Team: Huntress EDR
Product: Managed Defender Antivirus
Environment: Managed AV (MAV)
Summary: This article outlines the list of terms and definitions surrounding Huntress Managed Antivirus.
Managed Antivirus Status Definitions
|Microsoft Defender Antivirus is not running on the endpoint.
|Microsoft Defender Antivirus does not have all engines running on the endpoint. Drilling down onto the host, this state is identified if not all eight engines are enabled.
|The host has not updated its signature definitions within the last 7 days.
|The host has not performed a scan in the last 7 days but has been online.
|The host is running an old Huntress agent version that does not support Managed Antivirus (<0.12.2).
|Another antivirus solution is installed on the endpoint.
|Defender State Unknown
|Defender is returning an invalid value for the host status, which may be resolved with a reboot.
|Defender Management Unavailable
|Defender's local policies or exclusions are not able to be overwritten by the Huntress policies
Managed Antivirus Policy Status
Inheritance settings that are set at the account level will apply to all organizations within the account. Inheritance settings that are set at the organization level will apply to all hosts within the organization. More on Huntress Recommended Defaults
|Configuration policy is not enforced on the endpoint; Huntress audits and reports on the current configuration of settings on the endpoint.
Huntress actively enforces the set configuration policy on the endpoint. If the endpoint is observed to have a setting that does not match the configuration policy, Huntress will actively update the configuration setting to match the associated configuration policy.
Huntress is attempting to push one of the policy modes
NOTE: Enforce mode ensures the settings from the configuration policy are enforced on the endpoint; it does not enable Microsoft Defender Antivirus which should be enabled by default unless actively disabled (usually by another AV).
|All current Defender settings on the endpoint match the set configuration policy
|One or more configuration settings does not match the configuration policy