<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco AMP and Windows Defender in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4481356#M6431</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I use Secure Endpoint (AMP) and Windows Firewall at the same time. And I had not any issue.&lt;/P&gt;&lt;P&gt;M&lt;/P&gt;</description>
    <pubDate>Wed, 06 Oct 2021 19:48:47 GMT</pubDate>
    <dc:creator>mljevakovic</dc:creator>
    <dc:date>2021-10-06T19:48:47Z</dc:date>
    <item>
      <title>Cisco AMP and Windows Defender</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/3338078#M4981</link>
      <description>&lt;P&gt;We recently attended a "test drive" class for Cisco AMP where they mentioned that AMP was approved by Microsoft as a 3rd party AV client that should disable windows defender. I've linked the KB below. We have several test machines with AMP deployed that also have windows defender enabled by default in Windows 10. Does anyone have any insight into this?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/windows-defender-antivirus-compatibility" target="_blank"&gt;https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/windows-defender-antivirus-compatibility&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 09 Mar 2019 01:46:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/3338078#M4981</guid>
      <dc:creator>JDoobs</dc:creator>
      <dc:date>2019-03-09T01:46:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AMP and Windows Defender</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/3338524#M4982</link>
      <description>&lt;P&gt;In order to replace Windows defender, the AMP policy for the endpoints must include the optional Tetra engine so that the ClamAV signatures will be downloaded and in effect.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once you do that, Windows Defender Security Center will indicate that Virus and threat Protection is being provided by Cisco AMP for Endpoints.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AMP4E as Windows AV and TP.PNG" style="width: 661px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/8058i996C47CCF95DA6F9/image-size/large?v=v2&amp;amp;px=999" role="button" title="AMP4E as Windows AV and TP.PNG" alt="AMP4E as Windows AV and TP.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 09:23:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/3338524#M4982</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-02-27T09:23:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AMP and Windows Defender</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4391802#M6113</link>
      <description>&lt;P&gt;Does this disable Windows Defender completely?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 20:05:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4391802#M6113</guid>
      <dc:creator>wade</dc:creator>
      <dc:date>2021-04-22T20:05:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AMP and Windows Defender</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4481227#M6430</link>
      <description>&lt;P&gt;Should the machine still run Windows Defender firewall?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Oct 2021 16:49:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4481227#M6430</guid>
      <dc:creator>rcarmack1</dc:creator>
      <dc:date>2021-10-06T16:49:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AMP and Windows Defender</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4481356#M6431</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I use Secure Endpoint (AMP) and Windows Firewall at the same time. And I had not any issue.&lt;/P&gt;&lt;P&gt;M&lt;/P&gt;</description>
      <pubDate>Wed, 06 Oct 2021 19:48:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4481356#M6431</guid>
      <dc:creator>mljevakovic</dc:creator>
      <dc:date>2021-10-06T19:48:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AMP and Windows Defender</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4503634#M6506</link>
      <description>&lt;P&gt;I am finding that on Windows 10 multi-session ( 7.4.5.20701) and on Windows Server 2019 (7.3.9.20091) AMP/Endpoint Security is failing to register with Windows Security Centre - well WSC does not show AMP/Endpoint Security as the active AV, and Defender is still running.&amp;nbsp; This has caused problems where both product ran scheduled scans at the same time.&amp;nbsp; &amp;nbsp;I read in the "Secure Endpoint (formerly AMP for Endpoints) User Guide,&amp;nbsp;Last Updated: July 30, 2021" page 108 "IMPORTANT!&amp;nbsp;Windows Defender cannot be automatically disabled in Windows Server versions 2016 and later. If you want to run TETRA on those operating systems you must disable Windows Defender manually."&lt;/P&gt;&lt;P&gt;So which is true, does 7.4.1 and later register with WSC regardless of Tetra, 7.3.9 depending on Tetra (which is enabled); or on Server 2016 and later, is that really broken?&amp;nbsp; &amp;nbsp;Windows 10 multi-session does report as a server OS in some regards.&amp;nbsp; I am trying to understand if this is not working as expected (so we open a TAC call) or just how it is, bad luck.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 15:48:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4503634#M6506</guid>
      <dc:creator>noc</dc:creator>
      <dc:date>2021-11-16T15:48:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AMP and Windows Defender</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4510152#M6520</link>
      <description>&lt;P&gt;We're experiencing a similar situation with our Windows 10 workstations; AMP is not registering itself as the primary av provider thus Windows Defender is not getting disabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did your issue resolved, if so could you share?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Nov 2021 18:53:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4510152#M6520</guid>
      <dc:creator>mark.smith3</dc:creator>
      <dc:date>2021-11-29T18:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AMP and Windows Defender</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4510442#M6521</link>
      <description>&lt;P&gt;It is very innovative. Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 10:14:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4510442#M6521</guid>
      <dc:creator>vbespiritu</dc:creator>
      <dc:date>2021-11-30T10:14:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AMP and Windows Defender</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4521110#M6557</link>
      <description>&lt;P&gt;Same problem here.&lt;/P&gt;</description>
      <pubDate>Sun, 19 Dec 2021 09:01:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4521110#M6557</guid>
      <dc:creator>gernot.schmied</dc:creator>
      <dc:date>2021-12-19T09:01:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AMP and Windows Defender</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4522627#M6561</link>
      <description>&lt;P&gt;It seems that Windows 10 multi-session behaves like a Windows Server build, and also lacks the service that allows Endpoint Security to notify the Windows Security Centre that it is running.&amp;nbsp; &amp;nbsp;There is a Microsoft article about Windows Defender and 3rd party anti-virus product co-existence:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/microsoft-defender-antivirus-compatibility?view=o365-worldwide" target="_self"&gt;https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/microsoft-defender-antivirus-compatibility?view=o365-worldwide&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That is helpful but you just have to experiment.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 10:53:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4522627#M6561</guid>
      <dc:creator>noc</dc:creator>
      <dc:date>2021-12-22T10:53:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AMP and Windows Defender</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4522798#M6562</link>
      <description>&lt;P&gt;Hi folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;with the help of TAC this got resoved quickly.&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/88801"&gt;@noc&lt;/a&gt;&amp;nbsp;: No, this is only the case for the server version and it was not Tetra-related.&lt;BR /&gt;In my case, the following solution worked (quoted from my TAC resolution), removing the registry key was essential:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;I already finished to review the logs, It seems there is an issue with &lt;STRONG&gt;CiscoSCMS service&lt;/STRONG&gt;:&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;(529562, +0 ms) Dec 18 21:54:47 [21304]: ERROR: AmpMonitor::ScmInstall: CreateService failed : 1073 : Der angegebene Dienst ist bereits vorhanden.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;(529671, +0 ms) Dec 18 21:54:47 [21292]: ERROR: AmpMonitor::ScmProtect: ChangeServiceConfig2 failed : 5 : Zugriff verweigert&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;(529812, +16 ms) Dec 18 21:54:47 [27392]: ERROR: AmpMonitor::ScmStart: StartService failed : 2 : Das System kann die angegebene Datei nicht finden.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Action Plan&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;- Manually Uninstall completely the AMP connector&lt;/EM&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;EM&gt;When this message appears, please select &amp;nbsp;“NO”&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="gernotschmied_0-1640188869062.jpeg" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/140058i1A2E3A489F3AB67B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="gernotschmied_0-1640188869062.jpeg" alt="gernotschmied_0-1640188869062.jpeg" /&gt;&lt;/span&gt;&lt;/EM&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;EM&gt;- Verify if CiscoSCMS service remained in Windows services and remove the registry key manually using powershell commands with Administrator privlidges:&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;:\&amp;gt; set-Location HKLM:\system\currentControlSet\Services\&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;:\&amp;gt; Remove-Item .\CiscoSCMS_7.3.*&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;- Reboot the endpoint&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Perform a full reboot, you can use the following command from CLI:&amp;nbsp; &lt;STRONG&gt;shutdown -r &amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;or&lt;STRONG&gt; &amp;nbsp;&amp;nbsp;shutdown /r&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;- Download a fresh connector installer, install the connector again and verify if the issue persist.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 16:04:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4522798#M6562</guid>
      <dc:creator>gernot.schmied</dc:creator>
      <dc:date>2021-12-22T16:04:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AMP and Windows Defender</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4522802#M6563</link>
      <description>Gernot,&lt;BR /&gt;To clarify... after installing using the new installer, AMP now disabled the Windows Defender on server OS?&lt;BR /&gt;Ken&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 22 Dec 2021 16:13:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4522802#M6563</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2021-12-22T16:13:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AMP and Windows Defender</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4522804#M6564</link>
      <description>&lt;P&gt;We were able to resolve this issue by updating Windows Defender to version 4.18.2110.6.&amp;nbsp; Once this was in effect all systems switched over to using AMP as the primary AV provider and disabled Windows Defender.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We did not have to make any registry changes.&amp;nbsp; Hope you are able to find some success with this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 16:19:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4522804#M6564</guid>
      <dc:creator>mark.smith3</dc:creator>
      <dc:date>2021-12-22T16:19:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AMP and Windows Defender</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4522892#M6567</link>
      <description>&lt;P&gt;Hi Ken,&lt;/P&gt;&lt;P&gt;no, I am only talking about Windows 10 notebooks and workstations, not servers! However, you can happily run both, AMP now is the active (primary) one, as ist is supposed to be. Technically defender ist listed as inactive, but you can still let it run scheduled scans in addition. In the perception of defender it switches to inactive, because the main component "real-time protection" is disabled and taken over by AMP.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;PS: Don't do that with Kaspersky, Avira or others, leads to all kind of unpredictable effects.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that clarifies matters.&lt;/P&gt;&lt;P&gt;Regards, gernot&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 20:48:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4522892#M6567</guid>
      <dc:creator>gernot.schmied</dc:creator>
      <dc:date>2021-12-22T20:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AMP and Windows Defender</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4528896#M6584</link>
      <description>&lt;P&gt;I am also having the same issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2022-01-10 101737.png" style="width: 520px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/140866i298E728CF2B24342/image-dimensions/520x364?v=v2" width="520" height="364" role="button" title="Screenshot 2022-01-10 101737.png" alt="Screenshot 2022-01-10 101737.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jan 2022 15:45:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4528896#M6584</guid>
      <dc:creator>carlos.cordeiro</dc:creator>
      <dc:date>2022-01-10T15:45:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AMP and Windows Defender</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4529276#M6585</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;latest releases should disable Windows Defender and register itself to the Windows Security Center as the AV vendor. Since connector version 7.4.1 Secure Endpoint registers directly after the installation of the product.&lt;/P&gt;
&lt;P&gt;If Defender does not get disabled, please open a TAC case, so we can take a look if there is any issue.&lt;/P&gt;
&lt;P&gt;Thanks and Greetings, Thorsten&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jan 2022 07:45:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4529276#M6585</guid>
      <dc:creator>Troja007</dc:creator>
      <dc:date>2022-01-11T07:45:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AMP and Windows Defender</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4534684#M6618</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're having the same issue, it's working with 7.4.3, but 7.4.5 and 7.5.1.20833, both are never detected by the windows security center. I checked that all needed services are up. It's on a Windows 10 21H2 citrix virtual desktop built with Citrix app layering. The Cisco Secure Endpoint layer is installed with "/R /S /skiptetra 1 /skipdfc 1 /goldenimage 1".&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jan 2022 21:25:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4534684#M6618</guid>
      <dc:creator>serveurs</dc:creator>
      <dc:date>2022-01-19T21:25:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AMP and Windows Defender</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4535759#M6626</link>
      <description>&lt;P&gt;There was a bug in the 7.4.3 release of the Cisco Secure Endpoint Windows connector &lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvz12295" target="_self"&gt;&lt;SPAN&gt;CSCvz12295&lt;/SPAN&gt;&lt;/A&gt;. The connector would disable Windows Defender and Cisco Secure Endpoint would be listed even when the TETRA antivirus was disabled. This bug was resolved in version 7.4.5. Since you are not installing the TETRA antivirus engine, Windows Defender will continue to run to provide traditional antivirus detection.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jan 2022 14:29:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4535759#M6626</guid>
      <dc:creator>johnosn</dc:creator>
      <dc:date>2022-01-21T14:29:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AMP and Windows Defender</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4683730#M7085</link>
      <description>&lt;P&gt;Similar problem. I checked our Windows protect policy and the Tetra engine is enabled the convict modes for the connector all check out yet our Windows 10 workstations are showing Windows built-in Virus and threat protection and not Cisco secure endpoint even though the Connector is installed and has a status of Connected and policy has been synced. Connector version is 7.5.1.2. Maybe I have to enable Malicious Activity Protection for it to take over in our Windows workstations ?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2022 15:15:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-amp-and-windows-defender/m-p/4683730#M7085</guid>
      <dc:creator>sysnet_striver</dc:creator>
      <dc:date>2022-09-08T15:15:15Z</dc:date>
    </item>
  </channel>
</rss>

