Cloud-delivered protection
You’ve seen the marketing emails. You’ve read the white papers. You’ve watched the webinars. They all preach one buzz phrase you’re probably now numb to: the power of the cloud. As much of a cliché as this now is, we cannot discuss MDAV and MDE without emphasizing the importance of its cloud-delivered protection.
As you learned in Chapter 2, Microsoft Defender Antivirus has a layered approach to threat protection, with layers beyond the client using cloud-delivered protection for defense. Detonation, reputation, file classification, behavioral, and metadata-based machine learning engines are all dependent on it. Even client-side capabilities, such as Antimalware Scan Interface (AMSI) are enhanced by it, to analyze potential fileless attacks. Suffice it to say, without cloud-delivered protection enabled, you severely limit the system’s ability to guard against threats that are not yet included (or cannot be included...