Configure Microsoft Defender Antivirus always-on protection
In brief
The page now focuses on configuring always-on protection, identifies supported management tools, adds Intune and Configuration Manager prerequisites, and updates the Intune procedure and links.
What Defender admins need to know
Administrators have clearer guidance for selecting and preparing management tools; no immediate action is required.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Enable and configure Microsoft Defender Antivirus always-on protection
Always-on protection consists ofin Microsoft Defender Antivirus uses real-time protection, behavior monitoring, and heuristics to identify malware based on knowndetect suspicious and malicious activities. Suspicious and malicious activities include events, such as processes making unusual changes to existing files, modifyingactivity. Security administrators can configure these capabilities on Windows devices by using Microsoft Intune, the Microsoft Defender portal, Microsoft Configuration Manager, or creating automatic startup registry keys and startup locations (also known as autostart extensibility points,Group Policy. You can also use PowerShell or ASEPs), and other changes to the file system or file structure. Always-on protection is an important part of your antivirus protection and should be enabled. Windows Security app. Review the supported operating systems before you begin.
Prerequisites
Supported operating systems
The following operating systems support always-on protection:
- Windows
Manage antivirus settings with Microsoft
To use the Intune
You can use Intune to configure antivirus policies, and then apply those policies across procedure, enroll Windows devices in your organization. Antivirus policies help security admins focus on managing the discrete group of antivirus settingsIntune.
Before using Configuration Manager, configure it for managed devices. Each antivirus policy includes several profiles. Each profile contains only the settings that are relevant for Microsoft Defender Antivirus for macOS and Windows devices, or for the user experience in the Windows Security app on Windows devices.Endpoint Protection. For more information, see Antivirus policy for endpoint security in IntuneConfigure Endpoint Protection in Configuration Manager.
Configure always-on protection settings in Microsoft Intune
[!INCLUDE Intune is recommended but is a separate product]
To create a new policy and manage antivirusconfigure always-on protection settings within Microsoft Intune, use an endpoint security Antivirus policy. For detailed instructions, see Create endpoint security policies (opens in aor Modify existing policies (links open new tabtabs in the Intune documentation).
When creating a new policy for Windows, chooseyou create the following options:policy, use these specific settings:
- Policy type: Go to Manage > Antivirus on the Endpoint security | Overview page at https://intune.microsoft.com/#view/Microsoft_Intune_Workflows/SecurityManagementMenu/~/overview.
- Platform: Select Windows
10, Windows 11, and Windows Server. - Profile: Select Microsoft Defender Antivirus
Basics: Type a name and description for your policy.Configuration settings: ExpandDefenderand select the settings you want to use for your policy. To get help with your settings, refer to Policy CSP - Defender.Scope tags: ChooseSelect scope tagsto open theSelect tagspane to assign scope tags to the profile.Assignments: Select the groups to receive this profile. For more information on assigning profiles, see Assign user and device profiles.
When creating a new policy for macOS, chooseyou create or modify the policy, use these specific settings on the Configuration settings tab:
- In the Defender section, configure the following
options:settings:- Allow Real-Time Monitoring: Select Allowed.
- Allow On Access Protection: Select Allowed.
- Real Time Scan Direction: Select Monitor all files (bi-directional).
- Allow behavior monitoring: Select Allowed.
The Microsoft Defender Antivirus profile doesn't include a separate setting for heuristics. Heuristics are part of real-time protection. For descriptions of all available Windows settings, options, defaults, recommendations, and CSP mappings, see Configure Microsoft Defender Antivirus using Microsoft Intune.
Configure always-on protection settings in the Microsoft Defender portal
If your organization manages endpoint security policies in the Microsoft Defender portal, use a Microsoft Defender Antivirus policy to configure always-on protection.
For detailed instructions, see Create an endpoint security policy or Edit an endpoint security policy (links open new tabs).
When you create the policy on the Endpoint security policies page in the Microsoft Defender portal at https://security.microsoft.com/policy-inventory, use these specific settings:
PlatformSelect platform:macOSSelect Windows.ProfileSelect template: Select Microsoft Defender Antivirus.Basics: Type a name and description for your policy. On
When you create or modify the
- In the Defender section, configure the following settings:
- Allow Real-Time Monitoring: Select
the settings you want to use for your policy. To get help with your settings, refer to Set preferences for Microsoft Defender for Endpoint on macOSAllowed. Scope tags: ChooseSelect scope tagsto open theSelect tagspane to assign scope tags to the profileAssignmentsAllow On Access Protection: Selectthe groups to receive this profile. For more information on assigning profiles, see Assign user and device profilesAllowed.- Real Time Scan Direction: Select Monitor all files (bi-directional).
- Allow behavior monitoring: Select Allowed.
- Allow Real-Time Monitoring: Select
To edit an existing policy for Windows devices, see Modify existing policies (opens in a new tab in the Intune documentation). Select your policy, expand Defender, and edit settings for your policy. To get help with your settings, refer to Policy CSP - Defender.
To edit an existing policy for macOS devices, select your policy, select Properties, and choose Edit next to Configuration settings. Edit the policy settings under Microsoft Defender for Endpoint. To get help with your settings, refer to Set preferences for Microsoft Defender for Endpoint on macOS.
Are you using Group Policy?
In the Real-time protection settings of the antimalware policy, configure the following settings:
- Enable real-time protection: Select Yes.
- Monitor file and program activity on your computer: Select Yes.
- Scan system files: Select Scan incoming and outgoing files.
- Enable behavior monitoring: Select Yes.
Configure always-on protection settings in Group Policy
You can use Group Policy to manage some Microsoft Defender Antivirus settings. If tamper protection is enabled in your organization, any changes made to tamper-protected settings are ignored. You can't turn off tamper protection by using Group Policy.
If you must make changes to a device and those changes are blocked by tamper protection, we recommend usingTo temporarily change tamper-protected settings for testing or diagnostics, use troubleshooting mode to temporarily disable tamper protection on the device.. After troubleshooting mode ends, anythe settings return to their configured values. To make permanent changes, use a management tool that supports changes made to tamper-protected settings are reverted to their configured state.settings, such as Intune.
You can use Local Group Policy Editor to enable and configure Microsoft Defender Antivirus always-on protection settings.
Enable and configure always-on protection using Group Policy
ThisThe following procedure applies to Windows 10 and Windows 11 devices.
Use the following steps to enable and configure always-on protection using Local Group Policy Editor:
OpenLocal Group Policy Editor, as follows:In Centralized Group Policy, open the Group Policy Management Console (GPMC) on your
taskbar search box, typeGroup Policy management computer.In the GPMC console tree, expand
gpeditGroup Policy Objects in the forest and domain containing the Group Policy Object (GPO) you want to edit.Right-click the GPO, and then select Edit.
UnderIn theBest match, selectEdit group policyto launchLocalGroup PolicyEditor.:::image type="content" source="media/gpedit-search.png" alt-text="The GPEdit taskbar search result in the Control panel" lightbox="media/gpedit-search.png":::
In the left pane ofLocal Group PolicyManagement Editor,expand the treego to ComputerConfigurationconfiguration > AdministrativeTemplatestemplates > WindowsComponentscomponents > Microsoft Defender Antivirus.ConfigureIn theMicrosoft Defender Antivirus antimalware service policy setting.In thedetails pane of Microsoft Defender Antivirusdetails pane, the folders used to configure always-onright, double-protection are:- Real-time Protection: Configure real-time protection settings.
- Scan: Turn on heuristics.
To open and configure a setting, use any of the following methods:
- Double-click
Allow antimalware service to start up with normal priority,the setting. - Right-click the setting, and
set it tothen selectEnabledEdit. - Select the setting, and then select Action > Edit.
Configure the settings as described in the following subsections.
Configure real-time protection settings in Group Policy
If a setting described in this article isn't available in Group Policy Management Editor, update the Administrative Templates in your Group Policy Central Store. The Central Store isn't updated automatically. For instructions, see How to create and manage the Central Store for Group Policy Administrative Templates in Windows
.Then select OK.
Configure the Microsoft Defender Antivirusfollowing policies to turn on real-time and behavior monitoring:
| Policy | Value |
|---|---|
| Turn off real-time protection | Disabled |
| Configure monitoring for incoming and outgoing file and program activity | Enabled, bi-directional (full on-access) |
| Turn on behavior monitoring | Enabled |
| Monitor file and program activity on your computer | Enabled |
In theGo to Microsoft Defender Antivirusdetails pane, double-click> Real-time Protection.Or, from- In the details pane of Real-time Protection, select a policy setting to view its description and supported options in the help pane. For a list of the settings and links to related guidance, see Group Policy settings and resources.
- Open each policy setting in the table, configure the specified value, and then select OK.
Turn on heuristics in Group Policy
Enable the heuristics policy in the Scan folder:
- Go to Microsoft Defender Antivirus
tree on left pane, select>Real-time ProtectionScan. In the
Real-time Protectiondetails pane of Scan, open Turn onright, double-click the policy setting as specified in Real-time protection policy settingsheuristics.Configure the setting as appropriate,Select Enabled, and then select OK.Repeat the previous steps for each setting in the table.
Configure the Microsoft Defender Antivirus scanning policy setting, as follows:
From theMicrosoft Defender Antivirustree on left pane, selectScan.In theScandetails pane on right, double-clickTurn on heuristics, and set it toEnabled.SelectOK.
Close Local Group Policy Editor.
Real-time protection policy settings
For the most current settings, get the latest ADMX files in the Group Policy Central Store. See How to create and manage the Central Store for Group Policy Administrative Templates in Windows and download the latest files.
Disable real-time protection in Group Policy
OpenLocalTo disable real-time protection by using GroupPolicy Editor.Policy:In your Windows 10 or Windows 11 taskbar search box, typegpedit.UnderBest match, selectEdit group policyGo tolaunchLocal Group Policy Editor.
In the left pane ofLocal Group Policy Editor, expand the tree toComputer Configuration>Administrative Templates>Windows Components>Microsoft Defender Antivirus > Real-time Protection.In the details pane of Real-time Protection
details pane on right, double-click, open Turn off real-time protection.- Select Enabled, and then select OK.
Configure always-on protection settings using PowerShell
Run the commands in an elevated PowerShell session (a PowerShell window you opened by selecting Run as administrator).
The following command turns on real-time monitoring and behavior monitoring, and configures Microsoft Defender Antivirus to scan incoming and outgoing files:
Set-MpPreference -DisableRealtimeMonitoring $false -DisableBehaviorMonitoring $false -RealTimeScanDirection Both
The following command displays the configured values:
Get-MpPreference | Select-Object DisableRealtimeMonitoring, DisableBehaviorMonitoring, RealTimeScanDirection
Verify that DisableRealtimeMonitoring and DisableBehaviorMonitoring are set to False, and RealTimeScanDirection is set to 0.
For detailed syntax and parameter information, see Set-MpPreference and Get-MpPreference.
Turn on real-time protection in the Windows Security app
You can use the Windows Security app to turn on real-time protection on an individual device. It doesn't provide separate controls for all the always-on protection settings described in this article.
To turn on real-time protection in the Windows Security app:
- In the
Turn offWindows security app on the device, go to Virus & threat protection. - In the Virus & threat protection pane, in the Virus & threat protection settings section, select Manage settings.
- In the Virus & threat protection settings pane, slide the Real-time protection toggle to :::image type="icon" source="media/toggle-on.png" border="false"::: On.
If your organization manages real-time protection, the Real-time protection setting window, set the option to Enabledmight be unavailable. If you turn off real-time protection, it turns on again automatically after a short delay.
For more information, see Microsoft Defender Antivirus in the Windows Security app.
select OK.
Close Local Group Policy Editor.
See also
Related content
- Configure behavioral, heuristic, and real-time protection
- Microsoft Defender Antivirus in Windows 10
Other platforms
If you're looking for antivirus-related information for other platforms, see:
- Set preferences for Microsoft Defender for Endpoint on macOS
- Microsoft Defender for Endpoint on Mac
- macOS Antivirus policy settings for Microsoft Defender Antivirus for Intune
- Microsoft Defender for Endpoint on Linux
- Configure Defender for Endpoint on Android features
- Configure Microsoft Defender for Endpoint on iOS features
@@ -1,6 +1,6 @@ ----title: Enable and configure Microsoft Defender Antivirus always-on protection-description: Enable and configure Microsoft Defender Antivirus real-time protection features such as behavior monitoring, heuristics, and machine learning.+title: Configure Microsoft Defender Antivirus always-on protection+description: Configure Microsoft Defender Antivirus always-on protection with supported management tools to monitor files, programs, and behavior for threats. ms.service: defender-endpoint ms.subservice: ngp ms.localizationpriority: medium@@ -8,9 +8,9 @@ author: chrisda ms.author: chrisda ms.reviewer: yongrhee ms.topic: how-to-ms.date: 07/02/2026-ms.custom: nextgen, msecd-doc-authoring-1016-ms.collection: +ms.date: 09/02/2026+ms.custom: nextgen, msecd-doc-authoring-1015+ms.collection: - m365-security - tier2 - mde-ngp@@ -19,134 +19,185 @@ appliesto: - Microsoft Defender for Endpoint Plan 2 - Microsoft Defender Antivirus +#customer intent: As a security administrator, I want to configure Microsoft Defender Antivirus always-on protection so that Windows devices continuously monitor files, programs, and behavior for threats.+ ai-usage: ai-assisted ----# Enable and configure Microsoft Defender Antivirus always-on protection- +# Enable and configure Microsoft Defender Antivirus always-on protection -Always-on protection consists of real-time protection, behavior monitoring, and heuristics to identify malware based on known suspicious and malicious activities. Suspicious and malicious activities include events, such as processes making unusual changes to existing files, modifying or creating automatic startup registry keys and startup locations (also known as autostart extensibility points, or ASEPs), and other changes to the file system or file structure. Always-on protection is an important part of your antivirus protection and should be enabled. +Always-on protection in Microsoft Defender Antivirus uses real-time protection, behavior monitoring, and heuristics to detect suspicious and malicious activity. Security administrators can configure these capabilities on Windows devices by using Microsoft Intune, the Microsoft Defender portal, Microsoft Configuration Manager, or Group Policy. You can also use PowerShell or the Windows Security app. Review the supported operating systems before you begin. > [!NOTE]-> [Tamper protection](prevent-changes-to-security-settings-with-tamper-protection.md) helps keep always-on protection and other security settings from being changed. As a result, when tamper protection is enabled, any changes made to [tamper-protected settings](prevent-changes-to-security-settings-with-tamper-protection.md#what-happens-when-tamper-protection-is-turned-on) are ignored. If you must make changes to a device and those changes are blocked by tamper protection, we recommend using [troubleshooting mode](enable-troubleshooting-mode.md) to temporarily disable tamper protection on the device. Note that after troubleshooting mode ends, any changes made to tamper-protected settings are reverted to their configured state.-> If a file that contains a threat is placed in an Azure file share, it's not remediated when placed. A user has to open the file for it to be detected by real-time protection.+> [Tamper protection](prevent-changes-to-security-settings-with-tamper-protection.md) helps keep always-on protection and other security settings from being changed. As a result, when tamper protection is enabled, any changes made to [tamper-protected settings](prevent-changes-to-security-settings-with-tamper-protection.md#what-happens-when-tamper-protection-is-turned-on) are ignored. To temporarily change tamper-protected settings for testing or diagnostics, use [troubleshooting mode](enable-troubleshooting-mode.md). After troubleshooting mode ends, the settings return to their configured values. To make permanent changes, update the policy in the management tool that configures the device.+>+> If a file containing a threat is added to an Azure file share, the file isn't remediated immediately. Real-time protection detects the threat when a user opens the file. ## Prerequisites -### Supported operating systems +### Supported operating systems The following operating systems support always-on protection: - Windows -## Manage antivirus settings with Microsoft Intune+To use the Intune procedure, enroll Windows devices in Intune.++Before using Configuration Manager, configure it for Endpoint Protection. For more information, see [Configure Endpoint Protection in Configuration Manager](/intune/configmgr/protect/deploy-use/endpoint-protection-configure).++## Configure always-on protection settings in Microsoft Intune -You can use Intune to configure antivirus policies, and then apply those policies across devices in your organization. Antivirus policies help security admins focus on managing the discrete group of antivirus settings for managed devices. Each antivirus policy includes several profiles. Each profile contains only the settings that are relevant for Microsoft Defender Antivirus for macOS and Windows devices, or for the user experience in the Windows Security app on Windows devices. For more information, see [Antivirus policy for endpoint security in Intune](/intune/intune-service/protect/endpoint-security-antivirus-policy).+[!INCLUDE [Intune is recommended but is a separate product](includes/intune-recommended-separate-product.md)] -To create a new policy and manage antivirus settings with Intune, see <a href="/intune/intune-service/protect/endpoint-security-policy#create-endpoint-security-policies" target="_blank">Create an endpoint security policy</a> (opens in a new tab in the Intune documentation). When creating a new policy for Windows, choose the following options:+To configure always-on protection settings in Microsoft Intune, use an endpoint security **Antivirus** policy. For detailed instructions, see <a href="/intune/intune-service/protect/endpoint-security-policy#create-endpoint-security-policies" target="_blank">Create endpoint security policies</a> or <a href="/intune/device-configuration/endpoint-security/manage-policies#modify-existing-policies" target="_blank">Modify existing policies</a> (links open new tabs in the Intune documentation). -- **Policy type**: Antivirus-- **Platform**: Windows 10, Windows 11, and Windows Server-- **Profile**: Microsoft Defender Antivirus-- **Basics**: Type a name and description for your policy.-- **Configuration settings**: Expand **Defender** and select the settings you want to use for your policy. To get help with your settings, refer to [Policy CSP - Defender](/windows/client-management/mdm/policy-csp-defender?WT.mc_id=Portal-fx).-- **Scope tags**: Choose **Select scope tags** to open the *Select tags* pane to assign scope tags to the profile.-- **Assignments**: Select the groups to receive this profile. For more information on assigning profiles, see [Assign user and device profiles](/intune/intune-service/configuration/device-profile-assign).+When you create the policy, use these specific settings: -When creating a new policy for macOS, choose the following options:+- **Policy type**: Go to **Manage** \> **Antivirus** on the **Endpoint security \| Overview** page at <https://intune.microsoft.com/#view/Microsoft_Intune_Workflows/SecurityManagementMenu/~/overview>.+- **Platform**: Select **Windows**.+- **Profile**: Select **Microsoft Defender Antivirus**. -- **Platform**: macOS-- **Profile**: Antivirus-- **Basics**: Type a name and description for your policy. On the -- **Configuration settings**: Select the settings you want to use for your policy. To get help with your settings, refer to [Set preferences for Microsoft Defender for Endpoint on macOS](mac-preferences.md).-- **Scope tags**: Choose **Select scope tags** to open the *Select tags* pane to assign scope tags to the profile-- **Assignments**: Select the groups to receive this profile. For more information on assigning profiles, see [Assign user and device profiles](/intune/intune-service/configuration/device-profile-assign)+When you create or modify the policy, use these specific settings on the **Configuration settings** tab: -To edit an existing policy for Windows devices, see <a href="/intune/device-configuration/endpoint-security/manage-policies#modify-existing-policies" target="_blank">Modify existing policies</a> (opens in a new tab in the Intune documentation). Select your policy, expand **Defender**, and edit settings for your policy. To get help with your settings, refer to [Policy CSP - Defender](/windows/client-management/mdm/policy-csp-defender?WT.mc_id=Portal-fx).+- In the **Defender** section, configure the following settings:+ - **Allow Real-Time Monitoring**: Select **Allowed**.+ - **Allow On Access Protection**: Select **Allowed**.+ - **Real Time Scan Direction**: Select **Monitor all files (bi-directional)**.+ - **Allow behavior monitoring**: Select **Allowed**. -To edit an existing policy for macOS devices, select your policy, select **Properties**, and choose **Edit** next to **Configuration settings**. Edit the policy settings under **Microsoft Defender for Endpoint**. To get help with your settings, refer to [Set preferences for Microsoft Defender for Endpoint on macOS](mac-preferences.md).+The Microsoft Defender Antivirus profile doesn't include a separate setting for heuristics. Heuristics are part of real-time protection. For descriptions of all available Windows settings, options, defaults, recommendations, and CSP mappings, see [Configure Microsoft Defender Antivirus using Microsoft Intune](use-intune-config-manager-microsoft-defender-antivirus.md#policies-and-settings). -## Are you using Group Policy?+## Configure always-on protection settings in the Microsoft Defender portal -> [!IMPORTANT]-> We recommend using [Microsoft Intune](/intune/intune-service/fundamentals/what-is-intune) to manage Microsoft Defender Antivirus settings for your organization. With Intune, you can control where tamper protection is enabled (or disabled) through policies. You can also protect Microsoft Defender Antivirus exclusions. For more information, see [Protect Microsoft Defender Antivirus exclusions from tampering](prevent-changes-to-security-settings-with-tamper-protection.md#protect-microsoft-defender-antivirus-exclusions).+If your organization [manages endpoint security policies in the Microsoft Defender portal](endpoint-security-policies-configure.md), use a Microsoft Defender Antivirus policy to configure always-on protection. -You can use Group Policy to manage some Microsoft Defender Antivirus settings. If [tamper protection](prevent-changes-to-security-settings-with-tamper-protection.md) is enabled in your organization, any changes made to [tamper-protected settings](prevent-changes-to-security-settings-with-tamper-protection.md#what-happens-when-tamper-protection-is-turned-on) are ignored. You can't turn off tamper protection by using Group Policy. +For detailed instructions, see <a href="endpoint-security-policies-configure.md#create-an-endpoint-security-policy" target="_blank">Create an endpoint security policy</a> or <a href="endpoint-security-policies-configure.md#edit-an-endpoint-security-policy" target="_blank">Edit an endpoint security policy</a> (links open new tabs). -If you must make changes to a device and those changes are blocked by tamper protection, we recommend using [troubleshooting mode](enable-troubleshooting-mode.md) to temporarily disable tamper protection on the device. After troubleshooting mode ends, any changes made to tamper-protected settings are reverted to their configured state.- -You can use **Local Group Policy Editor** to enable and configure Microsoft Defender Antivirus always-on protection settings.+When you create the policy on the **Endpoint security policies** page in the Microsoft Defender portal at <https://security.microsoft.com/policy-inventory>, use these specific settings: -### Enable and configure always-on protection using Group Policy+- **Select platform**: Select **Windows**.+- **Select template**: Select **Microsoft Defender Antivirus**. -This procedure applies to Windows 10 and Windows 11 devices.+When you create or modify the policy, use these specific settings on the **Configuration settings** tab: -Use the following steps to enable and configure always-on protection using Local Group Policy Editor:+- In the **Defender** section, configure the following settings:+ - **Allow Real-Time Monitoring**: Select **Allowed**.+ - **Allow On Access Protection**: Select **Allowed**.+ - **Real Time Scan Direction**: Select **Monitor all files (bi-directional)**.+ - **Allow behavior monitoring**: Select **Allowed**. -1. Open **Local Group Policy Editor**, as follows:+The Microsoft Defender Antivirus template doesn't include a separate setting for heuristics. Heuristics are part of real-time protection. - 1. In your taskbar search box, type **gpedit**.+## Configure always-on protection settings in Microsoft Configuration Manager - 1. Under **Best match**, select **Edit group policy** to launch **Local Group Policy Editor**.- - :::image type="content" source="media/gpedit-search.png" alt-text="The GPEdit taskbar search result in the Control panel" lightbox="media/gpedit-search.png":::+For instructions to create and deploy an antimalware policy, see [Endpoint Protection antimalware policies in Configuration Manager](/intune/configmgr/protect/deploy-use/endpoint-antimalware-policies). -1. In the left pane of **Local Group Policy Editor**, expand the tree to **Computer Configuration** \> **Administrative Templates** \> **Windows Components** \> **Microsoft Defender Antivirus**.+In the **Real-time protection** settings of the antimalware policy, configure the following settings: -1. Configure the Microsoft Defender Antivirus antimalware service policy setting.+- **Enable real-time protection**: Select **Yes**.+- **Monitor file and program activity on your computer**: Select **Yes**.+- **Scan system files**: Select **Scan incoming and outgoing files**.+- **Enable behavior monitoring**: Select **Yes**. - In the **Microsoft Defender Antivirus** details pane on right, double-click **Allow antimalware service to start up with normal priority**, and set it to **Enabled**.+<a name="group-policy"></a> - Then select **OK**.+## Configure always-on protection settings in Group Policy -1. Configure the Microsoft Defender Antivirus real-time protection policy settings, as follows:+You can use Group Policy to manage some Microsoft Defender Antivirus settings. If [tamper protection](prevent-changes-to-security-settings-with-tamper-protection.md) is enabled in your organization, any changes made to [tamper-protected settings](prevent-changes-to-security-settings-with-tamper-protection.md#what-happens-when-tamper-protection-is-turned-on) are ignored. You can't turn off tamper protection by using Group Policy. - 1. In the **Microsoft Defender Antivirus** details pane, double-click **Real-time Protection**. Or, from the **Microsoft Defender Antivirus** tree on left pane, select **Real-time Protection**.+To temporarily change tamper-protected settings for testing or diagnostics, use [troubleshooting mode](enable-troubleshooting-mode.md). After troubleshooting mode ends, the settings return to their configured values. To make permanent changes, use a management tool that supports changes to tamper-protected settings, such as Intune. - 1. In the **Real-time Protection** details pane on right, double-click the policy setting as specified in [Real-time protection policy settings](#real-time-protection-policy-settings).+The following procedure applies to Windows devices. - 1. Configure the setting as appropriate, and select **OK**.+1. In Centralized Group Policy, open the [Group Policy Management Console (GPMC)](/windows-server/identity/ad-ds/manage/group-policy/group-policy-management-console) on your Group Policy management computer.+1. In the GPMC console tree, expand **Group Policy Objects** in the forest and domain containing the Group Policy Object (GPO) you want to edit.+1. Right-click the GPO, and then select **Edit**.+1. In the **Group Policy Management Editor**, go to **Computer configuration** \> **Administrative templates** \> **Windows components** \> **Microsoft Defender Antivirus**.+1. In the details pane of **Microsoft Defender Antivirus**, the folders used to configure always-on protection are:+ - **Real-time Protection**: [Configure real-time protection settings](#configure-real-time-protection-settings-in-group-policy).+ - **Scan**: [Turn on heuristics](#turn-on-heuristics-in-group-policy). - 1. Repeat the previous steps for each setting in the table.+ To open and configure a setting, use any of the following methods:+ - Double-click the setting.+ - Right-click the setting, and then select **Edit**.+ - Select the setting, and then select **Action** \> **Edit**. -1. Configure the Microsoft Defender Antivirus scanning policy setting, as follows:+> [!TIP]+> You can also configure Group Policy locally on individual devices by using the Local Group Policy Editor (`gpedit.msc`). Navigate to the same path: **Computer configuration** \> **Administrative templates** \> **Windows components** \> **Microsoft Defender Antivirus**. - 1. From the **Microsoft Defender Antivirus** tree on left pane, select **Scan**.- - 1. In the **Scan** details pane on right, double-click **Turn on heuristics**, and set it to **Enabled**. +Configure the settings as described in the following subsections. - 1. Select **OK**.+### Configure real-time protection settings in Group Policy -1. Close **Local Group Policy Editor**.+If a setting described in this article isn't available in Group Policy Management Editor, update the Administrative Templates in your Group Policy Central Store. The Central Store isn't updated automatically. For instructions, see [How to create and manage the Central Store for Group Policy Administrative Templates in Windows](/troubleshoot/windows-client/group-policy/create-and-manage-central-store). -### Real-time protection policy settings+Configure the following policies to turn on real-time and behavior monitoring: -For the most current settings, get the latest ADMX files in the Group Policy Central Store. See [How to create and manage the Central Store for Group Policy Administrative Templates in Windows](/troubleshoot/windows-client/group-policy/create-and-manage-central-store) and download the latest files. +|Policy|Value|+|---|---|+|Turn off real-time protection|Disabled|+|Configure monitoring for incoming and outgoing file and program activity|Enabled, bi-directional (full on-access)|+|Turn on behavior monitoring|Enabled|+|Monitor file and program activity on your computer|Enabled|++1. Go to **Microsoft Defender Antivirus** \> **Real-time Protection**.+1. In the details pane of **Real-time Protection**, select a policy setting to view its description and supported options in the help pane. For a list of the settings and links to related guidance, see [Group Policy settings and resources](use-group-policy-microsoft-defender-antivirus.md#group-policy-settings-and-resources).+1. Open each policy setting in the table, configure the specified value, and then select **OK**.++### Turn on heuristics in Group Policy++Enable the heuristics policy in the **Scan** folder:++1. Go to **Microsoft Defender Antivirus** \> **Scan**.+1. In the details pane of **Scan**, open **Turn on heuristics**.+1. Select **Enabled**, and then select **OK**. ### Disable real-time protection in Group Policy > [!WARNING]-> **Disabling real-time protection drastically reduces the protection on your endpoints and is not recommended**. In addition, if [tamper protection](prevent-changes-to-security-settings-with-tamper-protection.md) is enabled, you cannot turn it off by using Group Policy. If you must make changes to a device and those changes are blocked by tamper protection, we recommend using [troubleshooting mode](enable-troubleshooting-mode.md) to temporarily disable tamper protection on the device. Note that after troubleshooting mode ends, any changes made to tamper-protected settings are reverted to their configured state.+> Disabling real-time protection drastically reduces the protection on your endpoints and isn't recommended. If [tamper protection](prevent-changes-to-security-settings-with-tamper-protection.md) is enabled, you can't turn off real-time protection by using Group Policy. To turn off real-time protection temporarily for testing or diagnostics, use [troubleshooting mode](enable-troubleshooting-mode.md). After troubleshooting mode ends, real-time protection returns to its configured value.++To disable real-time protection by using Group Policy: -1. Open **Local Group Policy Editor**.+1. Go to **Microsoft Defender Antivirus** \> **Real-time Protection**.+1. In the details pane of **Real-time Protection**, open **Turn off real-time protection**.+1. Select **Enabled**, and then select **OK**. - 1. In your Windows 10 or Windows 11 taskbar search box, type `gpedit`.+## Configure always-on protection settings using PowerShell - 1. Under **Best match**, select **Edit group policy** to launch **Local Group Policy Editor**.+Run the commands in an elevated PowerShell session (a PowerShell window you opened by selecting **Run as administrator**). -1. In the left pane of **Local Group Policy Editor**, expand the tree to **Computer Configuration** \> **Administrative Templates** \> **Windows Components** \> **Microsoft Defender Antivirus** \> **Real-time Protection**.+The following command turns on real-time monitoring and behavior monitoring, and configures Microsoft Defender Antivirus to scan incoming and outgoing files: -1. In the **Real-time Protection** details pane on right, double-click **Turn off real-time protection**.+```powershell+Set-MpPreference -DisableRealtimeMonitoring $false -DisableBehaviorMonitoring $false -RealTimeScanDirection Both+``` -1. In the **Turn off real-time protection** setting window, set the option to **Enabled**.- -1. select **OK**.+The following command displays the configured values: -1. Close **Local Group Policy Editor**.+```powershell+Get-MpPreference | Select-Object DisableRealtimeMonitoring, DisableBehaviorMonitoring, RealTimeScanDirection+``` -## See also+Verify that _DisableRealtimeMonitoring_ and _DisableBehaviorMonitoring_ are set to `False`, and _RealTimeScanDirection_ is set to `0`. -### Related content+For detailed syntax and parameter information, see [**Set-MpPreference**](/powershell/module/defender/set-mppreference) and [**Get-MpPreference**](/powershell/module/defender/get-mppreference).++## Turn on real-time protection in the Windows Security app++You can use the [Windows Security app](https://support.microsoft.com/Windows/Security/Windows-Security/stay-protected-with-the-windows-security-app) to turn on real-time protection on an individual device. It doesn't provide separate controls for all the always-on protection settings described in this article.++To turn on real-time protection in the Windows Security app:++1. In the **Windows security** app on the device, go to **Virus & threat protection**.+1. In the **Virus & threat protection** pane, in the **Virus & threat protection settings** section, select **Manage settings**.+1. In the **Virus & threat protection settings** pane, slide the **Real-time protection** toggle to :::image type="icon" source="media/toggle-on.png" border="false"::: **On**.++If your organization manages real-time protection, the **Real-time protection** setting might be unavailable. If you turn off real-time protection, it turns on again automatically after a short delay.++For more information, see [Microsoft Defender Antivirus in the Windows Security app](microsoft-defender-security-center-antivirus.md).++## Related content - [Configure behavioral, heuristic, and real-time protection](configure-protection-features-microsoft-defender-antivirus.md) - [Microsoft Defender Antivirus in Windows 10](microsoft-defender-antivirus-windows.md)@@ -154,6 +205,7 @@ For the most current settings, get the latest ADMX files in the Group Policy Cen ### Other platforms If you're looking for antivirus-related information for other platforms, see:+ - [Set preferences for Microsoft Defender for Endpoint on macOS](mac-preferences.md) - [Microsoft Defender for Endpoint on Mac](microsoft-defender-endpoint-mac.md) - [macOS Antivirus policy settings for Microsoft Defender Antivirus for Intune](/intune/intune-service/protect/antivirus-microsoft-defender-settings-macos)@@ -161,6 +213,3 @@ If you're looking for antivirus-related information for other platforms, see: - [Microsoft Defender for Endpoint on Linux](microsoft-defender-endpoint-linux.md) - [Configure Defender for Endpoint on Android features](android-configure.md) - [Configure Microsoft Defender for Endpoint on iOS features](ios-configure-features.md)--- 