Info required for migration of MMA to Windows defender Unified agent.

Fadikar, Subhadip 0 Reputation points
2024-05-31T05:22:12.44+00:00

Please help me to identify the specific process for that Microsoft Defender unified agent is running on the server.

Scenario is that there are some servers in the environment running with 2012R2 and 2016. And MMA is running on the servers. As a result, they are onboarded to MDE portal. But as we know EOL for MMA is August 2024, I just want to migrate the servers to Microsoft Defender unified agent. So, I just want to ensure some information-

How to identify MMA is still running on the server?

How to migrate it to Microsoft defender unified agent locally? (There are some articles to ensure the job through MECM. But I just want to do it locally).

After migration, how can I identify that Microsoft defender unified agent is running on the server? (I just want to ensure if there is any specific ".exe" file or any other process is running for Microsoft defender unified agent)

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Alan La Pietra (CSA) 80 Reputation points Microsoft Employee
    2024-06-20T12:22:03.7933333+00:00

    Hi, did you go through this https://video2.skills-academy.com/en-us/azure/azure-monitor/agents/azure-monitor-agent-migration

    Once you onboard your VM to Arc you can install extensions, one of which would be MDE.windows, which is also the unified extension for Defender for Endpoint and Defender for Server.

    You install extensions based on the service you want to use, MDE, Update Manager, Defender, Vulnerability Management, Assessments, etc etc

    you can install extensions manually or through Azure Policies (DeployIfNotExist)

    Alan

    0 comments No comments