Configuring Windows Defender With RocketCyber

Updated 4 months ago by Carl Banzhof

Microsoft has continually advanced its threat protection of devices with Windows Defender. Since Windows 8 and especially with Windows 10 and later the advanced capabilities to protect the Operating System and user from malicious threats has improved dramatically.

MSPs however have not embraced Windows Defender because it lacks multi-tenant management capabilities.

Until Now

RocketCyber introduces the Defender Manager RocketApp that provides full multi-tenant command, control and reporting of Windows Defender running on Windows 8 and higher Desktops and Windows 2016 and higher Servers.

Getting Started

This section will walk through how to configure Defender Manager and cover some best practices.The first thing you'll want to do is decide which clients are candidates for migrating their advanced threat prevention and anti-virus from their current solution to Windows Defender. 

After you've decided on which customer will be migrated, then deploy the RocketCyber agent to the desired endpoints. 

To begin, logon to the RocketCyber console, navigate to the Dashboard and choose the appropriate customer from the Customers dashboard widget.

To begin, logon to the RocketCyber console, from the left hand navigation menu click on All Customers.

Next, click Deploy for the appropriate customer.

From the deployment screen, choose the option that is best for your environment. There are integrations with most of the popular RMM tools which can deploy the agent.

Enable the Defender Manager RocketApp

After you've deployed the agents, the next step will be to Enable the Defender Manager app.

From the left hand Nav click on App Store

On the Defender Manager App Tile, switch the App status to ON

On the left hand navigation menu, you should now see a new item for Defender Manager.

Configuring the Defender Manager Settings

You are now ready to configure the settings that control Windows Defender. From the left hand navigation menu click on Dashboard.

From the Defender Manager App Card, click on Configure

The Defender Manager Configuration dialog, presents a series of tabs that control the behavior of various characteristics of Windows Defender.

General - Includes options for controlling UI elements and signature updates.

Real-time Protection - Includes options for enabling various real-time protection options.

Cloud Protection - Includes options for protection delivered from the Microsoft cloud to your endpoints.

Scans - Includes options for when and how to scan devices.

Threat Actions - Includes options for tailoring automatic threat responses.

Advanced - Includes options for Attack Surface Reduction and Advanced Threat Protection.

Exclusions - Includes options for whitelisting processes and files.

The RocketCyber console provides a default configuration that should be useable by most customers without modification. 

More details about the default configuration can be found here

Review all of the default configuration options and tailor them to suite your customer environment. When finished Click Update.

Make The Big Switch

Now that you've tailored the configuration options, its time to switch on Microsoft Defender.

From the Defender Manager App Card, click on Configure

In the General Tab, Click Enable Windows Defender.

Click Update

By performing this step you effectively have laid down the configuration and staged Windows Defender. If there is already another active AV client on the device, Windows Defender won't be active until that AV client is removed.To fully activate Windows Defender uninstall the current AV solution. For details on uninstalling the current AV/ATP solution refer to the vendors instructions.

Congratulations, you devices are now protected by Windows Defender and RocketCyber.

How did we do?

Powered by HelpDocs

Powered by HelpDocs