diff --git a/docs/getting-started/configure-integration-policy.asciidoc b/docs/getting-started/configure-integration-policy.asciidoc index 9ef4e7796e..d0cb0a5bd9 100644 --- a/docs/getting-started/configure-integration-policy.asciidoc +++ b/docs/getting-started/configure-integration-policy.asciidoc @@ -212,7 +212,9 @@ register {elastic-sec} as your hosts' antivirus software by enabling **Register NOTE: Windows Server versions are not supported. Antivirus registration requires Windows Security Center, which is not included in Windows Server operating systems. -You can also choose **Sync with malware protection level** to automatically set antivirus registration based on how you've configured {elastic-defend}'s <>. If malware protection is turned on and set to **Prevent**, antivirus registration will also be enabled; in any other case, antivirus registration will be disabled. +By default, the **Sync with malware protection level** is selected to automatically set antivirus registration to match how you've configured {elastic-defend}'s <>. If malware protection is turned on _and_ set to **Prevent**, antivirus registration will also be enabled; in any other case, antivirus registration will be disabled. + +If you don't want to sync antivirus registration, you can set it manually with **Enabled** or **Disabled**. [role="screenshot"] image::images/register-as-antivirus.png[Detail of Register as antivirus option.] diff --git a/docs/getting-started/images/register-as-antivirus.png b/docs/getting-started/images/register-as-antivirus.png index 25a12eea74..61fb3d2fa6 100644 Binary files a/docs/getting-started/images/register-as-antivirus.png and b/docs/getting-started/images/register-as-antivirus.png differ diff --git a/docs/serverless/edr-install-config/configure-endpoint-integration-policy.mdx b/docs/serverless/edr-install-config/configure-endpoint-integration-policy.mdx index a59a02988f..bcab7e77be 100644 --- a/docs/serverless/edr-install-config/configure-endpoint-integration-policy.mdx +++ b/docs/serverless/edr-install-config/configure-endpoint-integration-policy.mdx @@ -249,7 +249,9 @@ register ((elastic-sec)) as your hosts' antivirus software by enabling **Registe Windows Server is not supported. Antivirus registration requires Windows Security Center, which is not included in Windows Server operating systems. -You can also choose **Sync with malware protection level** to automatically set antivirus registration based on how you've configured ((elastic-defend))'s malware protection. If malware protection is turned on and set to **Prevent**, antivirus registration will also be enabled; in any other case, antivirus registration will be disabled. +By default, the **Sync with malware protection level** is selected to automatically set antivirus registration to match how you've configured ((elastic-defend))'s malware protection. If malware protection is turned on _and_ set to **Prevent**, antivirus registration will also be enabled; in any other case, antivirus registration will be disabled. + +If you don't want to sync antivirus registration, you can set it manually with **Enabled** or **Disabled**. ![Detail of Register as antivirus option.](../images/configure-endpoint-integration-policy/-getting-started-register-as-antivirus.png) diff --git a/docs/serverless/images/configure-endpoint-integration-policy/-getting-started-register-as-antivirus.png b/docs/serverless/images/configure-endpoint-integration-policy/-getting-started-register-as-antivirus.png index 25a12eea74..61fb3d2fa6 100644 Binary files a/docs/serverless/images/configure-endpoint-integration-policy/-getting-started-register-as-antivirus.png and b/docs/serverless/images/configure-endpoint-integration-policy/-getting-started-register-as-antivirus.png differ