Windows-itpro-docs: If EICAR is not detected, it could be that you have set preferences via Ansible or Puppet.

Created on 5 Dec 2020  Â·  5Comments  Â·  Source: MicrosoftDocs/windows-itpro-docs

[Enter feedback here]

Symptom:

While you are going thru Client configuration

  1. Run a detection test to verify that the device is properly onboarded and reporting to the service. Perform the following steps on the newly onboarded device:

curl -o ~/Downloads/eicar.com.txt https://www.eicar.org/download/eicar.com.txt

Reference:
https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/linux-install-manually#client-configuration

You might wait and not get any notifications in the MDE portal.

Cause:

In the "Set preferences" section, you might have the sample "Full configuration profile example" deployed to /etc/opt/microsoft/mdatp/managed/mdatp_managed.json via Ainsible, or Puppet.

You will see that it has this allowed threat in the example:

  "allowedThreats":[
     "EICAR-Test-File (not a virus)"
  ],

You will want to remove that portion if you want to

https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/linux-preferences#full-profile

Resolution:

In Ansible or Puppet, remove the following:
"allowedThreats":[
"EICAR-Test-File (not a virus)"
],

for testing, you could edit /etc/opt/microsoft/mdatp/managed/mdatp_managed.json with VI or Nano.


Document Details

⚠ Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Microsoft submitter defender for endpoint

Most helpful comment

Very good catch and info. Updating https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/linux-install-manually#client-configuration would help alot.
I might have the time to submit a PR later today

All 5 comments

@nam31, will you look into this issue #8760, only if you have free time

@konstruktoid : Sorry for bothering you, I just wanted to know if you would like to have a quick look at this and maybe offer some pointers.

Very good catch and info. Updating https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/linux-install-manually#client-configuration would help alot.
I might have the time to submit a PR later today

@YongRhee-MSFT, can you have a look at #8848 and see if it makes sense to you?

Thx for the help, looks good team.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

illfated picture illfated  Â·  3Comments

thohun picture thohun  Â·  3Comments

iadgovuser1 picture iadgovuser1  Â·  3Comments

LanceMcCarthy picture LanceMcCarthy  Â·  3Comments

KamilSzafarczyk picture KamilSzafarczyk  Â·  3Comments