Description | Windows defender is flaging FortiEDR as a false positive and seeing it as a virus |
Scope | FortiEDR 5.X. |
Solution |
Workarounds:
1) Enable 'Register collectors to Windows Security Center' in the FortiEDR Central Manager.
In FortiEDR Central Manager choose choose 'Administration -> Tools' - Under Windows Security Center, check the box next to "Register collectors to Windows Security Center".
2) Whitelist FortiEDR in Defender. Exclude this path:
'C:\ProgramData\FortiEDR\Config\Collector\Signatures\' - In the Microsoft Endpoint Manager admin center choose 'Endpoint security -> Antivirus' and then select an existing policy. - Expand Microsoft Defender Antivirus Exclusions and then specify the exclusion.
"C:\ProgramData\FortiEDR\Config\Collector\Signatures\"
Review this article from Microsoft on how to address false positives and how to create exclusions. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2023 Fortinet, Inc. All Rights Reserved.