Microsoft Defender for Endpoint
Endpoint protection

Configure Microsoft Defender Antivirus scanning options

In brief

The article now links to newer Windows 10 and Windows 11 Group Policy reference spreadsheets, provides expanded GPMC navigation and setting-edit steps, and adds guidance for Local Group Policy and legacy policy names.

What Defender admins need to know

Administrators can use the updated paths and references when configuring scan settings. No required action is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Configure Microsoft Defender Antivirus scanning options

Prerequisites

Supported operating systems

  1. OnIn Centralized Group Policy, open the Group Policy Management Console (GPMC) on your Group Policy management computer, opencomputer.

  2. In the Group Policy Management Console.GPMC console tree, expand Group Policy Objects in the forest and domain containing the GPO you want to edit.

  3. Right-click the Group Policy Object you want to configure,GPO, and then select Edit.

  4. In the Group Policy Management Editor, go to Computer configuration and select> Administrative templates.

  5. Expand the tree to > Windows components > Microsoft Defender Antivirus,.

  1. In the details pane of Microsoft Defender Antivirus, select a location from the Settings and locations section.

  2. In the details pane of the selected location, open the setting you want to configure. To open and configure a setting, use any of the following methods:

    • Double-click the setting.
    • Right-click the setting, and then select a location (refer toEdit.
    • Select the Settings and locations section)setting, and then select Action > Edit.

  3. EditIn the policy object.

  4. Selectsetting window that opens, configure the setting, and then select OK, and repeat for any other settings..

    Repeat this step as many times as necessary.

Settings and locations

Policy item and locationDefault setting
(if not configured)
PowerShell Set-MpPreference parameter
or WMI property for
MSFT_MpPreference class
Email scanning
Scan > Turn on e-mail scanning
See Email scanning limitations

Settings and locations

Policy item and location Default setting
(if not configured)
PowerShell Set-MpPreference parameter
or WMI property for MSFT_MpPreference class
Email scanning
Scan > Turn on e-mail scanning
See Email scanning limitations (in this article)
Disabled -DisableEmailScanning
Script scanning Enabled This policy setting allows you to configure script scanning. If you enable or don't configure this setting, script scanning is enabled.

See Defender/AllowScriptScanning
Scan reparse points
Scan > Turn on reparse point scanning
Disabled Not available
See Reparse points
Scan mapped network drives
Scan > Run full scan on mapped network drives
Disabled -DisableScanningMappedNetworkDrivesForFullScan
Scan archive files (such as .zip or .rar files).
Scan > Scan archive files
Enabled -DisableArchiveScanning

The extensions exclusion list takes precedence over this setting.
Scan files on the network
Scan > Scan network files
Disabled -DisableScanningNetworkFiles
Scan packed executables
Scan > Scan packed executables
Enabled Not available

Scan packed executables were removed from the following templates:
- Administrative Templates (.admx) for Windows 11 2023 Update (23H2)
- Administrative Templates (.admx) for Windows 11 2022 Update (22H2) - v3.0
- Administrative Templates (.admx) for Windows 11 2022 Update (22H2)
- Administrative Templates (.admx) for Windows 11 October 2021 Update (21H2)
Scan removable drives during full scans only
Scan > Scan removable drives
Disabled -DisableRemovableDriveScanning
Specify the level of subfolders within an archive folder to scan

Scan > Specify the maximum depth to scan archive files

0 Not available
Specify the maximum CPU load (as a percentage) during a scan.

Scan > Specify the maximum percentage of CPU utilization during a scan

50 -ScanAvgCPULoadFactor

The maximum CPU load isn't a hard limit, but is guidance for the scanning engine to not exceed the maximum on average. Manual scans ignore this setting and run without any CPU limits.
Specify the maximum size (in kilobytes) of archive files that should be scanned.
Scan > Specify the maximum size of archive files to be scanned
No limit Not available

The default value of 0 applies no limit
Configure low CPU priority for scheduled scans
Scan > Configure low CPU priority for scheduled scans
Disabled Not available
Configure scanning of network files
Scan > Configure scanning of network files
Disabled -DisableScanningNetworkFiles
CPU throttling type
Scan > CPU throttling type
Disabled -ThrottleForScheduledScanOnly
Scan excluded files and directories during quick scan
Scan > Scan excluded files and directories during quick scan
Disabled Not available

Scanning mapped network drives

On all supported operating systems, only the network drives that are mapped at system level are scanned. User-level mapped network drives aren't scanned. User-level mapped network drives are those that a user maps in their session manually and using their own credentials.