﻿---
title: Configure endpoint protection with Elastic Defend
description: Install and configure Elastic Defend to protect endpoints against malware, ransomware, and behavioral threats.
url: https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/configure-elastic-defend
products:
  - Elastic Cloud Serverless
  - Elastic Documentation
  - Elastic Security
applies_to:
  - Serverless Security projects: Generally available
  - Elastic Stack: Generally available
---

# Configure endpoint protection with Elastic Defend
Elastic Defend is Elastic's endpoint protection integration. It prevents and detects malware, ransomware, memory threats, and malicious behavior on Windows, macOS, and Linux hosts. When a threat is detected, Elastic Defend can generate an alert or block the activity outright, depending on your protection settings.
Elastic Defend runs as part of [Elastic Agent](https://www.elastic.co/elastic/docs-builder/docs/4384/reference/fleet), which you deploy to each host you want to protect. Once installed, Elastic Agent communicates with Fleet for centralized policy management and sends security data to Elastic Security, where you can investigate alerts, manage exceptions, and respond to threats.

## How Elastic Defend, Elastic Agent, and Elastic Endpoint work together

Elastic Defend relies on three components that each play a distinct role in endpoint protection:
- **Elastic Defend** is the integration that defines your protection policy — which threat protections are active, which events to collect, and which exceptions to apply. You add it to an Elastic Agent policy and configure it through the Elastic Security UI or API.
- **Elastic Agent** is the unified agent you install on each host. It manages integrations (including Elastic Defend), handles enrollment and communication with Fleet, and ships collected data to Elasticsearch.
- **Elastic Endpoint** is the component that Elastic Agent installs on the host when the Elastic Defend integration is added. It performs the actual threat monitoring, prevention, and response actions at the operating system level.

In practice, you add the Elastic Defend integration from the **Integrations** page, assign it to an Elastic Agent policy, and deploy Elastic Agent to your hosts. Elastic Agent installs Elastic Endpoint, which immediately begins monitoring the host according to your policy settings.

## Data that Elastic Defend collects

Elastic Defend collects events from each host it protects, such as process, network, and file activity. The preset you select when you install it sets which event categories it collects, and you can change them later in the integration policy. For the categories available on each operating system, refer to [Event collection](/elastic/docs-builder/docs/4384/solutions/security/configure-elastic-defend/configure-an-integration-policy-for-elastic-defend#event-collection).
To bring in data from other sources, refer to [Ingest data to Elastic Security](https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/get-started/ingest-data-to-elastic-security).

## Where to start


| Your goal                                                                                                                                                                                                                     | Start here                                                                                                                                                                                                                                                                                         |
|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Deploy Elastic Defend for the first time                                                                                                                                                                                      | [Requirements](https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/configure-elastic-defend/elastic-defend-requirements) → [Install Elastic Defend](https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/configure-elastic-defend/install-elastic-defend) |
| Deploy to macOS hosts without user prompts                                                                                                                                                                                    | [Deploy on macOS with MDM](https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/configure-elastic-defend/deploy-on-macos-with-mdm)                                                                                                                                             |
| Set up endpoints in restricted networks                                                                                                                                                                                       | [Configure offline endpoints and air-gapped environments](https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/configure-elastic-defend/configure-offline-endpoints-air-gapped-environments)                                                                                   |
| <applies-to>Elastic Stack: Generally available since 9.5</applies-to> <applies-to>Elastic Cloud Serverless: Unavailable</applies-to> Store endpoint data in a different cluster from the one that manages your Elastic Agents | [Use Elastic Defend with a remote Elasticsearch output](https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/configure-elastic-defend/use-elastic-defend-with-remote-output-and-ccs)                                                                                           |
| Tune protection, manage privileges, or remove agents after deployment                                                                                                                                                         | [Manage Elastic Defend](https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/manage-elastic-defend)                                                                                                                                                                            |


## Next steps

After installing and configuring Elastic Defend, you can:
- [Manage endpoints, policies, and exceptions](https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/manage-elastic-defend) to tune protection for your environment.
- Read [Optimize Elastic Defend](https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/manage-elastic-defend/optimize-elastic-defend) to understand different Elastic Endpoint configuration settings.
- [Set up endpoint response actions](https://www.elastic.co/elastic/docs-builder/docs/4384/solutions/security/endpoint-response-actions) to isolate hosts, run commands, or take other actions on protected endpoints.
- [Troubleshoot Elastic Defend](https://www.elastic.co/elastic/docs-builder/docs/4384/troubleshoot/security/elastic-defend) if you run into installation, connectivity, or policy issues.