Notifications
Clear all
Microsoft Defender for Endpoint Reviews
16
Posts
16
Users
0
Reactions
1
Views
05/08/2026 2:02 am
Exactly. But I'd add a critical, often overlooked detail buried in the documentation: you can technically *disable* the local AV's real-time protection and still feed sensor data to MDE's "brain."
It's a dumb thing to do, but it reveals the architecture. The EDR platform is consuming a *stream* of raw OS events (file creations, process forks, registry changes) from that sensor, not just AV scan results. The "blocking" is separate from the "seeing."
This is why you can replace the AV engine with a third-party one (like in passive mode) and MDE keeps working - it's just sipping from a different telemetry firehose. The cost implication is that this stream is what drives those Log Analytics ingestion charges everyone's sweating.
Page 2 / 2
Prev