Insights /Server security and infrastructure governance

Should domain controllers, SQL Server and Hyper-V hosts run antivirus, and what should be excluded?

Servers should use supported antimalware controls, but exclusions must follow role and vendor guidance, with minimum scope, current documentation and performance validation.

Quick answer

Servers should use supported antimalware controls, but exclusions must follow role and vendor guidance, with minimum scope, current documentation and performance validation. For this case, first verify supportability of server roles and vendor-recommended exclusions, then use database and virtualization I/O paths to decide whether remediation is needed.

Define the failure boundary first

For this server and database case, establish the failure boundary with supportability of server roles and vendor-recommended exclusions, then continue to database and virtualization I/O paths. Capture the current state, incident time and one known-good comparison before changing production configuration.

Work through the dependency chain

CheckWhy it mattersRecommended action
01 · supportability of server rolesVerify supportability of server roles on the affected path using logs, counters or state information rather than relying only on the configured rule.Record the current value, evidence source and timestamp for supportability of server roles. If adjustment is required, change one condition only and retain the original setting for rollback.
02 · vendor-recommended exclusionsVerify vendor-recommended exclusions on the affected path using logs, counters or state information rather than relying only on the configured rule.Check vendor-recommended exclusions read-only and save the result. If it differs from the baseline, correlate it with the incident time and recent changes before remediation.
03 · database and virtualization I/O pathsVerify database and virtualization I/O paths on the affected path using logs, counters or state information rather than relying only on the configured rule.Compare database and virtualization I/O paths with a known-good peer, the log timeline and the real application path; confirm whether it is causal before changing production.
04 · real-time scanning performanceReview the current state, related logs and recent changes for real-time scanning performance, then align them with the incident timeline before deciding whether a change is required.Record the current value, evidence source and timestamp for real-time scanning performance. If adjustment is required, change one condition only and retain the original setting for rollback.
05 · antivirus definition update pathReview the current state, related logs and recent changes for antivirus definition update path, then align them with the incident timeline before deciding whether a change is required.Check antivirus definition update path read-only and save the result. If it differs from the baseline, correlate it with the incident time and recent changes before remediation.
06 · minimal exclusions with periodic reviewReview the current state, related logs and recent changes for minimal exclusions with periodic review, then align them with the incident timeline before deciding whether a change is required.Compare minimal exclusions with periodic review with a known-good peer, the log timeline and the real application path; confirm whether it is causal before changing production.

Change only after the evidence is clear

  1. Start with read-only evidence. Check supportability of server roles and vendor-recommended exclusions before changing configuration.
  2. If the first checks are normal, continue with database and virtualization I/O paths and real-time scanning performance, keeping evidence tied to the incident time.
  3. Change configuration only when the evidence explains the symptom. For antivirus definition update path, preserve the original value and define the rollback trigger before adjustment.
  4. Validate minimal exclusions with periodic review in a controlled scope before expanding to production users or traffic.

Validation and rollback

  • Validate the complete user or application workflow; do not stop at the single status of supportability of server roles.
  • Recheck antivirus definition update path and minimal exclusions with periodic review after the change and confirm that no new bypass, permission expansion or secondary error has appeared.
  • Archive evidence from supportability of server roles through minimal exclusions with periodic review, together with before/after configuration, business validation and the rollback point.

Common wrong turns

  • Changing supportability of server roles and vendor-recommended exclusions at the same time, which makes the original cause impossible to prove.
  • Treating a normal result for database and virtualization I/O paths as proof that real-time scanning performance and the rest of the business path are healthy.
  • Leaving a temporary exception related to antivirus definition update path or minimal exclusions with periodic review in production without an owner, expiry time and rollback note.

Related questions

Where should I start with “Should domain controllers, SQL Server and Hyper-V hosts run antivirus, and what should be excluded?”?

Start with supportability of server roles and vendor-recommended exclusions; they establish the first useful troubleshooting boundary without changing production state.

What should be checked after the first layer looks normal?

Continue with database and virtualization I/O paths and real-time scanning performance, then correlate the result with the incident time and the actual user or application path.

What should be retained after the change?

Keep evidence for antivirus definition update path and minimal exclusions with periodic review, plus the original configuration, validation result, observation notes and rollback point.

PreviousUsing a UPS to shut down Windows Server, virtualisation hosts and NAS in the correct orderNextgpupdate /force succeeds but policy still does not apply: what evidence should be checked?

Need an assessment based on the actual environment?