Ability to Mute / Ignore Devices in Managed AV that are running other AV solutions / AV Removal Tools
E
Eric Weast
We are running Managed AV but are having a difficult time auditing the solution with devices with known other Antivirus solutions.
It's often hard to audit health status from the dashboard as a whole. Is there the ability to mute / ignore devices with other known solutions or a better way to audit?
It would also be good if there was a way to run a script from Huntress to remove other AV tools as well.
G
Gary Herbstman
We also have Systems with alternative primary antivirus but also run Defender as a secondary. These are sometimes connected to Microsoft 365 Defender as well.
In Huntress, Some of them are starting to show up as unhealthy once they run a scan or gather additional info. These endpoints are not unhealthy and should not be flagged as unhealthy. Defender running in the background as a secondary AV when there is an alternative primary is a normal and expected situation and Microsoft fully documents this as supported.
Flagging these devices as unhealthy insinuates we need to take a look at these and figure out what is wrong. There is nothing wrong it should not be unhealthy. I think the rules that define this unhealthy flag need to be reevaluated.
Autopilot
Merged in a post:
Be able to White-list units that have AntiVirus instead of Windows Defender
T
Tyler Ashline
We get alerts on units that leverage Bitdefender instead of windows firewall. Need to be able to whitelist those.
Henry Washburn
Would the "Filter" process be a better way for you? I know its not automatic but you could check all the subsets under "Unhealthy" and that should take out any hosts that are listed as "Other AV"
Photo Viewer
View photos in a modal
A
Annie Ballew
Thank you for the feedback! I'd love to hear more about this from you. You may have already seen the "Unmanaged" and "Other AV" filter options. "Unmanaged" means that Defender is completely off and another AV solution is detected on the endpoint. "Other AV" is a superset of that for all endpoints where we've detected another AV (regardless of whether Defender is on or not). Beyond this, would you be open to chatting more about some of your thoughts?