
Removed Windows Server SAC from the comparison because… did anyone really care? Trying to simplify things.This informs device compliance if the app hasn’t protected the device in a week. Not really the same as TP for Windows, but it’s the name that’s been chosen. Tamper protection for iOS and Android was added.macOS and Linux live response capabilities added, including isolation, investigation packages, and scan initiation.Debian, iOS, and Android TVM support added.This lets you manage config in Endpoint Manager, just like Intune, but without needing to Intune enrol. Defender for servers is a feature of Defender for Cloud that includes Defender for Endpoint for servers plus loads more like JIT access to VMs.Defender for Cloud replaces Azure Defender.Renamed Azure Defender for Microsoft Defender for Cloud + Microsoft Defender for servers.Similarly, removed a number of mentions that things are in preview.If in doubt, if it’s a Windows 10 or Server 2019 feature, it needs the unified agent. Removed qualifiers for Windows Server 2012 R2/2016 features that need the unified agent.Added passive mode for Windows Server 2012 R2/2016 (unified agent), macOS, and Linux.So here it is 🙂 I’ve also decided to rename it to The Ultimate Comparison of MDE Features by OS… because renaming’s what we do, right? Three months later, it’s overdue an update.

This is a “matrix” of the tons of features, services, and important components that make up Microsoft Defender for Endpoint. It’s been about 5 months since I last updated my comparison of Defender for Endpoint features by OS.
