Can SEP AutoProtect co-exist with Windows Defender?
search cancel

Can SEP AutoProtect co-exist with Windows Defender?

book

Article ID: 262613

calendar_today

Updated On:

Products

Endpoint Protection Endpoint Security Complete

Issue/Introduction

You would like to know if the SEP Auto Protect and Windows Defender Real-time protection run together in 14.3 RU7

Environment

Release : 14.3 RU7

Resolution

Location and how to enable it:

SEP 14.3 RU7 - Virus and Spyware policy

https://api-broadcom-ca.wolkenservicedesk.com/attachment/get_attachment_content?uniqueFileId=n8d9wRWcMwksFBfyMHXlQw==


SES:Complete - Antimalware Policy 

https://api-broadcom-ca.wolkenservicedesk.com/attachment/get_attachment_content?uniqueFileId=vVZyXtBgQi21eRML8c4mRg==

Coexist with Windows Defender (Available in 14.3 RU1 to 14.3 RU1 MP1 and 14.3 RU7 and later.)

When Windows Defender and Symantec Endpoint Protection are both enabled and running on the same computer, the Auto-Protect scan runs after Windows Defender. Auto-Protect can detect any threats that Windows Defender misses.
If Windows Defender is disabled on the client computers, you should disable this option. Otherwise, Auto-Protect continues to run in a delayed state for real-time file system scans, but not for AMSI scans or command-line scans. 

Auto-Protect cannot run in coexistence mode on an endpoint that is protected by a File Based Write Filter (FBWF). These endpoints ignore this option.

Additional Information

REF: https://techdocs.broadcom.com/us/en/symantec-security-software/endpoint-security-and-management/endpoint-protection/all/Dialog-Overview/virus-and-spyware-protection-dialog/miscellaneous-v45100362-d49e11152.html

NOTE: In some cases to get coexistence to function, it may be required to place Windows Defender into passive mode following steps found in this Microsoft document: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/microsoft-defender-antivirus-compatibility?view=o365-worldwide