Microsoft Defender for Endpoint
Endpoint protection

Configure Microsoft Defender Antivirus cloud block time-out

In brief

The article now clarifies the 10-second default, 50-second extension limit, required prerequisites, Windows Server notes, and the Microsoft Intune Antivirus policy configuration path.

What Defender admins need to know

Administrators configuring this setting should follow the updated prerequisites and Intune steps; existing configurations require no action.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Configure the Microsoft Defender Antivirus cloud block time time-out period

When Microsoft Defender Antivirus finds a suspicious file, it can prevent the file from running while it queries the Microsoft Defender Antivirus cloud service.

The default period thatBy default, Block at first sight blocks the file is blocked by Block at first sight isfor 10 seconds. If you'reseconds while waiting for a security administrator, youcloud determination. You can specify more timeadd up to wait before the file is allowed to run. Extending the cloud block time 50 seconds, for a maximum time-out period can help ensure there's enough time to receive a proper determination from the Microsoft Defender Antivirus cloud service.of 60 seconds. Before you begin, review the prerequisites for this feature.

Prerequisites

Block at first sight and its prerequisites must be enabled beforeBefore you can specify an extended time time-out period.period, enable Block at first sight, cloud protection, and automatic sample submission. Keep Microsoft Defender Antivirus up to date on the devices.

Supported operating systems

  • Windows
  • Windows Server

Specify the extended time time-out period using Microsoft Defender for Endpoint Security settings managementIntune

[!INCLUDE intune-recommended-separate-product]

To specify the cloud block time time-out period within Microsoft Defender for Endpoint Security settings management:Intune, use an endpoint security Antivirus policy. For detailed instructions, see Create endpoint security policies or Modify existing policies (links open new tabs in the Intune documentation).

    When you create the policy, use these specific settings:

    When you create or modify the Defender dropdown, go topolicy, use these specific settings on the Configuration settings tab:

    • Slide the toggle for Cloud Extended Timeout and toggle it to :::image type="icon" source="media/toggle-on.png" border="false"::: Configured.
    • SpecifyIn the extended time, in seconds,box that appears, specify a value from 1 second0 to 50 seconds. Whatever you specifyThe value is added to the default 1010-second time-out period. For example, enter 50 for a total time-out period of 60 seconds.
    • Select Next and Save to finish configuring your policy.

Specify the extended time time-out period using the Microsoft IntuneDefender portal

ToIf your organization manages endpoint security policies in the Microsoft Defender portal, you specify the cloud block time time-out period with an endpoint security policy in Microsoft Intune,the same endpoint security policies that Intune uses.

For detailed instructions, see Modify existing policies (opens in aCreate an endpoint security policy or Edit an endpoint security policy (links open new tabs).

When you create the policy on the Windows policiestab of the Endpoint security policies page in the Intune documentation). When modifying the endpoint security policy,Defender portal at https://security.microsoft.com/policy-inventory?osPlatform=Windows, use these specific settings:

  • Select platform: Select Windows.
  • Select template: Select Microsoft Defender Antivirus.

When you create or modify the policy, use these specific settings on the Configuration settings: Scroll down to tab:

  • Slide the toggle for Cloud Extended Timeout andto :::image type="icon" source="media/toggle-on.png" border="false"::: Configured.
  • In the box that appears, specify the time out, in seconds,a value from 0 to 50 seconds. Whatever you specifyThe value is added to the default 1010-second time-out period. For example, enter 50 for a total time-out period of 60 seconds.
  • (Optional) Make any other changes to your antivirus policy. (Need help? See Settings for Microsoft Defender Antivirus policy in Microsoft Intune.)

Specify the extended time time-out period using Microsoft Configuration Manager

For instructions to create and deploy an antimalware policy, see Endpoint Protection antimalware policies in Configuration Manager.

In the Cloud Protection Service settings of the antimalware policy, configure Allow extended cloud check to block and scan for up to (seconds). Enter a value from 0 to 50. The value is added to the default 10-second time-out period.

Specify the extended time-out period using Group Policy

You can use Group Policy to specify an extended time time-out period for cloud checks.

  1. OnIn Centralized Group Policy, open the Group Policy Management Console (GPMC) on your Group Policy management computer, opencomputer.

  2. In the Group Policy Management ConsoleGPMC console tree, expand Group Policy Objects in the forest and domain containing the GPO you want to edit.

  3. Right-click the Group Policy Object you want to configureGPO, and then select Edit.

  4. In the Group Policy Management Editor, go to Computer configuration, and then select > Administrative templates.

  5. Expand the tree to > Windows components > Microsoft Defender Antivirus > MpEngine.

  1. In the details pane of MpEngine, open the Configure extended cloud check setting. To open the setting, use any of the following methods:

    • Double-click the setting.
    • Right-click the setting, and then select Edit.
    • Select the setting, and then select Action > Edit.
  2. In the setting window that opens, select Enabled.

  3. In the Options section, for Specify the extended cloud check time in seconds, enter the extra time that Defender Antivirus prevents the file from running while waiting for a cloud determination. Enter a value from 0 to 50. The value is added to the default 10-second time-out period.

  4. Select OK.

Specify the extended time-out period using PowerShell

In an elevated PowerShell session (a PowerShell window you opened by selecting Run as administrator), replace <0-50> with an integer from 0 to 50, and then run the following command:

Set-MpPreference -CloudExtendedTimeout <0-50>

For example, the following command adds 50 seconds to the default 10-second period, for a total of 60 seconds:

Set-MpPreference -CloudExtendedTimeout 50

For detailed syntax and parameter information, see Set-MpPreference.

Double-click Configure extended cloud check

Related content

For information about Microsoft Defender Antivirus and ensure the option is enabled. Defender for Endpoint on other platforms, see:

Specify the extra amount of time to prevent the file from running while waiting for a cloud determination. Specify the extra time, in seconds, from 1 second to 50 seconds. Whatever you specify is added to the default 10 seconds.