Microsoft Defender and WSL: Visibility Across Windows and Linux Boundaries
What enterprise endpoint protection can observe and enforce inside WSL, and why Linux package hygiene and least privilege still matter regardless.
Operating systems, infrastructure, emulation, and technical history.
What enterprise endpoint protection can observe and enforce inside WSL, and why Linux package hygiene and least privilege still matter regardless.
Why the WSL ext4 disk, NTFS DrvFs, and ReFS Dev Drive serve genuinely different build and Windows-tool workflows, not interchangeable options.
Why DNS resolution breaks behind VPNs in classic WSL networking, how tunneling changes the path, and which config assumptions stop applying.
How DrvFs mount metadata and per-directory case sensitivity interact with Windows ACLs, permissions, and tools on /mnt/c.
Controlling WSL versions, mounts, networking, and nested virtualization through Intune and the WSL ADMX template without blocking real developer work.
A field guide to global WSL 2 VM settings versus per-distribution boot, automount, networking, and interop configuration.
How Windows firewall policy reaches WSL traffic under mirrored networking, and why Linux iptables rules alone cannot describe the real host exposure.
When wsl --import-in-place is the right migration tool, how it differs from a tar import, and how to avoid registering your only copy of the disk.
A safe procedure for wsl --mount covering Windows disk ownership, filesystem support, read-only inspection, and clean detachment.
Separating VM startup, distribution boot, systemd, and fstab failures so you can repair a broken WSL distro without deleting its data.