Microsoft Defender for Endpoint
Endpoint protection

Configure Microsoft Defender Antivirus notifications that appear on endpoints

In brief

The article now provides clearer GPMC navigation, updated links, the full policy path, guidance for older Windows policy names, and instructions for configuring the setting locally with Local Group Policy Editor.

What Defender admins need to know

Administrators can use the revised steps to find and configure notification settings more easily. No action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Configure Microsoft Defender Antivirus notifications that appear on endpoints

This article explains how to configure Microsoft Defender Antivirus notifications on Windows endpoints, including threat-detection, scan-completion, and reboot-required notifications.

You can configure the display of enhanced notifications (additional notification summaries such as recent threat detections) in the Windows Security app and with Group Policy.

Setting Description
Configure time interval for service health reports This policy setting configures the time interval (in minutes) for the service health reports to be sent from endpoints. If you disable or don't configure this setting, the default value is applied. The default value is set at 60 minutes (1 hour). If you configure this setting to 0, no service health reports are sent. The maximum value allowed to be set is 14400 minutes (10 days).
Configure time out for detections in critically failed state This policy setting configures the time in minutes before a detection in the "critically failed" state to moves to either the "additional action" state or the "cleared" state.
Configure time out for detections in noncritical failed state This policy setting configures the time in minutes before a detection in the "non-critically failed" state moves to the "cleared" state.
Configure WPP tracing level This policy allows you to configure tracing levels for Windows software trace preprocessor (WPP Software Tracing). Tracing levels are defined as: 1 - Error 2 - Warning 3 - Info 4 - Debug
Turn off enhanced notifications Use this policy setting to specify if you want Microsoft Defender Antivirus enhanced notifications to display on clients. If you disable or do not configure this setting, Microsoft Defender Antivirus enhanced notifications will display on clients. If you enable this setting, Microsoft Defender Antivirus enhanced notifications will not display on clients.

Use Group Policy to disable other notifications

To disable additional notifications by using Group Policy, perform the following steps:

  1. In Centralized Group Policy, open the Group Policy Management Console (GPMC). on your Group Policy management computer.

  2. In the GPMC console tree, expand Group Policy Objects in the forest and domain containing the GPO you want to edit.

  3. Right-click the Group Policy Object you want to configure,GPO, and then select Edit.

  4. In the Group Policy Management Editor, go to Computer configuration.

  5. Select > Administrative templates.

  6. Expand the tree to > Windows components > Microsoft Defender Antivirus > Reporting.

  7. Double-click Turn off enhanced notifications, and set the option to Enabled. Then select OK. Enabling Turn off enhanced notifications prevents additional notifications from appearing.

  1. In the details pane of Reporting, open the Turn off enhanced notifications setting. To open the setting, use any of the following methods:

    • Double-click the setting.
    • Right-click the setting, and then select Edit.
    • Select the setting, and then select Action > Edit.
  2. In the setting window that opens, select Enabled, and then select OK.

    Enabling Turn off enhanced notifications prevents more notifications from appearing.

Use the Windows Security app to disable additional notifications

Use the following steps to disable additional notifications in the Windows Security app:

  1. Open the Windows Security app by clicking the shield icon in the task bar or searching the start menu for Security.

  2. Slide the switch to Off or On to disable or enable other notifications.

Configure standard notifications on endpoints using Group Policy

Hide notifications with Group Policy

  • Hide all notifications on endpoints
  • Hide reboot notifications on endpoints

Hiding notifications can be useful in situations where you can't hide the entire Microsoft Defender Antivirus interface. See Prevent users from seeing or interacting with the Microsoft Defender Antivirus user interface for more information. Hiding notifications will only occur on endpoints to which the policy is deployed. Notifications related to actions that must be taken (such as a reboot) will still appear on the Microsoft Configuration Manager Endpoint Protection monitoring dashboard and reports.

To add custom contact information to endpoint notifications, see Customize the Windows Security app for your organizationCustomize the Windows Security app for your organization.

Use Group Policy to hide notifications

To hide all notifications by using Group Policy, perform the following steps:

  1. OnIn Centralized Group Policy, open the Group Policy Management Console (GPMC) on your Group Policy management computer, opencomputer.

  2. In the Group Policy Management Console.GPMC console tree, expand Group Policy Objects in the forest and domain containing the GPO you want to edit.

  3. Right-click the Group Policy Object you want to configure,GPO, and then select Edit.

  4. In the Group Policy Management Editor, go to Computer configuration and then select> Administrative templates.

  5. Expand the tree to > Windows components > Microsoft Defender Antivirus > Client interface.

  6. Double-click Suppress all notifications and set the option to Enabled.

  7. Select OK. Enabling Suppress all notifications prevents additional notifications from appearing.

Use Group Policy to hide reboot notifications

To hide reboot notifications by using Group Policy, perform the following steps:

  1. On

    1. In the details pane of Client interface, open the Suppress all notifications setting. To open the setting, use any of the following methods:
      • Double-click the setting.
      • Right-click the setting, and then select Edit.
      • Select the setting, and then select Action > Edit.
    1. In the setting window that opens, select Enabled, and then select OK.

      Enabling Suppress all notifications prevents more notifications from appearing.

    Use Group Policy to hide reboot notifications

    To hide reboot notifications by using Group Policy, perform the following steps:

    1. In Centralized Group Policy, open the Group Policy Management Console (GPMC) on your Group Policy management computer, opencomputer.

    2. In the Group Policy Management Console.GPMC console tree, expand Group Policy Objects in the forest and domain containing the GPO you want to edit.

    3. Right-click the Group Policy Object you want to configureGPO, and then select Edit.

    4. In the Group Policy Management Editor, go to Computer configuration.

    5. Click > Administrative templates.

    6. Expand the tree to > Windows components > Microsoft Defender Antivirus > Client interface.

    7. Double-click Suppresses reboot notifications and set the option to Enabled.

    8. Select OK. Enabling Suppresses reboot notifications prevents reboot notifications from appearing.

    1. In the details pane of Client interface, open the Suppresses reboot notifications setting. To open the setting, use any of the following methods:
      • Double-click the setting.
      • Right-click the setting, and then select Edit.
      • Select the setting, and then select Action > Edit.
    1. In the setting window that opens, select Enabled, and then select OK.

      Enabling Suppresses reboot notifications prevents reboot notifications from appearing.