Configure block at first sight in Microsoft Defender Antivirus
In brief
The article now explains how block at first sight works, lists its required conditions—cloud protection, automatic sample submission, and current Defender updates—and documents coverage for downloaded executable and nonportable files. It also adds Configuration Manager to the supported management tools and includes updated links and visuals.
What Defender admins need to know
Administrators can use the revised guidance to verify prerequisites, understand protection coverage, and configure the feature. The page also warns that disabling it lowers device and network protection.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Turn onConfigure block at first sight in Microsoft Defender Antivirus
This article describes an antivirus/antimalware feature known as "block at first sight", and describes how to enable block at first sight for your organization. Before you begin, review the Prerequisites section for required settings and supported operating systems.
Prerequisites
Windows
What is "block at first sight"?
Block at first sight is a threat protection feature of next-generation protection.next-generation protection. It detects new malware and blocks it within seconds. The feature is enabled when you turn on these settings:all of the following statements are true:
- Cloud protection (also called cloud-delivered protection in Windows Security) is turned on.
- Sample submission is set to send samples automatically.
- Microsoft Defender Antivirus is up to date on devices.
In most enterprise organizations, these settings are already configured with Microsoft Defender Antivirus deployments. For more information, see Turn on cloud protection in Microsoft Defender Antivirus.
How it works
When Microsoft Defender Antivirus finds a suspicious file it hasn't seen before, it sends a query to the cloud protection backend. The cloud backend checks the file using heuristics, machine learning, and automated analysis. It then decides if the file is malicious or safe.
Microsoft Defender Antivirus uses multiple detection and prevention methods to deliver accurate, real-time protection.
:::image type="content" source="media/microsoft-defender-atp-next-generation-protection-engines.png" alt-text=" Keep the following details in mind when using block at first sight:
Block at first sight can block executable files and nonportable executable files (such as JS, VBS, or macros) Block at first sight only uses the cloud protection backend for executable files and nonportable executable files that are downloaded from the Internet, or that originate from the Internet zone. A hash value of the If the cloud backend is unable to make a determination, Microsoft Defender Antivirus locks the file and uploads a copy to the cloud. The cloud performs more analysis to reach a determination. The cloud then either allows the file to run or blocks the file in all future encounters, depending on whether the cloud determines the file to be malicious or not a threat. In many cases, this cloud-based analysis and blocking process can reduce the response time for new malware from hours to seconds. You can specify how long a file should be prevented from running while the cloud-based protection service analyzes the file. [!INCLUDE intune-recommended-separate-product] To configure block at first sight in Microsoft Intune, use an endpoint security Antivirus policy. For detailed instructions, see Create endpoint security policies or Modify existing policies (links open new tabs in the Intune documentation). When you create the policy, use these specific settings: For more information about To turn off block at first sight, set Allow cloud protection to Not allowed. Turns off Cloud Protection. If your organization manages endpoint security policies in the Microsoft Defender portal, use a Microsoft Defender Antivirus policy to configure block at first sight. For detailed instructions, see Create an endpoint security policy or Edit an endpoint security policy (links open new tabs). When you create the policy on the Windows policies tab of the Endpoint security policies page in the Defender portal at https://security.microsoft.com/policy-inventory?osPlatform=Windows, use these specific settings: When you create or modify the policy, use these specific settings on the Configuration settings tab: To turn off block at first sight, set Allow cloud protection to Not allowed. Turns off Cloud Protection. For instructions to create and deploy an antimalware policy, see Endpoint Protection antimalware policies in Configuration Manager. Configuration Manager doesn't include a separate setting named Block at First Sight. Configure the cloud protection and sample submission settings that the feature requires. To turn on block at first sight, configure the following settings in the antimalware policy: To turn off block at first sight, set Cloud Protection Service membership to Do not join Cloud Protection Service. In Centralized Group Policy, open the Group Policy Management Console (GPMC) In Centralized Group Policy, open the Group Policy Management Console (GPMC) on your Group Policy management computer.
In the Group Policy Management Editor, go to Computer configuration > Administrative templates > Windows components > Microsoft Defender Antivirus > MAPS.
In the details pane of MAPS, the settings used to configure block at first sight are: To open and configure a setting, use any of the following methods:
To turn on block at first sight in the Group Policy MAPS settings, follow these steps:
To turn off block at first sight in the Group Policy MAPS settings, follow these steps:
Run the commands in an elevated PowerShell session (a PowerShell window you opened by selecting Run as administrator).
The following command turns on cloud protection, automatic safe sample submission, and block at first sight:
To submit all samples automatically instead of only safe samples, use The following command displays the current block at first sight settings:
To verify block at first sight is turned on, confirm the following values:
The following command turns off block at first sight without changing the cloud protection and sample submission settings:
For detailed syntax and parameter information, see Set-MpPreference Use the following steps to turn off block at first sight with Group Policy:
In Centralized Group Policy, open the Group Policy Management Console (GPMC) on your Group Policy management computer. On an unmanaged device, you To configure block at first sight, follow these steps:
The listDiagram of Microsoft Defender Antivirus enginesprotection engines." lightbox="media/microsoft-defender-atp-next-generation-protection-engines.png":::
A few things to know about block at first sight
and executable files, running the latest Defender antimalware platform on Windows or Windows Server.Server devices that run the latest Defender antimalware platform..exe file is checked via the cloud backend to determine if the file is a previously undetected file.And, youYou can customize the message displayed on users' desktopsalso customize the message displayed on users' desktops when a file is blocked. You can change the company name, contact information, and message URL.Prerequisites
Configure block at first sight using Microsoft Intune
Turn on block at first sight with Microsoft Intune
To enable block at first sight using a Microsoft Intune Endpoint Security Antivirus policy, see Create an endpoint security policy (opens in a new tab in the Intune documentation). When creatingyou create or modify the policy, use these settings:Policy type: AntivirusPlatform: WindowsProfile: Microsoft Defender Antivirus: Configure the following settings: tab:
antivirus profiles in Microsoft Intune,the available settings, see Antivirus policy for endpoint security in Intune.
Turn off block at first sight with Microsoft Intune
Configure block at first sight in the Microsoft Defender portal
Turn on block at first sight with the Microsoft Defender portal
Turn off block at first sight with the Microsoft Defender portal
Configure block at first sight in Microsoft Configuration Manager
Turn on block at first sight with Microsoft Configuration Manager
Turn off block at first sight with Microsoft Configuration Manager
Configure block at first sight using Group Policy
following settings. 'Block at First Sight' feature
Turn on block at first sight with Group Policy
Turn off block at first sight with Group Policy
Configure block at first sight using PowerShell
Turn on block at first sight with PowerShell
Set-MpPreference -MAPSReporting Advanced -SubmitSamplesConsent SendSafeSamples -DisableBlockAtFirstSeen $false
SendAllSamples for the SubmitSamplesConsent value.
Verify the configuration
Get-MpPreference | Select-Object MAPSReporting, SubmitSamplesConsent, DisableBlockAtFirstSeen
2 (Advanced)1 (Send safe samples automatically) or 3 (Send all samples automatically)FalseTurn off block at first sight with PowerShell
Set-MpPreference -DisableBlockAtFirstSeen $true
(opens in a new tab in the Intune documentation)and Get-MpPreference. Choose the following options:
Policy: Antivirus, then select your Microsoft Defender Antivirus policyAllow cloud protection: Not allowed. Turns off Cloud ProtectionTurn offConfigure block at first sight
with Group Policy
In the GPMC console tree, expand Group Policy Objects in the forest and domain containing the GPOWindows Security appwant to edit.Right-click the GPO, and then select Edit.In the Group Policy Management Editor, go to Computer configuration > Administrative templates > Windows components > Microsoft Defender Antivirus > MAPS.In the details pane of MAPS, open the Configure the 'Block at First Sight' feature setting.In the setting window that opens, select Disabled, and then select OK.Not an enterprise admin or IT Pro?If you aren't an enterprise admin or an IT Pro, but you have questions about block at first sight, the following guidance for personal device users can help. Block at first sight is a threat protection feature that detects and blocks malware within seconds. Although there isn't a specific setting called "Block at first sight," the feature is enabled when certain settings are configured on your device.How to manageconfigure block at first sight on or off on your own deviceIf youin the Windows Security app. Although the app doesn't have a personal device that isn't managed by an organization, you might be wondering how to turn blocksetting named Block at first sight, the feature turns on or off. You can use the Windows Security app to manage block at first sight.On your Windows 10 or Windows 11 computer, open the Windows Security app.Select Virus & threat protection.Under Virus & threatwhen you enable cloud-delivered protection settings, select Manage settings.Take one of the following steps:To enable block at first sight, make sure that both Cloud-delivered protectionand Automaticautomatic sample submission are both turned on.submission.To disable block at first sight:
See also
@@ -1,36 +1,60 @@ ----title: Enable block at first sight to detect malware in seconds-description: Turn on the block at first sight feature to detect and block malware within seconds.+title: Configure block at first sight in Microsoft Defender Antivirus+description: Configure block at first sight in Microsoft Defender Antivirus by using supported management tools, including Microsoft Configuration Manager. ms.service: defender-endpoint ms.localizationpriority: high author: chrisda ms.author: chrisda ms.reviewer: marcmcc ms.custom:- - msecd-doc-authoring-1016+ - msecd-doc-authoring-1015 - nextgen - sfi-image-nochange-ms.date: 07/02/2026+ms.date: 09/02/2026 ms.subservice: ngp ms.topic: how-to-ms.collection: +ms.collection: - m365-security - tier2 - mde-ngp appliesto: - Microsoft Defender for Endpoint Plan 1 - Microsoft Defender for Endpoint Plan 2- ai-usage: ai-assisted+#customer intent: As a security administrator, I want to configure block at first sight so that Microsoft Defender Antivirus can block new malware within seconds. ----# Turn on block at first sight +# Configure block at first sight in Microsoft Defender Antivirus++<a name="what-is-block-at-first-sight"></a> -This article describes an antivirus/antimalware feature known as "block at first sight", and describes how to enable block at first sight for your organization. Before you begin, review the [Prerequisites](#prerequisites) section for required settings and supported operating systems.+Block at first sight is a threat protection feature of [next-generation protection](next-generation-protection.md). It detects new malware and blocks it within seconds. The feature is enabled when all of the following statements are true:++- [Cloud protection](cloud-protection-microsoft-defender-antivirus.md) (also called _cloud-delivered protection_ in Windows Security) is turned on.+- [Sample submission](cloud-protection-microsoft-antivirus-sample-submission.md) is set to send samples automatically.+- Microsoft Defender Antivirus [is up to date](microsoft-defender-antivirus-updates.md) on devices.++In most enterprise organizations, these settings are already configured with Microsoft Defender Antivirus deployments. For more information, see [Turn on cloud protection in Microsoft Defender Antivirus](enable-cloud-protection-microsoft-defender-antivirus.md).++When Microsoft Defender Antivirus finds a suspicious file it hasn't seen before, it sends a query to the cloud protection backend. The cloud backend checks the file using heuristics, machine learning, and automated analysis. It then decides if the file is malicious or safe. Microsoft Defender Antivirus uses multiple detection and prevention methods to deliver accurate, real-time protection.++:::image type="content" source="media/microsoft-defender-atp-next-generation-protection-engines.png" alt-text="Diagram of Microsoft Defender Antivirus protection engines." lightbox="media/microsoft-defender-atp-next-generation-protection-engines.png":::++Keep the following details in mind when using block at first sight:++- Block at first sight can block executable files and nonportable executable files (such as JS, VBS, or macros) on Windows or Windows Server devices that run the [latest Defender antimalware platform](microsoft-defender-antivirus-updates.md).+- Block at first sight only uses the cloud protection backend for executable files and nonportable executable files that are downloaded from the Internet, or that originate from the Internet zone. A hash value of the `.exe` file is checked via the cloud backend to determine if the file is a previously undetected file.+- If the cloud backend is unable to make a determination, Microsoft Defender Antivirus locks the file and uploads a copy to the cloud. The cloud performs more analysis to reach a determination. The cloud then either allows the file to run or blocks the file in all future encounters, depending on whether the cloud determines the file to be malicious or not a threat.+- In many cases, this cloud-based analysis and blocking process can reduce the response time for new malware from hours to seconds.+- You can [specify how long a file should be prevented from running](configure-cloud-block-timeout-period-microsoft-defender-antivirus.md) while the cloud-based protection service analyzes the file. You can also [customize the message displayed on users' desktops](/windows/security/operating-system-security/system-security/windows-defender-security-center/wdsc-customize-contact-information) when a file is blocked. You can change the company name, contact information, and message URL. > [!TIP]-> This article is intended for enterprise admins and IT Pros who manage security settings for organizations. If you aren't an enterprise admin or IT Pro but you have questions about block at first sight, see the [Not an enterprise admin or IT Pro?](#not-an-enterprise-admin-or-it-pro) section.+> To learn more, see [(Blog) Get to know the advanced technologies at the core of Microsoft Defender for Endpoint next-generation protection](https://www.microsoft.com/security/blog/2019/06/24/inside-out-get-to-know-the-advanced-technologies-at-the-core-of-microsoft-defender-atp-next-generation-protection/).+>+> This article is intended for enterprise administrators and IT professionals who manage security settings for organizations. If you don't manage security settings for an organization, see [Configure block at first sight in the Windows Security app](#configure-block-at-first-sight-in-the-windows-security-app). +> [!CAUTION]+> Turning off block at first sight lowers the protection state of your devices and your network. We don't recommend disabling block at first sight permanently. ## Prerequisites @@ -40,61 +64,77 @@ Block at first sight is supported on the following operating systems: - Windows +## Configure block at first sight using Microsoft Intune -## What is "block at first sight"?+[!INCLUDE [intune-recommended-separate-product](includes/intune-recommended-separate-product.md)] -Block at first sight is a threat protection feature of next-generation protection. It detects new malware and blocks it within seconds. The feature is enabled when you turn on these settings:+To configure block at first sight in Microsoft Intune, use an endpoint security **Antivirus** policy. For detailed instructions, see <a href="/intune/intune-service/protect/endpoint-security-policy#create-endpoint-security-policies" target="_blank">Create endpoint security policies</a> or <a href="/intune/device-configuration/endpoint-security/manage-policies#modify-existing-policies" target="_blank">Modify existing policies</a> (links open new tabs in the Intune documentation). -- [Cloud protection](cloud-protection-microsoft-defender-antivirus.md) (also called *cloud-delivered protection* in Windows Security) is turned on.-- [Sample submission](cloud-protection-microsoft-antivirus-sample-submission.md) is set to send samples automatically.-- [Microsoft Defender Antivirus is up to date](microsoft-defender-antivirus-updates.md) on devices.+When you create the policy, use these specific settings: -In most enterprise organizations, these settings are already configured with Microsoft Defender Antivirus deployments. For more information, see [Turn on cloud protection in Microsoft Defender Antivirus](enable-cloud-protection-microsoft-defender-antivirus.md).+- **Policy type**: Go to **Manage** \> **Antivirus** on the **Endpoint security \| Overview** page at <https://intune.microsoft.com/#view/Microsoft_Intune_Workflows/SecurityManagementMenu/~/overview>.+- **Platform**: Select **Windows**.+- **Profile**: Select **Microsoft Defender Antivirus**. -## How it works+### Turn on block at first sight with Microsoft Intune -When Microsoft Defender Antivirus finds a suspicious file it hasn't seen before, it sends a query to the cloud protection backend. The cloud backend checks the file using heuristics, machine learning, and automated analysis. It then decides if the file is malicious or safe.+When you create or modify the policy, use these specific settings on the **Configuration settings** tab: -Microsoft Defender Antivirus uses multiple detection and prevention methods to deliver accurate, real-time protection.+- **Allow cloud protection**: Select **Allowed. Turns on Cloud Protection (Default)**.+- **Submit samples consent**: Select one of the following values:+ - **Send safe samples automatically. (Default)**+ - **Send all samples automatically** -:::image type="content" source="media/microsoft-defender-atp-next-generation-protection-engines.png" alt-text="The list of Microsoft Defender Antivirus engines" lightbox="media/microsoft-defender-atp-next-generation-protection-engines.png":::+For more information about the available settings, see [Antivirus policy for endpoint security in Intune](/intune/device-configuration/endpoint-security/antivirus). -> [!TIP]-> To learn more, see [(Blog) Get to know the advanced technologies at the core of Microsoft Defender for Endpoint next-generation protection](https://www.microsoft.com/security/blog/2019/06/24/inside-out-get-to-know-the-advanced-technologies-at-the-core-of-microsoft-defender-atp-next-generation-protection/).+### Turn off block at first sight with Microsoft Intune -## A few things to know about block at first sight+To turn off block at first sight, set **Allow cloud protection** to **Not allowed. Turns off Cloud Protection**. -Keep the following details in mind when using block at first sight:+## Configure block at first sight in the Microsoft Defender portal -- Block at first sight can block nonportable executable files (such as JS, VBS, or macros) and executable files, running the [latest Defender antimalware platform](microsoft-defender-antivirus-updates.md) on Windows or Windows Server.+If your organization [manages endpoint security policies in the Microsoft Defender portal](endpoint-security-policies-configure.md), use a Microsoft Defender Antivirus policy to configure block at first sight. -- Block at first sight only uses the cloud protection backend for executable files and nonportable executable files that are downloaded from the Internet, or that originate from the Internet zone. A hash value of the `.exe` file is checked via the cloud backend to determine if the file is a previously undetected file.+For detailed instructions, see <a href="endpoint-security-policies-configure.md#create-an-endpoint-security-policy" target="_blank">Create an endpoint security policy</a> or <a href="endpoint-security-policies-configure.md#edit-an-endpoint-security-policy" target="_blank">Edit an endpoint security policy</a> (links open new tabs). -- If the cloud backend is unable to make a determination, Microsoft Defender Antivirus locks the file and uploads a copy to the cloud. The cloud performs more analysis to reach a determination. The cloud then either allows the file to run or blocks the file in all future encounters, depending on whether the cloud determines the file to be malicious or not a threat.+When you create the policy on the **Windows policies** tab of the **Endpoint security policies** page in the Defender portal at <https://security.microsoft.com/policy-inventory?osPlatform=Windows>, use these specific settings: -- In many cases, this cloud-based analysis and blocking process can reduce the response time for new malware from hours to seconds.+- **Select platform**: Select **Windows**.+- **Select template**: Select **Microsoft Defender Antivirus**. -- You can [specify how long a file should be prevented from running](configure-cloud-block-timeout-period-microsoft-defender-antivirus.md) while the cloud-based protection service analyzes the file. And, you can [customize the message displayed on users' desktops](/windows/security/threat-protection/windows-defender-security-center/wdsc-customize-contact-information) when a file is blocked. You can change the company name, contact information, and message URL.+### Turn on block at first sight with the Microsoft Defender portal -## Turn on block at first sight with Microsoft Intune+When you create or modify the policy, use these specific settings on the **Configuration settings** tab: -To enable block at first sight using a Microsoft Intune Endpoint Security **Antivirus** policy, see <a href="/intune/intune-service/protect/endpoint-security-policy#create-endpoint-security-policies" target="_blank">Create an endpoint security policy</a> (opens in a new tab in the Intune documentation). When creating the policy, use these settings:+- **Allow cloud protection**: Select **Allowed. Turns on Cloud Protection (Default)**.+- **Submit samples consent**: Select one of the following values:+ - **Send safe samples automatically. (Default)**+ - **Send all samples automatically** -- **Policy type**: Antivirus-- **Platform**: Windows-- **Profile**: Microsoft Defender Antivirus-- **Configuration settings**: Configure the following settings:- - **Allow cloud protection**: Select **Allowed. Turns on Cloud Protection (Default)**.- - **Submit samples consent**: Select one of the following values:- - **Send safe samples automatically. (Default)**- - **Send all samples automatically**+### Turn off block at first sight with the Microsoft Defender portal -For more information about antivirus profiles in Microsoft Intune, see [Antivirus policy for endpoint security in Microsoft Intune](/intune/device-configuration/endpoint-security/antivirus).+To turn off block at first sight, set **Allow cloud protection** to **Not allowed. Turns off Cloud Protection**. -## Turn on block at first sight with Group Policy+## Configure block at first sight in Microsoft Configuration Manager -> [!NOTE]-> We recommend using Intune or Microsoft Configuration Manager to turn on block at first sight.+For instructions to create and deploy an antimalware policy, see [Endpoint Protection antimalware policies in Configuration Manager](/intune/configmgr/protect/deploy-use/endpoint-antimalware-policies).++Configuration Manager doesn't include a separate setting named **Block at First Sight**. Configure the cloud protection and sample submission settings that the feature requires.++### Turn on block at first sight with Microsoft Configuration Manager++To turn on block at first sight, configure the following settings in the antimalware policy:++- **Advanced Settings**:+ - **Enable auto sample file submission to help Microsoft determine whether certain detected items are Malicious**: Select **Yes**.+- **Cloud Protection Service**:+ - **Cloud Protection Service membership**: Select **Advanced**.++### Turn off block at first sight with Microsoft Configuration Manager++To turn off block at first sight, set **Cloud Protection Service membership** to **Do not join Cloud Protection Service**.++## Configure block at first sight using Group Policy 1. In Centralized Group Policy, open the [Group Policy Management Console (GPMC)](/windows-server/identity/ad-ds/manage/group-policy/group-policy-management-console) on your Group Policy management computer. @@ -104,7 +144,11 @@ For more information about antivirus profiles in Microsoft Intune, see [Antiviru 1. In the **Group Policy Management Editor**, go to **Computer configuration** \> **Administrative templates** \> **Windows components** \> **Microsoft Defender Antivirus** \> **MAPS**. -1. In the details pane of **MAPS**, configure the following settings. To open and configure a setting, use any of the following methods:+1. In the details pane of **MAPS**, the settings used to configure block at first sight are:+ - **Configure the 'Block at First Sight' feature**+ - **Send file samples when further analysis is required**++ To open and configure a setting, use any of the following methods: - Double-click the setting. - Right-click the setting, and then select **Edit**. - Select the setting, and then select **Action** \> **Edit**.@@ -112,102 +156,88 @@ For more information about antivirus profiles in Microsoft Intune, see [Antiviru > [!TIP] > You can also configure Group Policy locally on individual devices by using the Local Group Policy Editor (`gpedit.msc`). Navigate to the same path: **Computer configuration** \> **Administrative templates** \> **Windows components** \> **Microsoft Defender Antivirus** \> **MAPS**. - **Configure the 'Block at First Sight' feature**:-- 1. In the details pane of **MAPS**, open the **Configure the 'Block at First Sight' feature** setting.- 1. In the setting window that opens, select **Enabled**, and then select **OK**.-- **Send file samples when further analysis is required**:-- 1. In the details pane of **MAPS**, open the **Send file samples when further analysis is required** setting.- 1. In the setting window that opens, configure the following options:- 1. Select **Enabled**.- 1. **Send file samples when further analysis is required**: Select one of the following values:- - **Send safe samples** (0x1)- - **Send all samples** (0x3)-- > [!IMPORTANT]- > Setting to **Always prompt** (0x0) lowers the protection state of the device. **Never send** (0x2) means block at first sight doesn't function.+### Turn on block at first sight with Group Policy - 1. Select **OK**.+To turn on block at first sight in the Group Policy **MAPS** settings, follow these steps: -## Confirm block at first sight is enabled on individual client devices+1. Open the **Configure the 'Block at First Sight' feature** setting.+1. In the setting window that opens, select **Enabled**, and then select **OK**.+1. Open the **Send file samples when further analysis is required** setting.+1. In the setting window that opens, configure the following options:+ 1. Select **Enabled**.+ 1. **Send file samples when further analysis is required**: Select one of the following values:+ - **Send safe samples** (0x1)+ - **Send all samples** (0x3) -You can confirm that block at first sight is enabled on individual client devices using the Windows Security app. Block at first sight is automatically enabled as long as **Cloud-delivered protection** and **Automatic sample submission** are both turned on.+ > [!IMPORTANT]+ > **Always prompt** (0x0) lowers the protection state of the device. **Never send** (0x2) prevents block at first sight from functioning. -1. Open the Windows Security app.+ 1. Select **OK**. -1. Select **Virus & threat protection**, and then, under **Virus & threat protection settings**, select **Manage Settings**.-- :::image type="content" source="/defender/media/wdav-protection-settings-wdsc.png" alt-text="The Virus & threat protection settings label in the Windows Security app" lightbox="/defender/media/wdav-protection-settings-wdsc.png":::--1. Confirm that **Cloud-delivered protection** and **Automatic sample submission** are both turned on.--> [!NOTE]->-> - If Group Policy manages these settings, they appear greyed-out on individual endpoints and can't be changed locally.-> - Group Policy changes must reach each endpoint before the **Cloud-delivered protection** and **Automatic sample submission** settings update in Windows Settings.--## Turn off block at first sight--> [!CAUTION]-> Turning off block at first sight lowers the protection state of your devices and your network. We don't recommend disabling block at first sight protection permanently.--### Turn off block at first sight with Microsoft Intune--> [!CAUTION]-> Disabling block at first sight lowers the protection state of your devices and your network.+### Turn off block at first sight with Group Policy -To disable block at first sight with Microsoft Intune, see <a href="/intune/device-configuration/endpoint-security/manage-policies#modify-existing-policies" target="_blank">Modify existing policies</a> (opens in a new tab in the Intune documentation). Choose the following options:+> [!TIP]+> Disabling block at first sight doesn't disable or change the cloud protection and sample submission policies. -- **Policy**: **Antivirus**, then select your Microsoft Defender Antivirus policy-- **Allow cloud protection**: Not allowed. Turns off Cloud Protection+To turn off block at first sight in the Group Policy **MAPS** settings, follow these steps: -### Turn off block at first sight with Group Policy+1. Open the **Configure the 'Block at First Sight' feature** setting.+1. In the setting window that opens, select **Disabled**, and then select **OK**. -> [!CAUTION]-> Disabling block at first sight lowers the protection state of your devices and your network.+## Configure block at first sight using PowerShell -> [!NOTE]-> Disabling block at first sight doesn't disable or alter the prerequisite group policies.+Run the commands in an elevated PowerShell session (a PowerShell window you opened by selecting **Run as administrator**). -Use the following steps to turn off block at first sight with Group Policy:+### Turn on block at first sight with PowerShell -1. In Centralized Group Policy, open the [Group Policy Management Console (GPMC)](/windows-server/identity/ad-ds/manage/group-policy/group-policy-management-console) on your Group Policy management computer.+The following command turns on cloud protection, automatic safe sample submission, and block at first sight: -1. In the GPMC console tree, expand Group Policy Objects in the forest and domain containing the GPO you want to edit.+```powershell+Set-MpPreference -MAPSReporting Advanced -SubmitSamplesConsent SendSafeSamples -DisableBlockAtFirstSeen $false+``` -1. Right-click the GPO, and then select **Edit**.+To submit all samples automatically instead of only safe samples, use `SendAllSamples` for the _SubmitSamplesConsent_ value. -1. In the **Group Policy Management Editor**, go to **Computer configuration** \> **Administrative templates** \> **Windows components** \> **Microsoft Defender Antivirus** \> **MAPS**.+### Verify the configuration -1. In the details pane of **MAPS**, open the **Configure the 'Block at First Sight' feature** setting.+The following command displays the current block at first sight settings: -1. In the setting window that opens, select **Disabled**, and then select **OK**.+```powershell+Get-MpPreference | Select-Object MAPSReporting, SubmitSamplesConsent, DisableBlockAtFirstSeen+``` -## Not an enterprise admin or IT Pro?+To verify block at first sight is turned on, confirm the following values: -If you aren't an enterprise admin or an IT Pro, but you have questions about block at first sight, the following guidance for personal device users can help. Block at first sight is a threat protection feature that detects and blocks malware within seconds. Although there isn't a specific setting called "Block at first sight," the feature is enabled when certain settings are configured on your device.+- _MAPSReporting_: `2` (Advanced)+- _SubmitSamplesConsent_: `1` (Send safe samples automatically) or `3` (Send all samples automatically)+- _DisableBlockAtFirstSeen_: `False` -### How to manage block at first sight on or off on your own device+### Turn off block at first sight with PowerShell -If you have a personal device that isn't managed by an organization, you might be wondering how to turn block at first sight on or off. You can use the Windows Security app to manage block at first sight.+The following command turns off block at first sight without changing the cloud protection and sample submission settings: -1. On your Windows 10 or Windows 11 computer, open the Windows Security app.+```powershell+Set-MpPreference -DisableBlockAtFirstSeen $true+``` -1. Select **Virus & threat protection**.+For detailed syntax and parameter information, see [**Set-MpPreference**](/powershell/module/defender/set-mppreference) and [**Get-MpPreference**](/powershell/module/defender/get-mppreference). -1. Under **Virus & threat protection settings**, select **Manage settings**.+## Configure block at first sight in the Windows Security app -1. Take one of the following steps:- - To enable block at first sight, make sure that both **Cloud-delivered protection** and **Automatic sample submission** are both turned on.+On an unmanaged device, you can configure block at first sight in the [Windows Security app](https://support.microsoft.com/Windows/Security/Windows-Security/stay-protected-with-the-windows-security-app). Although the app doesn't have a setting named **Block at first sight**, the feature turns on when you enable cloud-delivered protection and automatic sample submission. - - To disable block at first sight:+> [!NOTE]+> If Group Policy manages these settings, they appear greyed-out in the Windows Security app and can't be changed locally.+>+> Group Policy changes must reach the device before the settings are updated in the Windows Security app. - > [!CAUTION]- > Turning off block at first sight lowers the level of protection for your device. We don't recommend permanently disabling block at first sight.+To configure block at first sight, follow these steps: - Turn off **Cloud-delivered protection** or **Automatic sample submission**.+1. In the **Windows security** app on the device, go to **Virus & threat protection**.+1. In the **Virus & threat protection** pane, in the **Virus & threat protection settings** section, select **Manage settings**.+1. In the **Virus & threat protection settings** pane, take one of the following actions:+ - To turn on block at first sight, turn on **Cloud-delivered protection** and **Automatic sample submission**.+ - To turn off block at first sight, turn off either setting. ## See also @@ -215,8 +245,5 @@ For more information about Microsoft Defender Antivirus and related features, se - [Microsoft Defender Antivirus in Windows](microsoft-defender-antivirus-windows.md) - [Enable cloud-delivered protection](enable-cloud-protection-microsoft-defender-antivirus.md)-- [Stay protected with Windows Security](https://support.microsoft.com/windows/stay-protected-with-windows-security-2ae0363d-0ada-c064-8b56-6a39afb6a963)+- [Stay protected with Windows Security](https://support.microsoft.com/Windows/Security/Windows-Security/stay-protected-with-the-windows-security-app) - [Onboard to Microsoft Defender for Endpoint](onboarding.md)--- 