Edit

Use installer script based deployment to deploy Microsoft Defender for Endpoint on Linux

Introduction

You can deploy Defender for Endpoint on Linux by using various tools and methods. This article describes how to automate the deployment of Defender for Endpoint on Linux by using an installer script. This script identifies the distribution and version, selects the right repository, sets up the device to pull the latest agent version, and onboards the device to Defender for Endpoint using the onboarding package. This method is highly recommended for simplifying the deployment process.

To use another method, refer to the Related content section.

Important

If you want to run multiple security solutions side by side, see Considerations for performance, configuration, and support.

You might have already configured mutual security exclusions for devices onboarded to Microsoft Defender for Endpoint. If you still need to set mutual exclusions to avoid conflicts, see Add Microsoft Defender for Endpoint to the exclusion list for your existing solution.

Prerequisites and system requirements

Before you get started, see Prerequisites for Defender for Endpoint on Linux for a description of prerequisites and system requirements.

Tip

Before running the installer script to deploy Defender on your Linux server, it's recommended to run the script with the --pre-req option to check minimum system requirements (memory, CPU, disk space, supported OS) before deployment.

Deployment process

  1. Download the onboarding package from Microsoft Defender portal by following these steps:

    1. In the Microsoft Defender portal, expand the System section and select Settings > Endpoints > Device management > Onboarding.

    2. In the first drop-down menu, select Linux Server as the operating system.

    3. In the second drop-down menu, select Local Script as the deployment method.

    4. Select Download onboarding package. Save the file as WindowsDefenderATPOnboardingPackage.zip.

      Screenshot showing the options to select to download the onboarding package.

    5. From a command prompt, extract the contents of the archive:

      unzip WindowsDefenderATPOnboardingPackage.zip
      
      Archive:  WindowsDefenderATPOnboardingPackage.zip
      inflating: MicrosoftDefenderATPOnboardingLinuxServer.py
      

      Warning

      Repackaging the Defender for Endpoint installation package isn't a supported scenario. Doing so can negatively affect the integrity of the product and lead to adverse results, including but not limited to triggering tampering alerts and updates failing to apply.

      Important

      If you miss this step, any command executed shows a warning message indicating that the product is unlicensed. Also the mdatp health command returns a value of false.

  2. Download the installer bash script provided in our public GitHub repository.

  3. Grant executable permissions to the installer script:

    chmod +x mde_installer.sh
    
  4. Execute the installer script and provide the onboarding package as a parameter to install the agent and onboard the device to the Defender portal.

    sudo ./mde_installer.sh --install --onboard ./MicrosoftDefenderATPOnboardingLinuxServer.py --channel prod --pre-req
    

    This command deploys the latest agent version to the production channel, checks minimum system requirements (memory, CPU, disk space, supported OS), and onboards the device to Defender Portal.

    Additionally you can pass more parameter based on your requirements to modify the installation. Check help for all the available options:

     ❯ ./mde_installer.sh --help
    mde_installer.sh v0.7.0
    usage: basename ./mde_installer.sh [OPTIONS]
    Options:
    -c|--channel              specify the channel (insiders-fast / insiders-slow / prod) from which to install. Default: prod
    -i|--install              install the product
    -r|--remove               uninstall the product
    -u|--upgrade              upgrade the existing product to a newer version if available
    -l|--downgrade            downgrade the existing product to an older version if available
    -o|--onboard