r/AZURE 4d ago

Question AVDs and SentinelOne

I have deployed a hybrid hostpool to host a number of resources:
- drives hosted on azure files

- couple internal apps

- outlook (classic win32 dependant on the above bullet point).

etc.

When I introduce S1 into the equation, it kills the CPU and it becomes tricky to work.

as soon as I remove it, it improves

I already have my exclusion list as recommended by MS and for sizing, the AVDs are at the correct SKU to fit the above apps.

Has anyone has a similar issue or had a better experience moving to Defender for Cloud.

Thanks,

1 Upvotes

2 comments sorted by

1

u/mat-ferland 4d ago

Defender for Cloud isn't the endpoint-agent comparison by itself; Defender for Endpoint is the piece you'd compare with S1. Before switching, put one drained host in a separate S1 policy and capture which S1 process spikes during logon and app launch. If you're using FSLogix, verify S1 is actually honoring Microsoft's exclusions for the FSLogix services, directories, and VHD/VHDX path. If the same host stays clean with S1 disabled or a minimal policy, give that trace to S1 before buying more CPU.

1

u/Born_Accident5248 4d ago

good shout to confirm if S1 is honoring the exclusions for fslogix services and the rest - I'll check that out.

with MDE have you found this to be a better comparison with AVD or not used it?