Running modes
As it is built into the OS, MDAV has different running modes to provide compatibility with other endpoint protection software. If no other antimalware service is running, normal mode is used, and MDAV provides its configured threat protection capabilities.
In the presence of a third-party service for endpoint protection, MDAV can enter passive mode. This is only an option if the device is onboarded to MDE: consumer or unlicensed devices cannot leverage it, and instead use disabled mode. In passive mode, many of the features you will learn about in this chapter enter a state you can think of as hibernating: they are not explicitly disabled but will not be active either, on the assumption the third-party service has been chosen to replace them. The following will not be available in passive mode:
- Real-time protection and Cloud-delivered protection, and anything that has those as a prerequisite
- Attack surface reduction (ASR) rules
- Network protection and...