Configure Endpoint Security - Windows Defender

How to configure multi-tenant command and reporting with RocketCyber

Overview

Microsoft has continually advanced its threat protection of devices with Windows Defender. Since Windows 8 and especially with Windows 10 and later, the advanced capabilities to protect the Operating System and user from malicious threats has improved dramatically.

MSPs have not embraced Windows Defender because it lacks multi-tenant management capabilities.

Getting Started

The first thing needed is to deploy the RocketCyber agent to all devices you wish to control.

  1. Log in to the RocketCyber console
  2. From the left-hand navigation menu, click All Organizations.
  3. Click Deploy for the appropriate organization.

From the deployment screen, choose the option that is best for your environment. There are integrations with most of the popular RMM tools which can deploy the agent.

Enabling the Defender Manager RocketApp

After you've deployed the agents, the next step will be to Enable the Defender Manager app.

  1. From the left-hand Nav, click App Store
  2. On the Defender Manager App Tile, switch the App status to ON

On the left-hand navigation menu, you should now see a new item for Defender Manager.

Configuring the Defender Manager Settings

You are now ready to configure the settings that control Windows Defender.

  1. From the left-hand navigation menu, click Dashboard.
  2. From the Defender Manager App Card, click Configure. The Defender Manager Configuration dialog presents a series of tabs that control the behavior of various characteristics of Windows Defender.
    • General - Includes options for controlling UI elements and signature updates.
    • Real-time Protection - Includes options for enabling various real-time protection options.
    • Cloud Protection - Includes options for protection delivered from the Microsoft cloud to your endpoints.
    • Scans - Includes options for when and how to scan devices.
    • Threat Actions - Includes options for tailoring automatic threat responses.
    • Advanced - Includes options for Attack Surface Reduction and Advanced Threat Protection.
    • Exclusions - Includes options for allowlisting processes and files.

The RocketCyber console provides a default configuration that should be usable by most organizations without modification. 

More details about the default configuration can be found

here

Review all of the default configuration options and tailor them to suit your organization environment. When finished Click Update.

Making The Big Switch

Now that you've tailored the configuration options, it's time to switch on Microsoft Defender.

  1. From the Defender Manager App Card, click Configure
  2. In the General Tab, Click Enable Windows Defender.
  3. Click Update

Congratulations, your devices are now protected by Windows Defender and RocketCyber!

By performing this step you effectively have laid down the configuration and staged Windows Defender. If there is already another active AV client on the device, Windows Defender won't be active until that AV client is removed. To fully activate Windows Defender uninstall the current AV solution. For details on uninstalling the current AV/ATP solution refers to the vendor's instructions.