Proposed Pull Request Change

title description services author ms.assetid ms.service ms.subservice ms.topic ms.date ms.author ms.custom ai-usage
Microsoft Antimalware code samples for Azure Use PowerShell code samples to enable and configure Microsoft Antimalware for Azure virtual machines, cloud services, and Azure Arc-enabled servers. security msmbaldwin 265683c8-30d7-4f2b-b66c-5082a18f7a8b security security-fundamentals article 07/20/2026 mbaldwin devx-track-azurepowershell, devx-track-arm-template ai-assisted
📄 Document Links
GitHub View on GitHub Microsoft Learn View on Microsoft Learn
⚠ Content Truncation Detected
The generated rewrite appears to be incomplete.
Original lines: -
Output lines: -
Ratio: -
Raw New Markdown
Generating updated version of doc...
Rendered New Markdown
Generating updated version of doc...
+0 -0
+0 -0
--- title: Microsoft Antimalware code samples for Azure description: Use PowerShell code samples to enable and configure Microsoft Antimalware for Azure virtual machines, cloud services, and Azure Arc-enabled servers. services: security author: msmbaldwin ms.assetid: 265683c8-30d7-4f2b-b66c-5082a18f7a8b ms.service: security ms.subservice: security-fundamentals ms.topic: article ms.date: 07/20/2026 ms.author: mbaldwin ms.custom: devx-track-azurepowershell, devx-track-arm-template ai-usage: ai-assisted --- # Code samples to enable and configure Microsoft Antimalware for Azure This article provides PowerShell code samples to enable and configure Microsoft Antimalware for different Azure services including: - Azure Resource Manager VMs - Azure Service Fabric clusters - Azure Cloud Services (extended support) - Azure Arc-enabled servers Use these samples to deploy and configure the Microsoft Antimalware extension across your Azure environments. ## Deploy Microsoft Antimalware on Azure Resource Manager VMs > [!NOTE] > Before you run this code sample, uncomment the variables and provide appropriate values. > [!WARNING] > Deploying or updating this extension replaces existing Microsoft Defender Antivirus settings, including exclusions. To preserve your settings, specify them in the extension configuration. For more information, see [Default and Custom Antimalware Configuration](antimalware.md#default-and-custom-antimalware-configuration). ```powershell # Script to add Microsoft Antimalware extension to Azure Resource Manager VMs # Specify your subscription ID $subscriptionId= " SUBSCRIPTION ID HERE " # Specify location, resource group, and VM for the extension $location = " LOCATION HERE " # For example, "Southeast Asia" or "Central US" $resourceGroupName = " RESOURCE GROUP NAME HERE " $vmName = " VM NAME HERE " # Enable Antimalware with default policies $settingString = '{"AntimalwareEnabled": true}' # Enable Antimalware with custom policies # $settingString = '{ # "AntimalwareEnabled": true, # "RealtimeProtectionEnabled": true, # "ScheduledScanSettings": { # "isEnabled": true, # "day": 0, # "time": 120, # "scanType": "Quick" # }, # "Exclusions": { # "Extensions": ".ext1,.ext2", # "Paths":"", # "Processes":"sampl1e1.exe, sample2.exe" # }, # "SignatureUpdates": { # "FileSharesSources": "", # "FallbackOrder": "", # "ScheduleDay": 0, # "UpdateInterval": 0, # }, # "CloudProtection": true # # }' # Sign in to Azure and select the subscription to use Connect-AzAccount Set-AzContext -SubscriptionId $subscriptionId # Retrieve the most recent version number of the extension $allVersions = (Get-AzVMExtensionImage -Location $location -PublisherName "Microsoft.Azure.Security" -Type "IaaSAntimalware").Version $versionString = $allVersions[($allVersions.Count)-1].Split(".")[0] + "." + $allVersions[($allVersions.Count)-1].Split(".")[1] # Set the extension by using prepared values Set-AzVMExtension -ResourceGroupName $resourceGroupName -Location $location -VMName $vmName -Name "IaaSAntimalware" -Publisher "Microsoft.Azure.Security" -ExtensionType "IaaSAntimalware" -TypeHandlerVersion $versionString -SettingString $settingString ``` ## Add Microsoft Antimalware to Azure Service Fabric clusters Azure Service Fabric uses Azure virtual machine scale sets to create Service Fabric clusters. The virtual machine scale sets template that creates Service Fabric clusters isn't enabled with the Antimalware extension. Enable Antimalware separately on the scale sets. When you enable it on scale sets, all nodes created under the virtual machine scale sets inherit and get the extension automatically. The following code sample shows how to enable the IaaS Antimalware extension by using the Az.Compute PowerShell cmdlets. > [!NOTE] > Before you run this code sample, uncomment the variables and provide appropriate values. > [!WARNING] > Deploying or updating this extension replaces existing Microsoft Defender Antivirus settings, including exclusions. To preserve your settings, specify them in the extension configuration. For more information, see [Default and Custom Antimalware Configuration](antimalware.md#default-and-custom-antimalware-configuration). ```powershell # Script to add Microsoft Antimalware extension to a virtual machine scale set (VMSS) and Service Fabric cluster # Sign in to Azure and select the subscription to use Connect-AzAccount # Specify your subscription ID $subscriptionId="SUBSCRIPTION ID HERE" Set-AzContext -SubscriptionId $subscriptionId # Specify location, resource group, and VMSS for the extension $location = "LOCATION HERE" # For example, "West US", "Southeast Asia", or "Central US" $resourceGroupName = "RESOURCE GROUP NAME HERE" $vmScaleSetName = "YOUR VM SCALE SET NAME" # Customize the configuration.json configuration file according to the documentation: https://msdn.microsoft.com/library/dn771716.aspx $settingString = '{"AntimalwareEnabled": true}' # Enable Antimalware with custom policies # $settingString = '{ # "AntimalwareEnabled": true, # "RealtimeProtectionEnabled": true, # "ScheduledScanSettings": { # "isEnabled": true, # "day": 0, # "time": 120, # "scanType": "Quick" # }, # "Exclusions": { # "Extensions": ".ext1,.ext2", # "Paths":"", # "Processes":"sampl1e1.exe, sample2.exe" # } , # "SignatureUpdates": { # "FileSharesSources": "", # "FallbackOrder": "", # "ScheduleDay": 0, # "UpdateInterval": 0, # }, # "CloudProtection": true # }' # Retrieve the most recent version number of the extension $allVersions = (Get-AzVMExtensionImage -Location $location -PublisherName "Microsoft.Azure.Security" -Type "IaaSAntimalware").Version $versionString = $allVersions[($allVersions.Count)-1].Split(".")[0] + "." + $allVersions[($allVersions.Count)-1].Split(".")[1] $vmss = Get-AzVmss -ResourceGroupName $resourceGroupName -VMScaleSetName $vmScaleSetName Add-AzVmssExtension -VirtualMachineScaleSet $vmss -Name "IaaSAntimalware" -Publisher "Microsoft.Azure.Security" -Type "IaaSAntimalware" -TypeHandlerVersion $versionString -Setting $settingString Update-AzVmss -ResourceGroupName $resourceGroupName -VMScaleSetName $vmScaleSetName -VirtualMachineScaleSet $vmss ``` ## Add Microsoft Antimalware to Azure Cloud Services by using extended support The following code sample shows how to add or configure Microsoft Antimalware to Azure Cloud Services by using extended support through PowerShell cmdlets. > [!NOTE] > Before you run this code sample, uncomment the variables and provide appropriate values. > [!WARNING] > Deploying or updating this extension replaces existing Microsoft Defender Antivirus settings, including exclusions. To preserve your settings, specify them in the extension configuration. For more information, see [Default and Custom Antimalware Configuration](antimalware.md#default-and-custom-antimalware-configuration). ```powershell # Create an Antimalware extension object, where file is AntimalwareSettings $xmlconfig = [IO.File]::ReadAllText("C:\path\to\file.xml") $extension = New-AzCloudServiceExtensionObject -Name "AntimalwareExtension" -Type "PaaSAntimalware" -Publisher "Microsoft.Azure.Security" -Setting $xmlconfig -TypeHandlerVersion "1.5" -AutoUpgradeMinorVersion $true # Get existing Cloud Service $cloudService = Get-AzCloudService -ResourceGroup "ContosOrg" -CloudServiceName "ContosoCS" # Add Antimalware extension to existing Cloud Service extension object $cloudService.ExtensionProfile.Extension = $cloudService.ExtensionProfile.Extension + $extension # Update Cloud Service $cloudService | Update-AzCloudService ``` Here's an example of the private configuration XML file: ```xml <?xml version="1.0" encoding="utf-8"?> <AntimalwareConfig xmlns:i="http://www.w3.org/2001/XMLSchema-instance"> <AntimalwareEnabled>true</AntimalwareEnabled> <RealtimeProtectionEnabled>true</RealtimeProtectionEnabled> <ScheduledScanSettings isEnabled="true" day="1" time="120" scanType="Full" /> <Exclusions> <Extensions> <Extension>.ext1</Extension> <Extension>.ext2</Extension> </Extensions> <Paths> <Path>c:\excluded-path-1</Path> <Path>c:\excluded-path-2</Path> </Paths> <Processes> <Process>excludedproc1.exe</Process> <Process>excludedproc2.exe</Process> </Processes> </Exclusions> </AntimalwareConfig> ``` ## Add Microsoft Antimalware for Azure Arc-enabled servers The following code sample shows how to add Microsoft Antimalware for Azure Arc-enabled servers through PowerShell cmdlets. > [!NOTE] > Before you run this code sample, uncomment the variables and provide appropriate values. ```powershell # Before you use Azure PowerShell to manage VM extensions on your hybrid server managed by Azure Arc-enabled servers, install the Az.ConnectedMachine module. Run the following command on your Azure Arc-enabled server: # If Az.ConnectedMachine is installed, ensure the version is at least 0.4.0 Install-Module -Name Az.ConnectedMachine Import-Module -Name Az.ConnectedMachine # Specify location, resource group, and machine for the extension $subscriptionid =" SUBSCRIPTION ID HERE " $location = " LOCATION HERE " # For example, "Southeast Asia" or "Central US" $resourceGroupName = " RESOURCE GROUP NAME HERE " $machineName = "MACHINE NAME HERE " # Enable Antimalware with default policies $setting = @{"AntimalwareEnabled"=$true} # Enable Antimalware with custom policies $setting2 = @{ "AntimalwareEnabled"=$true; "RealtimeProtectionEnabled"=$true; "ScheduledScanSettings"= @{ "isEnabled"=$true; "day"=0; "time"=120; "scanType"="Quick" }; "Exclusions"= @{ "Extensions"=".ext1, .ext2"; "Paths"=""; "Processes"="sampl1e1.exe, sample2.exe" }; "SignatureUpdates"= @{ "FileSharesSources"=""; "FallbackOrder"=""; "ScheduleDay"=0; "UpdateInterval"=0; }; "CloudProtection"=$true } # Sign in to Azure Connect-AzAccount # Enable Antimalware with the policies New-AzConnectedMachineExtension -Name "IaaSAntimalware" -ResourceGroupName $resourceGroupName -MachineName $machineName -Location $location -SubscriptionId $subscriptionid -Publisher "Microsoft.Azure.Security" -Settings $setting -ExtensionType "IaaSAntimalware" ``` ## Next steps - [Microsoft Antimalware for Azure Cloud Services and Virtual Machines](antimalware.md) - [Microsoft Defender for Cloud](/azure/defender-for-cloud/)
Success! Branch created successfully. Create Pull Request on GitHub
Error: