defender for endpoint EDR vs AIR

eg1995 1,131 Reputation points
2023-02-14T15:49:00.07+00:00

Hi team,

i need your help in differentiating between EDR and AIR in defender for endpoint.

As AIR currently is not available for MacOs and i have a requirement for Macos. I need to understand what EDR can do in this case in terms of blocking and remediation options

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
4,207 questions
Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,817 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
Microsoft Intune MacOs
Microsoft Intune MacOs
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.MacOs: A family of Apple operating systems for the Apple Mac line of computers.
76 questions
{count} votes

Accepted answer
  1. Givary-MSFT 30,251 Reputation points Microsoft Employee
    2023-02-22T06:24:54.9666667+00:00

    @eg1995 Apologies for the delay in reviewing this post, As I understand you are looking for difference between EDR & AIR in defender for endpoint.

    EDR in block mode will allow EDR detections to be blocked. EDR detections are detections that are based on AI and run in the Microsoft Cloud. For example, EDR might notice that a process is doing phishy stuff and after analysis of the data in the cloud, it can be blocked.

    AIR is an investigation that will launch after an alert is generated. This investigation will check the evidence from the alert and (according to your automation level) remediate certain threats.

    Reference:

    https://video2.skills-academy.com/en-us/microsoft-365/security/defender-endpoint/edr-in-block-mode?view=o365-worldwide

    https://video2.skills-academy.com/en-us/microsoft-365/security/defender-endpoint/automated-investigations?view=o365-worldwide

    Let me know if you have any further questions, feel free to post back.

    0 comments No comments

0 additional answers

Sort by: Most helpful