Prerequisites
Deployment of Kaspersky Managed Detection and Response by using Kaspersky Security Center proceeds in stages:
Activate the Kaspersky Managed Detection and Response solution with your license.
Ensure that you have installed the EPP applications that support Kaspersky Managed Detection and Response functionality on your assets.
Download the MDR configuration file for your organization or download separate archives for every tenant from the Tenants section of MDR Web Console.
Starting from Kaspersky Endpoint Security for Windows 12.6, if you have only root tenant and if you are not using the MDR solution together with Kaspersky Endpoint Detection and Response Optimum you do not need to download MDR configuration file. Please refer to the instruction provided for Kaspersky Endpoint Security for Windows at stage 5.
Set up KPSN on your assets by using your KSN configuration file from the MDR configuration file.
This step ensures that telemetry is sent to dedicated servers that comply are compliant with GDPR. If you do not set up Private KSN, your telemetry is not transmitted, and the Kaspersky Managed Detection and Response service is not provided.
Perform the application-specific deployment scenarios for all the Kaspersky applications installed on your assets:
Deployment depends on the version of Kaspersky Endpoint Security for Windows that is installed on your assets. If you have more than one version of Kaspersky Endpoint Security for Windows installed in your infrastructure, you can perform the scenarios for these versions in any order:
If you have only root tenant, you can skip downloading the MDR configuration file and add and deploy your license key directly in Kaspersky Security Center.
To deploy Kaspersky Managed Detection and Response on Kaspersky Endpoint Security for Windows 12.6 and later:
For details about simultaneous use of MDR and EDR Optimum solutions refer to Kaspersky Endpoint Security for Windows help.
Kaspersky Endpoint Security for Windows 11.6–12.5 and later with several tenants
If you are switching to the built-in MDR functionality in Kaspersky Endpoint Security for Windows after working with it by using the Kaspersky Endpoint Agent functionality, make sure to disable Kaspersky Managed Detection and Response in the Kaspersky Endpoint Agent policy after configuring the integration with Kaspersky Managed Detection and Response in the Kaspersky Endpoint Security for Windows policy for all assets with Kaspersky Endpoint Security for Windows 11.6 and later.
Note that if the same policy is also applied to assets with Kaspersky Endpoint Security for Windows 11.5 and earlier, it is necessary to create and configure a separate policy for these assets first, to maintain their integration with Kaspersky Managed Detection and Response via the Kaspersky Endpoint Agent policy.
Kaspersky Endpoint Security for Windows 11.0–11.5
Make sure that the task is performed on all of your assets.
The following components must be enabled:
In the Kaspersky Security Network settings, select the Enable Extended KSN mode check box.
Enabling these components is mandatory. Otherwise, Kaspersky Managed Detection and Response is not operable, as sending telemetry is not possible.
Additionally, Kaspersky Managed Detection and Response can use data from the following components:
Enabling these components is optional. If they are disabled, Kaspersky Managed Detection and Response continues sending telemetry, but with limited data.
Once the rule is created, move it to the top of the rules list.
Kaspersky Endpoint Agent can be installed:
Kaspersky Endpoint Agent 3.10 or later is required for Kaspersky Endpoint Security for Windows 11.5.
The following components must be enabled:
In the Kaspersky Security Network settings, select the Enable Extended KSN mode check box.
Enabling these components is mandatory. Otherwise, Kaspersky Managed Detection and Response is not operable, as sending telemetry is not possible.
Additionally, Kaspersky Managed Detection and Response can use data from the following components:
Enabling these components is optional. If they are disabled, Kaspersky Managed Detection and Response continues sending telemetry, but with limited data.
Once the rule is created, move it to the top of the rules list.
Deployment depends on the version of Kaspersky Security for Windows Server that is installed on your assets. If you have more than one version of Kaspersky Security for Windows Server installed in your infrastructure, you can perform the scenarios for these versions in any order:
Kaspersky Security for Windows Server 11 and later
Kaspersky Endpoint Agent for Windows can be installed:
Starting the KSN Usage task enables using Kaspersky Security Network in Kaspersky Security for Windows Server.
In the Data processing window of the KSN Usage task, select all of the check boxes on all tabs.
In the Settings window of the KSN Usage task, on the Task management tab, select the Run by schedule check box. In the Frequency drop-down list, select the At application launch value.
In the KSN Usage subsection, ensure that a closed lock is displayed. The closed lock means the policy sets the specified settings for the assets.
Starting the Traffic Security task enables the processing of web traffic (including traffic received via email), as well as intercepting and scanning objects transferred through web traffic, in order to detect known computer and other threats on the protected device.
In the Settings window of the Traffic Security task, on the General tab, select the Driver interceptor value from the Task mode drop-down list.
In the Settings window of the Traffic Security task, on the Task management tab, select the Run by schedule check box. In the Frequency drop-down list, select the At application launch value.
In the Traffic Security subsection, ensure that a closed lock is displayed. The closed lock means the policy sets the specified settings for the assets.
Starting the Applications Launch Control task enables the monitoring of users' attempts to start applications, and allows or denies the start of these applications.
In the Settings window of the Applications Launch Control task, on the General tab, select the Monitor loading of DLL modules and Allow applications trusted by KSN check boxes.
In the Settings window of the Applications Launch Control task, on the Task management tab, select the Run by schedule check box. In the Frequency drop-down list, select the At application launch value.
In the Applications Launch Control subsection, ensure that a closed lock is displayed. The closed lock means the policy sets the specified settings for the assets.
Kaspersky Security for Windows Server 10.1.*
Starting the KSN Usage task enables using Kaspersky Security Network in Kaspersky Security for Windows Server.
In the Data processing window of the KSN Usage task, select all of the check boxes on all tabs.
In the Settings window of the KSN Usage task, on the Task management tab, select the Run by schedule check box. In the Frequency drop-down list, select the At application launch value.
In the KSN Usage subsection, ensure that a closed lock is displayed. The closed lock means the policy sets the specified settings for the assets.
Starting the Traffic Security task enables the processing of web traffic (including traffic received via email), as well as intercepting and scanning objects transferred through web traffic, in order to detect known computer and other threats on the protected device.
In the Settings window of the Traffic Security task, on the General tab, select the Driver interceptor value from the Task mode drop-down list.
In the Settings window of the Traffic Security task, on the Task management tab, select the Run by schedule check box. In the Frequency drop-down list, select the At application launch value.
In the Traffic Security subsection, ensure that a closed lock is displayed. The closed lock means the policy sets the specified settings for the assets.
Starting the Applications Launch Control task enables the monitoring of users' attempts to start applications, and allows or denies the start of these applications.
In the Settings window of the Applications Launch Control task, on the General tab, select the Monitor loading of DLL modules and Allow applications trusted by KSN check boxes.
In the Settings window of the Applications Launch Control task, on the Task management tab, select the Run by schedule check box. In the Frequency drop-down list, select the At application launch value.
In the Applications Launch Control subsection, ensure that a closed lock is displayed. The closed lock means the policy sets the specified settings for the assets.
Kaspersky Endpoint Agent can be installed:
Kaspersky Endpoint Agent 3.10 or later is required for Kaspersky Endpoint Security for Windows 11.5.
The following components must be enabled:
In the Kaspersky Security Network settings, select the Enable Extended KSN mode check box.
Enabling these components is mandatory. Otherwise, Kaspersky Managed Detection and Response is not operable, as sending telemetry is not possible.
Additionally, Kaspersky Managed Detection and Response can use data from the following components:
Enabling these components is optional. If they are disabled, Kaspersky Managed Detection and Response continues sending telemetry, but with limited data.
Once the rule is created, move it to the top of the rules list.
Kaspersky Endpoint Agent can be installed:
Kaspersky Endpoint Agent 3.10 or later is required for Kaspersky Endpoint Security for Windows 11.5.
The following components must be enabled:
In the Kaspersky Security Network settings, select the Enable Extended KSN mode check box.
Enabling these components is mandatory. Otherwise, Kaspersky Managed Detection and Response is not operable, as sending telemetry is not possible.
Additionally, Kaspersky Managed Detection and Response can use data from the following components:
Enabling these components is optional. If they are disabled, Kaspersky Managed Detection and Response continues sending telemetry, but with limited data.
Once the rule is created, move it to the top of the rules list.
Kaspersky Endpoint Agent can be installed:
Kaspersky Endpoint Agent 3.10 or later is required for Kaspersky Endpoint Security for Windows 11.5.
The following components must be enabled:
In the Kaspersky Security Network settings, select the Enable Extended KSN mode check box.
Enabling these components is mandatory. Otherwise, Kaspersky Managed Detection and Response is not operable, as sending telemetry is not possible.
Additionally, Kaspersky Managed Detection and Response can use data from the following components:
Enabling these components is optional. If they are disabled, Kaspersky Managed Detection and Response continues sending telemetry, but with limited data.
Once the rule is created, move it to the top of the rules list.
Kaspersky Managed Detection and Response allows you to analyze and monitor the data from Kaspersky Anti-Targeted Attack (KATA) Platform.
Integration with Kaspersky Anti-Targeted Attack Platform is not available when using a license key for the Saudi Arabia region.
To configure integration between Kaspersky Managed Detection and Response and Kaspersky Anti-Targeted Attack Platform, you need to receive an MDR configuration file, first. For details on how to configure the integration, refer to Kaspersky Anti-Targeted Attack Platform online help.
Kaspersky Anti-Targeted Attack Platform is not part of Kaspersky Managed Detection and Response. If you want to use Kaspersky Anti-Targeted Attack Platform, you must purchase it separately.
If you have more than one Kaspersky application installed in your infrastructure, you can perform the application-specific scenarios in any order.
You can check the status of your assets by using the MDR Health functionality.