A cloud-native solution that protects workloads across hybrid and multi-cloud environments with threat detection and security recommendations
For Windows Server 2016 with CrowdStrike as the primary AV, the supported next steps depend on whether the server is still onboarded to Microsoft Defender for Endpoint.
- Confirm whether the server is still onboarded to Defender for Endpoint.
- If it is onboarded, Microsoft Defender Antivirus can run in passive mode.
- If it is not onboarded, passive mode is not supported on Windows Server 2016. In that case, Microsoft Defender Antivirus must be disabled or uninstalled manually to avoid multiple antivirus products on the server.
- If the server is onboarded and passive mode is required, verify these conditions:
-
ForceDefenderPassiveModemust be set before onboarding to Microsoft Defender for Endpoint. - On Windows Server 2016, passive mode requires onboarding by using the modern unified solution.
- Use
Get-MpComputerStatusand checkAMRunningMode. Expected values are Normal, Passive, or EDR Block Mode.
-
- Check whether tamper protection is preventing the switch.
- On platform version
4.18.2208.0and later, if the server is onboarded to Microsoft Defender for Endpoint, tamper protection allows switching to active mode, but not back to passive mode. - If Defender Antivirus was already switched to active mode, setting
ForceDefenderPassiveMode=1does not return it to passive mode when tamper protection is enabled.
- On platform version
- If the goal is to stop Defender for Endpoint deployment from Defender for Cloud, disabling the Defender for Cloud integration is only part of the process.
- In Defender for Cloud > Environment settings > select the subscription > Defender plans > Settings & Monitoring.
- Set the Endpoint protection component to Off.
- Select Continue and Save.
- Remove the
MDE.Windowsextension from the VM. - Offboard the device from the Microsoft Defender for Endpoint service.
- If CrowdStrike must remain the only AV on this Windows Server 2016 VM, and passive mode is not achievable or not desired, the supported path is to remove Microsoft Defender Antivirus from the server.
- Run as administrator:
Uninstall-WindowsFeature Windows-Defender Uninstall-WindowsFeature Windows-Defender-Gui - Restart the server to complete removal.
- Risk: removing Microsoft Defender Antivirus also removes its local AV capability. If CrowdStrike is later removed, Microsoft Defender Antivirus must be re-enabled.
- Run as administrator:
- Avoid unsupported methods.
- Manual modification of Microsoft Defender Antivirus service and driver start types is not supported.
- If Defender for Cloud previously onboarded the VM, registry tags can remain after offboarding and do not affect functionality.
- Those tags are under:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Advanced Threat Protection\DeviceTags - Risk: editing the registry incorrectly can cause device issues.
- Those tags are under:
Based on the described state—Endpoint protection disabled, passive mode registry set, but Get-MpComputerStatus still showing Normal—the most likely supported checks are:
- verify the VM is still onboarded to Defender for Endpoint,
- verify whether onboarding used the modern unified solution,
- verify whether tamper protection is blocking the return to passive mode,
- if Falcon must be the sole AV, remove
MDE.Windows, offboard from Defender for Endpoint, and uninstall Microsoft Defender Antivirus from Windows Server 2016.
- Microsoft Defender Antivirus compatibility with other security products
- Enable Defender for Endpoint integration in Microsoft Defender for Cloud
- Microsoft Defender Antivirus compatibility with other security products
- Microsoft Defender Antivirus compatibility with other security products
- Microsoft Defender Antivirus and non-Microsoft antivirus solutions without Defender for Endpoint
- Microsoft Defender Antivirus and non-Microsoft antivirus solutions without Defender for Endpoint