This article lists some of the most commonly asked questions regarding Red Canary and provisioning for Microsoft Defender for Endpoint (MDE).
In order for Red Canary’s security analysts to log into a user’s MDE console, Microsoft requires the user to give permission to the Red Canary tenant, which contains all of our trusted and verified Red Canary employees.
Please open a support case if there are any further questions we can help with.
General Requirements and Compatibility
What operating systems are supported by Microsoft Defender for Endpoint?
Microsoft Defender for Endpoint supports a wide range of Windows, macOS, Linux, Android, and iOS operating systems. To learn more about operating systems supported by Microsoft Defender for Endpoint, check out Minimum requirements for Microsoft Defender for Endpoint.
Can I run Microsoft Defender for Endpoint with another endpoint security or antivirus program installed?
Defender for Endpoint relies on the Microsoft Defender AV to provide metadata to the sensor and service. Defender will enter passive mode when another AV tool is present, allowing these functions to operate normally. If your organization has fully disabled Defender via GPO or another method, you will need to re-enable Defender on machines that are scheduled for Defender for Endpoint enrollment. For more information, see Microsoft Defender Antivirus compatibility.
What are the networking requirements for Microsoft Defender?
When you deploy Microsoft Defender for Endpoint sensors, you want to know all of the associated network requirements so that your sensors will communicate properly and behave as expected.
If you proxy your outbound traffic, you need to be aware of important network requirements. The following documentation includes all the allowlist domains and IPs necessary to deliver telemetry to Red Canary:
You can also download a spreadsheet that lists the services and associated URLs that your network must be able to connect to. The spreadsheet also lists specific DNS records for service locations, geographic locations and operating systems. Download the spreadsheet here.
Licensing and Plan Management
Where can I find information about my Microsoft Defender for Endpoint plan?
Microsoft offers multiple plans for MDE. Learn more about your MDE plan here.
Can you automatically assign a license using Entra ID?
From the Entra ID Admin Center, Red Canary recommends assigning licenses via a group. You can do this as long as you’re a license admin within Entra ID for your organization. For more information, see Assign or unassign licenses for users in the Microsoft 365 admin center in Microsoft’s documentation.
How does MDE licensing work for a computer shared by 20 or more users?
Official Microsoft guidelines recommend that you can use up to 5 devices per user account associated with MDE. If you have additional questions, reach out to Microsoft for guidance on your specific scenario.
If admins have E5 licenses, can they track the compliance of users without E5, or do they require E5 licenses as well?
For features to be fully enabled, each user must have a license assigned to that particular user. This ensures that metrics and tooling are enabled properly inside of M365 to support this user. There are exceptions to this based on the various technologies available, but compliance is also a consideration.
Where can I find information about my MDE plan?
Microsoft offers multiple plans for MDE. Learn more about your MDE plan here.
Red Canary Integration and Configuration
What happens if I uncheck the Defender for Endpoint option within the Graph integration?
If you uncheck the MDE option within the Microsoft Graph integration, you’ll stop receiving MDE alerts. The configuration in the Graph integration takes precedence. Even if your MDE standalone integration is still active, disabling the MDE option in the Graph integration will prevent alerts from being ingested. To resume the flow of alerts, you must re-enable the MDE option.
Does the tenant ID that Red Canary provides represent a separate tenant for each user?
No. The redcanary.com tenant ID represents Red Canary’s corporate tenant, which is managed by Red Canary.
How many users are in the Entra ID tenant/directory? What is the role of the personnel?
The tenant has users who are strategically enabled to have Microsoft Entra ID accounts due to their role. This consists of Red Canary employees who require access to your tenant/directory to help with detection and troubleshooting.
Are there any considerations with Automate interfering with MDE?
Automate actions will queue in MDE through the API.
Are there any considerations for MDE response actions? Will the actions interfere with Red Canary's automated capabilities?
Red Canary response actions use MDE response capabilities, so there shouldn't be any issues when using both.
Access, Identity, and Security
How is Microsoft Defender for Endpoint protected from tampering or disabling?
Disabling Microsoft Defender for Endpoint on Windows client operating systems (Win 10 / Win 11) is difficult for adversaries. Microsoft has hardened it in multiple ways so it’s highly unlikely that it could be disabled.
If you are deeply concerned about this risk, ensure that tamper protection is enabled for Windows Defender. Tamper protection is supported by the following Operating Systems:
Windows 10 (1709, 1803, 1809, or later)
Windows 11
Windows Server 2012 R2*†
Windows Server 2016†
Windows Server 2019†
Windows Server 2022†
Windows Server, version 1803 or later†
* Requires that the server be onboarded with the Modern Unified Solution package.
† Requires Configuration Manager version 2006, with tenant attach.
Microsoft has an in-depth blog post on the various methods used to enable tamper protection.
Can I set up two roles, one without live response and one with live response that requires justification?
Yes. You can configure roles both ways. Live Response is currently not a prerequisite for Red Canary to perform our service, but it gives our Threat Hunting team on-demand access to a device via a remote shell using the customer MDE console. This helps us to respond and contain threats instantaneously.
Can single sign-on setup be applied to computers without a federated server?
Yes. In the context of Entra ID SSO, single sign-on can be applied when cloud applications federation protocols are used. However, use Entra ID App Proxy for on-premise.
How does conditional access work? If we don't want to require multi-factor authentication for all users, how can we set this up?
Conditional access policies are configured through the Entra ID admin center. Click Conditional Access, and then click New Policy to create a conditional access. Various actions and conditions can be assigned to specific users or groups in this manner. Learn more about creating a conditional access policy.
How is Microsoft Defender for Endpoint protected from tampering or disabling?
Disabling Microsoft Defender for Endpoint on Windows client operating systems (Win 10 / Win 11) is difficult for adversaries. Microsoft has hardened it in multiple ways so it’s highly unlikely that it could be disabled.
If you are deeply concerned about this risk, ensure that tamper protection is enabled for Windows Defender. Tamper protection is supported by the following Operating Systems:
Windows 10 (1709, 1803, 1809, or later)
Windows 11
Windows Server 2012 R2*†
Windows Server 2016†
Windows Server 2019†
Windows Server 2022†
Windows Server, version 1803 or later†
* Requires that the server be onboarded with the Modern Unified Solution package.
† Requires Configuration Manager version 2006, with tenant attach.
Microsoft has an in-depth blog post on the various methods used to enable tamper protection.
Deployment and Management
Is there quality documentation on Microsoft InTune set up and registration?
Red Canary recommends reviewing Microsoft InTune documentation. The deployment planning guide for Microsoft InTune is thorough and covers migration and configuration scenarios, costs and licensing, policies, and rollout plans.
Is pushing group policy in a hybrid environment done through on-premise Microsoft Active Directory or InTune?
Red Canary recommends that you use Microsoft InTune (which is part of Microsoft Endpoint Manager) whenever possible as it has more configuration choices. However, you can use either.
How do we block the Microsoft store? Is this a group policy setting?
Using a Group Policy Object (GPO) or Device Restriction Settings in Microsoft InTune is the most efficient way to accomplish this.
What is the best way to group sensors dynamically?
The easiest way to dynamically group sensors is to use a reporting tag.
If a user has Defender and the ability to group endpoints is not available, can they use reporting tags to do this? Is there another way the user can do this?
When we sync endpoints, we will populate the Red Canary “Sensor Group” field with whatever value the user has configured as the “Device Group Name” in Defender.
Operations and Incident Response
What happens when a Microsoft Defender-protected endpoint loses connectivity?
The Microsoft Defender for Endpoint agent will cache data locally for roughly three days. If a machine has not communicated (sending via “cyber data channel” but not command and control) for over two days, the machine is considered impaired.
How can a user continue remediation once an endpoint is isolated? What is the access to the endpoint the user will have?
MDE is still able to monitor the endpoint after isolation. For more information, see Isolate devices from the network.
What other Microsoft solutions does Microsoft Defender for Endpoint currently integrate with?
Microsoft Defender for Endpoint directly integrates with various Microsoft solutions, including:
Microsoft Intune
Office 365 Threat Intelligence
Defender for Azure
Azure Security Center
Skype for Business
Defender for Cloud Apps
Microsoft Sentinel