Microsoft Defender for Endpoint
Endpoint protection

Configure Microsoft Defender Antivirus always-on protection

In brief

The page now focuses on configuring always-on protection, identifies supported management tools, adds Intune and Configuration Manager prerequisites, and updates the Intune procedure and links.

What Defender admins need to know

Administrators have clearer guidance for selecting and preparing management tools; no immediate action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Enable and configure Microsoft Defender Antivirus always-on protection

Always-on protection consists ofin Microsoft Defender Antivirus uses real-time protection, behavior monitoring, and heuristics to identify malware based on knowndetect suspicious and malicious activities. Suspicious and malicious activities include events, such as processes making unusual changes to existing files, modifyingactivity. Security administrators can configure these capabilities on Windows devices by using Microsoft Intune, the Microsoft Defender portal, Microsoft Configuration Manager, or creating automatic startup registry keys and startup locations (also known as autostart extensibility points,Group Policy. You can also use PowerShell or ASEPs), and other changes to the file system or file structure. Always-on protection is an important part of your antivirus protection and should be enabled. Windows Security app. Review the supported operating systems before you begin.

Prerequisites

Supported operating systems

The following operating systems support always-on protection:

  • Windows

Manage antivirus settings with Microsoft

To use the Intune

You can use Intune to configure antivirus policies, and then apply those policies across procedure, enroll Windows devices in your organization. Antivirus policies help security admins focus on managing the discrete group of antivirus settingsIntune.

Before using Configuration Manager, configure it for managed devices. Each antivirus policy includes several profiles. Each profile contains only the settings that are relevant for Microsoft Defender Antivirus for macOS and Windows devices, or for the user experience in the Windows Security app on Windows devices.Endpoint Protection. For more information, see Antivirus policy for endpoint security in IntuneConfigure Endpoint Protection in Configuration Manager.

Configure always-on protection settings in Microsoft Intune

[!INCLUDE Intune is recommended but is a separate product]

To create a new policy and manage antivirusconfigure always-on protection settings within Microsoft Intune, use an endpoint security Antivirus policy. For detailed instructions, see Create endpoint security policies (opens in aor Modify existing policies (links open new tabtabs in the Intune documentation).

When creating a new policy for Windows, chooseyou create the following options:policy, use these specific settings:

  • Policy type: Go to Manage > Antivirus on the Endpoint security | Overview page at https://intune.microsoft.com/#view/Microsoft_Intune_Workflows/SecurityManagementMenu/~/overview.
  • Platform: Select Windows 10, Windows 11, and Windows Server.
  • Profile: Select Microsoft Defender Antivirus
  • Basics: Type a name and description for your policy.
  • Configuration settings: Expand Defender and select the settings you want to use for your policy. To get help with your settings, refer to Policy CSP - Defender.
  • Scope tags: Choose Select scope tags to open the Select tags pane to assign scope tags to the profile.
  • Assignments: Select the groups to receive this profile. For more information on assigning profiles, see Assign user and device profiles.

When creating a new policy for macOS, chooseyou create or modify the policy, use these specific settings on the Configuration settings tab:

  • In the Defender section, configure the following options:settings:
    • Allow Real-Time Monitoring: Select Allowed.
    • Allow On Access Protection: Select Allowed.
    • Real Time Scan Direction: Select Monitor all files (bi-directional).
    • Allow behavior monitoring: Select Allowed.

The Microsoft Defender Antivirus profile doesn't include a separate setting for heuristics. Heuristics are part of real-time protection. For descriptions of all available Windows settings, options, defaults, recommendations, and CSP mappings, see Configure Microsoft Defender Antivirus using Microsoft Intune.

Configure always-on protection settings in the Microsoft Defender portal

If your organization manages endpoint security policies in the Microsoft Defender portal, use a Microsoft Defender Antivirus policy to configure always-on protection.

For detailed instructions, see Create an endpoint security policy or Edit an endpoint security policy (links open new tabs).

When you create the policy on the Endpoint security policies page in the Microsoft Defender portal at https://security.microsoft.com/policy-inventory, use these specific settings:

  • PlatformSelect platform: macOSSelect Windows.
  • ProfileSelect template: Select Microsoft Defender Antivirus.
  • Basics: Type a name and description for your policy. On

When you create or modify the

  • policy, use these specific settings on the Configuration settings tab:
    • In the Defender section, configure the following settings:
      • Allow Real-Time Monitoring: Select the settings you want to use for your policy. To get help with your settings, refer to Set preferences for Microsoft Defender for Endpoint on macOSAllowed.
      • Scope tags: Choose Select scope tags to open the Select tags pane to assign scope tags to the profile
      • AssignmentsAllow On Access Protection: Select the groups to receive this profile. For more information on assigning profiles, see Assign user and device profilesAllowed.
      • Real Time Scan Direction: Select Monitor all files (bi-directional).
      • Allow behavior monitoring: Select Allowed.

    To edit an existing policy for Windows devices, see Modify existing policies (opens in a new tab in the Intune documentation). Select your policy, expand Defender, and edit settings for your policy. To get help with your settings, refer to Policy CSP - Defender.

    To edit an existing policy for macOS devices, select your policy, select Properties, and choose Edit next to Configuration settings. Edit the policy settings under Microsoft Defender for Endpoint. To get help with your settings, refer to Set preferences for Microsoft Defender for Endpoint on macOS.

    Are you using Group Policy?

    In the Real-time protection settings of the antimalware policy, configure the following settings:

    • Enable real-time protection: Select Yes.
    • Monitor file and program activity on your computer: Select Yes.
    • Scan system files: Select Scan incoming and outgoing files.
    • Enable behavior monitoring: Select Yes.

    Configure always-on protection settings in Group Policy

    You can use Group Policy to manage some Microsoft Defender Antivirus settings. If tamper protection is enabled in your organization, any changes made to tamper-protected settings are ignored. You can't turn off tamper protection by using Group Policy.

    If you must make changes to a device and those changes are blocked by tamper protection, we recommend usingTo temporarily change tamper-protected settings for testing or diagnostics, use troubleshooting mode to temporarily disable tamper protection on the device.. After troubleshooting mode ends, anythe settings return to their configured values. To make permanent changes, use a management tool that supports changes made to tamper-protected settings are reverted to their configured state.settings, such as Intune.

    You can use Local Group Policy Editor to enable and configure Microsoft Defender Antivirus always-on protection settings.

    Enable and configure always-on protection using Group Policy

    ThisThe following procedure applies to Windows 10 and Windows 11 devices.

    Use the following steps to enable and configure always-on protection using Local Group Policy Editor:

    1. Open Local Group Policy Editor, as follows:

      1. In Centralized Group Policy, open the Group Policy Management Console (GPMC) on your taskbar search box, typeGroup Policy management computer.

      2. In the GPMC console tree, expand gpeditGroup Policy Objects in the forest and domain containing the Group Policy Object (GPO) you want to edit.

      3. Right-click the GPO, and then select Edit.

      4. UnderIn the Best match, select Edit group policy to launch Local Group Policy Editor.

        :::image type="content" source="media/gpedit-search.png" alt-text="The GPEdit taskbar search result in the Control panel" lightbox="media/gpedit-search.png":::

    2. In the left pane of Local Group PolicyManagement Editor, expand the treego to Computer Configurationconfiguration > Administrative Templatestemplates > Windows Componentscomponents > Microsoft Defender Antivirus.

    3. ConfigureIn the Microsoft Defender Antivirus antimalware service policy setting.

      In thedetails pane of Microsoft Defender Antivirus details pane , the folders used to configure always-on right, double-protection are:

      To open and configure a setting, use any of the following methods:

      • Double-click Allow antimalware service to start up with normal priority,the setting.
      • Right-click the setting, and set it tothen select EnabledEdit.
      • Select the setting, and then select Action > Edit.

    Configure the settings as described in the following subsections.

    Configure real-time protection settings in Group Policy

    If a setting described in this article isn't available in Group Policy Management Editor, update the Administrative Templates in your Group Policy Central Store. The Central Store isn't updated automatically. For instructions, see How to create and manage the Central Store for Group Policy Administrative Templates in Windows.

    Then select OK.

  • Configure the Microsoft Defender Antivirusfollowing policies to turn on real-time and behavior monitoring:

    PolicyValue
    Turn off real-time protection policy settings, as follows:Disabled
    Configure monitoring for incoming and outgoing file and program activityEnabled, bi-directional (full on-access)
    Turn on behavior monitoringEnabled
    Monitor file and program activity on your computerEnabled
    1. In theGo to Microsoft Defender Antivirus details pane, double-click> Real-time Protection. Or, from

    2. In the details pane of Real-time Protection, select a policy setting to view its description and supported options in the help pane. For a list of the settings and links to related guidance, see Group Policy settings and resources.
    3. Open each policy setting in the table, configure the specified value, and then select OK.

    Turn on heuristics in Group Policy

    Enable the heuristics policy in the Scan folder:

    1. Go to Microsoft Defender Antivirus tree on left pane, select> Real-time ProtectionScan.
    2. In the Real-time Protectiondetails pane of Scan, open Turn on right, double-click the policy setting as specified in Real-time protection policy settingsheuristics.

    3. Configure the setting as appropriate,Select Enabled, and then select OK.

    4. Repeat the previous steps for each setting in the table.

  • Configure the Microsoft Defender Antivirus scanning policy setting, as follows:

    1. From the Microsoft Defender Antivirus tree on left pane, select Scan.

    2. In the Scan details pane on right, double-click Turn on heuristics, and set it to Enabled.

    3. Select OK.

  • Close Local Group Policy Editor.

  • Real-time protection policy settings

    For the most current settings, get the latest ADMX files in the Group Policy Central Store. See How to create and manage the Central Store for Group Policy Administrative Templates in Windows and download the latest files.

    Disable real-time protection in Group Policy

    1. Open LocalTo disable real-time protection by using Group Policy Editor.Policy:

      1. In your Windows 10 or Windows 11 taskbar search box, type gpedit.

      2. Under Best match, select Edit group policyGo to launch Local Group Policy Editor.

    2. In the left pane of Local Group Policy Editor, expand the tree to Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Antivirus > Real-time Protection.

    3. In the details pane of Real-time Protection details pane on right, double-click, open Turn off real-time protection.

    4. Select Enabled, and then select OK.

    Configure always-on protection settings using PowerShell

    Run the commands in an elevated PowerShell session (a PowerShell window you opened by selecting Run as administrator).

    The following command turns on real-time monitoring and behavior monitoring, and configures Microsoft Defender Antivirus to scan incoming and outgoing files:

    Set-MpPreference -DisableRealtimeMonitoring $false -DisableBehaviorMonitoring $false -RealTimeScanDirection Both
    

    The following command displays the configured values:

    Get-MpPreference | Select-Object DisableRealtimeMonitoring, DisableBehaviorMonitoring, RealTimeScanDirection
    

    Verify that DisableRealtimeMonitoring and DisableBehaviorMonitoring are set to False, and RealTimeScanDirection is set to 0.

    For detailed syntax and parameter information, see Set-MpPreference and Get-MpPreference.

    Turn on real-time protection in the Windows Security app

    You can use the Windows Security app to turn on real-time protection on an individual device. It doesn't provide separate controls for all the always-on protection settings described in this article.

    To turn on real-time protection in the Windows Security app:

    1. In the Turn offWindows security app on the device, go to Virus & threat protection.
    2. In the Virus & threat protection pane, in the Virus & threat protection settings section, select Manage settings.
    3. In the Virus & threat protection settings pane, slide the Real-time protection toggle to :::image type="icon" source="media/toggle-on.png" border="false"::: On.

    If your organization manages real-time protection, the Real-time protection setting window, set the option to Enabledmight be unavailable. If you turn off real-time protection, it turns on again automatically after a short delay.

    For more information, see Microsoft Defender Antivirus in the Windows Security app.

  • select OK.

  • Close Local Group Policy Editor.

  • See also

    Related content

    Other platforms

    If you're looking for antivirus-related information for other platforms, see: