Configure local overrides for Microsoft Defender Antivirus settings
In brief
The article now states that Group Policy is the only supported method for configuring local override policies. It clarifies the configuration steps, supported tools for users, and local-versus-global exclusion list merge behavior.
What Defender admins need to know
Use the revised Group Policy procedure when managing local Microsoft Defender Antivirus overrides; no administrator action is explicitly required.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Prevent or allow users to locally modify Microsoft Defender Antivirus policy settings
By default, Microsoft Defender Antivirus settings deployed viathat you deploy through a Group Policy Object (GPO) to the endpoints in your organization preventsprevent users from locally changing the settings. You might want to allowthose settings locally. However, some users might need to change these settings.settings on their own devices. For example, security researchers and threat investigators mightoften need more control over individual settings on the endpoints they use.settings.
This article explains how toThe following procedures configure local overrides and merge behavior ofcontrol how local and global exclusion lists.lists are merged.
- Windows
Configure local overrides for Microsoft Defender Antivirus settings using Group Policy
The default settingGroup Policy is the only supported method for configuring these local override policies. By default, the policies isare set to Disabled. WhenIf you change the policiesset a policy to Enabled, users can make changes tochange the associated settingsrelated setting on their devices by using one of the following methods:
- The Windows Security app
app.. - The Local
group policy settings.Group Policy Editor (gpedit.msc). PowerShell cmdletsThe Set-MpPreference cmdlet (whereappropriate)supported).
To configure local override policies by using Group Policy, follow these settings:steps:
Open the Group Policy Management Console (GPMC) on your Group Policy management computer.
In the GPMC console tree, expand Group Policy Objects in the forest and domain containing the GPO you want to edit.
Right-click
onthe GPO, and then select Edit.In the Group Policy Management Editor, go to Computer configuration > Administrative templates > Windows components > Microsoft Defender Antivirus.
|Real-time protection|Configure local setting override for monitoring file and program activity on your computer|Enable and configure Microsoft Defender Antivirus always-on protection and monitoring| |Real-time protection|Configure local setting override for monitoring for incoming and outgoing file activity|Enable and configure Microsoft Defender Antivirus always-on protection and monitoring| |Real-time protection|Configure local setting override for scanning all downloaded files and attachments|Enable and configure Microsoft Defender Antivirus always-on protection and monitoring| |Real-time protection|Configure local setting override
forto turn on behavior monitoring|Enable and configure Microsoft Defender Antivirus always-on protection and monitoring| |Real-time protection|Configure local setting override to turn on real-time protection|Enable and configure Microsoft Defender Antivirus always-on protection and monitoring| |Remediation|Configure local setting override for the time of day to run a scheduled full scan to complete remediation|Configure remediation for scans| |Scan|Configure local setting override for maximum percentage of CPU utilization|Configure and run scans| |Scan|Configure local setting override forschedulethe scheduled scan day|About scheduled scans| |Scan|Configure local setting override for scheduled quick scan time|About scheduled scans| |Scan|Configure local setting override for scheduled scan time|About scheduled scans| |Scan|Configure local setting override for the scan type to use for a scheduled scan|About scheduled scans|In the details pane
offor the selected Locationyou selected, open, find the settingyou want to configure as identified bylisted in the Settingvalue incolumn of theprevious table (fortable. For example, select Configure local setting override for reporting to Microsoft MAPS).You can useOpen the setting by using any of the followingmethods to open the setting:methods:- Double-click
onthe setting. - Right-click
onthe setting, and then select Edit. - Select the setting, and then select Action > Edit.
- Double-click
In the setting window that opens, select
your desiredthe required configuration (for example, Enabled or Disabled), and thenSelectselect OK.Repeat
the previousthese steps forany other settings.each setting you want to configure.Deploy the GPO
as usual.to the devices you want to manage.
Configure how locally and globally defined threat remediation and exclusions lists are merged
You can also configurecontrol how locally and globally defined lists are combined or merged with globally defined lists. Thismerged. The local administrator merge behavior setting applies to the following features:
- Exclusion lists
- Specified remediation lists
- File and folder exclusions for attack surface reduction (ASR) rules
By default, lists configured in local group policyLocal Group Policy and the Windows Security app are mergedmerge with lists defined byfrom your deployed GPO. If the appropriatelists conflict, the deployed GPO you deployed. Where there are conflicts, the globally defined list takes precedence. You can disable this setting to ensurelocal list merging so that only globally defined lists (for example, from any deployed GPOs)management policies are used.
Use Microsoft Intune to disable local list merging
[!INCLUDE intune-recommended-separate-product]
To disable local list merging in Microsoft Intune, use an endpoint security Antivirus policy. For detailed instructions, see Create endpoint security policies or Modify existing policies (links open new tabs in the Intune documentation).
When you create the policy, use these specific settings:
- Policy type: Go to Manage > Antivirus on the Endpoint security | Overview page at https://intune.microsoft.com/#view/Microsoft_Intune_Workflows/SecurityManagementMenu/~/overview.
- Platform: Select Windows.
- Profile: Select Microsoft Defender Antivirus.
When you create or modify the policy, use these specific settings on the Configuration settings tab:
- Disable local admin merge: Select Disable local admin merge.
For more information about antivirus policy profiles available in Microsoft Intune, see Antivirus policy for endpoint security in Intune.
Use the Microsoft Defender portal to disable local list merging
If your organization manages endpoint security policies in the Microsoft Defender portal, use a Microsoft Defender Antivirus policy to disable local list merging.
For detailed instructions, see Create an endpoint security policy or Edit an endpoint security policy (links open new tabs).
When you create the policy on the Windows policies tab of the Endpoint security policies page in the Defender portal at https://security.microsoft.com/policy-inventory?osPlatform=Windows, use these specific settings:
- Select platform: Select Windows.
- Select template: Select Microsoft Defender Antivirus.
When you create or modify the policy, use this specific setting on the Configuration settings tab:
- Disable local admin merge: Select Disable local admin merge.
Use Group Policy to disable local list merging
To disable local list merging by using Group Policy, follow these steps:
Open the Group Policy Management Console (GPMC) on your Group Policy management computer.
In the GPMC console tree, expand Group Policy Objects in the forest and domain containing the GPO you want to edit.
Right-click
onthe GPO, and then select Edit.In the Group Policy Management Editor, go to Computer configuration > Administrative templates > Windows components > Microsoft Defender Antivirus.
In the details pane of Microsoft Defender Antivirus, open the Configure local administrator merge behavior for lists setting by using any of the following methods:
- Double-click
onthe setting. - Right-click
onthe setting, and then select Edit. - Select the setting, and then select Action > Edit.
- Double-click
In the setting window that opens, select Disabled, and then select OK.
- Administrative Templates (.admx) for Windows 11 2022 Update (22H2)
- Administrative Templates (.admx) for Windows 10 November 2021 Update (21H2)
Use Microsoft Intune to disable local list merging
To disable local list merging in a Microsoft Intune Endpoint Security Antivirus policy, see Create an endpoint security policy (opens in a new tab in the Intune documentation).
When creating an Antivirus policy, use these settings:
Policy type: AntivirusPlatform: WindowsProfile: Microsoft Defender Antivirus
When creating or modifying an Antivirus policy, use this setting on the Configuration settings tab:
Disable local admin merge: SelectDisable local admin merge.
For more information about antivirus policy profiles available in Microsoft Intune, see Antivirus policy for endpoint security in Intune.
@@ -1,14 +1,14 @@ --- title: Configure local overrides for Microsoft Defender Antivirus settings-description: Enable or disable users from locally changing settings in Microsoft Defender Antivirus.+description: Configure Group Policy local overrides and local administrator merge behavior for Microsoft Defender Antivirus settings on managed Windows devices. ms.service: defender-endpoint ms.subservice: ngp ms.localizationpriority: medium author: paulinbar ms.author: painbar ms.topic: how-to-ms.custom: nextgen, msecd-doc-authoring-1014-ms.date: 06/17/2026+ms.custom: nextgen, msecd-doc-authoring-1016+ms.date: 09/02/2026 ms.reviewer: yongrhee ms.collection: - m365-security@@ -19,17 +19,18 @@ appliesto: - Microsoft Defender for Endpoint Plan 2 - Microsoft Defender Antivirus ai-usage: ai-assisted+#customer intent: As a security administrator, I want to control local changes to Microsoft Defender Antivirus settings so that managed policy remains authoritative. --- # Prevent or allow users to locally modify Microsoft Defender Antivirus policy settings -By default, Microsoft Defender Antivirus settings deployed via a Group Policy Object (GPO) to the endpoints in your organization prevents users from locally changing the settings. You might want to allow some users to change these settings. For example, security researchers and threat investigators might need more control over individual settings on the endpoints they use.+By default, Microsoft Defender Antivirus settings that you deploy through a Group Policy Object (GPO) prevent users from changing those settings locally. However, some users might need to change settings on their own devices. For example, security researchers and threat investigators often need more control over individual settings. -This article explains how to configure local overrides and merge behavior of local and global exclusion lists.+The following procedures configure local overrides and control how local and global exclusion lists are merged. > [!TIP] > If you're looking for antivirus-related information for other platforms, see the following articles:-+> > - [Set preferences for Microsoft Defender for Endpoint on macOS](mac-preferences.md) > - [Microsoft Defender for Endpoint on Mac](microsoft-defender-endpoint-mac.md) > - [macOS Antivirus policy settings for Microsoft Defender Antivirus for Intune](/intune/intune-service/protect/antivirus-microsoft-defender-settings-macos)@@ -44,21 +45,23 @@ This article explains how to configure local overrides and merge behavior of loc - Windows -## Configure local overrides for Microsoft Defender Antivirus settings+<a name="configure-local-overrides-for-microsoft-defender-antivirus-settings"></a>++## Configure local overrides for Microsoft Defender Antivirus settings using Group Policy -The default setting for these local override policies is **Disabled**. When you change the policies to **Enabled**, users can make changes to the associated settings on their devices by using the following methods:+Group Policy is the only supported method for configuring these local override policies. By default, the policies are set to **Disabled**. If you set a policy to **Enabled**, users can change the related setting on their devices by using one of the following methods: -- The [Windows Security](microsoft-defender-security-center-antivirus.md) app.-- Local group policy settings.-- PowerShell cmdlets (where appropriate).+- The [Windows Security app](microsoft-defender-security-center-antivirus.md).+- The Local Group Policy Editor (`gpedit.msc`).+- The [**Set-MpPreference**](/powershell/module/defender/set-mppreference) cmdlet (where supported). -To configure these settings:+To configure local override policies by using Group Policy, follow these steps: 1. Open the [Group Policy Management Console (GPMC)](/windows-server/identity/ad-ds/manage/group-policy/group-policy-management-console) on your Group Policy management computer. 1. In the GPMC console tree, expand Group Policy Objects in the forest and domain containing the GPO you want to edit. -1. Right-click on the GPO, and then select **Edit**.+1. Right-click the GPO, and then select **Edit**. 1. In the **Group Policy Management Editor**, go to **Computer configuration** \> **Administrative templates** \> **Windows components** \> **Microsoft Defender Antivirus**. @@ -71,51 +74,86 @@ To configure these settings: |Real-time protection|Configure local setting override for monitoring file and program activity on your computer|[Enable and configure Microsoft Defender Antivirus always-on protection and monitoring](configure-real-time-protection-microsoft-defender-antivirus.md)| |Real-time protection|Configure local setting override for monitoring for incoming and outgoing file activity|[Enable and configure Microsoft Defender Antivirus always-on protection and monitoring](configure-real-time-protection-microsoft-defender-antivirus.md)| |Real-time protection|Configure local setting override for scanning all downloaded files and attachments|[Enable and configure Microsoft Defender Antivirus always-on protection and monitoring](configure-real-time-protection-microsoft-defender-antivirus.md)|- |Real-time protection|Configure local setting override for turn on behavior monitoring|[Enable and configure Microsoft Defender Antivirus always-on protection and monitoring](configure-real-time-protection-microsoft-defender-antivirus.md)|+ |Real-time protection|Configure local setting override to turn on behavior monitoring|[Enable and configure Microsoft Defender Antivirus always-on protection and monitoring](configure-real-time-protection-microsoft-defender-antivirus.md)| |Real-time protection|Configure local setting override to turn on real-time protection|[Enable and configure Microsoft Defender Antivirus always-on protection and monitoring](configure-real-time-protection-microsoft-defender-antivirus.md)| |Remediation|Configure local setting override for the time of day to run a scheduled full scan to complete remediation|[Configure remediation for scans](configure-remediation-microsoft-defender-antivirus.md)| |Scan|Configure local setting override for maximum percentage of CPU utilization|[Configure and run scans](run-scan-microsoft-defender-antivirus.md)|- |Scan|Configure local setting override for schedule scan day|[About scheduled scans](schedule-antivirus-scans.md)|+ |Scan|Configure local setting override for the scheduled scan day|[About scheduled scans](schedule-antivirus-scans.md)| |Scan|Configure local setting override for scheduled quick scan time|[About scheduled scans](schedule-antivirus-scans.md)| |Scan|Configure local setting override for scheduled scan time|[About scheduled scans](schedule-antivirus-scans.md)| |Scan|Configure local setting override for the scan type to use for a scheduled scan|[About scheduled scans](schedule-antivirus-scans.md)| -1. In the details pane of the **Location** you selected, open the setting you want to configure as identified by the **Setting** value in the previous table (for example, **Configure local setting override for reporting to Microsoft MAPS**). You can use any of the following methods to open the setting:- - Double-click on the setting.- - Right-click on the setting, and then select **Edit**+1. In the details pane for the selected **Location**, find the setting listed in the **Setting** column of the table. For example, select **Configure local setting override for reporting to Microsoft MAPS**. Open the setting by using any of the following methods:+ - Double-click the setting.+ - Right-click the setting, and then select **Edit**. - Select the setting, and then select **Action** \> **Edit**. -1. In the setting window that opens, select your desired configuration (for example, **Enabled** or **Disabled**), and then Select **OK**+1. In the setting window that opens, select the required configuration (for example, **Enabled** or **Disabled**), and then select **OK**. - Repeat the previous steps for any other settings.+ Repeat these steps for each setting you want to configure. -1. Deploy the GPO as usual.+1. Deploy the GPO to the devices you want to manage. <a id="merge-lists"></a> ## Configure how locally and globally defined threat remediation and exclusions lists are merged -You can also configure how locally defined lists are combined or merged with globally defined lists. This setting applies to the following features:+You can also control how locally and globally defined lists are merged. The local administrator merge behavior setting applies to the following features: - [Exclusion lists](microsoft-defender-antivirus-exclusions-configure.md) - [Specified remediation lists](configure-remediation-microsoft-defender-antivirus.md) - [File and folder exclusions for attack surface reduction (ASR) rules](attack-surface-reduction-rules-overview.md#file-and-folder-exclusions-for-asr-rules) -By default, lists configured in local group policy and the Windows Security app are merged with lists defined by the appropriate GPO you deployed. Where there are conflicts, the globally defined list takes precedence. You can disable this setting to ensure that only globally defined lists (for example, from any deployed GPOs) are used.+By default, lists configured in Local Group Policy and the Windows Security app merge with lists from your deployed GPO. If the lists conflict, the deployed GPO takes precedence. You can disable local list merging so that only lists from management policies are used.++### Use Microsoft Intune to disable local list merging++[!INCLUDE [intune-recommended-separate-product](includes/intune-recommended-separate-product.md)]++To disable local list merging in Microsoft Intune, use an endpoint security **Antivirus** policy. For detailed instructions, see <a href="/intune/intune-service/protect/endpoint-security-policy#create-endpoint-security-policies" target="_blank">Create endpoint security policies</a> or <a href="/intune/device-configuration/endpoint-security/manage-policies#modify-existing-policies" target="_blank">Modify existing policies</a> (links open new tabs in the Intune documentation).++When you create the policy, use these specific settings:++- **Policy type**: Go to **Manage** \> **Antivirus** on the **Endpoint security \| Overview** page at <https://intune.microsoft.com/#view/Microsoft_Intune_Workflows/SecurityManagementMenu/~/overview>.+- **Platform**: Select **Windows**.+- **Profile**: Select **Microsoft Defender Antivirus**.++When you create or modify the policy, use these specific settings on the **Configuration settings** tab:++- **Disable local admin merge**: Select **Disable local admin merge**.++For more information about antivirus policy profiles available in Microsoft Intune, see [Antivirus policy for endpoint security in Intune](/intune/device-configuration/endpoint-security/antivirus).++### Use the Microsoft Defender portal to disable local list merging++If your organization [manages endpoint security policies in the Microsoft Defender portal](endpoint-security-policies-configure.md), use a Microsoft Defender Antivirus policy to disable local list merging.++For detailed instructions, see <a href="endpoint-security-policies-configure.md#create-an-endpoint-security-policy" target="_blank">Create an endpoint security policy</a> or <a href="endpoint-security-policies-configure.md#edit-an-endpoint-security-policy" target="_blank">Edit an endpoint security policy</a> (links open new tabs).++When you create the policy on the **Windows policies** tab of the **Endpoint security policies** page in the Defender portal at <https://security.microsoft.com/policy-inventory?osPlatform=Windows>, use these specific settings:++- **Select platform**: Select **Windows**.+- **Select template**: Select **Microsoft Defender Antivirus**.++When you create or modify the policy, use this specific setting on the **Configuration settings** tab:++- **Disable local admin merge**: Select **Disable local admin merge**. ### Use Group Policy to disable local list merging +To disable local list merging by using Group Policy, follow these steps:+ 1. Open the [Group Policy Management Console (GPMC)](/windows-server/identity/ad-ds/manage/group-policy/group-policy-management-console) on your Group Policy management computer. 1. In the GPMC console tree, expand Group Policy Objects in the forest and domain containing the GPO you want to edit. -1. Right-click on the GPO, and then select **Edit**.+1. Right-click the GPO, and then select **Edit**. 1. In the **Group Policy Management Editor**, go to **Computer configuration** \> **Administrative templates** \> **Windows components** \> **Microsoft Defender Antivirus**. -1. In the details pane of **Microsoft Defender Antivirus**, open the **Configure local administrator merge behavior for lists** setting using any of the following methods:- - Double-click on the setting.- - Right-click on the setting, and then select **Edit**+1. In the details pane of **Microsoft Defender Antivirus**, open the **Configure local administrator merge behavior for lists** setting by using any of the following methods:+ - Double-click the setting.+ - Right-click the setting, and then select **Edit**. - Select the setting, and then select **Action** \> **Edit**. 1. In the setting window that opens, select **Disabled**, and then select **OK**.@@ -126,28 +164,13 @@ By default, lists configured in local group policy and the Windows Security app > - Administrative Templates (.admx) for Windows 11 2022 Update (22H2) > - Administrative Templates (.admx) for Windows 10 November 2021 Update (21H2) -### Use Microsoft Intune to disable local list merging--To disable local list merging in a Microsoft Intune Endpoint Security **Antivirus** policy, see <a href="/intune/intune-service/protect/endpoint-security-policy#create-endpoint-security-policies" target="_blank">Create an endpoint security policy</a> (opens in a new tab in the Intune documentation).--When creating an Antivirus policy, use these settings:--- **Policy type**: Antivirus-- **Platform**: Windows-- **Profile**: Microsoft Defender Antivirus--When creating or modifying an Antivirus policy, use this setting on the **Configuration settings** tab:--- **Disable local admin merge**: Select **Disable local admin merge**.--For more information about antivirus policy profiles available in Microsoft Intune, see [Antivirus policy for endpoint security in Intune](/intune/device-configuration/endpoint-security/antivirus).- > [!NOTE]-> Disabling local list merging overrides controlled folder access settings. It also overrides any protected folders or allowed apps set by the local administrator. For more information about controlled folder access settings, see [Allow a blocked app in Windows Security](https://support.microsoft.com/help/4046851/windows-10-allow-blocked-app-windows-security).-+> Disabling local list merging overrides controlled folder access settings. It also overrides any protected folders or allowed apps set by the local administrator. For more information about controlled folder access settings, see [Allow a blocked app in Windows Security](https://support.microsoft.com/Windows/Security/Threat-Malware-Protection/virus-and-threat-protection-in-the-windows-security-app). ## Related articles +See the following related articles:+ - [Microsoft Intune](/intune/intune-service/protect/advanced-threat-protection-configure) - [Microsoft Defender Antivirus in Windows](microsoft-defender-antivirus-windows.md) - [Configure end-user interaction with Microsoft Defender Antivirus](configure-local-policy-overrides-microsoft-defender-antivirus.md) 