Select to view content in your preferred language

Update ARCGIS ANTIVIRUS GUIDANCE document

563
5
Jump to solution
02-19-2026 04:38 AM
SimonReman2010
Occasional Contributor

Hello,

 

Would it be possible to update the ArcGIS Antivirus Guidance document to integrate a specific paragraph about Windows Exploit Protection, as ArcGIS Enterprise 11.3 and the new ArcGIS Pro licensing system introduce interference (crash) with Exploit Protection

See https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-portal-11-5-crashes-when-requiring-...

 

Thanks in avance,

 

Best regards,

 

Simon

1 Solution

Accepted Solutions
RandallWilliams
Esri Regular Contributor

Hi @SimonReman2010  - closing up on this item. 

We worked through this item and with the help various teams, including yourself, discovered that this crash was related to Windows Defender Endpoint Protection - specifically the "Import Address Filtering" functionality. 

We worked with Microsoft to understand, what, if anything, Esri could do to prevent this crash. Unfortunately, the issue is related to intrinsic flaws in Import Address Filtering. Even when we configured Import Address Filtering to only "Audit" events, our processes still crashed. That's a clear bug in Import Address Filtering - an event audit should not crash a process.

Microsoft acknowledges that "Import address filtering (IAF) has been deprecated due to all the reported compatibility issues so even when you have it in "Audit only", you will still see the crashes and compatibility issues." Microsoft no longer recommends enabling Import address filtering (IAF) due to compatibility issues. 

This deprecation is documented here:

See how Exploit protection works in a demo - Microsoft Defender for Endpoint | Microsoft Learn

At Esri, we've documented this issue here:

[#BUG-000183052 The Import Address Filtering "program setting" mitigation in Microsoft Windows Defender for Exploit causes the ArcGIS Enterprise portal's web server to intermittently crash when handling certain licensing requests.]

We've marked this bug as a known limit with the detail above as the reason. 

We'll also add a note in our anti-virus document about this limit. While Windows Exploit Prevention isn't really an "anti-virus" per se, our AV doc is a good place to include a discussion about the deprecation of Import address filtering (IAF) .

We will also provide a knowledge article describing the symptoms so that users can quickly understand root cause of this issue. 

Thank you and Esri Belux for helping us come to a root cause understanding of this problem. 

 

 

View solution in original post

5 Replies
RandallWilliams
Esri Regular Contributor

Hi Simon,

It would not be appropriate to update the AV guide for this issue. Instead, please open a case with Esri support and provide your repro case so that they can investigate as a product bug. Enabling Windows Defender Exploit Protection should not cause a crash. 

0 Kudos
SimonReman2010
Occasional Contributor

Hello @RandallWilliams 

 

Thank you for you answer.

I did create a case for this problem with Esri Belux. Esri Belux team was able to reproduce the crash of the portal with ArcGIS Enterprise 11.4, 11.5 and 12. They considered that it is a Windows issue and not an Esri one. They closed the case because they consider that Exploit Protection must not monitor javaw process.

You can find the description of this crash issue in my post here :

https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-portal-11-5-crashes-when-requiring-... 

 

Kind regards,

 

Simon

 

0 Kudos
RandallWilliams
Esri Regular Contributor

I disagree with Esri Belux's assessment. A software crash is a bug that they should log. This is a misinterpretation of the AV guidance document. That doc is not meant to explain away crashes. 

RandallWilliams
Esri Regular Contributor

Hi @SimonReman2010  - closing up on this item. 

We worked through this item and with the help various teams, including yourself, discovered that this crash was related to Windows Defender Endpoint Protection - specifically the "Import Address Filtering" functionality. 

We worked with Microsoft to understand, what, if anything, Esri could do to prevent this crash. Unfortunately, the issue is related to intrinsic flaws in Import Address Filtering. Even when we configured Import Address Filtering to only "Audit" events, our processes still crashed. That's a clear bug in Import Address Filtering - an event audit should not crash a process.

Microsoft acknowledges that "Import address filtering (IAF) has been deprecated due to all the reported compatibility issues so even when you have it in "Audit only", you will still see the crashes and compatibility issues." Microsoft no longer recommends enabling Import address filtering (IAF) due to compatibility issues. 

This deprecation is documented here:

See how Exploit protection works in a demo - Microsoft Defender for Endpoint | Microsoft Learn

At Esri, we've documented this issue here:

[#BUG-000183052 The Import Address Filtering "program setting" mitigation in Microsoft Windows Defender for Exploit causes the ArcGIS Enterprise portal's web server to intermittently crash when handling certain licensing requests.]

We've marked this bug as a known limit with the detail above as the reason. 

We'll also add a note in our anti-virus document about this limit. While Windows Exploit Prevention isn't really an "anti-virus" per se, our AV doc is a good place to include a discussion about the deprecation of Import address filtering (IAF) .

We will also provide a knowledge article describing the symptoms so that users can quickly understand root cause of this issue. 

Thank you and Esri Belux for helping us come to a root cause understanding of this problem. 

 

 

SimonReman2010
Occasional Contributor

Hello @RandallWilliams ,

 

Thank you for the deep investigation and for keeping me in the loop. It's great to have a clear root cause identified, and I appreciate the effort from you and the various teams involved. This complex case taught me a lot about ArcGIS Enterprise architecture.

I can now move forward with the upgrade to ArcGIS Enterprise 11.5.

Thanks again to you and the Esri team for the collaboration!

 

Best regards,


Simon

0 Kudos