Skip to main content

Microsoft Defender for Endpoint Linux Onboarding

MDE LINUX ONBOARDING

Extend Defender visibility to Linux servers and workloads

Linux onboarding should validate distribution support, connectivity, package deployment, sensor health and Defender portal visibility before operational handover.

LinuxServer
AgentMDE
PortalSignal
OpsOwner

Executive Summary​

This guide describes Linux onboarding procedures for Microsoft Defender for Endpoint.

Linux onboarding enables endpoint visibility, threat detection and vulnerability management for Linux servers and workloads.


Supported Distributions​

DistributionSupported
UbuntuYes
DebianYes
RHELYes
CentOSYes
Oracle LinuxYes
SUSEYes

Prerequisites​

Required:

  • Python Installed
  • Internet Connectivity
  • Root Access
  • Supported Linux Version

Before onboarding, confirm whether the server is internet-connected, proxy-routed or isolated. Linux onboarding often fails because package repository access, SSL inspection, proxy authentication or outbound firewall rules were not reviewed before installation. Treat these checks as part of the deployment readiness review, not as post-install troubleshooting.


Architecture​

Linux onboarding architectureServer signal to Defender portal
01Linux serverSupported Linux workload is selected for Defender for Endpoint onboarding.
02Prerequisite checkConfirm distribution, package manager, Python, connectivity and proxy requirements.
03Defender agentInstall, onboard and validate sensor health and telemetry flow.
04Defender portalConfirm device inventory, alerting, vulnerability data and operational ownership.

Installation Workflow​

Repository Configuration​

curl -o microsoft.list

Import Microsoft Key​

curl -sSL https://packages.microsoft.com/keys/microsoft.asc

Install Defender​

sudo apt-get install mdatp

Onboarding​

Deploy onboarding package.

sudo python3 MicrosoftDefenderATPOnboardingLinuxServer.py

Validation​

Check status.

mdatp health

Check Org ID.

mdatp health --field org_id

Enable real-time protection.

mdatp config real-time-protection --value enabled

Operational Acceptance Criteria​

Use the following criteria before marking the onboarding as complete:

  • the device appears in Microsoft Defender XDR with the expected hostname and operating system
  • mdatp health reports healthy cloud connectivity, real-time protection and valid organization ID
  • vulnerability management data is visible for the onboarded server
  • alert routing to the SOC or operations team has been validated
  • proxy and update paths are documented for future patching or incident response

For production Linux servers, capture a validation screenshot or command output as handover evidence. This prevents later disputes about whether the endpoint was onboarded, merely installed or fully operational.


Security Best Practices​

  • Enable RTP
  • Enable Vulnerability Management
  • Monitor Health Status
  • Integrate with SIEM
  • Enable Alerting

Deliverables​

  • Linux Onboarding Guide
  • Validation Report
  • Security Baseline
  • Monitoring Guide

한국어 요약​

이 문서는 Linux 서버를 Microsoft Defender for Endpoint에 온보딩할 때 필요한 사전 조건, 설치 절차, 검증 기준을 정리합니다.

Linux onboarding은 agent 설치만으로 완료되지 않습니다. Microsoft Defender XDR portal에 device가 정상 표시되고, mdatp health 결과가 정상이며, vulnerability management와 alert routing까지 확인되어야 운영 인수인계가 가능합니다.

Field Checklist​

AreaWhat to Confirm
OS support배포판과 버전이 Microsoft Defender for Endpoint 지원 범위에 있는가?
Network pathproxy, SSL inspection, firewall, package repository 접근이 가능한가?
Onboarding packagetenant에 맞는 onboarding package를 사용했는가?
Health validationmdatp health, cloud connectivity, org ID, RTP 상태가 정상인가?
SOC operationalert routing, incident ownership, escalation path가 정의되었는가?
Handover evidencecommand output, portal screenshot, validation checklist가 남아 있는가?

Search Keywords​

이 문서는 다음 검색 의도에 답합니다.

  • Microsoft Defender for Endpoint Linux onboarding
  • MDE Linux server onboarding
  • mdatp health validation
  • Defender XDR Linux server
  • Microsoft Defender Linux proxy configuration
  • Microsoft Defender for Endpoint Linux 설치
  • MDE Linux 온보딩
  • Linux 서버 보안 모니터링

Contact / Asset Request​

Linux 서버 대량 온보딩, proxy 환경, isolated network, SOC handover 기준이 필요한 경우 Contact and Asset Request를 통해 체크리스트와 validation report template을 요청할 수 있습니다.