<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Sophos and Windows Defender on Windows Server 2016</title><link>https://community.sophos.com/on-premise-endpoint/f/sophos-endpoint-software/127837/sophos-and-windows-defender-on-windows-server-2016</link><description>Greetings to the well of knowledge... 
 I have been rolling out Intercept X to my virtual servers. I notice than when Sophos is actively scanning, the Windows built-in &amp;quot;Anti-malware Service Executable&amp;quot; is also actively doing something. Together, they</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Sophos and Windows Defender on Windows Server 2016</title><link>https://community.sophos.com/thread/468434?ContentTypeID=1</link><pubDate>Mon, 17 May 2021 19:54:16 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:ce592ab2-d86d-49b5-b4d4-b10feea9b6ce</guid><dc:creator>Sophos User930</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;If you run fltmc.exe from an admin prompt, do you see wdfilter in the list of filter drivers loaded?&lt;br /&gt;&lt;br /&gt;It is my understanding that when Sophos reports into Security Center, Defender should disable itself, evidence of this is in&amp;nbsp;\windows\temp\MpCmdRun.log.&lt;/p&gt;
&lt;p&gt;For example, the driver and service is set to manual start.&lt;/p&gt;
&lt;p&gt;-------------------------------------------------------------------------------------&lt;br /&gt;MpCmdRun: Command Line: &amp;quot;C:\Program Files\Windows Defender\MpCmdRun.exe&amp;quot; -DisableService&lt;br /&gt; Start Time: &amp;lrm;Sat &amp;lrm;Apr &amp;lrm;17 &amp;lrm;2021 22:53:50&lt;/p&gt;
&lt;p&gt;MpEnsureProcessMitigationPolicy: hr = 0x1&lt;br /&gt;EnableService(0, 3)&lt;br /&gt;Stoping WinDefend and setting to SERVICE_DEMAND_START ...&lt;br /&gt;Setting WdBoot to SERVICE_DEMAND_START and remove from early launch group...&lt;br /&gt;Stopping WdFilter and setting to SERVICE_DEMAND_START ...&lt;br /&gt;EnableService(0, 3) - finished.&lt;br /&gt;MpCmdRun: End Time: &amp;lrm;Sat &amp;lrm;Apr &amp;lrm;17 &amp;lrm;2021 22:53:53&lt;br /&gt;-------------------------------------------------------------------------------------&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>