Skip to main content

Hi all, 

 

Does anyone know if Automox has any recommended Microsoft Defender exclusions please? We use Microsoft Defender for Endpoint and want to ensure we’re not impeding on Automox performance / usability at all please. Further, if anyone knows of any local client firewall rules (other than the 7844 for Cloudflare Tunnels) that might be needed please. 

 

I tried to search but I can’t seem to see anything, so thought I’d best double check.

 

Thanks in advance! 

 

Hey Marshyp,

 

The Automox Agent Notifier must be added to the Windows Defender firewall allowed applications. Here are some articles detailing the EPP and Firewall allowlisting requirements for Automox!

Please don’t hesitate to reach out if you have any other questions!


Hey Marshyp,

 

The Automox Agent Notifier must be added to the Windows Defender firewall allowed applications. Here are some articles detailing the EPP and Firewall allowlisting requirements for Automox!

Please don’t hesitate to reach out if you have any other questions!

Thanks Corey, 

Looks like I’ve covered everything there, so that’s great news - Thanks for confirming! 


@Marshyp 

For MDE, after observing this alert Suspicious 'PsHiddenWindowLaunch' behavior was blocked. The following rule was added under Security Settings > Endpoints > Folder Exclusions at https://security.microsoft.com/securitysettings/endpoints/folder_exclusions

Example of the rule added:

 

 

 


@Marshyp 

For MDE, after observing this alert Suspicious 'PsHiddenWindowLaunch' behavior was blocked. The following rule was added under Security Settings > Endpoints > Folder Exclusions at https://security.microsoft.com/securitysettings/endpoints/folder_exclusions

 

Thanks Jack, 

I am eager not to exclude a folder if possible as this feels like an unnecessary attack surface. Will be running some test Worklets later today to test the functionality, and if I get the blocks or alerts as you mention then will revisit but confident I can get away with the processes and firewall rules for now. 

 

Appreciate your assistance! 


Reply