- Newest
- Most votes
- Most comments
While for anti-virus software or programs such as Windows defender can be used on AppStream 2.0. However, it can impact the performance of your fleet instances during user sessions even if automatic updates are not enabled [1] as it may perform hard drive scans or other operations that may impact the performance of your fleet instances during user sessions. [2]
While Microsoft releases its security updates for defender service and other components at monthly/quarterly basis. That means, you only need to update the defender service on the image builder when a new update is released by Microsoft. Then create a image and update your fleet with the latest image. So, you do not need to update your image hourly or daily basis. You are only required to update the image once Microsoft releases a latest update.
You can read more about this on the Microsoft article: Microsoft Endpoint Security and Configuring Microsoft Defender Antivirus for non-persistent VDI machines [3].
I found out this documentation page as well describing how it can be enabled. [4]
Additionally, I would love to investigate the issue further, as we require details that are non-public information. Please reach out to us by a support case.
References:
[1] Image Assistant CLI operations: https://docs.aws.amazon.com/appstream2/latest/developerguide/programmatically-create-image.html
[2] Scanning exclusions: https://docs.aws.amazon.com/whitepapers/latest/best-practices-for-deploying-amazon-appstream-2/security-1.html
[3] Configuring Microsoft Defender Antivirus for non-persistent VDI machines: https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/configuring-microsoft-defender-antivirus-for-non-persistent-vdi/ba-p/1489633
[4] Windows Update and Antivirus Software on AppStream 2.0: https://docs.aws.amazon.com/appstream2/latest/developerguide/administer-images.html#windows-update-antivirus-software
Relevant content
- asked 5 years ago
- asked 7 months ago
- AWS OFFICIALUpdated 7 months ago
- How do I turn on the EC2 serial console, SAC, and boot menu to troubleshoot my Windows EC2 instance?AWS OFFICIALUpdated 22 days ago
- AWS OFFICIALUpdated 2 years ago
- AWS OFFICIALUpdated 2 years ago