cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2574
Views
1
Helpful
8
Replies

Cisco Secure endpoint with Defender

Tobias.S
Level 1
Level 1

We currently use Cisco Secure Endpoint (Tetra enabled) together with Windows Defender on servers (2019, 2022). We havent noticed any issues with this combination yet, but would we benefit from disabling Windows Defender or possibly turning off the tetra?

 

8 Replies 8

Matthew Franks
Cisco Employee
Cisco Employee

Tobias,

When you have Tetra enabled and the definitions are downloaded, Secure Endpoint registers as the system's Threat Protection software.  You can see this in the Virus & threat protection settings section. 

MatthewFranks_0-1686141197130.png

 

There are currently no known compatibility issues with Secure Endpoint and Defender so running them together shouldn't cause any issues but disabling one would cause the other to take over.

Thanks,

-Matt

Thank you for the answer Matthew. As of windows server 2019 the WCS do not register Cisco Secure Endpoint if you do not disable defender, even if tetra is enabled.

I always tried so hard not to run multiple AVs on a single machine. 

Matthew Franks
Cisco Employee
Cisco Employee

Good point. Sorry, I wasn't paying enough attention to the OS you mentioned!

-Matt

JJ999
Level 1
Level 1

@Tobias.S how did you disable defender? I uninstalled it, didn't see a way to disable. Now AMP doesn't show as the AV/Threat Protection at all.

I did not disable defender. I run Cisco Secure Endpoint and defender side by side on both servers and clients. But as you say its not registring as in security center.

 

ThinkG_AB
Level 1
Level 1

Its a windows server policy, you have to remove the feature to disable it now. 

jmornhineway
Level 1
Level 1

Log file from Defender. Cisco Secure Client turns off a setting in defender, Defender sees it, reports a threat, turns it back on...

 

2023-11-01T11:52:16.456Z DETECTION VirTool:Win32/DefenderTamperingRestore regkeyvalue:hklm\software\policies\microsoft\windows defender\\DisableAntiSpyware

 

Screenshot 2023-11-01 164346.png

Windows 11 build 22621.2506

Cisco Secure Client version 8.1.5.2132