Microsoft Defender for Endpoint
Endpoint protection

Configure block at first sight in Microsoft Defender Antivirus

In brief

The article now explains how block at first sight works, lists its required conditions—cloud protection, automatic sample submission, and current Defender updates—and documents coverage for downloaded executable and nonportable files. It also adds Configuration Manager to the supported management tools and includes updated links and visuals.

What Defender admins need to know

Administrators can use the revised guidance to verify prerequisites, understand protection coverage, and configure the feature. The page also warns that disabling it lowers device and network protection.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Turn onConfigure block at first sight in Microsoft Defender Antivirus

This article describes an antivirus/antimalware feature known as "block at first sight", and describes how to enable block at first sight for your organization. Before you begin, review the Prerequisites section for required settings and supported operating systems.

Prerequisites

  • Windows

What is "block at first sight"?

Block at first sight is a threat protection feature of next-generation protection.next-generation protection. It detects new malware and blocks it within seconds. The feature is enabled when you turn on these settings:all of the following statements are true:

In most enterprise organizations, these settings are already configured with Microsoft Defender Antivirus deployments. For more information, see Turn on cloud protection in Microsoft Defender Antivirus.

How it works

When Microsoft Defender Antivirus finds a suspicious file it hasn't seen before, it sends a query to the cloud protection backend. The cloud backend checks the file using heuristics, machine learning, and automated analysis. It then decides if the file is malicious or safe.

Microsoft Defender Antivirus uses multiple detection and prevention methods to deliver accurate, real-time protection.

:::image type="content" source="media/microsoft-defender-atp-next-generation-protection-engines.png" alt-text="The listDiagram of Microsoft Defender Antivirus enginesprotection engines." lightbox="media/microsoft-defender-atp-next-generation-protection-engines.png":::

A few things to know about block at first sight

Keep the following details in mind when using block at first sight:

  • Block at first sight can block executable files and nonportable executable files (such as JS, VBS, or macros) and executable files, running the latest Defender antimalware platform on Windows or Windows Server.Server devices that run the latest Defender antimalware platform.

  • Block at first sight only uses the cloud protection backend for executable files and nonportable executable files that are downloaded from the Internet, or that originate from the Internet zone. A hash value of the .exe file is checked via the cloud backend to determine if the file is a previously undetected file.

  • If the cloud backend is unable to make a determination, Microsoft Defender Antivirus locks the file and uploads a copy to the cloud. The cloud performs more analysis to reach a determination. The cloud then either allows the file to run or blocks the file in all future encounters, depending on whether the cloud determines the file to be malicious or not a threat.

  • In many cases, this cloud-based analysis and blocking process can reduce the response time for new malware from hours to seconds.

  • You can specify how long a file should be prevented from running while the cloud-based protection service analyzes the file. And, youYou can customize the message displayed on users' desktopsalso customize the message displayed on users' desktops when a file is blocked. You can change the company name, contact information, and message URL.

Prerequisites

  • Windows

Configure block at first sight using Microsoft Intune

[!INCLUDE intune-recommended-separate-product]

To configure block at first sight in Microsoft Intune, use an endpoint security Antivirus policy. For detailed instructions, see Create endpoint security policies or Modify existing policies (links open new tabs in the Intune documentation).

When you create the policy, use these specific settings:

Turn on block at first sight with Microsoft Intune

To enable block at first sight using a Microsoft Intune Endpoint Security Antivirus policy, see Create an endpoint security policy (opens in a new tab in the Intune documentation). When creatingyou create or modify the policy, use these settings:

  • Policy type: Antivirus
  • Platform: Windows
  • Profile: Microsoft Defender Antivirus
  • specific settings on the Configuration settings: Configure the following settings: tab:
    • Allow cloud protection: Select Allowed. Turns on Cloud Protection (Default).
    • Submit samples consent: Select one of the following values:
      • Send safe samples automatically. (Default)
      • Send all samples automatically

For more information about antivirus profiles in Microsoft Intune,the available settings, see Antivirus policy for endpoint security in Intune.

Turn off block at first sight with Microsoft Intune

To turn off block at first sight, set Allow cloud protection to Not allowed. Turns off Cloud Protection.

Configure block at first sight in the Microsoft Defender portal

If your organization manages endpoint security policies in the Microsoft Defender portal, use a Microsoft Defender Antivirus policy to configure block at first sight.

For detailed instructions, see Create an endpoint security policy or Edit an endpoint security policy (links open new tabs).

When you create the policy on the Windows policies tab of the Endpoint security policies page in the Defender portal at https://security.microsoft.com/policy-inventory?osPlatform=Windows, use these specific settings:

  • Select platform: Select Windows.
  • Select template: Select Microsoft Defender Antivirus.

Turn on block at first sight with the Microsoft Defender portal

When you create or modify the policy, use these specific settings on the Configuration settings tab:

  • Allow cloud protection: Select Allowed. Turns on Cloud Protection (Default).
  • Submit samples consent: Select one of the following values:
    • Send safe samples automatically. (Default)
    • Send all samples automatically

Turn off block at first sight with the Microsoft Defender portal

To turn off block at first sight, set Allow cloud protection to Not allowed. Turns off Cloud Protection.

Configure block at first sight in Microsoft Configuration Manager

For instructions to create and deploy an antimalware policy, see Endpoint Protection antimalware policies in Configuration Manager.

Configuration Manager doesn't include a separate setting named Block at First Sight. Configure the cloud protection and sample submission settings that the feature requires.

Turn on block at first sight with Microsoft Configuration Manager

To turn on block at first sight, configure the following settings in the antimalware policy:

  • Advanced Settings:
    • Enable auto sample file submission to help Microsoft determine whether certain detected items are Malicious: Select Yes.
  • Cloud Protection Service:
    • Cloud Protection Service membership: Select Advanced.

Turn off block at first sight with Microsoft Configuration Manager

To turn off block at first sight, set Cloud Protection Service membership to Do not join Cloud Protection Service.

Configure block at first sight using Group Policy

  1. In Centralized Group Policy, open the Group Policy Management Console (GPMC)

    1. In Centralized Group Policy, open the Group Policy Management Console (GPMC) on your Group Policy management computer.

    2. In the Group Policy Management Editor, go to Computer configuration > Administrative templates > Windows components > Microsoft Defender Antivirus > MAPS.

    3. In the details pane of MAPS, the settings used to configure block at first sight are:

      • Configure the following settings. 'Block at First Sight' feature
      • Send file samples when further analysis is required

      To open and configure a setting, use any of the following methods:

      • Double-click the setting.
      • Right-click the setting, and then select Edit.
      • Select the setting, and then select Action > Edit.

    Turn on block at first sight with Group Policy

    To turn on block at first sight in the Group Policy MAPS settings, follow these steps:

    1. Open the Configure the 'Block at First Sight' feature setting.
    2. In the setting window that opens, select Enabled, and then select OK.
    3. Open the Send file samples when further analysis is required setting.
    4. In the setting window that opens, configure the following options:
      1. Select Enabled.
      2. Send file samples when further analysis is required: Select one of the following values:
        • Send safe samples (0x1)
        • Send all samples (0x3)
    1. Select OK.

    Turn off block at first sight with Group Policy

    To turn off block at first sight in the Group Policy MAPS settings, follow these steps:

    1. Open the Configure the 'Block at First Sight' feature setting.
    2. In the setting window that opens, select Disabled, and then select OK.

    Configure block at first sight using PowerShell

    Run the commands in an elevated PowerShell session (a PowerShell window you opened by selecting Run as administrator).

    Turn on block at first sight with PowerShell

    The following command turns on cloud protection, automatic safe sample submission, and block at first sight:

    Set-MpPreference -MAPSReporting Advanced -SubmitSamplesConsent SendSafeSamples -DisableBlockAtFirstSeen $false
    

    To submit all samples automatically instead of only safe samples, use SendAllSamples for the SubmitSamplesConsent value.

    Verify the configuration

    The following command displays the current block at first sight settings:

    Get-MpPreference | Select-Object MAPSReporting, SubmitSamplesConsent, DisableBlockAtFirstSeen
    

    To verify block at first sight is turned on, confirm the following values:

    • MAPSReporting: 2 (Advanced)
    • SubmitSamplesConsent: 1 (Send safe samples automatically) or 3 (Send all samples automatically)
    • DisableBlockAtFirstSeen: False

    Turn off block at first sight with PowerShell

    The following command turns off block at first sight without changing the cloud protection and sample submission settings:

    Set-MpPreference -DisableBlockAtFirstSeen $true
    

    For detailed syntax and parameter information, see Set-MpPreference (opens in a new tab in the Intune documentation)and Get-MpPreference. Choose the following options:

    • Policy: Antivirus, then select your Microsoft Defender Antivirus policy
    • Allow cloud protection: Not allowed. Turns off Cloud Protection

    Turn off

    Configure block at first sight with Group Policy

    Use the following steps to turn off block at first sight with Group Policy:

    1. In Centralized Group Policy, open the Group Policy Management Console (GPMC) on your Group Policy management computer.

    2. In the GPMC console tree, expand Group Policy Objects in the forest and domain containing the GPOWindows Security app

      On an unmanaged device, you want to edit.

    3. Right-click the GPO, and then select Edit.

    4. In the Group Policy Management Editor, go to Computer configuration > Administrative templates > Windows components > Microsoft Defender Antivirus > MAPS.

    5. In the details pane of MAPS, open the Configure the 'Block at First Sight' feature setting.

    6. In the setting window that opens, select Disabled, and then select OK.

    Not an enterprise admin or IT Pro?

    If you aren't an enterprise admin or an IT Pro, but you have questions about block at first sight, the following guidance for personal device users can help. Block at first sight is a threat protection feature that detects and blocks malware within seconds. Although there isn't a specific setting called "Block at first sight," the feature is enabled when certain settings are configured on your device.

    How to manageconfigure block at first sight on or off on your own device

    If youin the Windows Security app. Although the app doesn't have a personal device that isn't managed by an organization, you might be wondering how to turn blocksetting named Block at first sight, the feature turns on or off. You can use the Windows Security app to manage block at first sight.

    1. On your Windows 10 or Windows 11 computer, open the Windows Security app.

    2. Select Virus & threat protection.

    3. Under Virus & threatwhen you enable cloud-delivered protection settings, select Manage settings.

    4. Take one of the following steps:

      • To enable block at first sight, make sure that both Cloud-delivered protectionand Automaticautomatic sample submission are both turned on.submission.

      • To disable block at first sight:

    To configure block at first sight, follow these steps:

    1. In the Windows security app on the device, go to Virus & threat protection.
    2. In the Virus & threat protection pane, in the Virus & threat protection settings section, select Manage settings.
    3. In the Virus & threat protection settings pane, take one of the following actions:
      • To turn on block at first sight, turn on Cloud-delivered protection and Automatic sample submission.
      • To turn off block at first sight, turn off either setting.

    See also