

* IMPORTANT* if you provide FULL CONTROL to the folder or share, then you may experience the definitions being automatically purged by the child VM’s after they self-update, making the definitions unavailable at next boot. Share permission: Authenticated Users: Readįolder Permission: Authenticated Users: Read/Execute, SYSTEM: Read/Writed Get-SMBShareAccess -name wdav-update result should mirror the above I recommend using the same folder names as this will tie together with the download script that will be used later on. The below example resides in C:\wdav-update on the management VM. Setup a file share that will store the unpacked definitions. Create an SMB file share to store definitions. The endpoint will require internet access and I refer to this machine as the management VM. Identify a virtual machine/server/desktop or some endpoint that will be responsible for running the scheduled tasks for fetching definitions and storing them in an SMB file share.

Step 1: Setup a share and scheduled tasks to download, unpack and clean-up definitions… Use a clean build, ideally with an image that has not had any AV agent previously installed.

WINDOWS SERVER VDI SETUP HOW TO
The guide does not cover how to configure VM’s to use MMPC, WSUS, Cloud based definitons or ATP/MAPS.Įnvironment: VMWare Instant Clones, Win 10 1909. I recently had to setup a proof of concept of this for a client who had been using McAfee ENS and we saw a notable improvement in performance and overall desktop experience.
WINDOWS SERVER VDI SETUP SOFTWARE
Windows Defender AV for non-persistent instant clone desktops is a lightweight and free AV solution for VDI that is growing in popularity as an alternative to typical third party options as people move to O365 and want to align themselves with Microsoft across their software stack.īelow is a quick guide on how to configure Defender for Endpoint ( not ATP) which is a free version of Defender included with E3 O365 licensing using.Ī file share is used as the source for definition files.
