[Enter feedback here]
While you are going thru Client configuration
curl -o ~/Downloads/eicar.com.txt https://www.eicar.org/download/eicar.com.txt
Reference:
https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/linux-install-manually#client-configuration
You might wait and not get any notifications in the MDE portal.
In the "Set preferences" section, you might have the sample "Full configuration profile example" deployed to /etc/opt/microsoft/mdatp/managed/mdatp_managed.json via Ainsible, or Puppet.
You will see that it has this allowed threat in the example:
"allowedThreats":[
"EICAR-Test-File (not a virus)"
],
You will want to remove that portion if you want to
In Ansible or Puppet, remove the following:
"allowedThreats":[
"EICAR-Test-File (not a virus)"
],
for testing, you could edit /etc/opt/microsoft/mdatp/managed/mdatp_managed.json with VI or Nano.
⚠Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.
@nam31, will you look into this issue #8760, only if you have free time
@konstruktoid : Sorry for bothering you, I just wanted to know if you would like to have a quick look at this and maybe offer some pointers.
Very good catch and info. Updating https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/linux-install-manually#client-configuration would help alot.
I might have the time to submit a PR later today
@YongRhee-MSFT, can you have a look at #8848 and see if it makes sense to you?
Thx for the help, looks good team.
Most helpful comment
Very good catch and info. Updating https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/linux-install-manually#client-configuration would help alot.
I might have the time to submit a PR later today