

On Windows Server 2016, you might see Windows Defender Antivirus instead of Microsoft Defender Antivirus.ĭefender for Endpoint includes capabilities that further extend the antivirus protection that is installed on your endpoint.

You should see Normal, Passive, or EDR Block Mode if Microsoft Defender Antivirus is enabled on the endpoint. You can view your protection status in PowerShell by using the command Get-MpComputerStatus. Path: HKLM\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection.You can set Microsoft Defender Antivirus to passive mode using a registry key as follows: In those cases, set Microsoft Defender Antivirus to passive mode to prevent problems caused by having multiple antivirus products installed on a server.

( 2) On Windows Server 2019, Windows Server, version 1803 or newer, Windows Server 2016, or Windows Server 2012 R2, Microsoft Defender Antivirus doesn't enter passive mode automatically when you install a non-Microsoft antivirus product. Microsoft Defender Antivirus must be disabled (manually) Microsoft Defender Antivirus must be set to passive mode (manually) The following table summarizes the state of Microsoft Defender Antivirus in several scenarios.
