Microsoft Defender for Endpoint
Endpoint protection

Configure Microsoft Defender Antivirus using Microsoft Intune

In brief

The documentation now describes creating antivirus policies in Intune, adds Windows Server devices managed through Defender for Endpoint security settings management, and notes that Windows 10 support is not guaranteed after October 14, 2025.

What Defender admins need to know

Verify that devices are enrolled in Intune or managed through the specified Defender for Endpoint integration, and account for the Windows 10 support limitation when planning policies.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

UseConfigure Microsoft Defender Antivirus using Microsoft Intune

Security administrators can use Microsoft Intune to configure and manage Microsoft Defender Antivirus on managed Windows devices. This article explains how to create an antivirus policy and describes the available policy settings, values, defaults, and recommended configurations.

Supported platforms and Intune compatibility

You can manage Microsoft Defender Antivirus management through Intune is supported on the following platforms:

You can configure Microsoft Defender Antivirus settings by using Microsoft Intune or Configuration Manager.

Configure Microsoft Defender Antivirus settings in Intune

To createCreate an antivirus policy by following Create an endpoint security policy (opens in a new tab in the Intune documentation). Use the following settings:

  • Policy type: Antivirus
  • Platform: Windows
  • Profile: Microsoft Defender Antivirus
  • Basics: Enter a name and optional description for the policy.
  • Configuration settings: Expand each group of settings, and configure a Microsoft Defender Antivirus policy in Intune, perform the following steps:
    1. Gosettings you want to manage with this policy. For descriptions of the Microsoft Intune admin center,available settings and sign in.options, see Policies and settings.

    2. NavigateScope tags: If your organization uses scope tags, select the tags you want to Endpoint Security.use.

    3. Under ManageAssignments, choose Antivirus: Select the users or groups to receive this policy. For more information, see Assign policies in Microsoft Intune.

Click Create Policy, choose Windows as the platform and Microsoft Defender Antivirus for the profile type then select on CreateFor more information, see Antivirus policy for endpoint security in Intune.

  • Enter a Name for the policy and optionally a description and select Next to go to Configuration settings.

  • Edit your Microsoft Defender Antivirus settings.

  • Choose Review + save.

  • The following CSP settings can be configured in a Microsoft Defender Antivirus policy within Intune.

    Policies and settings

    This section lists eachThe following sections list the Microsoft Defender Antivirus policy settingsettings that you can configure in Intune, along with its CSPIntune. Each entry includes a configuration service provider (CSP) reference and the available options.

    Allow Archive Scanning

    CSP: AllowArchiveScanning

    This policyUse this setting enables you to configure scans for malicious software withinin archive filesfiles, such as .ZIPZIP or .CABCAB files.

    • Not configured -: The setting reverts to the clientpolicy doesn't set a value. By default, which is to scan archivedMicrosoft Defender Antivirus scans archive files. UserDevice users can disable this setting.archive scanning.
    • Not allowed -: Archive files aren't scanned, instead they're alwaysscanned during regular scans but are scanned during directed scans.
    • Allowed - Enable scans of archive files.: Archive files are scanned. This option is the recommended configuration.recommended.

    Changes to this setting arendon't applied ifapply when tamper protection is enabled.

    Allow behavior monitoring

    CSP: AllowBehaviorMonitoring

    This policyUse this setting enables you to configure behavior monitoring.

    • Not configured -: The setting reverts to the system default (real-policy doesn't set a value. By default, Microsoft Defender Antivirus enables real-time behavior monitoring is enabled).monitoring.

    • Not allowed - The setting: Behavior monitoring is disabled.

    • Allowed -: Real-time behavior monitoring is enabled. This option is the recommended configuration.recommended.

    Changes to this setting arendon't applied ifapply when tamper protection is enabled.

    Turn on cloud-delivered protection

    CSP: AllowCloudProtection

    This policy setting enables you to joincontrols membership in Microsoft MAPS (Microsoft Active Protection Service)Service (MAPS). Microsoft MAPS is thean online communityservice that helps you choosedetermine how to respond to potential threats. The community also helpsthreats and stop the spread of new malicious software infections.malware.

    Information about items detected on the detected items on your computerdevice is automatically collected and sent to Microsoft.

    The following information is collected about any detected malicious software,malware, spyware, and potentially unwanted software:

    • The source of the softwaresoftware.
    • The actions that you apply or that are applied automaticallyMicrosoft Defender Antivirus apply, and their success,whether the actions succeed.
    • The location of the softwaresoftware.
    • File namesnames.
    • How the software operatesoperates.
    • Its impactThe effect of the software on your computer.the device.

    Cloud-delivered protection options

    The following options are available for cloud-delivered protection:

    • Not configured -: The setting reverts to the system default (cloud-policy doesn't set a value. By default, Microsoft Defender Antivirus turns on cloud-delivered protection is turned off).protection.
    • Not allowed -: Cloud-delivered protection is turned off.
    • Allowed -: Cloud-delivered protection is turned on.

    Changes to this setting wondon't be applied ifapply when tamper protection is enabled.

    Allow email scanning

    CSP: AllowEmailScanning

    This policyUse this setting enables you to configure e-mailemail scanning. When e-mailemail scanning is enabled, the engineMicrosoft Defender Antivirus parses thesupported mailbox and mail files, according to their specific format, in order to analyze the mail bodiesemail files during on-demand and attachments. Several e-mailscheduled scans. Supported formats are currently supported, for example: pst (Outlook), dbx, mbx, mime (Outlook Express), binhex (Mac). Email scanning isninclude DBX, MBX, and MIME. Non-Unicode PST files from Outlook 2003 or earlier can also be scanned, but detected threats inside PST files can't supported on modernbe remediated. Modern email clients.clients don't support email scanning.

    • Not configured -: The setting reverts to the system default (turn off email scanning).
    • Not allowed - Turnpolicy doesn't set a value. By default, Microsoft Defender Antivirus turns off email scanning.
    • Not allowed: Email scanning is turned off.
    • Allowed - Turn on email scanning.: Email scanning is turned on. This option is the recommended configuration.recommended.

    Allow Full Scan On Mapped Network Drives

    CSP: AllowFullScanOnMappedNetworkDrives

    This policyUse this setting enables you to configure scanningscans of mapped network drives.

    • Not configured -: The setting reverts to the system default (mappedpolicy doesn't set a value. By default, Microsoft Defender Antivirus doesn't scan mapped network drives won't be scanned).drives.
    • Not allowed -: Mapped network drives wonaren't be scanned.
    • Allowed - Enable scans of mapped: Mapped network drives.drives are scanned.

    Allow Full Scan Removable Drive Scanning

    CSP: AllowFullScanRemovableDriveScanning

    This policyUse this setting enables you to managecontrol whether or not to scan for malicious software and unwanted software in the contents offull scans check removable drives, such as USB flash drives, when running a full scan.for malware and unwanted software.

    • Not configured -: The setting reverts to the system default (removablepolicy doesn't set a value. By default, Microsoft Defender Antivirus doesn't check removable drives won't be scanned during a full scan but theyscans. Quick and custom scans might still be scanned during quick scan and custom scan).check removable drives.
    • Not allowed - Removable drives won: Full scans don't be scanned during a full scancheck removable drives, but they might still be scanned during quick scan and custom scan.scans might.
    • Allowed - Removable drives are scanned during any type of scan.: All scan types check removable drives. This option is the recommended configuration.recommended.

    Allow scanning of all downloaded files and attachments

    CSP: AllowIOAVProtection

    This policyUse this setting enables you to configure scanning for allof downloaded files and attachments.

    • Not configured -: The setting reverts to the system default (scanning forpolicy doesn't set a value. By default, Microsoft Defender Antivirus scans all downloaded files and attachments are enabled).attachments.
    • Not allowed - Scanning for all downloaded: Downloaded files and attachments aren't scanned.
    • Allowed: Downloaded files and attachments are disabled.
    • Allowed - Scanning for all downloaded files and attachments are enabled.scanned. This option is the recommended configuration.recommended.

    Changes to this setting wondon't be applied ifapply when tamper protection is enabled.

    Allow Real-Time Monitoring

    CSP: AllowRealtimeMonitoring

    EnablesUse this setting to enable or disenables Windowsdisable Microsoft Defender Antivirus real-time Monitoring functionality.monitoring.

    • Not configured -: The setting reverts to the system default (turns on andpolicy doesn't set a value. By default, Microsoft Defender Antivirus runs the real-time monitoring service).
    • Not allowed - Turns off the real-time monitoring service.
    • AllowedNot allowed - Turns on and runs the: The real-time monitoring service.service is turned off.
    • Allowed: The real-time monitoring service is turned on. This option is the recommended configuration.recommended.

    Changes to this setting wondon't be applied ifapply when tamper protection is enabled.

    Allow Scanning Network Files

    CSP: enablescanningNetworkFilesAllowScanningNetworkFiles

    This policyUse this setting enables you to configure both scheduled scans and on-demand (manually initiated) scans forof files accessed over the network.

    • Not configured -: The setting reverts to the system default (network files is scanned).policy doesn't set a value. By default, Microsoft Defender Antivirus scans network files.
    • Not allowed -: Network files isnaren't scanned.
    • Allowed -: Network files are scanned. This option is the recommended configuration.recommended.

    Allow Script Scanning

    CSP: enablescriptScanningAllowScriptScanning

    This policyUse this setting enablesto enable or disables the Windowsdisable Microsoft Defender Script Scanning functionality.Antivirus script scanning.

    • Not configured -: The setting reverts to the system default (script scanning is allowed).policy doesn't set a value. By default, Microsoft Defender Antivirus allows script scanning.
    • Not allowed - The setting: Script scanning is disabled, scripts won't be scanned.disabled.
    • Allowed - The setting: Script scanning and the Antimalware Scan Interface are enabled. This option is enabled, scripts are scanned(enables the Anti-malware Scan Interface). This is the recommended configuration.recommended.

    Changes to this setting arendon't applied if theapply when tamper protection setting is enabled.

    Allow User UI Access

    CSP: AllowUserUIAccess

    This policyUse this setting enables you to configurecontrol whether or not to displaydevice users can access the Microsoft Defender app UI to the users.user interface and notifications.

    • Not configured -: The setting revertspolicy doesn't set a value. By default, Microsoft Defender Antivirus allows access to the system default (the UIuser interface and notifications are allowed).notifications.
    • Not allowed - The setting is disabled. Prevents: Device users from accessing UIcan't access the user interface, and the notifications are suppressed.
    • Allowed - The setting is enabled. The: Device users can access the Defender UIuser interface and notifications are allowed.receive notifications. This option is the recommended configuration.recommended.

    Avg CPU Load Factor

    CSP: AvgCPULoadFactor

    This policyUse this setting enables you to specify the maximum CPU load factor for theMicrosoft Defender Antivirus scans.

    • Not configured -: The setting reverts to the system default, where CPU utilizationpolicy doesn't exceedset a value. By default, the default value ofmaximum CPU load factor in Microsoft Defender Antivirus is 50%.
    • [0-100] -: Set the target maximum average CPU utilization won't exceeduse for scans. The value is guidance for the specified percentage. A valuescanning engine, not a hard limit. Values of 0 means there's no throttling ofor 100 disable CPU utilization.throttling. Manual scans ignore this setting.

    Archive Max Depth

    CSP: ArchiveMaxDepth

    This policyUse this setting enables you to specify the maximum folder depth to extract from archive files for scanning.

    • Not configured -: The setting reverts to the system default (allpolicy doesn't set a value. By default, Microsoft Defender Antivirus extracts all archives are extracted up to the deepest folder for scanning).scanning.
    • [0-4294967295] - All archives: Archives are extracted up to the folder depth specified in the policy.

    Archive Max Size

    CSP: ArchiveMaxSize

    This policyUse this setting enables you to specify the maximum size, in KB, of archive files to be extractedextract and scanned.scan.

    • Not configured -: The setting reverts to the systempolicy doesn't set a value. By default, whereMicrosoft Defender Antivirus extracts and scans all archives are extracted and scanned regardless of size.
    • [0-4294967295] -: Archives smaller than the specified maximum size are extracted and scanned if their size is smaller than the maximum size specified in the policy.scanned.

    Check For Signatures Before Running Scan

    CSP: CheckForSignaturesBeforeRunningScan

    This policyUse this setting allows you to managecontrol whether a checkMicrosoft Defender Antivirus checks for new virus and spyware security intelligence occurs before running a scan. This is only applicable to scheduled scans.scan.

    • Not configured -: The setting reverts to the systempolicy doesn't set a value. By default, whereMicrosoft Defender Antivirus starts the scan starts usingwith the currentexisting security intelligence.
    • Disabled -: The scan begins usingstarts with the existing security intelligence.
    • Enabled - Before running a scan, the system: Microsoft Defender Antivirus checks for new security intelligence.intelligence before starting the scan. This option is the recommended configuration.recommended.

    Cloud Block Level

    CSP: CloudBlockLevel

    This policy setting controls the level of intensity that Microsoft Defender Antivirus uses when blocking and scanning suspicious files.

    • Not configured: The policy doesn't set a value. By default, the Microsoft Defender Antivirus blocking level is 0x0.
    • (0x0) Default state: Use the default Microsoft Defender Antivirus blocking level.
    • (0x2) High: Aggressively block unknown files while optimizing client performance. This option increases the chance of false positives and is recommended.
    • (0x4) High Plus: Aggressively block unknown files and apply more protection measures. This option might affect client performance.
    • (0x6) Zero Tolerance: Block all unknown executable files.

    Changes to this setting don't apply when tamper protection is enabled.

    Cloud Extended Timeout

    This feature allowsCSP: CloudExtendedTimeout

    Use this setting to extend the time that Microsoft Defender Antivirus to blockblocks a suspicious file for up to 60 seconds, and scanwhile scanning it in the cloud to make sure it's safe.

    cloud. The default cloud cloud-check time-outtimeout is 10 seconds. To enable this feature, specify the extended time in seconds. TheYou can add up to 50 seconds for a maximum time-out is 50timeout of 60 seconds.

    • Not configured -: The setting reverts topolicy doesn't set a value. By default, the system default (cloud time outMicrosoft Defender Antivirus cloud-check timeout is 10 seconds).seconds.
    • [0-50] - The cloud time out is extended with: Add the specified amount.number of seconds to the default timeout. The recommended value is 50.

    Days To Retain Cleaned Malware

    CSP: DaysToRetainCleanedMalware

    This policyUse this setting defines the number ofto specify how many days to keep items should be kept in the Quarantine folderquarantine before being removed.removing them.

    • Not configured -: The setting reverts to the system default.policy doesn't set a value. By default, Microsoft Defender Antivirus keeps items in quarantine for 90 days.
    • 0: Items are keptremain in the quarantine folder indefinitely and wonaren't be automatically removed.removed automatically.
    • [0-1-90] -: Items are removed from the Quarantine folderquarantine after the specified number of days specified.days.

    Disable Catchup Full Scan

    CSP: DisableCatchupFullScan

    This policyUse this setting enables you to configurecontrol whether catch-up full scans forrun after missed scheduled full scans. ABecause the setting name begins with Disable, enabling the setting disables catch-up scan is a scan that's initiated because a regularly scheduled scan was missed. Usually these scheduled scans are missed becausefull scans, and disabling the computer was turned off at the scheduled time.setting enables them.

    • Not configured -: The setting reverts to the system default.policy doesn't set a value. By default, Microsoft Defender Antivirus disables catch-up full scans.
    • Disabled -: Catch-up scans for scheduled full scans are turned on.enabled. If a computer is offline fordevice misses two consecutive scheduled full scans, a catch-up full scan is startedstarts the next time someone sign-ins the computer. If there's nosigns in. Catch-up scans require a configured scheduled scan configured, there's no catch-up scan run.scan.
    • Enabled (Default) -: Catch-up scans for scheduled full scans isare disabled.

    Disable Catchup Quick Scan

    CSP: DisableCatchupQuickScan

    This policyUse this setting allows you to configurecontrol whether catch-up quick scans forrun after missed scheduled quick scans. ABecause the setting name begins with Disable, enabling the setting disables catch-up scan is a scan that's initiated because a regularly scheduled scan was missed. Usually these scheduled scans are missed becausequick scans, and disabling the computer was turned off at the scheduled time.setting enables them.

    • Not configured -: The setting reverts to the system default (catch-policy doesn't set a value. By default, Microsoft Defender Antivirus disables catch-up scans for scheduled quick scans is turned on).scans.
    • Disabled -: Catch-up scans for scheduled quick scans are turned on.enabled. If a computer is offline fordevice misses two consecutive scheduled quick scans, a catch-up quick scan is startedstarts the next time someone sign-ins the computer. If there's nodevice powers on or resumes from sleep or hibernation. Catch-up scans require a configured scheduled scan configured, there's no catch-up scan run.scan.
    • Enabled (Default) -: Catch-up scans for scheduled quick scans isare disabled.

    Enable Low CPU Priority

    CSP: EnableLowCPUPriority

    This policyUse this setting enables you to enable or disablecontrol whether scheduled scans use low CPU priority for scheduled scans.priority.

    • Not configured -: The setting reverts topolicy doesn't set a value. By default, Microsoft Defender Antivirus doesn't change the system default, meaning no changes is made to CPU priority for scheduled scans.
    • Disabled - No change is made to: The CPU priority for scheduled scans.scans isn't changed.
    • Enabled - Low: Scheduled scans use low CPU priority is used during scheduled scans.priority.

    Enable Network Protection

    CSP: EnableNetworkProtection

    Enable or disable Microsoft Defender Exploit GuardUse this setting to configure network protection to prevent employeesprotection, which prevents applications from using applications to accessaccessing dangerous domains that might host phishing scams, exploit-hosting sites, andexploits, or other malicious content on the internet.content.

    • Not configured -: The setting reverts to the systempolicy doesn't set a value. By default, meaningMicrosoft Defender Antivirus doesn't block users andor applications won't be blocked from connecting to dangerous domains.
    • Disabled -: Users and applications aren't blocked from connecting to dangerous domains.
    • Enabled(blockEnabled (block mode) -: Users and applications won't be able to accessare blocked from accessing dangerous domains. This option is the recommended configuration.recommended.
    • Enabled(auditEnabled (audit mode) -: Users and applications can connect toaccess dangerous domains. However, if this featureEvents that network protection would have blocked access when set to Block, a record of the event will be loggedblock in block mode are recorded in the event logs.log.

    Excluded Extensions

    CSP: ExcludedExtensions

    Allows administratorsUse this setting to specify a list of file extensions to ignore during a scan.exclude from scans. For more details on how these exclusions can be defined you can read this article:information, see Exclusions based on file extension and folder location.

    Excluded Paths

    CSP: ExcludedPaths

    Allows administratorsUse this setting to specify a list of directory paths to ignore during a scan.exclude from scans. For more details on how these exclusions can be defined you can read this article:information, see Exclusions based on file extension and folder location.

    Excluded Processes

    CSP: ExcludedProcesses

    Allows administratorsUse this setting to specify a list of files that processes can open without being scanned. For more details on how these exclusions can be defined you can read this article:information, see Exclusions based on file extension and folder location.

    PUA Protection

    CSP: PUAProtection

    Enable or disableUse this setting to configure detection forof potentially unwanted applications.applications (PUAs). You can choose to block, audit, or allow when potentially unwanted software is beingwhen it's downloaded or attempts to install itself on your computer.a device.

    • Not configured -: The setting revertspolicy doesn't set a value. The Microsoft Defender Antivirus default depends on the Windows version, security intelligence version, Smart App Control availability, and whether the device is onboarded to the system default, meaningDefender for Endpoint. For details, see Default PUA protection settings.
    • Disabled: PUA protection is turned off, and potentially unwanted software wonisn't be blocked.
    • Disabled - PUA protection is off, meaning potentially unwanted software won't be blocked.
    • Block -: PUA protection is turned on, meaningand potentially unwanted software is blocked. This option is the recommended configuration.recommended.
    • Audit mode -: Potentially unwanted software wonisn't be blocked. However, if this featureEvents that PUA protection would have blocked access when set to Block, a record of the event will be loggedblock in block mode are recorded in the event logs.log.

    Real Time Scan Direction

    CSP: RealTimeScanDirection

    This policyUse this setting allows you to configure monitoring forof incoming and outgoing files without disabling monitoring entirely. It's recommendedThis setting is useful for servers with high volumes of file activity, whereactivity when scanning needs tomust be disabled for a specificin one direction to maintain performance. TheEvaluate the appropriate configuration should be evaluated based on the server's role.

    This configuration isapplies only applicable to NTFS volumes. For any other file system type,Microsoft Defender Antivirus enforces full monitoring of file and program activity will be enforced on those volumes.other file-system types.

    • Not configured -: The setting reverts to the systempolicy doesn't set a value. By default, meaning, monitoring forMicrosoft Defender Antivirus monitors incoming and outgoing files are enabled.files.
    • Monitor all files (bi-directional) -: Scan incoming and outgoing files (default)files. This option is the default.
    • Monitor incoming files -: Scan incoming files only.
    • Monitor outgoing files -: Scan outgoing files only.

    Scan Parameter

    CSP: ScanParameter

    This policyUse this setting allows you to specify the scan type used during afor scheduled scan.scans. This setting interacts with the settings Schedule Scan Day and Schedule Scan Time.

    • Not configured -: The setting reverts to the system default.policy doesn't set a value. By default, Microsoft Defender Antivirus uses quick scans.
    • Quick Scan (default) -: Microsoft Defender Antivirus runs a scheduled quick scan.
    • Full Scan -: Microsoft Defender Antivirus runs a scheduled full scan.

    Schedule Quick Scan Time

    CSP: ScheduleQuickScanTime

    This policyUse this setting allows you to specify the time of day at which to performfor a daily quick scan. The time value is represented asEnter the number of minutes past midnights.after midnight. This setting doesn't interact with the settings Scan Parameter, Schedule Scan Day, or Schedule Scan Time.

    • Not configured: The policy doesn't set a value. By default, Microsoft Defender Antivirus doesn't run the daily quick scan controlled by this setting.
    • [0-1380]: The daily quick scan runs at the specified time.

    Schedule Scan Day

    CSP: ScheduleScanDay

    Use this setting to specify the day of the week for a scheduled scan. You can also configure the scan to run every day or not run. This setting interacts with Scan Parameter, which controls the scan type, and Schedule Scan Time.

    • Not configured -: The setting reverts to the systempolicy doesn't set a value. By default, meaning, the daily quick scan controlled by this config won't run.
    • [0-1380] - A daily quick scanMicrosoft Defender Antivirus runs at the time of day specified.

    Schedule Scan Day

    CSP: ScheduleScanDay

    This policy setting allows you to specify the day of the week to perform a scheduled scan. The scan can also be configured to runscans every day or to never run at all. This setting interacts with the Scan Parameter setting (which controls whether the scan is a quick scan or full scan) and Schedule Scan Time.

    • Not configured - The setting reverts to the system default.day.
    • Every day (default) -: A scheduled scan runs daily.
    • Sunday/Monday/Tuesday/Wednesday/Thursday/Friday/Saturday -: A scheduled scan runs once per week on the selected day.
    • No scheduled scan - No: A scheduled scan runs.doesn't run.

    Schedule Scan Time

    CSP: ScheduleScanTime

    This policyUse this setting allows you to specify the time of day to performfor a scheduled scan. The time is represented asEnter the number of minutes past midnights, with theafter midnight. The default beingvalue is 120 minutes (whichminutes, which corresponds to 2:00 AM).AM. This setting interacts with the Scan Parameter and Schedule Scan Day settings.

    • Not configured -: The setting reverts topolicy doesn't set a value. By default, the system default (a scheduledMicrosoft Defender Antivirus scan runs at a default time).time is 2:00 AM.
    • [0-1380] -: A scheduled scan runs at the time of day specified.specified time.

    Signature Update Fallback Order

    CSP: SignatureUpdateFallbackOrder

    This policyUse this setting allows you to specify the order in which different security intelligence update sources are contacted. Although the underlying policy is stored asEnter a pipe-separated string, Intune presents this setting as a prioritized list of update sources. Administrators should configurestring that lists the sources in the desired order using the Intune UI, where sources are evaluated from top to bottom. Possibleorder. Available values include: "InternalDefinitionUpdateServer," "MicrosoftUpdateServer," "MMPC,"include InternalDefinitionUpdateServer, MicrosoftUpdateServer, MMPC, and "FileShares."FileShares.

    • Not configured -: The setting reverts to the system default. Meaning,policy doesn't set a value. By default, Microsoft Defender Antivirus contacts security intelligence update sources are contacted in athe default order.
    • Enabled -: Security intelligence update sources are contacted in the order specified.specified order.

    Signature Update File Shares Sources

    CSP: SignatureUpdateFileSharesSources

    This policyUse this setting allows you to configure UNC file Universal Naming Convention (UNC) file-share sources for downloading security intelligence updates. Sources are contacted in the order specified. The value of this setting should be entered asEnter a pipe-separated string enumeratingthat lists the security intelligence update sources.sources in the order in which Microsoft Defender Antivirus should contact them.

    • Not configured -: The setting reverts topolicy doesn't set a value. By default, the system default. Meaning, theMicrosoft Defender Antivirus source list remains empty by defaultis empty, and no file-share sources are contacted.
    • Enabled -: The specified file-share sources are contacted for security intelligence updates.in order.

    Signature Update Interval

    CSP: SignatureUpdateInterval

    This policyUse this setting allows you to specify an interval at which to checkthe number of hours between checks for security intelligence updates. The time valuedefault interval is represented as the number of hours between update checks. The default is 8h.eight hours.

    • Not configured -: The setting reverts to the system default. Meaning, itpolicy doesn't set a value. By default, Microsoft Defender Antivirus checks for updates every eight hours.
    • 0: Microsoft Defender Antivirus doesn't run scheduled checks for new security intelligenceintelligence.
    • [1-24]: Microsoft Defender Antivirus checks for updates occur at the defaultspecified interval.
    • [0-24] - Checks for security intelligence updates occur at the interval specified. The recommended value is 4.

    Submit Samples Consent

    CSP: SubmitSamplesConsent

    This policyUse this setting configures behavior of samplesto configure sample submission when opt-in for MAPS telemetry is set.enabled.

    • Not configured -: The setting reverts to the system default which is to sendpolicy doesn't set a value. By default, Microsoft Defender Antivirus sends safe samples automatically.
    • Always prompt - The user is always: Device users are prompted for consent before file submission.files are submitted.
    • Send safe samples automatically - Safe samples: Files that typically don't contain personally identifiable information (PII), such as .bat, .scr, .dll, and .exe files, are samples considered to not commonlysent automatically. Device users are prompted before files that might contain PII data (examples include .bat, .scr, .dll, and .exe). If file is likely to contain PII, the user gets a request to allow file sample submission.are submitted.
    • Never send - Prevents : File samples aren't sent. This option prevents block at first sight based on file file-sample analysis. MetadataDetection metadata is sent for detections even if sample submission is disabled.still sent.
    • Send all samples automatically -: All samples are sent automatically. This option is the recommended configuration.recommended.

    Disable Local Admin Merge

    CSP: DisableLocalAdminMerge

    When this valuesetting is set to no, it gives adisabled, local admin the ability toadministrators can configure local policy overrides for Microsoft Defender Antivirus on their devices by using the Windows Security app, localLocal Group Policy settings,Editor, or PowerShell cmdlets (where appropriate).cmdlets, where supported.

    • Not configured -: The setting reverts to the system default.policy doesn't set a value. By default, Microsoft Defender Antivirus enables local administrator merge.
    • Enable local admin merge (default) -: Unique items defined in preference settings that areitems configured by a local administrator mergeare merged into the resulting effective policy. If there are conflicts, management settings fromconflict, managed Intune policy settings override local preference settings.preferences.
    • Disable local admin merge -: Only itemssettings defined by management are used in the resulting effective policy. Managed settings override preference settings that are configured by the local administrator.preferences. This option is the recommended configuration.recommended.

    Allow On Access Protection

    CSP: AllowOnAccessProtection

    This policyUse this setting enables you to configure monitoring forof file and program activity.

    • Not configured -: The setting reverts to the system default which is to monitoring forpolicy doesn't set a value. By default, Microsoft Defender Antivirus monitors file and program activity.
    • Allowed: File and program activity is enabled.
    • Allowed - Monitoring for file and program activity is enabled.monitored.
    • Not allowed - Monitoring for file: File and program activity is disabled.isn't monitored.

    Changes to this setting arendon't applied ifapply when tamper protection is enabled.

    Threat Severity Default Action

    CSP: ThreatSeverityDefaultAction

    This policyUse this setting allows you to customize the automatic remediation action for each threat alert level. The following lists contain the valid remediation actions:

    • Not configured -: The setting reverts topolicy doesn't set a value. By default, Microsoft Defender Antivirus applies the system default which is to apply action based onspecified in the update definition.security intelligence update.
    • Clean - Service tries: Attempt to recover files and tries to disinfect.disinfect files.
    • Quarantine - Moves: Move files to quarantine.
    • Remove - Removes: Remove files from system.the device.
    • Allow - enables: Allow the file and doesn't take other actions.without taking another action.
    • User defined - The: Let the device user makesselect the decision on which action to take.action.
    • Block - Blocks: Block file execution.

    Changes to this setting arendon't applied ifapply when tamper protection is enabled.

    Allow Network Protection Down Level

    CSP: AllowNetworkProtectionDownLevel

    ThisUse this setting determinesto control whether Network Protection is allowed to be configured intonetwork protection can use block or audit mode on Windows downlevel ofversions earlier than RS3. If false,When this setting is disabled, the Enable Network Protectionvalue of EnableNetworkProtection is ignored.

    • Not configured -: The setting reverts to the system default which is topolicy doesn't set a value. By default, Microsoft Defender Antivirus disables network protection is disabled downlevel.on earlier Windows versions.
    • Enabled -: Network protection is enabled downlevel.on earlier Windows versions.
    • Disabled -: Network protection is disabled downlevel.on earlier Windows versions.

    Allow Datagram Processing On Win Server

    CSP: AllowDatagramProcessingOnWinServer

    ThisUse this setting determinesto control whether Network Protectionnetwork protection can enable datagram processing on Windows Server. If set to false,When this setting is disabled, the Disable Datagram Processingvalue of DisableDatagramProcessing is ignored, and datagram inspection is disabled by default.disabled.

    • Not configured -: The setting reverts to the systempolicy doesn't set a value. By default, meaning,Microsoft Defender Antivirus disables datagram processing on Windows Server is disabled.Server.
    • Enabled -: Datagram processing is enabled on Windows Server is enabled.Server.
    • Disabled -: Datagram processing is disabled on Windows Server is disabled.Server.

    Disable Dns Over Tcp Parsing

    CSP: DisableDnsOverTcpParsing

    ThisUse this setting disablesto disable DNS over TCP Parsingparsing for Network Protection.network protection.

    • Not configured -: The setting reverts to the systempolicy doesn't set a value. By default, meaning,Microsoft Defender Antivirus enables DNS over TCP parsing is enabled.parsing.
    • Enabled -: DNS over TCP parsing is disabled.
    • Disabled -: DNS over TCP parsing is enabled.

    Disable Http Parsing

    CSP: DisableHttpParsing

    ThisUse this setting disablesto disable HTTP Parsingparsing for Network Protection.network protection.

    • Not configured -: The setting reverts to the systempolicy doesn't set a value. By default, meaning,Microsoft Defender Antivirus enables HTTP parsing is enabled.parsing.
    • Enabled -: HTTP parsing is disabled.
    • Disabled -: HTTP parsing is enabled.

    Disable Ssh Parsing

    CSP: DisableSshParsing

    ThisUse this setting disables SSH Parsingto disable Secure Shell (SSH) parsing for Network Protection.network protection.

    • Not configured -: The setting reverts to the system default (SSH parsing is enabled).policy doesn't set a value. By default, Microsoft Defender Antivirus enables SSH parsing.
    • Enabled -: SSH parsing is disabled.
    • Disabled -: SSH parsing is enabled.

    Disable Tls Parsing

    CSP: DisableTlsParsing

    ThisUse this setting disables TLS Parsingto disable Transport Layer Security (TLS) parsing for Network Protection.network protection.

    • Not configured -: The setting reverts to the systempolicy doesn't set a value. By default, meaning,Microsoft Defender Antivirus enables TLS parsing is enabled.parsing.
    • Enabled -: TLS parsing is disabled.
    • Disabled -: TLS parsing is enabled.

    Engine Updates Channel

    CSP: EngineUpdatesChannel

    EnableUse this policysetting to specify when devices receive Microsoft Defender Antivirus engine updates during the monthly gradual rollout.

    • Not configured -: The setting reverts to the systempolicy doesn't set a value. By default, meaning, the device staysMicrosoft Defender Antivirus keeps devices up to date automatically during the gradual release cycle. Suitablerollout. This option is suitable for most devices.
    • Beta Channel -: Devices set toreceive updates first. Use this channel are the firston a limited number of test devices to receive new updates. Select Beta Channel to participate in identifyingidentify and reportingreport issues to Microsoft. Devices in the Windows Insider Program are subscribed touse this channel by default. For use in (manual) test environments only and a limited number of devices.
    • Current Channel (Preview) -: Devices set to this channel is offeredreceive updates earliest duringearly in the monthly gradual release cycle. Suggestedrollout. This channel is recommended for pre-production/preproduction or validation environments.
    • Current Channel (Staged) -: Devices is offeredreceive updates after the monthly gradual release cycle. Suggested to applyearly rollout stages. Apply this channel to a small, representative partgroup of your production population (~devices, such as 10%).
    • Current Channel (Broad) -: Devices is offeredreceive updates only after the gradual release cycle completes. Suggestedrollout is complete. Apply this channel broadly to apply to a broad set of devices in your production population (~10-100%).devices.
    • Critical - Time delay -: Devices are offeredreceive updates withafter a 48-hour delay. SuggestedUse this channel only for critical environments only.environments.

    Metered Connection Updates

    CSP: MeteredConnectionUpdates

    ThisUse this setting enablesto control whether managed devices to updatecan get updates through metered connections.

    • Not configured -: The setting reverts to the system default (not allowed).policy doesn't set a value. By default, Microsoft Defender Antivirus doesn't allow updates through metered connections.
    • Allowed - managed: Managed devices updatecan get updates through metered connections.
    • Not allowed - managed: Managed devices woncan't updateget updates through metered connections.

    Platform Updates Channel

    CSP: PlatformUpdatesChannel

    EnableUse this policysetting to specify when devices receive Microsoft Defender Antivirus platform updates during the monthly gradual rollout.

    • Not configured -: The setting reverts to the systempolicy doesn't set a value. By default, meaning, the device staysMicrosoft Defender Antivirus keeps devices up to date automatically during the gradual release cycle. Suitablerollout. This option is suitable for most devices.
    • Beta Channel -: Devices set toreceive updates first. Use this channel is the firston a limited number of test devices to receive new updates. Select Beta Channel to participate in identifyingidentify and reportingreport issues to Microsoft. Devices in the Windows Insider Program are subscribed touse this channel by default. For use in (manual) test environments only and a limited number of devices.
    • Current Channel (Preview) -: Devices set to this channel is offeredreceive updates earliest duringearly in the monthly gradual release cycle. Suggestedrollout. This channel is recommended for pre-production/preproduction or validation environments.
    • Current Channel (Staged) -: Devices is offeredreceive updates after the monthly gradual release cycle. Suggested to applyearly rollout stages. Apply this channel to a small, representative partgroup of your production population (~devices, such as 10%).
    • Current Channel (Broad) -: Devices is offeredreceive updates only after the gradual release cycle completes. Suggestedrollout is complete. Apply this channel broadly to apply to a broad set of devices in your production population (~10-100%).devices.
    • Critical - Time delay -: Devices are offeredreceive updates withafter a 48-hour delay. SuggestedUse this channel only for critical environments only.environments.

    Security Intelligence Updates Channel

    CSP: SecurityIntelligenceUpdatesChannel

    EnableUse this policysetting to specify when devices receive Microsoft Defender Antivirus security intelligence updates during the daily gradual rollout.

    • Not configured -: The policy doesn't set a value. By default, Microsoft will either assignassigns the device to Current Channel (Broad) or to a beta channel early in the gradual release cycle. Therollout. A beta channel selected by Microsoft might be one that receives updates early during the gradual release cycle, which might not be suitable for devices in a production or critical environment.devices.
    • Current Channel (Staged) - Same: Use the same rollout timing as Current Channel (Broad).
    • Current Channel (Broad) -: Devices is offeredreceive updates only after the gradual release cycle completes. Suggestedrollout is complete. Apply this channel broadly, including to apply to a broad set of devices in all populations, including production.production devices.

    Randomize Schedule Task Times

    CSP: RandomizeScheduleTaskTimes

    In Microsoft Defender Antivirus,Use this setting to randomize thescan start time of the scan to anytimes across an interval from 0 tothrough 23 hours. ThisRandomization can be usefulhelp distribute resource use in virtual machinesmachine or VDIvirtual desktop infrastructure (VDI) deployments.

    • Not configured -: The setting reverts to the system default (scheduled tasks are randomized).policy doesn't set a value. By default, Microsoft Defender Antivirus randomizes scheduled tasks.
    • Widen or narrow the randomization period for scheduled scans. Specifyscans (Default): Use Scheduler Randomization Time to specify a randomization window of betweenfrom 1 andthrough 23 hours by using the setting SchedulerRandomizationTimehours.
    • Scheduled tasks won't be randomized: Scheduled tasks run without randomization.

    Scheduler Randomization Time

    CSP: SchedulerRandomizationTime

    ThisUse this setting enables you to configure the scheduler randomization in hours. The randomization interval is [1 - 23]in hours.

    • Not configured -: The setting reverts topolicy doesn't set a value. By default, the system default (4 hours).Microsoft Defender Antivirus randomization interval is four hours.
    • [1-23] - The randomization interval is defined by: Scheduled tasks are randomized across the value specified in the policy.number of hours.

    Disable Core Service ECS Integration

    CSP: DisableCoreServiceECSIntegration

    Turn off ECSUse this setting to control Experimentation and Configuration Service (ECS) integration for the Defender core service.

    • Not configured -: The setting reverts to the systempolicy doesn't set a value. By default, meaning, the Defender core service uses ECS.
    • The Defender core service will use the Experimentation and Configuration Service (ECS) to rapidly deliver critical, org-specific fixes.: ECS integration is enabled.
    • The Defender core service stops using the Experimentation and Configuration Service (ECS). Fixes will continue to be delivered through security intelligence updates.: ECS integration is disabled.

    Disable Core Service Telemetry

    CSP: DisableCoreServiceTelemetry

    Turn offUse this setting to control OneDsCollector telemetry for the Defender core service.

    • Not configured -: The setting reverts to the systempolicy doesn't set a value. By default, meaning, the Defender core service uses the OneDsCollector framework.
    • The Defender core service will use the OneDsCollector framework to rapidly collect telemetry.: OneDsCollector telemetry is enabled.
    • The Defender core service stops using the OneDsCollector framework to rapidly collect telemetry, impacting Microsoft's ability to quickly recognize and address poor performance, false positives, and other problems.: OneDsCollector telemetry is disabled.