IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Carbon Black Cloud: Windows Defender Still Running on with 'Use Windows Security Center' enabled in Policy for Windows 2016 and other Servers.

Carbon Black Cloud: Windows Defender Still Running on with 'Use Windows Security Center' enabled in Policy for Windows 2016 and other Servers.

Environment

  • Carbon Black Cloud Console: All Versions
  • Endpoint Standard Sensor: All Versions
  • Microsoft Windows Defender

Symptoms

Windows Defender continuous to operate when Carbon Black sensor is active and running.

Cause

In Windows Server 2016 Operating system enabling "Windows Security Center" will not disable Windows Defender. 

Resolution

In Windows Server 2016 and on other server Operating system enabling "Windows Security Center" will not disable Windows Defender. Instead, it must be disabled manually.
 
1) Disable it through Powershell:

1. Open PowerShell as Administrator.
2. Type the following command:

Set-MpPreference -DisableRealtimeMonitoring $true

2) To Uninstall Windows Defender:

1. Open PowerShell as Administrator.
2. Type the following command and press Type the following command and press Enter:

Uninstall-WindowsFeature -Name Windows-Defender



 

Additional Notes

Carbon Black Sensor can operate along with Defender in parallel.

Add Permissions rules or Exclusions for both Defender and Endpoint Standard so they are not scanning one another to improve performance

Endpoint Standard: What Permission Rules are needed for Windows Defender?
 

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎08-31-2022
Views:
3536
Contributors