investigate-machines-windows-defender-advanced-threat-protection.md#manage-machine-group-and-tags)
|
||||||
### [Remove app restriction](respond-machine-alerts-windows-defender-advanced-threat-protection.md#remove-app-restriction)
|
#### [Alerts related to this machine](investigate-machines-windows-defender-advanced-threat-protection.md#alerts-related-to-this-machine)
|
||||||
### [Isolate machines from the network](respond-machine-alerts-windows-defender-advanced-threat-protection.md#isolate-machines-from-the-network)
|
#### [Machine timeline](investigate-machines-windows-defender-advanced-threat-protection.md#machine-timeline)
|
||||||
### [Release machine from isolation](respond-machine-alerts-windows-defender-advanced-threat-protection.md#release-machine-from-isolation)
|
##### [Search for specific events](investigate-machines-windows-defender-advanced-threat-protection.md#search-for-specific-events)
|
||||||
### [Check activity details in Action center](respond-machine-alerts-windows-defender-advanced-threat-protection.md#check-activity-details-in-action-center)
|
##### [Filter events from a specific date](investigate-machines-windows-defender-advanced-threat-protection.md#filter-events-from-a-specific-date)
|
||||||
### [Take response actions on a file](respond-file-alerts-windows-defender-advanced-threat-protection.md)
|
##### [Export machine timeline events](investigate-machines-windows-defender-advanced-threat-protection.md#export-machine-timeline-events)
|
||||||
### [Stop and quarantine files in your network](respond-file-alerts-windows-defender-advanced-threat-protection.md#stop-and-quarantine-files-in-your-network)
|
##### [Navigate between pages](investigate-machines-windows-defender-advanced-threat-protection.md#navigate-between-pages)
|
||||||
### [Remove file from quarantine](respond-file-alerts-windows-defender-advanced-threat-protection.md#remove-file-from-quarantine)
|
|
||||||
### [Block files in your network](respond-file-alerts-windows-defender-advanced-threat-protection.md#block-files-in-your-network)
|
|
||||||
### [Remove file from blocked list](respond-file-alerts-windows-defender-advanced-threat-protection.md#remove-file-from-blocked-list)
|
### [Take response actions](response-actions-windows-defender-advanced-threat-protection.md)
|
||||||
### [Check activity details in Action center](respond-file-alerts-windows-defender-advanced-threat-protection.md#check-activity-details-in-action-center)
|
#### [Take response actions on a machine](respond-machine-alerts-windows-defender-advanced-threat-protection.md)
|
||||||
### [Deep analysis](respond-file-alerts-windows-defender-advanced-threat-protection.md#deep-analysis)
|
##### [Collect investigation package](respond-machine-alerts-windows-defender-advanced-threat-protection.md#collect-investigation-package-from-machines)
|
||||||
#### [Submit files for analysis](respond-file-alerts-windows-defender-advanced-threat-protection.md#submit-files-for-analysis)
|
##### [Run antivirus scan](respond-machine-alerts-windows-defender-advanced-threat-protection.md#run-windows-defender-antivirus-scan-on-machines)
|
||||||
#### [View deep analysis reports](respond-file-alerts-windows-defender-advanced-threat-protection.md#view-deep-analysis-reports)
|
##### [Restrict app execution](respond-machine-alerts-windows-defender-advanced-threat-protection.md#restrict-app-execution)
|
||||||
#### [Troubleshoot deep analysis](respond-file-alerts-windows-defender-advanced-threat-protection.md#troubleshoot-deep-analysis)
|
##### [Remove app restriction](respond-machine-alerts-windows-defender-advanced-threat-protection.md#remove-app-restriction)
|
||||||
|
##### [Isolate machines from the network](respond-machine-alerts-windows-defender-advanced-threat-protection.md#isolate-machines-from-the-network)
|
||||||
|
##### [Release machine from isolation](respond-machine-alerts-windows-defender-advanced-threat-protection.md#release-machine-from-isolation)
|
||||||
|
##### [Check activity details in Action center](respond-machine-alerts-windows-defender-advanced-threat-protection.md#check-activity-details-in-action-center)
|
||||||
|
#### [Take response actions on a file](respond-file-alerts-windows-defender-advanced-threat-protection.md)
|
||||||
|
##### [Stop and quarantine files in your network](respond-file-alerts-windows-defender-advanced-threat-protection.md#stop-and-quarantine-files-in-your-network)
|
||||||
|
##### [Remove file from quarantine](respond-file-alerts-windows-defender-advanced-threat-protection.md#remove-file-from-quarantine)
|
||||||
|
##### [Block files in your network](respond-file-alerts-windows-defender-advanced-threat-protection.md#block-files-in-your-network)
|
||||||
|
##### [Remove file from blocked list](respond-file-alerts-windows-defender-advanced-threat-protection.md#remove-file-from-blocked-list)
|
||||||
|
##### [Check activity details in Action center](respond-file-alerts-windows-defender-advanced-threat-protection.md#check-activity-details-in-action-center)
|
||||||
|
##### [Deep analysis](respond-file-alerts-windows-defender-advanced-threat-protection.md#deep-analysis)
|
||||||
|
###### [Submit files for analysis](respond-file-alerts-windows-defender-advanced-threat-protection.md#submit-files-for-analysis)
|
||||||
|
###### [View deep analysis reports](respond-file-alerts-windows-defender-advanced-threat-protection.md#view-deep-analysis-reports)
|
||||||
|
###### [Troubleshoot deep analysis](respond-file-alerts-windows-defender-advanced-threat-protection.md#troubleshoot-deep-analysis)
|
||||||
|
|
||||||
|
### [Use Automated investigation to investigate and remediate threats](automated-investigations-windows-defender-advanced-threat-protection.md)
|
||||||
|
### [Query data using Advanced hunting](advanced-hunting-windows-defender-advanced-threat-protection.md)
|
||||||
|
#### [Advanced hunting reference](advanced-hunting-reference-windows-defender-advanced-threat-protection.md)
|
||||||
|
#### [Advanced hunting query language best practices](advanced-hunting-best-practices-windows-defender-advanced-threat-protection.md)
|
||||||
|
|
||||||
##API and SIEM support
|
##API and SIEM support
|
||||||
## [Pull alerts to your SIEM tools](configure-siem-windows-defender-advanced-threat-protection.md)
|
### [Pull alerts to your SIEM tools](configure-siem-windows-defender-advanced-threat-protection.md)
|
||||||
### [Enable SIEM integration](enable-siem-integration-windows-defender-advanced-threat-protection.md)
|
#### [Enable SIEM integration](enable-siem-integration-windows-defender-advanced-threat-protection.md)
|
||||||
### [Configure Splunk to pull alerts](configure-splunk-windows-defender-advanced-threat-protection.md)
|
#### [Configure Splunk to pull alerts](configure-splunk-windows-defender-advanced-threat-protection.md)
|
||||||
### [Configure HP ArcSight to pull alerts](configure-arcsight-windows-defender-advanced-threat-protection.md)
|
#### [Configure HP ArcSight to pull alerts](configure-arcsight-windows-defender-advanced-threat-protection.md)
|
||||||
### [Windows Defender ATP alert API fields](api-portal-mapping-windows-defender-advanced-threat-protection.md)
|
#### [Windows Defender ATP alert API fields](api-portal-mapping-windows-defender-advanced-threat-protection.md)
|
||||||
### [Pull alerts using REST API](pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md)
|
#### [Pull alerts using REST API](pull-alerts-using-rest-api-windows-defender-advanced-threat-protection.md)
|
||||||
### [Troubleshoot SIEM tool integration issues](troubleshoot-siem-windows-defender-advanced-threat-protection.md)
|
#### [Troubleshoot SIEM tool integration issues](troubleshoot-siem-windows-defender-advanced-threat-protection.md)
|
||||||
|
|
||||||
## [Use the threat intelligence API to create custom alerts](use-custom-ti-windows-defender-advanced-threat-protection.md)
|
### [Use the threat intelligence API to create custom alerts](use-custom-ti-windows-defender-advanced-threat-protection.md)
|
||||||
### [Understand threat intelligence concepts](threat-indicator-concepts-windows-defender-advanced-threat-protection.md)
|
#### [Understand threat intelligence concepts](threat-indicator-concepts-windows-defender-advanced-threat-protection.md)
|
||||||
### [Enable the custom threat intelligence application](enable-custom-ti-windows-defender-advanced-threat-protection.md)
|
#### [Enable the custom threat intelligence application](enable-custom-ti-windows-defender-advanced-threat-protection.md)
|
||||||
### [Create custom threat intelligence alerts](custom-ti-api-windows-defender-advanced-threat-protection.md)
|
#### [Create custom threat intelligence alerts](custom-ti-api-windows-defender-advanced-threat-protection.md)
|
||||||
### [PowerShell code examples](powershell-example-code-windows-defender-advanced-threat-protection.md)
|
#### [PowerShell code examples](powershell-example-code-windows-defender-advanced-threat-protection.md)
|
||||||
### [Python code examples](python-example-code-windows-defender-advanced-threat-protection.md)
|
#### [Python code examples](python-example-code-windows-defender-advanced-threat-protection.md)
|
||||||
### [Experiment with custom threat intelligence alerts](experiment-custom-ti-windows-defender-advanced-threat-protection.md)
|
#### [Experiment with custom threat intelligence alerts](experiment-custom-ti-windows-defender-advanced-threat-protection.md)
|
||||||
### [Troubleshoot custom threat intelligence issues](troubleshoot-custom-ti-windows-defender-advanced-threat-protection.md)
|
#### [Troubleshoot custom threat intelligence issues](troubleshoot-custom-ti-windows-defender-advanced-threat-protection.md)
|
||||||
## [Use the Windows Defender ATP exposed APIs](exposed-apis-windows-defender-advanced-threat-protection.md)
|
### [Use the Windows Defender ATP exposed APIs](exposed-apis-windows-defender-advanced-threat-protection.md)
|
||||||
### [Supported Windows Defender ATP APIs](supported-apis-windows-defender-advanced-threat-protection.md)
|
#### [Supported Windows Defender ATP APIs](supported-apis-windows-defender-advanced-threat-protection.md)
|
||||||
###Actor
|
#####Actor
|
||||||
#### [Get actor information](get-actor-information-windows-defender-advanced-threat-protection.md)
|
###### [Get actor information](get-actor-information-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Get actor related alerts](get-actor-related-alerts-windows-defender-advanced-threat-protection.md)
|
###### [Get actor related alerts](get-actor-related-alerts-windows-defender-advanced-threat-protection.md)
|
||||||
###Alerts
|
#####Alerts
|
||||||
#### [Get alerts](get-alerts-windows-defender-advanced-threat-protection.md)
|
###### [Get alerts](get-alerts-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Get alert information by ID](get-alert-info-by-id-windows-defender-advanced-threat-protection.md)
|
###### [Get alert information by ID](get-alert-info-by-id-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Get alert related actor information](get-alert-related-actor-info-windows-defender-advanced-threat-protection.md)
|
###### [Get alert related actor information](get-alert-related-actor-info-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Get alert related domain information](get-alert-related-domain-info-windows-defender-advanced-threat-protection.md)
|
###### [Get alert related domain information](get-alert-related-domain-info-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Get alert related file information](get-alert-related-files-info-windows-defender-advanced-threat-protection.md)
|
###### [Get alert related file information](get-alert-related-files-info-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Get alert related IP information](get-alert-related-ip-info-windows-defender-advanced-threat-protection.md)
|
###### [Get alert related IP information](get-alert-related-ip-info-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Get alert related machine information](get-alert-related-machine-info-windows-defender-advanced-threat-protection.md)
|
###### [Get alert related machine information](get-alert-related-machine-info-windows-defender-advanced-threat-protection.md)
|
||||||
###Domain
|
#####Domain
|
||||||
#### [Get domain related alerts](get-domain-related-alerts-windows-defender-advanced-threat-protection.md)
|
###### [Get domain related alerts](get-domain-related-alerts-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Get domain related machines](get-domain-related-machines-windows-defender-advanced-threat-protection.md)
|
###### [Get domain related machines](get-domain-related-machines-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Get domain statistics](get-domain-statistics-windows-defender-advanced-threat-protection.md)
|
###### [Get domain statistics](get-domain-statistics-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Is domain seen in organization](is-domain-seen-in-org-windows-defender-advanced-threat-protection.md)
|
###### [Is domain seen in organization](is-domain-seen-in-org-windows-defender-advanced-threat-protection.md)
|
||||||
|
|
||||||
###File
|
#####File
|
||||||
#### [Block file API](block-file-windows-defender-advanced-threat-protection.md)
|
###### [Block file API](block-file-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Get file information](get-file-information-windows-defender-advanced-threat-protection.md)
|
###### [Get file information](get-file-information-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Get file related alerts](get-file-related-alerts-windows-defender-advanced-threat-protection.md)
|
###### [Get file related alerts](get-file-related-alerts-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Get file related machines](get-file-related-machines-windows-defender-advanced-threat-protection.md)
|
###### [Get file related machines](get-file-related-machines-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Get file statistics](get-file-statistics-windows-defender-advanced-threat-protection.md)
|
###### [Get file statistics](get-file-statistics-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Get FileActions collection API](get-fileactions-collection-windows-defender-advanced-threat-protection.md)
|
###### [Get FileActions collection API](get-fileactions-collection-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Unblock file API](unblock-file-windows-defender-advanced-threat-protection.md)
|
###### [Unblock file API](unblock-file-windows-defender-advanced-threat-protection.md)
|
||||||
|
|
||||||
###IP
|
#####IP
|
||||||
#### [Get IP related alerts](get-ip-related-alerts-windows-defender-advanced-threat-protection.md)
|
###### [Get IP related alerts](get-ip-related-alerts-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Get IP related machines](get-ip-related-machines-windows-defender-advanced-threat-protection.md)
|
###### [Get IP related machines](get-ip-related-machines-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Get IP statistics](get-ip-statistics-windows-defender-advanced-threat-protection.md)
|
###### [Get IP statistics](get-ip-statistics-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Is IP seen in organization](is-ip-seen-org-windows-defender-advanced-threat-protection.md)
|
###### [Is IP seen in organization](is-ip-seen-org-windows-defender-advanced-threat-protection.md)
|
||||||
###Machines
|
#####Machines
|
||||||
#### [Collect investigation package API](collect-investigation-package-windows-defender-advanced-threat-protection.md)
|
###### [Collect investigation package API](collect-investigation-package-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Find machine information by IP](find-machine-info-by-ip-windows-defender-advanced-threat-protection.md)
|
###### [Find machine information by IP](find-machine-info-by-ip-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Get machines](get-machines-windows-defender-advanced-threat-protection.md)
|
###### [Get machines](get-machines-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Get FileMachineAction object API](get-filemachineaction-object-windows-defender-advanced-threat-protection.md)
|
###### [Get FileMachineAction object API](get-filemachineaction-object-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Get FileMachineActions collection API](get-filemachineactions-collection-windows-defender-advanced-threat-protection.md)
|
###### [Get FileMachineActions collection API](get-filemachineactions-collection-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Get machine by ID](get-machine-by-id-windows-defender-advanced-threat-protection.md)
|
###### [Get machine by ID](get-machine-by-id-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Get machine log on users](get-machine-log-on-users-windows-defender-advanced-threat-protection.md)
|
###### [Get machine log on users](get-machine-log-on-users-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Get machine related alerts](get-machine-related-alerts-windows-defender-advanced-threat-protection.md)
|
###### [Get machine related alerts](get-machine-related-alerts-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Get MachineAction object API](get-machineaction-object-windows-defender-advanced-threat-protection.md)
|
###### [Get MachineAction object API](get-machineaction-object-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Get MachineActions collection API](get-machineactions-collection-windows-defender-advanced-threat-protection.md)
|
###### [Get MachineActions collection API](get-machineactions-collection-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Get machines](get-machines-windows-defender-advanced-threat-protection.md)
|
###### [Get machines](get-machines-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Get package SAS URI API](get-package-sas-uri-windows-defender-advanced-threat-protection.md)
|
###### [Get package SAS URI API](get-package-sas-uri-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Isolate machine API](isolate-machine-windows-defender-advanced-threat-protection.md)
|
###### [Isolate machine API](isolate-machine-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Release machine from isolation API](unisolate-machine-windows-defender-advanced-threat-protection.md)
|
###### [Release machine from isolation API](unisolate-machine-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Remove app restriction API](unrestrict-code-execution-windows-defender-advanced-threat-protection.md)
|
###### [Remove app restriction API](unrestrict-code-execution-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Request sample API](request-sample-windows-defender-advanced-threat-protection.md)
|
###### [Request sample API](request-sample-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Restrict app execution API](restrict-code-execution-windows-defender-advanced-threat-protection.md)
|
###### [Restrict app execution API](restrict-code-execution-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Run antivirus scan API](run-av-scan-windows-defender-advanced-threat-protection.md)
|
###### [Run antivirus scan API](run-av-scan-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Stop and quarantine file API](stop-quarantine-file-windows-defender-advanced-threat-protection.md)
|
###### [Stop and quarantine file API](stop-quarantine-file-windows-defender-advanced-threat-protection.md)
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
###User
|
#####User
|
||||||
#### [Get alert related user information](get-alert-related-user-info-windows-defender-advanced-threat-protection.md)
|
###### [Get alert related user information](get-alert-related-user-info-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Get user information](get-user-information-windows-defender-advanced-threat-protection.md)
|
###### [Get user information](get-user-information-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Get user related alerts](get-user-related-alerts-windows-defender-advanced-threat-protection.md)
|
###### [Get user related alerts](get-user-related-alerts-windows-defender-advanced-threat-protection.md)
|
||||||
#### [Get user related machines](get-user-related-machines-windows-defender-advanced-threat-protection.md)
|
###### [Get user related machines](get-user-related-machines-windows-defender-advanced-threat-protection.md)
|
||||||
|
|
||||||
##Reporting
|
##Reporting
|
||||||
## [Create and build Power BI reports using Windows Defender ATP data](powerbi-reports-windows-defender-advanced-threat-protection.md)
|
### [Create and build Power BI reports using Windows Defender ATP data](powerbi-reports-windows-defender-advanced-threat-protection.md)
|
||||||
|
|
||||||
##Check service health and sensor state
|
##Check service health and sensor state
|
||||||
## [Check sensor state](check-sensor-status-windows-defender-advanced-threat-protection.md)
|
### [Check sensor state](check-sensor-status-windows-defender-advanced-threat-protection.md)
|
||||||
### [Fix unhealthy sensors](fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md)
|
### [Fix unhealthy sensors](fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md)
|
||||||
### [Inactive machines](fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md#inactive-machines)
|
### [Inactive machines](fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md#inactive-machines)
|
||||||
### [Misconfigured machines](fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md#misconfigured-machines)
|
### [Misconfigured machines](fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md#misconfigured-machines)
|
||||||
## [Check service health](service-status-windows-defender-advanced-threat-protection.md)
|
### [Check service health](service-status-windows-defender-advanced-threat-protection.md)
|
||||||
## [Configure Windows Defender ATP preferences settings](preferences-setup-windows-defender-advanced-threat-protection.md)
|
### [Configure Windows Defender ATP Settings](preferences-setup-windows-defender-advanced-threat-protection.md)
|
||||||
## [Update general settings](general-settings-windows-defender-advanced-threat-protection.md)
|
|
||||||
## [Enable advanced features](advanced-features-windows-defender-advanced-threat-protection.md)
|
###General
|
||||||
## [Enable preview experience](preview-settings-windows-defender-advanced-threat-protection.md)
|
#### [Update data retention settings](data-retention-settings-windows-defender-advanced-threat-protection.md)
|
||||||
## [Configure email notifications](configure-email-notifications-windows-defender-advanced-threat-protection.md)
|
#### [Configure alert notifications](configure-email-notifications-windows-defender-advanced-threat-protection.md)
|
||||||
## [Enable SIEM integration](enable-siem-integration-windows-defender-advanced-threat-protection.md)
|
#### [Enable and create Power BI reports using Windows Defender ATP data](powerbi-reports-windows-defender-advanced-threat-protection.md)
|
||||||
## [Enable Threat intel API](enable-custom-ti-windows-defender-advanced-threat-protection.md)
|
#### [Enable Secure score security controls](enable-secure-score-windows-defender-advanced-threat-protection.md)
|
||||||
## [Enable and create Power BI reports using Windows Defender ATP data](powerbi-reports-windows-defender-advanced-threat-protection.md)
|
#### [Configure advanced features](advanced-features-windows-defender-advanced-threat-protection.md)
|
||||||
## [Enable Security Analytics security controls](enable-security-analytics-windows-defender-advanced-threat-protection.md)
|
#### [Protect data with conditional access](conditional-access-windows-defender-advanced-threat-protection.md)
|
||||||
|
|
||||||
|
###Permissions
|
||||||
|
#### [Manage portal access using RBAC](rbac-windows-defender-advanced-threat-protection.md)
|
||||||
|
#### [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md)
|
||||||
|
|
||||||
|
###APIs
|
||||||
|
#### [Enable Threat intel](enable-custom-ti-windows-defender-advanced-threat-protection.md)
|
||||||
|
#### [Enable SIEM integration](enable-siem-integration-windows-defender-advanced-threat-protection.md)
|
||||||
|
|
||||||
|
###Rules
|
||||||
|
#### [Manage suppression rules](manage-suppression-rules-windows-defender-advanced-threat-protection.md)
|
||||||
|
#### [Manage automation allowed/blocked](manage-automation-allowed-blocked-list-windows-defender-advanced-threat-protection.md)
|
||||||
|
#### [Manage automation file uploads](manage-automation-file-uploads-windows-defender-advanced-threat-protection.md)
|
||||||
|
#### [Manage automation folder exclusions](manage-automation-folder-exclusions-windows-defender-advanced-threat-protection.md)
|
||||||
|
|
||||||
|
###Machine management
|
||||||
|
#### [Onboarding machines](onboard-configure-windows-defender-advanced-threat-protection.md)
|
||||||
|
#### [Offboarding machines](offboard-machines-windows-defender-advanced-threat-protection.md)
|
||||||
|
|
||||||
|
## [Configure Windows Defender ATP time zone settings](time-settings-windows-defender-advanced-threat-protection.md)
|
||||||
|
|
||||||
## [Configure Windows Defender ATP time zone settings](settings-windows-defender-advanced-threat-protection.md)
|
|
||||||
## [Access the Windows Defender ATP Community Center](community-windows-defender-advanced-threat-protection.md)
|
## [Access the Windows Defender ATP Community Center](community-windows-defender-advanced-threat-protection.md)
|
||||||
## [Troubleshoot Windows Defender ATP](troubleshoot-windows-defender-advanced-threat-protection.md)
|
## [Troubleshoot Windows Defender ATP](troubleshoot-windows-defender-advanced-threat-protection.md)
|
||||||
## [Review events and errors on endpoints with Event Viewer](event-error-codes-windows-defender-advanced-threat-protection.md)
|
### [Review events and errors on machines with Event Viewer](event-error-codes-windows-defender-advanced-threat-protection.md)
|
||||||
## [Windows Defender Antivirus compatibility with Windows Defender ATP](defender-compatibility-windows-defender-advanced-threat-protection.md)
|
## [Windows Defender Antivirus compatibility with Windows Defender ATP](defender-compatibility-windows-defender-advanced-threat-protection.md)
|
||||||
|
|
||||||
|
@ -18,7 +18,6 @@ ms.date: 04/24/2018
|
|||||||
|
|
||||||
- Windows Server 2012 R2
|
- Windows Server 2012 R2
|
||||||
- Windows Server 2016
|
- Windows Server 2016
|
||||||
- Windows Server, version 1803
|
|
||||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||||
|
|
||||||
[!include[Prerelease information](prerelease.md)]
|
[!include[Prerelease information](prerelease.md)]
|
||||||
@ -30,7 +29,6 @@ Windows Defender ATP extends support to also include the Windows Server operatin
|
|||||||
Windows Defender ATP supports the onboarding of the following servers:
|
Windows Defender ATP supports the onboarding of the following servers:
|
||||||
- Windows Server 2012 R2
|
- Windows Server 2012 R2
|
||||||
- Windows Server 2016
|
- Windows Server 2016
|
||||||
- Windows Server, version 1803
|
|
||||||
|
|
||||||
## Onboard Windows Server 2012 R2 and Windows Server 2016
|
## Onboard Windows Server 2012 R2 and Windows Server 2016
|
||||||
|
|
||||||
@ -82,31 +80,6 @@ Once completed, you should see onboarded servers in the portal within an hour.
|
|||||||
| winatp-gw-neu.microsoft.com | 443 |
|
| winatp-gw-neu.microsoft.com | 443 |
|
||||||
| winatp-gw-weu.microsoft.com | 443 |
|
| winatp-gw-weu.microsoft.com | 443 |
|
||||||
|
|
||||||
## Onboard Windows Server, version 1803
|
|
||||||
You’ll be able to onboard in the same method available for Windows 10 client machines. For more information, see [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md). Support for Windows Server, version 1803 provides deeper insight into activities happening on the server, coverage for kernel and memory attack detection, and enables response actions on Windows Server endpoint as well.
|
|
||||||
|
|
||||||
1. Install the latest Windows Server Insider build on a machine. For more information, see [Windows Server Insider Preview](https://www.microsoft.com/en-us/software-download/windowsinsiderpreviewserver).
|
|
||||||
|
|
||||||
2. Configure Windows Defender ATP onboarding settings on the server. For more information, see [Onboard Windows 10 machines](configure-endpoints-windows-defender-advanced-threat-protection.md).
|
|
||||||
|
|
||||||
3. If you’re running a third party antimalware solution, you'll need to apply the following Windows Defender AV passive mode settings and verify it was configured correctly:
|
|
||||||
|
|
||||||
a. Set the following registry entry:
|
|
||||||
- Path: `HKLM\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection`
|
|
||||||
- Name: ForceDefenderPassiveMode
|
|
||||||
- Value: 1
|
|
||||||
|
|
||||||
b. Run the following PowerShell command to verify that the passive mode was configured:
|
|
||||||
```Get-WinEvent -FilterHashtable @{ProviderName="Microsoft-Windows-Sense" ;ID=84}```
|
|
||||||
|
|
||||||
c. Confirm that a recent event containing the passive mode event is found:
|
|
||||||

|
|
||||||
|
|
||||||
4. Run the following command to check if Windows Defender AV is installed:
|
|
||||||
```sc query Windefend```
|
|
||||||
|
|
||||||
If the result is ‘The specified service does not exist as an installed service’, then you'll need to install Windows Defender AV. For more information, see [Windows Defender Antivirus in Windows 10](https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/windows-defender-antivirus-in-windows-10).
|
|
||||||
|
|
||||||
## Offboard servers
|
## Offboard servers
|
||||||
You have two options to offboard servers from the service:
|
You have two options to offboard servers from the service:
|
||||||
- Uninstall the MMA agent
|
- Uninstall the MMA agent
|
||||||
|
@ -47,7 +47,6 @@ The following features are included in the preview release:
|
|||||||
Windows Defender ATP supports the onboarding of the following servers:
|
Windows Defender ATP supports the onboarding of the following servers:
|
||||||
- Windows Server 2012 R2
|
- Windows Server 2012 R2
|
||||||
- Windows Server 2016
|
- Windows Server 2016
|
||||||
- Windows Server, version 1803
|
|
||||||
|
|
||||||
- [Create and build Power BI reports using Windows Defender ATP data](powerbi-reports-windows-defender-advanced-threat-protection.md)<br>
|
- [Create and build Power BI reports using Windows Defender ATP data](powerbi-reports-windows-defender-advanced-threat-protection.md)<br>
|
||||||
Windows Defender ATP supports the use of Power BI data connectors to enable you to connect and access Windows Defender ATP data using Microsoft Graph.
|
Windows Defender ATP supports the use of Power BI data connectors to enable you to connect and access Windows Defender ATP data using Microsoft Graph.
|
||||||
|
@ -297,9 +297,6 @@ For more information, see [Windows Defender Firewall with Advanced Security](htt
|
|||||||
### BitLocker optimization
|
### BitLocker optimization
|
||||||
For a machine to be considered "well configured", it must comply to a minimum baseline configuration setting. This tile shows you a specific list of actions you must apply on endpoints so that the minimum baseline configuration setting for BitLocker is fulfilled.
|
For a machine to be considered "well configured", it must comply to a minimum baseline configuration setting. This tile shows you a specific list of actions you must apply on endpoints so that the minimum baseline configuration setting for BitLocker is fulfilled.
|
||||||
|
|
||||||
>[!IMPORTANT]
|
|
||||||
>This security control is only applicable for machines with Windows 10, version 1803 or later.
|
|
||||||
|
|
||||||
#### Minimum baseline configuration setting for BitLocker
|
#### Minimum baseline configuration setting for BitLocker
|
||||||
- Ensure all supported internal drives are encrypted
|
- Ensure all supported internal drives are encrypted
|
||||||
- Ensure that all suspended protection on drives resume protection
|
- Ensure that all suspended protection on drives resume protection
|
||||||
|
Loading…
x
Reference in New Issue
Block a user