Configure Microsoft Defender Antivirus using Microsoft Intune
In brief
The documentation now describes creating antivirus policies in Intune, adds Windows Server devices managed through Defender for Endpoint security settings management, and notes that Windows 10 support is not guaranteed after October 14, 2025.
What Defender admins need to know
Verify that devices are enrolled in Intune or managed through the specified Defender for Endpoint integration, and account for the Windows 10 support limitation when planning policies.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
UseConfigure Microsoft Defender Antivirus using Microsoft Intune
Security administrators can use Microsoft Intune to configure and manage Microsoft Defender Antivirus on managed Windows devices. This article explains how to create an antivirus policy and describes the available policy settings, values, defaults, and recommended configurations.
Supported platforms and Intune compatibility
You can manage Microsoft Defender Antivirus management through Intune is supported on the following platforms:
- Windows
10 and laterdevices enrolled in Intune - Windows Server devices managed through Microsoft Defender for Endpoint security settings management
You can configure Microsoft Defender Antivirus settings by using Microsoft Intune or Configuration Manager.
CSP: AllowArchiveScanning
Changes to this setting Not configured Not allowed Allowed Changes to this setting CSP: AllowCloudProtection
This Information about items detected on the The following information is collected about The following options are available for cloud-delivered protection:
Changes to this setting CSP: AllowEmailScanning
CSP: AllowFullScanOnMappedNetworkDrives
CSP: AllowFullScanRemovableDriveScanning
CSP: AllowIOAVProtection
Changes to this setting Changes to this setting CSP: CSP: Changes to this setting CSP: AllowUserUIAccess
CSP: AvgCPULoadFactor
CSP: ArchiveMaxDepth
CSP: ArchiveMaxSize
CSP: CheckForSignaturesBeforeRunningScan
CSP: CloudBlockLevel
This policy setting controls the level of intensity that Microsoft Defender Antivirus uses when blocking and scanning suspicious files.
Changes to this setting don't apply when tamper protection is enabled.
Use this setting to extend the time that Microsoft Defender Antivirus cloud. The default CSP: DaysToRetainCleanedMalware
CSP: EnableLowCPUPriority
CSP: ExcludedExtensions
CSP: ExcludedPaths
CSP: ExcludedProcesses
CSP: PUAProtection
This configuration CSP: ScanParameter
CSP: ScheduleScanDay Use this setting to specify the day of the week for a scheduled scan. You can also configure the scan to run every day or not run. This setting interacts with Scan Parameter, which controls the scan type, and Schedule Scan Time.
CSP: ScheduleScanTime
CSP: SignatureUpdateFallbackOrder
CSP: SignatureUpdateFileSharesSources
CSP: SubmitSamplesConsent
When this Changes to this setting CSP: ThreatSeverityDefaultAction
Changes to this setting CSP: AllowNetworkProtectionDownLevel
CSP: AllowDatagramProcessingOnWinServer
CSP: DisableHttpParsing
CSP: DisableSshParsing
CSP: DisableTlsParsing
CSP: EngineUpdatesChannel
CSP: SecurityIntelligenceUpdatesChannel
CSP: RandomizeScheduleTaskTimes
CSP: SchedulerRandomizationTime
CSP: DisableCoreServiceECSIntegration
CSP: DisableCoreServiceTelemetry
Configure Microsoft Defender Antivirus settings in Intune
To createCreate an antivirus policy by following Create an endpoint security policy (opens in a new tab in the Intune documentation). Use the following settings:a Microsoft Defender Antivirus policy in Intune, perform the following steps:Gosettings you want to manage with this policy. For descriptions of the Microsoft Intune admin center,available settings and sign in.options, see Policies and settings.NavigateScope tags: If your organization uses scope tags, select the tags you want to Endpoint Security.use.Under ManageAssignments, choose Antivirus: Select the users or groups to receive this policy. For more information, see Assign policies in Microsoft Intune.Click Create Policy, choose Windows as the platform and Microsoft Defender Antivirus for the profile type then select on CreateFor more information, see Antivirus policy for endpoint security in Intune.Enter a Name for the policy and optionally a description and select Next to go to Configuration settings.Edit your Microsoft Defender Antivirus settings.Choose Review + save.The following CSP settings can be configured in a Microsoft Defender Antivirus policy within Intune.
Policies and settings
This section lists eachThe following sections list the Microsoft Defender Antivirus policy settingsettings that you can configure in Intune, along with its CSPIntune. Each entry includes a configuration service provider (CSP) reference and the available options.
Allow Archive Scanning
This policyUse this setting enables you to configure scans for malicious software withinin archive filesfiles, such as .ZIPZIP or .CABCAB files.
-: The setting reverts to the clientpolicy doesn't set a value. By default, which is to scan archivedMicrosoft Defender Antivirus scans archive files. UserDevice users can disable this setting.archive scanning. -: Archive files aren't scanned, instead they're alwaysscanned during regular scans but are scanned during directed scans. - Enable scans of archive files.: Archive files are scanned. This option is the recommended configuration.recommended.arendon't applied ifapply when tamper protection is enabled.
Allow behavior monitoring
This policyUse this setting enables you to configure behavior monitoring.
-: The setting reverts to the system default (real-policy doesn't set a value. By default, Microsoft Defender Antivirus enables real-time behavior monitoring is enabled).monitoring. - The setting: Behavior monitoring is disabled. -: Real-time behavior monitoring is enabled. This option is the recommended configuration.recommended.arendon't applied ifapply when tamper protection is enabled.
Turn on cloud-delivered protection
policy setting enables you to joincontrols membership in Microsoft MAPS (Microsoft Active Protection Service)Service (MAPS). Microsoft MAPS is thean online communityservice that helps you choosedetermine how to respond to potential threats. The community also helpsthreats and stop the spread of new malicious software infections.malware.
detected items on your computerdevice is automatically collected and sent to Microsoft.
any detected malicious software,malware, spyware, and potentially unwanted software:
softwaresoftware.apply or that are applied automaticallyMicrosoft Defender Antivirus apply, and their success,whether the actions succeed.softwaresoftware.namesnames.operatesoperates.Its impactThe effect of the software on your computer.the device.Cloud-delivered protection options
-: The setting reverts to the system default (cloud-policy doesn't set a value. By default, Microsoft Defender Antivirus turns on cloud-delivered protection is turned off).protection. -: Cloud-delivered protection is turned off. -: Cloud-delivered protection is turned on.wondon't be applied ifapply when tamper protection is enabled.
Allow email scanning
This policyUse this setting enables you to configure e-mailemail scanning. When e-mailemail scanning is enabled, the engineMicrosoft Defender Antivirus parses thesupported mailbox and mail files, according to their specific format, in order to analyze the mail bodiesemail files during on-demand and attachments. Several e-mailscheduled scans. Supported formats are currently supported, for example: pst (Outlook), dbx, mbx, mime (Outlook Express), binhex (Mac). Email scanning isninclude DBX, MBX, and MIME. Non-Unicode PST files from Outlook 2003 or earlier can also be scanned, but detected threats inside PST files can't supported on modernbe remediated. Modern email clients.clients don't support email scanning.
-: The setting reverts to the system default (turn off email scanning).Not allowed - Turnpolicy doesn't set a value. By default, Microsoft Defender Antivirus turns off email scanning. - Turn on email scanning.: Email scanning is turned on. This option is the recommended configuration.recommended.Allow Full Scan On Mapped Network Drives
This policyUse this setting enables you to configure scanningscans of mapped network drives.
-: The setting reverts to the system default (mappedpolicy doesn't set a value. By default, Microsoft Defender Antivirus doesn't scan mapped network drives won't be scanned).drives. -: Mapped network drives wonaren't be scanned. - Enable scans of mapped: Mapped network drives.drives are scanned.Allow Full Scan Removable Drive Scanning
This policyUse this setting enables you to managecontrol whether or not to scan for malicious software and unwanted software in the contents offull scans check removable drives, such as USB flash drives, when running a full scan.for malware and unwanted software.
-: The setting reverts to the system default (removablepolicy doesn't set a value. By default, Microsoft Defender Antivirus doesn't check removable drives won't be scanned during a full scan but theyscans. Quick and custom scans might still be scanned during quick scan and custom scan).check removable drives. - Removable drives won: Full scans don't be scanned during a full scancheck removable drives, but they might still be scanned during quick scan and custom scan.scans might. - Removable drives are scanned during any type of scan.: All scan types check removable drives. This option is the recommended configuration.recommended.Allow scanning of all downloaded files and attachments
This policyUse this setting enables you to configure scanning for allof downloaded files and attachments.
-: The setting reverts to the system default (scanning forpolicy doesn't set a value. By default, Microsoft Defender Antivirus scans all downloaded files and attachments are enabled).attachments. - Scanning for all downloaded: Downloaded files and attachments aren't scanned.disabled.Allowed - Scanning for all downloaded files and attachments are enabled.scanned. This option is the recommended configuration.recommended.wondon't be applied ifapply when tamper protection is enabled.
Allow Real-Time Monitoring
EnablesUse this setting to enable or disenables Windowsdisable Microsoft Defender Antivirus real-time Monitoring functionality.monitoring.
-: The setting reverts to the system default (turns on andpolicy doesn't set a value. By default, Microsoft Defender Antivirus runs the real-time monitoring service).Not allowed - Turns off the real-time monitoring service.AllowedNot allowed - Turns on and runs the: The real-time monitoring service.service is turned off.the recommended configuration.recommended.wondon't be applied ifapply when tamper protection is enabled.
Allow Scanning Network Files
enablescanningNetworkFilesAllowScanningNetworkFiles
This policyUse this setting enables you to configure both scheduled scans and on-demand (manually initiated) scans forof files accessed over the network.
-: The setting reverts to the system default (network files is scanned).policy doesn't set a value. By default, Microsoft Defender Antivirus scans network files. -: Network files isnaren't scanned. -: Network files are scanned. This option is the recommended configuration.recommended.Allow Script Scanning
enablescriptScanningAllowScriptScanning
This policyUse this setting enablesto enable or disables the Windowsdisable Microsoft Defender Script Scanning functionality.Antivirus script scanning.
-: The setting reverts to the system default (script scanning is allowed).policy doesn't set a value. By default, Microsoft Defender Antivirus allows script scanning. - The setting: Script scanning is disabled, scripts won't be scanned.disabled. - The setting: Script scanning and the Antimalware Scan Interface are enabled. This option is enabled, scripts are scanned(enables the Anti-malware Scan Interface). This is the recommended configuration.recommended.arendon't applied if theapply when tamper protection setting is enabled.
Allow User UI Access
This policyUse this setting enables you to configurecontrol whether or not to displaydevice users can access the Microsoft Defender app UI to the users.user interface and notifications.
-: The setting revertspolicy doesn't set a value. By default, Microsoft Defender Antivirus allows access to the system default (the UIuser interface and notifications are allowed).notifications. - The setting is disabled. Prevents: Device users from accessing UIcan't access the user interface, and the notifications are suppressed. - The setting is enabled. The: Device users can access the Defender UIuser interface and notifications are allowed.receive notifications. This option is the recommended configuration.recommended.Avg CPU Load Factor
This policyUse this setting enables you to specify the maximum CPU load factor for theMicrosoft Defender Antivirus scans.
-: The setting reverts to the system default, where CPU utilizationpolicy doesn't exceedset a value. By default, the default value ofmaximum CPU load factor in Microsoft Defender Antivirus is 50%. -: Set the target maximum average CPU utilization won't exceeduse for scans. The value is guidance for the specified percentage. A valuescanning engine, not a hard limit. Values of 0 means there's no throttling ofor 100 disable CPU utilization.throttling. Manual scans ignore this setting.Archive Max Depth
This policyUse this setting enables you to specify the maximum folder depth to extract from archive files for scanning.
-: The setting reverts to the system default (allpolicy doesn't set a value. By default, Microsoft Defender Antivirus extracts all archives are extracted up to the deepest folder for scanning).scanning. - All archives: Archives are extracted up to the folder depth specified in the policy.Archive Max Size
This policyUse this setting enables you to specify the maximum size, in KB, of archive files to be extractedextract and scanned.scan.
-: The setting reverts to the systempolicy doesn't set a value. By default, whereMicrosoft Defender Antivirus extracts and scans all archives are extracted and scanned regardless of size. -: Archives smaller than the specified maximum size are extracted and scanned if their size is smaller than the maximum size specified in the policy.scanned.Check For Signatures Before Running Scan
This policyUse this setting allows you to managecontrol whether a checkMicrosoft Defender Antivirus checks for new virus and spyware security intelligence occurs before running a scan. This is only applicable to scheduled scans.scan.
-: The setting reverts to the systempolicy doesn't set a value. By default, whereMicrosoft Defender Antivirus starts the scan starts usingwith the currentexisting security intelligence. -: The scan begins usingstarts with the existing security intelligence. - Before running a scan, the system: Microsoft Defender Antivirus checks for new security intelligence.intelligence before starting the scan. This option is the recommended configuration.recommended.Cloud Block Level
0x0.Cloud Extended Timeout
This feature allowsCSP: CloudExtendedTimeoutto blockblocks a suspicious file for up to 60 seconds, and scanwhile scanning it in the cloud to make sure it's safe.cloud cloud-check time-outtimeout is 10 seconds. To enable this feature, specify the extended time in seconds. TheYou can add up to 50 seconds for a maximum time-out is 50timeout of 60 seconds.
-: The setting reverts topolicy doesn't set a value. By default, the system default (cloud time outMicrosoft Defender Antivirus cloud-check timeout is 10 seconds).seconds. - The cloud time out is extended with: Add the specified amount.number of seconds to the default timeout. The recommended value is 50.Days To Retain Cleaned Malware
This policyUse this setting defines the number ofto specify how many days to keep items should be kept in the Quarantine folderquarantine before being removed.removing them.
-: The setting reverts to the system default.policy doesn't set a value. By default, Microsoft Defender Antivirus keeps items in quarantine for 90 days.are keptremain in the quarantine folder indefinitely and wonaren't be automatically removed.removed automatically.0-1-90] -: Items are removed from the Quarantine folderquarantine after the specified number of days specified.days.Disable Catchup Full Scan
This policyUse this setting enables you to configurecontrol whether catch-up full scans forrun after missed scheduled full scans. ABecause the setting name begins with Disable, enabling the setting disables catch-up scan is a scan that's initiated because a regularly scheduled scan was missed. Usually these scheduled scans are missed becausefull scans, and disabling the computer was turned off at the scheduled time.setting enables them.
-: The setting reverts to the system default.policy doesn't set a value. By default, Microsoft Defender Antivirus disables catch-up full scans. -: Catch-up scans for scheduled full scans are turned on.enabled. If a computer is offline fordevice misses two consecutive scheduled full scans, a catch-up full scan is startedstarts the next time someone sign-ins the computer. If there's nosigns in. Catch-up scans require a configured scheduled scan configured, there's no catch-up scan run.scan. -: Catch-up scans for scheduled full scans isare disabled.Disable Catchup Quick Scan
This policyUse this setting allows you to configurecontrol whether catch-up quick scans forrun after missed scheduled quick scans. ABecause the setting name begins with Disable, enabling the setting disables catch-up scan is a scan that's initiated because a regularly scheduled scan was missed. Usually these scheduled scans are missed becausequick scans, and disabling the computer was turned off at the scheduled time.setting enables them.
-: The setting reverts to the system default (catch-policy doesn't set a value. By default, Microsoft Defender Antivirus disables catch-up scans for scheduled quick scans is turned on).scans. -: Catch-up scans for scheduled quick scans are turned on.enabled. If a computer is offline fordevice misses two consecutive scheduled quick scans, a catch-up quick scan is startedstarts the next time someone sign-ins the computer. If there's nodevice powers on or resumes from sleep or hibernation. Catch-up scans require a configured scheduled scan configured, there's no catch-up scan run.scan. -: Catch-up scans for scheduled quick scans isare disabled.Enable Low CPU Priority
This policyUse this setting enables you to enable or disablecontrol whether scheduled scans use low CPU priority for scheduled scans.priority.
-: The setting reverts topolicy doesn't set a value. By default, Microsoft Defender Antivirus doesn't change the system default, meaning no changes is made to CPU priority for scheduled scans. - No change is made to: The CPU priority for scheduled scans.scans isn't changed. - Low: Scheduled scans use low CPU priority is used during scheduled scans.priority.Enable Network Protection
Enable or disable Microsoft Defender Exploit GuardUse this setting to configure network protection to prevent employeesprotection, which prevents applications from using applications to accessaccessing dangerous domains that might host phishing scams, exploit-hosting sites, andexploits, or other malicious content on the internet.content.
-: The setting reverts to the systempolicy doesn't set a value. By default, meaningMicrosoft Defender Antivirus doesn't block users andor applications won't be blocked from connecting to dangerous domains. -: Users and applications aren't blocked from connecting to dangerous domains.Enabled(blockEnabled (block mode) -: Users and applications won't be able to accessare blocked from accessing dangerous domains. This option is the recommended configuration.recommended.Enabled(auditEnabled (audit mode) -: Users and applications can connect toaccess dangerous domains. However, if this featureEvents that network protection would have blocked access when set to Block, a record of the event will be loggedblock in block mode are recorded in the event logs.log.Excluded Extensions
Allows administratorsUse this setting to specify a list of file extensions to ignore during a scan.exclude from scans. For more details on how these exclusions can be defined you can read this article:information, see Exclusions based on file extension and folder location.
Excluded Paths
Allows administratorsUse this setting to specify a list of directory paths to ignore during a scan.exclude from scans. For more details on how these exclusions can be defined you can read this article:information, see Exclusions based on file extension and folder location.
Excluded Processes
Allows administratorsUse this setting to specify a list of files that processes can open without being scanned. For more details on how these exclusions can be defined you can read this article:information, see Exclusions based on file extension and folder location.
PUA Protection
Enable or disableUse this setting to configure detection forof potentially unwanted applications.applications (PUAs). You can choose to block, audit, or allow when potentially unwanted software is beingwhen it's downloaded or attempts to install itself on your computer.a device.
-: The setting revertspolicy doesn't set a value. The Microsoft Defender Antivirus default depends on the Windows version, security intelligence version, Smart App Control availability, and whether the device is onboarded to the system default, meaningDefender for Endpoint. For details, see Default PUA protection settings.wonisn't be blocked.Disabled - PUA protection is off, meaning potentially unwanted software won't be blocked. -: PUA protection is turned on, meaningand potentially unwanted software is blocked. This option is the recommended configuration.recommended. -: Potentially unwanted software wonisn't be blocked. However, if this featureEvents that PUA protection would have blocked access when set to Block, a record of the event will be loggedblock in block mode are recorded in the event logs.log.Real Time Scan Direction
This policyUse this setting allows you to configure monitoring forof incoming and outgoing files without disabling monitoring entirely. It's recommendedThis setting is useful for servers with high volumes of file activity, whereactivity when scanning needs tomust be disabled for a specificin one direction to maintain performance. TheEvaluate the appropriate configuration should be evaluated based on the server's role.
isapplies only applicable to NTFS volumes. For any other file system type,Microsoft Defender Antivirus enforces full monitoring of file and program activity will be enforced on those volumes.other file-system types.
-: The setting reverts to the systempolicy doesn't set a value. By default, meaning, monitoring forMicrosoft Defender Antivirus monitors incoming and outgoing files are enabled.files. -: Scan incoming and outgoing files (default)files. This option is the default. -: Scan incoming files only. -: Scan outgoing files only.Scan Parameter
This policyUse this setting allows you to specify the scan type used during afor scheduled scan.scans. This setting interacts with the settings Schedule Scan Day and Schedule Scan Time.
-: The setting reverts to the system default.policy doesn't set a value. By default, Microsoft Defender Antivirus uses quick scans. -: Microsoft Defender Antivirus runs a scheduled quick scan. -: Microsoft Defender Antivirus runs a scheduled full scan.Schedule Quick Scan Time
This policyUse this setting allows you to specify the time of day at which to performfor a daily quick scan. The time value is represented asEnter the number of minutes past midnights.after midnight. This setting doesn't interact with the settings Scan Parameter, Schedule Scan Day, or Schedule Scan Time.Schedule Scan Day
-: The setting reverts to the systempolicy doesn't set a value. By default, meaning, the daily quick scan controlled by this config won't run.[0-1380] - A daily quick scanMicrosoft Defender Antivirus runs at the time of day specified.Schedule Scan Day CSP: ScheduleScanDay This policy setting allows you to specify the day of the week to perform a scheduled scan. The scan can also be configured to runscans every day or to never run at all. This setting interacts with the Scan Parameter setting (which controls whether the scan is a quick scan or full scan) and Schedule Scan Time.Not configured - The setting reverts to the system default.day. -: A scheduled scan runs daily. -: A scheduled scan runs once per week on the selected day. - No: A scheduled scan runs.doesn't run.Schedule Scan Time
This policyUse this setting allows you to specify the time of day to performfor a scheduled scan. The time is represented asEnter the number of minutes past midnights, with theafter midnight. The default beingvalue is 120 minutes (whichminutes, which corresponds to 2:00 AM).AM. This setting interacts with the Scan Parameter and Schedule Scan Day settings.
-: The setting reverts topolicy doesn't set a value. By default, the system default (a scheduledMicrosoft Defender Antivirus scan runs at a default time).time is 2:00 AM. -: A scheduled scan runs at the time of day specified.specified time.Signature Update Fallback Order
This policyUse this setting allows you to specify the order in which different security intelligence update sources are contacted. Although the underlying policy is stored asEnter a pipe-separated string, Intune presents this setting as a prioritized list of update sources. Administrators should configurestring that lists the sources in the desired order using the Intune UI, where sources are evaluated from top to bottom. Possibleorder. Available values include: "InternalDefinitionUpdateServer," "MicrosoftUpdateServer," "MMPC,"include InternalDefinitionUpdateServer, MicrosoftUpdateServer, MMPC, and "FileShares."FileShares.
-: The setting reverts to the system default. Meaning,policy doesn't set a value. By default, Microsoft Defender Antivirus contacts security intelligence update sources are contacted in athe default order. -: Security intelligence update sources are contacted in the order specified.specified order.Signature Update File Shares Sources
This policyUse this setting allows you to configure UNC file Universal Naming Convention (UNC) file-share sources for downloading security intelligence updates. Sources are contacted in the order specified. The value of this setting should be entered asEnter a pipe-separated string enumeratingthat lists the security intelligence update sources.sources in the order in which Microsoft Defender Antivirus should contact them.
-: The setting reverts topolicy doesn't set a value. By default, the system default. Meaning, theMicrosoft Defender Antivirus source list remains empty by defaultis empty, and no file-share sources are contacted. -: The specified file-share sources are contacted for security intelligence updates.in order.Signature Update Interval
This policyUse this setting allows you to specify an interval at which to checkthe number of hours between checks for security intelligence updates. The time valuedefault interval is represented as the number of hours between update checks. The default is 8h.eight hours.
-: The setting reverts to the system default. Meaning, itpolicy doesn't set a value. By default, Microsoft Defender Antivirus checks for updates every eight hours.intelligenceintelligence. occur at the defaultspecified interval.[0-24] - Checks for security intelligence updates occur at the interval specified. The recommended value is 4.Submit Samples Consent
This policyUse this setting configures behavior of samplesto configure sample submission when opt-in for MAPS telemetry is set.enabled.
-: The setting reverts to the system default which is to sendpolicy doesn't set a value. By default, Microsoft Defender Antivirus sends safe samples automatically. - The user is always: Device users are prompted for consent before file submission.files are submitted. - Safe samples: Files that typically don't contain personally identifiable information (PII), such as .bat, .scr, .dll, and .exe files, are samples considered to not commonlysent automatically. Device users are prompted before files that might contain PII data (examples include .bat, .scr, .dll, and .exe). If file is likely to contain PII, the user gets a request to allow file sample submission.are submitted. - Prevents : File samples aren't sent. This option prevents block at first sight based on file file-sample analysis. MetadataDetection metadata is sent for detections even if sample submission is disabled.still sent. -: All samples are sent automatically. This option is the recommended configuration.recommended.Disable Local Admin Merge
valuesetting is set to no, it gives adisabled, local admin the ability toadministrators can configure local policy overrides for Microsoft Defender Antivirus on their devices by using the Windows Security app, localLocal Group Policy settings,Editor, or PowerShell cmdlets (where appropriate).cmdlets, where supported.
-: The setting reverts to the system default.policy doesn't set a value. By default, Microsoft Defender Antivirus enables local administrator merge. -: Unique items defined in preference settings that areitems configured by a local administrator mergeare merged into the resulting effective policy. If there are conflicts, management settings fromconflict, managed Intune policy settings override local preference settings.preferences. -: Only itemssettings defined by management are used in the resulting effective policy. Managed settings override preference settings that are configured by the local administrator.preferences. This option is the recommended configuration.recommended.Allow On Access Protection
This policyUse this setting enables you to configure monitoring forof file and program activity.
-: The setting reverts to the system default which is to monitoring forpolicy doesn't set a value. By default, Microsoft Defender Antivirus monitors file and program activity.enabled.Allowed - Monitoring for file and program activity is enabled.monitored. - Monitoring for file: File and program activity is disabled.isn't monitored.arendon't applied ifapply when tamper protection is enabled.
Threat Severity Default Action
This policyUse this setting allows you to customize the automatic remediation action for each threat alert level. The following lists contain the valid remediation actions:
-: The setting reverts topolicy doesn't set a value. By default, Microsoft Defender Antivirus applies the system default which is to apply action based onspecified in the update definition.security intelligence update. - Service tries: Attempt to recover files and tries to disinfect.disinfect files. - Moves: Move files to quarantine. - Removes: Remove files from system.the device. - enables: Allow the file and doesn't take other actions.without taking another action. - The: Let the device user makesselect the decision on which action to take.action. - Blocks: Block file execution.arendon't applied ifapply when tamper protection is enabled.
Allow Network Protection Down Level
ThisUse this setting determinesto control whether Network Protection is allowed to be configured intonetwork protection can use block or audit mode on Windows downlevel ofversions earlier than RS3. If false,When this setting is disabled, the Enable Network Protectionvalue of EnableNetworkProtection is ignored.
-: The setting reverts to the system default which is topolicy doesn't set a value. By default, Microsoft Defender Antivirus disables network protection is disabled downlevel.on earlier Windows versions. -: Network protection is enabled downlevel.on earlier Windows versions. -: Network protection is disabled downlevel.on earlier Windows versions.Allow Datagram Processing On Win Server
ThisUse this setting determinesto control whether Network Protectionnetwork protection can enable datagram processing on Windows Server. If set to false,When this setting is disabled, the Disable Datagram Processingvalue of DisableDatagramProcessing is ignored, and datagram inspection is disabled by default.disabled.
-: The setting reverts to the systempolicy doesn't set a value. By default, meaning,Microsoft Defender Antivirus disables datagram processing on Windows Server is disabled.Server. -: Datagram processing is enabled on Windows Server is enabled.Server. -: Datagram processing is disabled on Windows Server is disabled.Server.Disable Dns Over Tcp Parsing
ThisUse this setting disablesto disable DNS over TCP Parsingparsing for Network Protection.network protection.
-: The setting reverts to the systempolicy doesn't set a value. By default, meaning,Microsoft Defender Antivirus enables DNS over TCP parsing is enabled.parsing. -: DNS over TCP parsing is disabled. -: DNS over TCP parsing is enabled.Disable Http Parsing
ThisUse this setting disablesto disable HTTP Parsingparsing for Network Protection.network protection.
-: The setting reverts to the systempolicy doesn't set a value. By default, meaning,Microsoft Defender Antivirus enables HTTP parsing is enabled.parsing. -: HTTP parsing is disabled. -: HTTP parsing is enabled.Disable Ssh Parsing
ThisUse this setting disables SSH Parsingto disable Secure Shell (SSH) parsing for Network Protection.network protection.
-: The setting reverts to the system default (SSH parsing is enabled).policy doesn't set a value. By default, Microsoft Defender Antivirus enables SSH parsing. -: SSH parsing is disabled. -: SSH parsing is enabled.Disable Tls Parsing
ThisUse this setting disables TLS Parsingto disable Transport Layer Security (TLS) parsing for Network Protection.network protection.
-: The setting reverts to the systempolicy doesn't set a value. By default, meaning,Microsoft Defender Antivirus enables TLS parsing is enabled.parsing. -: TLS parsing is disabled. -: TLS parsing is enabled.Engine Updates Channel
EnableUse this policysetting to specify when devices receive Microsoft Defender Antivirus engine updates during the monthly gradual rollout.
-: The setting reverts to the systempolicy doesn't set a value. By default, meaning, the device staysMicrosoft Defender Antivirus keeps devices up to date automatically during the gradual release cycle. Suitablerollout. This option is suitable for most devices. -: Devices set toreceive updates first. Use this channel are the firston a limited number of test devices to receive new updates. Select Beta Channel to participate in identifyingidentify and reportingreport issues to Microsoft. Devices in the Windows Insider Program are subscribed touse this channel by default. For use in (manual) test environments only and a limited number of devices. -: Devices set to this channel is offeredreceive updates earliest duringearly in the monthly gradual release cycle. Suggestedrollout. This channel is recommended for pre-production/preproduction or validation environments. -: Devices is offeredreceive updates after the monthly gradual release cycle. Suggested to applyearly rollout stages. Apply this channel to a small, representative partgroup of your production population (~devices, such as 10%). -: Devices is offeredreceive updates only after the gradual release cycle completes. Suggestedrollout is complete. Apply this channel broadly to apply to a broad set of devices in your production population (~10-100%).devices. -: Devices are offeredreceive updates withafter a 48-hour delay. SuggestedUse this channel only for critical environments only.environments.Metered Connection Updates
ThisUse this setting enablesto control whether managed devices to updatecan get updates through metered connections.
-: The setting reverts to the system default (not allowed).policy doesn't set a value. By default, Microsoft Defender Antivirus doesn't allow updates through metered connections. - managed: Managed devices updatecan get updates through metered connections. - managed: Managed devices woncan't updateget updates through metered connections.Platform Updates Channel
EnableUse this policysetting to specify when devices receive Microsoft Defender Antivirus platform updates during the monthly gradual rollout.
-: The setting reverts to the systempolicy doesn't set a value. By default, meaning, the device staysMicrosoft Defender Antivirus keeps devices up to date automatically during the gradual release cycle. Suitablerollout. This option is suitable for most devices. -: Devices set toreceive updates first. Use this channel is the firston a limited number of test devices to receive new updates. Select Beta Channel to participate in identifyingidentify and reportingreport issues to Microsoft. Devices in the Windows Insider Program are subscribed touse this channel by default. For use in (manual) test environments only and a limited number of devices. -: Devices set to this channel is offeredreceive updates earliest duringearly in the monthly gradual release cycle. Suggestedrollout. This channel is recommended for pre-production/preproduction or validation environments. -: Devices is offeredreceive updates after the monthly gradual release cycle. Suggested to applyearly rollout stages. Apply this channel to a small, representative partgroup of your production population (~devices, such as 10%). -: Devices is offeredreceive updates only after the gradual release cycle completes. Suggestedrollout is complete. Apply this channel broadly to apply to a broad set of devices in your production population (~10-100%).devices. -: Devices are offeredreceive updates withafter a 48-hour delay. SuggestedUse this channel only for critical environments only.environments.Security Intelligence Updates Channel
EnableUse this policysetting to specify when devices receive Microsoft Defender Antivirus security intelligence updates during the daily gradual rollout.
-: The policy doesn't set a value. By default, Microsoft will either assignassigns the device to Current Channel (Broad) or to a beta channel early in the gradual release cycle. Therollout. A beta channel selected by Microsoft might be one that receives updates early during the gradual release cycle, which might not be suitable for devices in a production or critical environment.devices. - Same: Use the same rollout timing as Current Channel (Broad). -: Devices is offeredreceive updates only after the gradual release cycle completes. Suggestedrollout is complete. Apply this channel broadly, including to apply to a broad set of devices in all populations, including production.production devices.Randomize Schedule Task Times
In Microsoft Defender Antivirus,Use this setting to randomize thescan start time of the scan to anytimes across an interval from 0 tothrough 23 hours. ThisRandomization can be usefulhelp distribute resource use in virtual machinesmachine or VDIvirtual desktop infrastructure (VDI) deployments.
-: The setting reverts to the system default (scheduled tasks are randomized).policy doesn't set a value. By default, Microsoft Defender Antivirus randomizes scheduled tasks.scans. Specifyscans (Default): Use Scheduler Randomization Time to specify a randomization window of betweenfrom 1 andthrough 23 hours by using the setting SchedulerRandomizationTimehours.Scheduler Randomization Time
ThisUse this setting enables you to configure the scheduler randomization in hours. The randomization interval is [1 - 23]in hours.
-: The setting reverts topolicy doesn't set a value. By default, the system default (4 hours).Microsoft Defender Antivirus randomization interval is four hours. - The randomization interval is defined by: Scheduled tasks are randomized across the value specified in the policy.number of hours.Disable Core Service ECS Integration
Turn off ECSUse this setting to control Experimentation and Configuration Service (ECS) integration for the Defender core service.
-: The setting reverts to the systempolicy doesn't set a value. By default, meaning, the Defender core service uses ECS..: ECS integration is enabled.Disable Core Service Telemetry
Turn offUse this setting to control OneDsCollector telemetry for the Defender core service.
-: The setting reverts to the systempolicy doesn't set a value. By default, meaning, the Defender core service uses the OneDsCollector framework..: OneDsCollector telemetry is enabled..: OneDsCollector telemetry is disabled.
@@ -1,621 +1,659 @@ --- title: Configure Microsoft Defender Antivirus using Microsoft Intune-description: Use Microsoft Intune to configure Microsoft Defender Antivirus and Endpoint Protection+description: Learn how to use Microsoft Intune to configure Microsoft Defender Antivirus policies, including catch-up scan behavior, on managed Windows devices. ms.service: defender-endpoint ms.localizationpriority: medium author: chrisda ms.author: chrisda-ms.custom: nextgen, msecd-doc-authoring-1016-ms.date: 07/02/2026+ms.custom: nextgen, msecd-doc-authoring-1015+ms.date: 08/21/2026 ms.reviewer: phuijbr, yongrhee ms.subservice: ngp ms.topic: how-to-ms.collection: +ms.collection: - m365-security - tier2 - mde-ngp appliesto: - Microsoft Defender for Endpoint Plan 1 - Microsoft Defender for Endpoint Plan 2- ai-usage: ai-assisted+#customer intent: As a security administrator, I want to configure Microsoft Defender Antivirus settings in Intune so that managed Windows devices use the intended protection settings. ----# Use Microsoft Intune to configure and manage Microsoft Defender Antivirus +# Configure Microsoft Defender Antivirus using Microsoft Intune++Security administrators can use Microsoft Intune to configure Microsoft Defender Antivirus on managed Windows devices. This article explains how to create an antivirus policy and describes the available policy settings, values, defaults, and recommended configurations. <a name="compatibility"></a> ## Supported platforms and Intune compatibility -Microsoft Defender Antivirus management through Intune is supported on the following platforms:--- Windows 10 and later--You can use the Microsoft Intune family of products to configure Microsoft Defender Antivirus settings, like [Microsoft Intune](/intune/intune-service/fundamentals/what-is-intune) and [Configuration Manager](/intune/configmgr/core/understand/introduction).--### Configure Microsoft Defender Antivirus settings in Intune+You can manage Microsoft Defender Antivirus through Intune on the following platforms: -To create and configure a Microsoft Defender Antivirus policy in Intune, perform the following steps:+- Windows devices enrolled in Intune+- Windows Server devices managed through [Microsoft Defender for Endpoint security settings management](/intune/intune-service/protect/mde-security-integration) -1. Go to the [Microsoft Intune admin center](https://intune.microsoft.com), and sign in.+You can configure Microsoft Defender Antivirus settings by using [Microsoft Intune](/intune/intune-service/fundamentals/what-is-intune) or [Configuration Manager](/intune/configmgr/core/understand/introduction). -1. Navigate to **Endpoint Security**.+> [!IMPORTANT]+> [Windows 10 reached end of support](/lifecycle/announcements/windows-10-end-of-support) on October 14, 2025. Windows 10 devices can still enroll in Intune and use eligible features, but functionality isn't guaranteed and can vary. -1. Under **Manage**, choose **Antivirus**.+> [!NOTE]+> Microsoft Intune is a separate product from Microsoft Defender for Endpoint and isn't included in every subscription. You need a subscription that includes Intune, or you can buy Intune as a standalone subscription or add-on. For licensing details, see [Microsoft Intune licensing](/intune/intune-service/fundamentals/licenses). If you don't use Intune, see [Reference articles for management and configuration tools](configuration-management-reference-microsoft-defender-antivirus.md) for other ways to configure Microsoft Defender Antivirus. -1. Click **Create Policy**, choose **Windows** as the platform and **Microsoft Defender Antivirus** for the profile type then select on **Create**.+<a name="configure-microsoft-defender-antivirus-settings-in-intune"></a> -1. Enter a **Name** for the policy and optionally a description and select **Next** to go to **Configuration settings**.+## Configure Microsoft Defender Antivirus settings in Intune -1. Edit your Microsoft Defender Antivirus settings.+Create an antivirus policy by following <a href="/intune/intune-service/protect/endpoint-security-policy#create-endpoint-security-policies" target="_blank">Create an endpoint security policy</a> (opens in a new tab in the Intune documentation). Use the following settings: -1. Choose **Review + save**.+- **Policy type**: Antivirus+- **Platform**: Windows+- **Profile**: Microsoft Defender Antivirus+- **Basics**: Enter a name and optional description for the policy.+- **Configuration settings**: Expand each group of settings, and configure the settings you want to manage with this policy. For descriptions of the available settings and options, see [Policies and settings](#policies-and-settings).+- **Scope tags**: If your organization uses [scope tags](/intune/intune-service/fundamentals/scope-tags), select the tags you want to use.+- **Assignments**: Select the users or groups to receive this policy. For more information, see [Assign policies in Microsoft Intune](/intune/intune-service/configuration/device-profile-assign). -The following CSP settings can be configured in a **Microsoft Defender Antivirus** policy within Intune.+For more information, see [Antivirus policy for endpoint security in Intune](/intune/intune-service/protect/endpoint-security-antivirus-policy). ## Policies and settings -This section lists each Microsoft Defender Antivirus policy setting that you can configure in Intune, along with its CSP reference and available options.+The following sections list the Microsoft Defender Antivirus policy settings that you can configure in Intune. Each entry includes a configuration service provider (CSP) reference and the available options. ### Allow Archive Scanning - CSP: [AllowArchiveScanning](/windows/client-management/mdm/policy-csp-defender#allowarchivescanning)+CSP: [AllowArchiveScanning](/windows/client-management/mdm/policy-csp-defender#allowarchivescanning) - This policy setting enables you to configure scans for malicious software within archive files such as .ZIP or .CAB files.+Use this setting to configure scans for malicious software in archive files, such as ZIP or CAB files. - - **Not configured** - The setting reverts to the client default, which is to scan archived files. User can disable this setting.- - **Not allowed** - Archive files aren't scanned, instead they're always scanned during directed scans.- - **Allowed** - Enable scans of archive files. This is the recommended configuration.+- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus scans archive files. Device users can disable archive scanning.+- **Not allowed**: Archive files aren't scanned during regular scans but are scanned during directed scans.+- **Allowed**: Archive files are scanned. This option is recommended. - Changes to this setting aren't applied if tamper protection is enabled.+Changes to this setting don't apply when tamper protection is enabled. ### Allow behavior monitoring - CSP: [AllowBehaviorMonitoring](/windows/client-management/mdm/policy-csp-defender#allowbehaviormonitoring)+CSP: [AllowBehaviorMonitoring](/windows/client-management/mdm/policy-csp-defender#allowbehaviormonitoring) - This policy setting enables you to configure behavior monitoring.+Use this setting to configure behavior monitoring. - - **Not configured** - The setting reverts to the system default (real-time behavior monitoring is enabled).- - **Not allowed** - The setting is disabled.- - **Allowed** - Real-time behavior monitoring is enabled. This is the recommended configuration.+- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus enables real-time behavior monitoring.+- **Not allowed**: Behavior monitoring is disabled.+- **Allowed**: Real-time behavior monitoring is enabled. This option is recommended. - Changes to this setting aren't applied if tamper protection is enabled.+Changes to this setting don't apply when tamper protection is enabled. ### Turn on cloud-delivered protection - CSP: [AllowCloudProtection](/windows/client-management/mdm/policy-csp-defender#allowcloudprotection)+CSP: [AllowCloudProtection](/windows/client-management/mdm/policy-csp-defender#allowcloudprotection) > [!IMPORTANT]->[We recommend keeping cloud protection turned on, because certain security features and capabilities in Microsoft Defender for Endpoint only work when cloud protection is enabled](enable-cloud-protection-microsoft-defender-antivirus.md).+> Microsoft recommends that you [keep cloud protection turned on](enable-cloud-protection-microsoft-defender-antivirus.md) because certain Microsoft Defender for Endpoint features work only when cloud protection is enabled.++This setting controls membership in Microsoft Active Protection Service (MAPS). MAPS is an online service that helps determine how to respond to potential threats and stop the spread of new malware.++Information about items detected on the device is automatically collected and sent to Microsoft. - This policy setting enables you to join Microsoft MAPS (Microsoft Active Protection Service). Microsoft MAPS is the online community that helps you choose how to respond to potential threats. The community also helps stop the spread of new malicious software infections.+The following information is collected about detected malware, spyware, and potentially unwanted software: - Information about the detected items on your computer is automatically collected and sent to Microsoft. - - The following information is collected about any detected malicious software, spyware, and potentially unwanted software:- - - The source of the software- - The actions you apply or that are applied automatically and their success,- - The location of the software- - File names- - How the software operates- - Its impact on your computer.+- The source of the software.+- The actions that you or Microsoft Defender Antivirus apply, and whether the actions succeed.+- The location of the software.+- File names.+- How the software operates.+- The effect of the software on the device. <a name="settings"></a> #### Cloud-delivered protection options - The following options are available for cloud-delivered protection:+The following options are available for cloud-delivered protection: - - **Not configured** - The setting reverts to the system default (cloud-delivered protection is turned off).- - **Not allowed** - Cloud-delivered protection is turned off.- - **Allowed** - Cloud-delivered protection is turned on.+- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus turns on cloud-delivered protection.+- **Not allowed**: Cloud-delivered protection is turned off.+- **Allowed**: Cloud-delivered protection is turned on. - Changes to this setting won't be applied if tamper protection is enabled.+Changes to this setting don't apply when tamper protection is enabled. -### Allow email scanning +### Allow email scanning - CSP: [AllowEmailScanning](/windows/client-management/mdm/policy-csp-defender#allowemailscanning)+CSP: [AllowEmailScanning](/windows/client-management/mdm/policy-csp-defender#allowemailscanning) - This policy setting enables you to configure e-mail scanning. When e-mail scanning is enabled, the engine parses the mailbox and mail files, according to their specific format, in order to analyze the mail bodies and attachments. Several e-mail formats are currently supported, for example: pst (Outlook), dbx, mbx, mime (Outlook Express), binhex (Mac). Email scanning isn't supported on modern email clients.+Use this setting to configure email scanning. When email scanning is enabled, Microsoft Defender Antivirus parses supported mailbox and email files during on-demand and scheduled scans. Supported formats include DBX, MBX, and MIME. Non-Unicode PST files from Outlook 2003 or earlier can also be scanned, but detected threats inside PST files can't be remediated. Modern email clients don't support email scanning.++- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus turns off email scanning.+- **Not allowed**: Email scanning is turned off.+- **Allowed**: Email scanning is turned on. This option is recommended. - - **Not configured** - The setting reverts to the system default (turn off email scanning).- - **Not allowed** - Turn off email scanning.- - **Allowed** - Turn on email scanning. This is the recommended configuration.- ### Allow Full Scan On Mapped Network Drives - CSP: [AllowFullScanOnMappedNetworkDrives](/windows/client-management/mdm/policy-csp-defender#allowfullscanonmappednetworkdrives)+CSP: [AllowFullScanOnMappedNetworkDrives](/windows/client-management/mdm/policy-csp-defender#allowfullscanonmappednetworkdrives) - This policy setting enables you to configure scanning mapped network drives.+Use this setting to configure scans of mapped network drives. - - **Not configured** - The setting reverts to the system default (mapped network drives won't be scanned).- - **Not allowed** - Mapped network drives won't be scanned.- - **Allowed** - Enable scans of mapped network drives.+- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus doesn't scan mapped network drives.+- **Not allowed**: Mapped network drives aren't scanned.+- **Allowed**: Mapped network drives are scanned. ### Allow Full Scan Removable Drive Scanning - CSP: [AllowFullScanRemovableDriveScanning](/windows/client-management/mdm/policy-csp-defender#allowfullscanremovabledrivescanning)+CSP: [AllowFullScanRemovableDriveScanning](/windows/client-management/mdm/policy-csp-defender#allowfullscanremovabledrivescanning) - This policy setting enables you to manage whether or not to scan for malicious software and unwanted software in the contents of removable drives, such as USB flash drives, when running a full scan.+Use this setting to control whether full scans check removable drives, such as USB flash drives, for malware and unwanted software. - - **Not configured** - The setting reverts to the system default (removable drives won't be scanned during a full scan but they might still be scanned during quick scan and custom scan).- - **Not allowed** - Removable drives won't be scanned during a full scan but they might still be scanned during quick scan and custom scan.- - **Allowed** - Removable drives are scanned during any type of scan. This is the recommended configuration.+- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus doesn't check removable drives during full scans. Quick and custom scans might still check removable drives.+- **Not allowed**: Full scans don't check removable drives, but quick and custom scans might.+- **Allowed**: All scan types check removable drives. This option is recommended. ### Allow scanning of all downloaded files and attachments- CSP: [AllowIOAVProtection](/windows/client-management/mdm/policy-csp-defender#allowioavprotection) - This policy setting enables you to configure scanning for all downloaded files and attachments.+CSP: [AllowIOAVProtection](/windows/client-management/mdm/policy-csp-defender#allowioavprotection)++Use this setting to configure scanning of downloaded files and attachments. - - **Not configured** - The setting reverts to the system default (scanning for all downloaded files and attachments are enabled).- - **Not allowed** - Scanning for all downloaded files and attachments are disabled.- - **Allowed** - Scanning for all downloaded files and attachments are enabled. This is the recommended configuration.+- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus scans all downloaded files and attachments.+- **Not allowed**: Downloaded files and attachments aren't scanned.+- **Allowed**: Downloaded files and attachments are scanned. This option is recommended. - Changes to this setting won't be applied if tamper protection is enabled.+Changes to this setting don't apply when tamper protection is enabled. ### Allow Real-Time Monitoring- CSP: [AllowRealtimeMonitoring](/windows/client-management/mdm/policy-csp-defender#allowrealtimemonitoring) - Enables or disenables Windows Defender real-time Monitoring functionality.+CSP: [AllowRealtimeMonitoring](/windows/client-management/mdm/policy-csp-defender#allowrealtimemonitoring)++Use this setting to enable or disable Microsoft Defender Antivirus real-time monitoring. - - **Not configured** - The setting reverts to the system default (turns on and runs the real-time monitoring service).- - **Not allowed** - Turns off the real-time monitoring service.- - **Allowed** - Turns on and runs the real-time monitoring service. This is the recommended configuration.+- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus runs the real-time monitoring service.+- **Not allowed**: The real-time monitoring service is turned off.+- **Allowed**: The real-time monitoring service is turned on. This option is recommended. - Changes to this setting won't be applied if tamper protection is enabled.+Changes to this setting don't apply when tamper protection is enabled. ### Allow Scanning Network Files- CSP: [enablescanningNetworkFiles](/windows/client-management/mdm/policy-csp-defender#enablescanningnetworkfiles) - This policy setting enables you to configure both scheduled scans and on-demand (manually initiated) scans for files accessed over the network.- - - **Not configured** - The setting reverts to the system default (network files is scanned).- - **Not allowed** - Network files isn't scanned.- - **Allowed** - Network files are scanned. This is the recommended configuration.+CSP: [AllowScanningNetworkFiles](/windows/client-management/mdm/policy-csp-defender#allowscanningnetworkfiles)++Use this setting to configure scheduled and on-demand scans of files accessed over the network.++- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus scans network files.+- **Not allowed**: Network files aren't scanned.+- **Allowed**: Network files are scanned. This option is recommended. ### Allow Script Scanning- CSP: [enablescriptScanning](/windows/client-management/mdm/policy-csp-defender#enablescriptscanning) - This policy setting enables or disables the Windows Defender Script Scanning functionality.- - - **Not configured** - The setting reverts to the system default (script scanning is allowed).- - **Not allowed** - The setting is disabled, scripts won't be scanned.- - **Allowed** - The setting is enabled, scripts are scanned(enables the [Anti-malware Scan Interface](amsi-on-mdav.md)). This is the recommended configuration.+CSP: [AllowScriptScanning](/windows/client-management/mdm/policy-csp-defender#allowscriptscanning) - Changes to this setting aren't applied if the tamper protection setting is enabled.+Use this setting to enable or disable Microsoft Defender Antivirus script scanning.++- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus allows script scanning.+- **Not allowed**: Script scanning is disabled.+- **Allowed**: Script scanning and the [Antimalware Scan Interface](amsi-on-mdav.md) are enabled. This option is recommended.++Changes to this setting don't apply when tamper protection is enabled. ### Allow User UI Access- CSP: [AllowUserUIAccess](/windows/client-management/mdm/policy-csp-defender#allowuseruiaccess) - This policy setting enables you to configure whether or not to display the Microsoft Defender app UI to the users.- - - **Not configured** - The setting reverts to the system default (the UI and notifications are allowed).- - **Not allowed** - The setting is disabled. Prevents users from accessing UI and the notifications are suppressed.- - **Allowed** - The setting is enabled. The users can access the Defender UI and notifications are allowed. This is the recommended configuration.+CSP: [AllowUserUIAccess](/windows/client-management/mdm/policy-csp-defender#allowuseruiaccess)++Use this setting to control whether device users can access the Microsoft Defender user interface and notifications.++- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus allows access to the user interface and notifications.+- **Not allowed**: Device users can't access the user interface, and notifications are suppressed.+- **Allowed**: Device users can access the user interface and receive notifications. This option is recommended. ### Avg CPU Load Factor- CSP: [AvgCPULoadFactor](/windows/client-management/mdm/policy-csp-defender#avgcpuloadfactor) - This policy setting enables you to specify the maximum CPU load factor for the Defender scans.- - - **Not configured** - The setting reverts to the system default, where CPU utilization doesn't exceed the default value of 50%.- - **[0-100]** - CPU utilization won't exceed the specified percentage. A value of 0 means there's no throttling of CPU utilization.- +CSP: [AvgCPULoadFactor](/windows/client-management/mdm/policy-csp-defender#avgcpuloadfactor)++Use this setting to specify the maximum CPU load factor for Microsoft Defender Antivirus scans.++- **Not configured**: The policy doesn't set a value. By default, the maximum CPU load factor in Microsoft Defender Antivirus is 50%.+- **[0-100]**: Set the target maximum average CPU use for scans. The value is guidance for the scanning engine, not a hard limit. Values of 0 or 100 disable CPU throttling. Manual scans ignore this setting.+ ### Archive Max Depth- CSP: [ArchiveMaxDepth](/windows/client-management/mdm/defender-csp#configurationarchivemaxdepth)-- This policy setting enables you to specify the maximum folder depth to extract from archive files for scanning.- - - **Not configured** - The setting reverts to the system default (all archives are extracted up to the deepest folder for scanning).- - **[0-4294967295]** - All archives are extracted up to the depth specified in the policy.--### Archive Max Size - CSP: [ArchiveMaxSize](/windows/client-management/mdm/defender-csp#configurationarchivemaxsize)-- This policy setting enables you to specify the maximum size, in KB, of archive files to be extracted and scanned.- - - **Not configured** - The setting reverts to the system default, where all archives are extracted and scanned regardless of size.- - **[0-4294967295]** - Archives are extracted and scanned if their size is smaller than the maximum size specified in the policy.--### Check For Signatures Before Running Scan - CSP: [CheckForSignaturesBeforeRunningScan](/windows/client-management/mdm/policy-csp-defender#checkforsignaturesbeforerunningscan)-- This policy setting allows you to manage whether a check for new virus and spyware security intelligence occurs before running a scan. This is only applicable to scheduled scans.- - - **Not configured** - The setting reverts to the system default, where the scan starts using the current security intelligence.- - **Disabled** - The scan begins using the existing security intelligence.- - **Enabled** - Before running a scan, the system checks for new security intelligence. This is the recommended configuration.- ++CSP: [ArchiveMaxDepth](/windows/client-management/mdm/defender-csp#configurationarchivemaxdepth)++Use this setting to specify the maximum folder depth to extract from archive files for scanning.++- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus extracts all archives to the deepest folder for scanning.+- **[0-4294967295]**: Archives are extracted to the folder depth specified in the policy.++### Archive Max Size++CSP: [ArchiveMaxSize](/windows/client-management/mdm/defender-csp#configurationarchivemaxsize)++Use this setting to specify the maximum size, in KB, of archive files to extract and scan.++- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus extracts and scans all archives regardless of size.+- **[0-4294967295]**: Archives smaller than the specified maximum size are extracted and scanned.++### Check For Signatures Before Running Scan++CSP: [CheckForSignaturesBeforeRunningScan](/windows/client-management/mdm/policy-csp-defender#checkforsignaturesbeforerunningscan)++Use this setting to control whether Microsoft Defender Antivirus checks for new security intelligence before a scheduled scan.++- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus starts the scan with the existing security intelligence.+- **Disabled**: The scan starts with the existing security intelligence.+- **Enabled**: Microsoft Defender Antivirus checks for new security intelligence before starting the scan. This option is recommended.+ ### Cloud Block Level- CSP: [CloudBlockLevel](/windows/client-management/mdm/policy-csp-defender#cloudblocklevel)++CSP: [CloudBlockLevel](/windows/client-management/mdm/policy-csp-defender#cloudblocklevel) > [!IMPORTANT]-> Prerequisite: **Allow cloud protection** must be enabled before you configure this setting.+> Enable **Allow cloud protection** before you configure this setting. This policy setting controls the level of intensity that Microsoft Defender Antivirus uses when blocking and scanning suspicious files.- - - **Not configured** - The setting reverts to the system default blocking level (0x0).- - **(0x0)Default state** - Default Microsoft Defender Antivirus blocking level.- - **(0x2)High** - High blocking level - aggressively block unknowns while optimizing client performance (greater chance of false positives). This is the recommended configuration- - **(0x4)High Plus** - High+ blocking level - aggressively block unknowns and apply other protection measures (might affect client performance).- - **(0x6)Zero Tolerance** - Zero tolerance blocking level - block all unknown executables- - Changes to this setting aren't applied if tamper protection is enabled.--### Cloud Extended time-out - CSP: [CloudExtendedTimeout](/windows/client-management/mdm/policy-csp-defender#cloudextendedtimeout)-- This feature allows Microsoft Defender Antivirus to block a suspicious file for up to 60 seconds, and scan it in the cloud to make sure it's safe.- - The default cloud check time-out is 10 seconds. To enable this feature, specify the extended time in seconds. The maximum time-out is 50 seconds.- - - **Not configured** - The setting reverts to the system default (cloud time out is 10 seconds).- - **[0-50]** - The cloud time out is extended with the specified amount. The recommended value is 50.--### Days To Retain Cleaned Malware - CSP: [DaysToRetainCleanedMalware](/windows/client-management/mdm/policy-csp-defender#daystoretaincleanedmalware)-- This policy setting defines the number of days items should be kept in the Quarantine folder before being removed.- - - **Not configured** - The setting reverts to the system default. Items are kept in the quarantine folder indefinitely and won't be automatically removed.- - **[0-90]** - Items are removed from the Quarantine folder after the number of days specified.++- **Not configured**: The policy doesn't set a value. By default, the Microsoft Defender Antivirus blocking level is `0x0`.+- **(0x0) Default state**: Use the default Microsoft Defender Antivirus blocking level.+- **(0x2) High**: Aggressively block unknown files while optimizing client performance. This option increases the chance of false positives and is recommended.+- **(0x4) High Plus**: Aggressively block unknown files and apply more protection measures. This option might affect client performance.+- **(0x6) Zero Tolerance**: Block all unknown executable files.++Changes to this setting don't apply when tamper protection is enabled.++<a name="cloud-extended-time-out"></a>++### Cloud Extended Timeout++CSP: [CloudExtendedTimeout](/windows/client-management/mdm/policy-csp-defender#cloudextendedtimeout)++Use this setting to extend the time that Microsoft Defender Antivirus blocks a suspicious file while scanning it in the cloud. The default cloud-check timeout is 10 seconds. You can add up to 50 seconds for a maximum timeout of 60 seconds.++- **Not configured**: The policy doesn't set a value. By default, the Microsoft Defender Antivirus cloud-check timeout is 10 seconds.+- **[0-50]**: Add the specified number of seconds to the default timeout. The recommended value is 50.++### Days To Retain Cleaned Malware++CSP: [DaysToRetainCleanedMalware](/windows/client-management/mdm/policy-csp-defender#daystoretaincleanedmalware)++Use this setting to specify how many days to keep items in quarantine before removing them.++- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus keeps items in quarantine for 90 days.+- **0**: Items remain in quarantine indefinitely and aren't removed automatically.+- **[1-90]**: Items are removed from quarantine after the specified number of days. ### Disable Catchup Full Scan- CSP: [DisableCatchupFullScan](/windows/client-management/mdm/policy-csp-defender#disablecatchupfullscan) - This policy setting enables you to configure catch-up scans for scheduled full scans. A catch-up scan is a scan that's initiated because a regularly scheduled scan was missed. Usually these scheduled scans are missed because the computer was turned off at the scheduled time.- - - **Not configured** - The setting reverts to the system default.- - **Disabled** - Catch-up scans for scheduled full scans are turned on. If a computer is offline for two consecutive scheduled scans, a catch-up scan is started the next time someone sign-ins the computer. If there's no scheduled scan configured, there's no catch-up scan run.- - **Enabled** - Catch-up scans for scheduled full scans is disabled.+CSP: [DisableCatchupFullScan](/windows/client-management/mdm/policy-csp-defender#disablecatchupfullscan)++Use this setting to control whether catch-up full scans run after missed scheduled full scans. Because the setting name begins with **Disable**, enabling the setting disables catch-up full scans, and disabling the setting enables them.++- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus disables catch-up full scans.+- **Disabled**: Catch-up full scans are enabled. If a device misses two consecutive scheduled full scans, a catch-up full scan starts the next time someone signs in. Catch-up scans require a configured scheduled scan.+- **Enabled (Default)**: Catch-up full scans are disabled. ### Disable Catchup Quick Scan- CSP: [DisableCatchupQuickScan](/windows/client-management/mdm/policy-csp-defender#disablecatchupquickscan) - This policy setting allows you to configure catch-up scans for scheduled quick scans. A catch-up scan is a scan that's initiated because a regularly scheduled scan was missed. Usually these scheduled scans are missed because the computer was turned off at the scheduled time.- - - **Not configured** - The setting reverts to the system default (catch-up scans for scheduled quick scans is turned on).- - **Disabled** - Catch-up scans for scheduled quick scans are turned on. If a computer is offline for two consecutive scheduled scans, a catch-up scan is started the next time someone sign-ins the computer. If there's no scheduled scan configured, there's no catch-up scan run.- - **Enabled** - Catch-up scans for scheduled quick scans is disabled.+CSP: [DisableCatchupQuickScan](/windows/client-management/mdm/policy-csp-defender#disablecatchupquickscan)++Use this setting to control whether catch-up quick scans run after missed scheduled quick scans. Because the setting name begins with **Disable**, enabling the setting disables catch-up quick scans, and disabling the setting enables them.++- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus disables catch-up quick scans.+- **Disabled**: Catch-up quick scans are enabled. If a device misses two consecutive scheduled quick scans, a catch-up quick scan starts the next time the device powers on or resumes from sleep or hibernation. Catch-up scans require a configured scheduled scan.+- **Enabled (Default)**: Catch-up quick scans are disabled. ### Enable Low CPU Priority- CSP: [EnableLowCPUPriority](/windows/client-management/mdm/policy-csp-defender#enablelowcpupriority) - This policy setting enables you to enable or disable low CPU priority for scheduled scans.- - - **Not configured** - The setting reverts to the system default, meaning no changes is made to CPU priority for scheduled scans.- - **Disabled** - No change is made to CPU priority for scheduled scans.- - **Enabled** - Low CPU priority is used during scheduled scans.+CSP: [EnableLowCPUPriority](/windows/client-management/mdm/policy-csp-defender#enablelowcpupriority)++Use this setting to control whether scheduled scans use low CPU priority.++- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus doesn't change the CPU priority for scheduled scans.+- **Disabled**: The CPU priority for scheduled scans isn't changed.+- **Enabled**: Scheduled scans use low CPU priority. ### Enable Network Protection- CSP: [EnableNetworkProtection](/windows/client-management/mdm/policy-csp-defender#enablenetworkprotection) - Enable or disable Microsoft Defender Exploit Guard network protection to prevent employees from using applications to access dangerous domains that might host phishing scams, exploit-hosting sites, and other malicious content on the internet.- - - **Not configured** - The setting reverts to the system default, meaning users and applications won't be blocked from connecting to dangerous domains.- - **Disabled** - Users and applications aren't blocked from connecting to dangerous domains.- - **Enabled(block mode)** - Users and applications won't be able to access dangerous domains. This is the recommended configuration.- - **Enabled(audit mode)** - Users and applications can connect to dangerous domains. However, if this feature would have blocked access when set to **Block**, a record of the event will be logged in the event logs.+CSP: [EnableNetworkProtection](/windows/client-management/mdm/policy-csp-defender#enablenetworkprotection)++Use this setting to configure network protection, which prevents applications from accessing dangerous domains that might host phishing scams, exploits, or other malicious content.++- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus doesn't block users or applications from connecting to dangerous domains.+- **Disabled**: Users and applications aren't blocked from connecting to dangerous domains.+- **Enabled (block mode)**: Users and applications are blocked from accessing dangerous domains. This option is recommended.+- **Enabled (audit mode)**: Users and applications can access dangerous domains. Events that network protection would block in block mode are recorded in the event log. ### Excluded Extensions - CSP: [ExcludedExtensions](/windows/client-management/mdm/policy-csp-defender#excludedextensions)+CSP: [ExcludedExtensions](/windows/client-management/mdm/policy-csp-defender#excludedextensions) - Allows administrators to specify a list of file extensions to ignore during a scan. For more details on how these exclusions can be defined you can read this article: [Exclusions based on file extension and folder location](microsoft-defender-antivirus-exclusions-configure.md)+Use this setting to specify file extensions to exclude from scans. For more information, see [Exclusions based on file extension and folder location](microsoft-defender-antivirus-exclusions-configure.md). ### Excluded Paths - CSP: [ExcludedPaths](/windows/client-management/mdm/policy-csp-defender#excludedpaths)+CSP: [ExcludedPaths](/windows/client-management/mdm/policy-csp-defender#excludedpaths) - Allows administrators to specify a list of directory paths to ignore during a scan. For more details on how these exclusions can be defined you can read this article: [Exclusions based on file extension and folder location](microsoft-defender-antivirus-exclusions-configure.md)+Use this setting to specify directory paths to exclude from scans. For more information, see [Exclusions based on file extension and folder location](microsoft-defender-antivirus-exclusions-configure.md). -### Excluded Processes +### Excluded Processes - CSP: [ExcludedProcesses](/windows/client-management/mdm/policy-csp-defender#excludedprocesses)+CSP: [ExcludedProcesses](/windows/client-management/mdm/policy-csp-defender#excludedprocesses) - Allows administrators to specify a list of files that processes can open without being scanned. For more details on how these exclusions can be defined you can read this article: [Exclusions based on file extension and folder location](microsoft-defender-antivirus-exclusions-configure.md)+Use this setting to specify files that processes can open without being scanned. For more information, see [Exclusions based on file extension and folder location](microsoft-defender-antivirus-exclusions-configure.md). > [!NOTE]-> When tamper protection is turned on the exclusions can't be modified and new exclusions can't be added. These exclusions need to [meet certain tamper protection conditions](manage-tamper-protection-intune.md) for tamper protection to work.+> When tamper protection is turned on, existing exclusions can't be changed and new exclusions can't be added unless they [meet the conditions for tamper protection](manage-tamper-protection-intune.md). > [!IMPORTANT]-> Defining exclusions reduces the protection provided by Microsoft Defender Antivirus.-> It's important to carefully assess the risks associated with implementing exclusions and only create them on devices where they're necessary.-> If an exclusion isn't needed on all devices, use the dedicated policy type **Microsoft Defender Antivirus exclusions** and assign the policy only to the specific group of devices or users that require it.+> Defining exclusions reduces the protection provided by Microsoft Defender Antivirus. Assess the risks before you create exclusions, and apply them only to devices where they're needed. If an exclusion isn't needed on all devices, use the **Microsoft Defender Antivirus exclusions** policy type and assign it only to the specific groups that require the exclusion. ### PUA Protection - CSP: [PUAProtection](/windows/client-management/mdm/policy-csp-defender#puaprotection)+CSP: [PUAProtection](/windows/client-management/mdm/policy-csp-defender#puaprotection)++Use this setting to configure detection of potentially unwanted applications (PUAs). You can block, audit, or allow potentially unwanted software when it's downloaded or attempts to install on a device. - Enable or disable detection for potentially unwanted applications. You can choose to block, audit, or allow when potentially unwanted software is being downloaded or attempts to install itself on your computer.- - - **Not configured** - The setting reverts to the system default, meaning potentially unwanted software won't be blocked.- - **Disabled** - PUA protection is off, meaning potentially unwanted software won't be blocked.- - **Block** - PUA protection is on, meaning potentially unwanted software is blocked. This is the recommended configuration.- - **Audit mode** - Potentially unwanted software won't be blocked. However, if this feature would have blocked access when set to **Block**, a record of the event will be logged in the event logs.+- **Not configured**: The policy doesn't set a value. The Microsoft Defender Antivirus default depends on the Windows version, security intelligence version, Smart App Control availability, and whether the device is onboarded to Defender for Endpoint. For details, see [Default PUA protection settings](detect-block-potentially-unwanted-apps-microsoft-defender-antivirus.md#microsoft-defender-antivirus-and-pua-protection).+- **Disabled**: PUA protection is turned off, and potentially unwanted software isn't blocked.+- **Block**: PUA protection is turned on, and potentially unwanted software is blocked. This option is recommended.+- **Audit mode**: Potentially unwanted software isn't blocked. Events that PUA protection would block in block mode are recorded in the event log. -### Real Time Scan Direction +### Real Time Scan Direction - CSP: [RealTimeScanDirection](/windows/client-management/mdm/policy-csp-defender#realtimescandirection)+CSP: [RealTimeScanDirection](/windows/client-management/mdm/policy-csp-defender#realtimescandirection) - This policy setting allows you to configure monitoring for incoming and outgoing files without disabling monitoring entirely. It's recommended for servers with high volumes of file activity, where scanning needs to be disabled for a specific direction to maintain performance. The appropriate configuration should be evaluated based on the server's role.+Use this setting to configure monitoring of incoming and outgoing files without disabling monitoring entirely. This setting is useful for servers with high volumes of file activity when scanning must be disabled in one direction to maintain performance. Evaluate the appropriate configuration based on the server role. - This configuration is only applicable to NTFS volumes. For any other file system type, full monitoring of file and program activity will be enforced on those volumes.- - - **Not configured** - The setting reverts to the system default, meaning, monitoring for incoming and outgoing files are enabled.- - **Monitor all files (bi-directional)** - Scan incoming and outgoing files (default)- - **Monitor incoming files** - Scan incoming files only.- - **Monitor outgoing files** - Scan outgoing files only.+This configuration applies only to NTFS volumes. Microsoft Defender Antivirus enforces full monitoring of file and program activity on other file-system types.++- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus monitors incoming and outgoing files.+- **Monitor all files (bi-directional)**: Scan incoming and outgoing files. This option is the default.+- **Monitor incoming files**: Scan incoming files only.+- **Monitor outgoing files**: Scan outgoing files only. ### Scan Parameter - CSP: [ScanParameter](/windows/client-management/mdm/policy-csp-defender#scanparameter)+CSP: [ScanParameter](/windows/client-management/mdm/policy-csp-defender#scanparameter) - This policy setting allows you to specify the scan type used during a scheduled scan. This setting interacts with the settings **Schedule Scan Day** and **Schedule Scan Time**.+Use this setting to specify the scan type for scheduled scans. This setting interacts with **Schedule Scan Day** and **Schedule Scan Time**. - - **Not configured** - The setting reverts to the system default.- - **Quick Scan (default)** - Defender runs a scheduled quick scan.- - **Full Scan** - Defender runs a scheduled full scan.+- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus uses quick scans.+- **Quick Scan (default)**: Microsoft Defender Antivirus runs a scheduled quick scan.+- **Full Scan**: Microsoft Defender Antivirus runs a scheduled full scan. ### Schedule Quick Scan Time - CSP: [ScheduleQuickScanTime](/windows/client-management/mdm/policy-csp-defender#schedulequickscantime)+CSP: [ScheduleQuickScanTime](/windows/client-management/mdm/policy-csp-defender#schedulequickscantime) - This policy setting allows you to specify the time of day at which to perform a daily quick scan. The time value is represented as the number of minutes past midnights. This setting doesn't interact with the settings **Scan Parameter**, **Schedule Scan Day** and **Schedule Scan Time**.+Use this setting to specify the time of day for a daily quick scan. Enter the number of minutes after midnight. This setting doesn't interact with **Scan Parameter**, **Schedule Scan Day**, or **Schedule Scan Time**. - - **Not configured** - The setting reverts to the system default, meaning, the daily quick scan controlled by this config won't run.- - **[0-1380]** - A daily quick scan runs at the time of day specified.+- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus doesn't run the daily quick scan controlled by this setting.+- **[0-1380]**: The daily quick scan runs at the specified time. ### Schedule Scan Day - CSP: [ScheduleScanDay](/windows/client-management/mdm/policy-csp-defender#schedulescanday)+CSP: [ScheduleScanDay](/windows/client-management/mdm/policy-csp-defender#schedulescanday) - This policy setting allows you to specify the day of the week to perform a scheduled scan. The scan can also be configured to run every day or to never run at all. This setting interacts with the [**Scan Parameter**](#scan-parameter) setting (which controls whether the scan is a quick scan or full scan) and **Schedule Scan Time**.+Use this setting to specify the day of the week for a scheduled scan. You can also configure the scan to run every day or not run. This setting interacts with [**Scan Parameter**](#scan-parameter), which controls the scan type, and **Schedule Scan Time**. - - **Not configured** - The setting reverts to the system default.- - **Every day (default)** - A scheduled scan runs daily.- - **Sunday/Monday/Tuesday/Wednesday/Thursday/Friday/Saturday** - A scheduled scan runs once per week on the selected day.- - **No scheduled scan** - No scheduled scan runs.+- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus runs scheduled scans every day.+- **Every day (default)**: A scheduled scan runs daily.+- **Sunday/Monday/Tuesday/Wednesday/Thursday/Friday/Saturday**: A scheduled scan runs once per week on the selected day.+- **No scheduled scan**: A scheduled scan doesn't run. ### Schedule Scan Time - CSP: [ScheduleScanTime](/windows/client-management/mdm/policy-csp-defender#schedulescantime)+CSP: [ScheduleScanTime](/windows/client-management/mdm/policy-csp-defender#schedulescantime) - This policy setting allows you to specify the time of day to perform a scheduled scan. The time is represented as the number of minutes past midnights, with the default being 120 minutes (which corresponds to 2:00 AM). This setting interacts with the **Scan Parameter** and **Schedule Scan Day settings**.+Use this setting to specify the time of day for a scheduled scan. Enter the number of minutes after midnight. The default value is 120 minutes, which corresponds to 2:00 AM. This setting interacts with **Scan Parameter** and **Schedule Scan Day**. - - **Not configured** - The setting reverts to the system default (a scheduled scan runs at a default time).- - **[0-1380]** - A scheduled scan runs at the time of day specified.+- **Not configured**: The policy doesn't set a value. By default, the Microsoft Defender Antivirus scan time is 2:00 AM.+- **[0-1380]**: A scheduled scan runs at the specified time. ### Signature Update Fallback Order - CSP: [SignatureUpdateFallbackOrder](/windows/client-management/mdm/policy-csp-defender#signatureupdatefallbackorder)+CSP: [SignatureUpdateFallbackOrder](/windows/client-management/mdm/policy-csp-defender#signatureupdatefallbackorder) - This policy setting allows you to specify the order in which different security intelligence update sources are contacted. Although the underlying policy is stored as a pipe-separated string, Intune presents this setting as a prioritized list of update sources. Administrators should configure the desired order using the Intune UI, where sources are evaluated from top to bottom. Possible values include: "InternalDefinitionUpdateServer," "MicrosoftUpdateServer," "MMPC," and "FileShares."+Use this setting to specify the order in which security intelligence update sources are contacted. Enter a pipe-separated string that lists the sources in the desired order. Available values include `InternalDefinitionUpdateServer`, `MicrosoftUpdateServer`, `MMPC`, and `FileShares`. - - **Not configured** - The setting reverts to the system default. Meaning, security intelligence update sources are contacted in a default order.- - **Enabled** - Security intelligence update sources are contacted in the order specified.+- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus contacts security intelligence update sources in the default order.+- **Enabled**: Security intelligence update sources are contacted in the specified order. ### Signature Update File Shares Sources - CSP: [SignatureUpdateFileSharesSources](/windows/client-management/mdm/policy-csp-defender#signatureupdatefilesharessources)+CSP: [SignatureUpdateFileSharesSources](/windows/client-management/mdm/policy-csp-defender#signatureupdatefilesharessources) - This policy setting allows you to configure UNC file share sources for downloading security intelligence updates. Sources are contacted in the order specified. The value of this setting should be entered as a pipe-separated string enumerating the security intelligence update sources.+Use this setting to configure Universal Naming Convention (UNC) file-share sources for security intelligence updates. Enter a pipe-separated string that lists the sources in the order in which Microsoft Defender Antivirus should contact them. - - **Not configured** - The setting reverts to the system default. Meaning, the list remains empty by default and no sources are contacted.- - **Enabled** - The specified sources are contacted for security intelligence updates.+- **Not configured**: The policy doesn't set a value. By default, the Microsoft Defender Antivirus source list is empty, and no file-share sources are contacted.+- **Enabled**: The specified file-share sources are contacted in order. ### Signature Update Interval - CSP: [SignatureUpdateInterval](/windows/client-management/mdm/policy-csp-defender#signatureupdateinterval)+CSP: [SignatureUpdateInterval](/windows/client-management/mdm/policy-csp-defender#signatureupdateinterval) - This policy setting allows you to specify an interval at which to check for security intelligence updates. The time value is represented as the number of hours between update checks. The default is 8h.+Use this setting to specify the number of hours between checks for security intelligence updates. The default interval is eight hours. - - **Not configured** - The setting reverts to the system default. Meaning, it checks for security intelligence updates occur at the default interval.- - **[0-24]** - Checks for security intelligence updates occur at the interval specified. The recommended value is 4.+- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus checks for updates every eight hours.+- **0**: Microsoft Defender Antivirus doesn't run scheduled checks for new security intelligence.+- **[1-24]**: Microsoft Defender Antivirus checks for updates at the specified interval. The recommended value is 4. ### Submit Samples Consent - CSP: [SubmitSamplesConsent](/windows/client-management/mdm/policy-csp-defender#submitsamplesconsent)+CSP: [SubmitSamplesConsent](/windows/client-management/mdm/policy-csp-defender#submitsamplesconsent) - This policy setting configures behavior of samples submission when opt-in for MAPS telemetry is set.+Use this setting to configure sample submission when MAPS telemetry is enabled. - - **Not configured** - The setting reverts to the system default which is to send safe samples automatically.- - **Always prompt** - The user is always prompted for consent before file submission.- - **Send safe samples automatically** - Safe samples are samples considered to not commonly contain PII data (examples include .bat, .scr, .dll, and .exe). If file is likely to contain PII, the user gets a request to allow file sample submission.- - **Never send** - Prevents **block at first sight** based on file sample analysis. Metadata is sent for detections even if sample submission is disabled.- - **Send all samples automatically** - All samples are sent automatically. This is the recommended configuration.+- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus sends safe samples automatically.+- **Always prompt**: Device users are prompted for consent before files are submitted.+- **Send safe samples automatically**: Files that typically don't contain personally identifiable information (PII), such as `.bat`, `.scr`, `.dll`, and `.exe` files, are sent automatically. Device users are prompted before files that might contain PII are submitted.+- **Never send**: File samples aren't sent. This option prevents block at first sight based on file-sample analysis. Detection metadata is still sent.+- **Send all samples automatically**: All samples are sent automatically. This option is recommended. ### Disable Local Admin Merge - CSP: [DisableLocalAdminMerge](/windows/client-management/mdm/defender-csp#configurationdisablelocaladminmerge)+CSP: [DisableLocalAdminMerge](/windows/client-management/mdm/defender-csp#configurationdisablelocaladminmerge) - When this value is set to no, it gives a local admin the ability to [configure local policy overrides for Microsoft Defender Antivirus](configure-local-policy-overrides-microsoft-defender-antivirus.md) on their devices by using the Windows Security app, local Group Policy settings, or PowerShell cmdlets (where appropriate).+When this setting is disabled, local administrators can [configure local policy overrides for Microsoft Defender Antivirus](configure-local-policy-overrides-microsoft-defender-antivirus.md) by using the Windows Security app, Local Group Policy Editor, or PowerShell cmdlets, where supported. - - **Not configured** - The setting reverts to the system default.- - **Enable local admin merge (default)** - Unique items defined in preference settings that are configured by a local administrator merge into the resulting effective policy. If there are conflicts, management settings from Intune policy override local preference settings.- - **Disable local admin merge** - Only items defined by management are used in the resulting effective policy. Managed settings override preference settings that are configured by the local administrator. This is the recommended configuration.+- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus enables local administrator merge.+- **Enable local admin merge (default)**: Unique preference items configured by a local administrator are merged into the effective policy. If settings conflict, managed Intune policy settings override local preferences.+- **Disable local admin merge**: Only settings defined by management are used in the effective policy. Managed settings override local preferences. This option is recommended. ### Allow On Access Protection - CSP: [AllowOnAccessProtection](/windows/client-management/mdm/policy-csp-defender#allowonaccessprotection)+CSP: [AllowOnAccessProtection](/windows/client-management/mdm/policy-csp-defender#allowonaccessprotection)++Use this setting to configure monitoring of file and program activity. - This policy setting enables you to configure monitoring for file and program activity.+- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus monitors file and program activity.+- **Allowed**: File and program activity is monitored.+- **Not allowed**: File and program activity isn't monitored. - - **Not configured** - The setting reverts to the system default which is to monitoring for file and program activity is enabled.- - **Allowed** - Monitoring for file and program activity is enabled.- - **Not allowed** - Monitoring for file and program activity is disabled.- - Changes to this setting aren't applied if tamper protection is enabled.+Changes to this setting don't apply when tamper protection is enabled. ### Threat Severity Default Action - CSP: [ThreatSeverityDefaultAction](/windows/client-management/mdm/policy-csp-defender#threatseveritydefaultaction)+CSP: [ThreatSeverityDefaultAction](/windows/client-management/mdm/policy-csp-defender#threatseveritydefaultaction)++Use this setting to customize the automatic remediation action for each threat alert level. - This policy setting allows you to customize the automatic remediation action for each threat alert level. The following lists contain the valid remediation actions:+- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus applies the action specified in the security intelligence update.+- **Clean**: Attempt to recover and disinfect files.+- **Quarantine**: Move files to quarantine.+- **Remove**: Remove files from the device.+- **Allow**: Allow the file without taking another action.+- **User defined**: Let the device user select the action.+- **Block**: Block file execution.++Changes to this setting don't apply when tamper protection is enabled. - - **Not configured** - The setting reverts to the system default which is to apply action based on the update definition.- - **Clean** - Service tries to recover files and tries to disinfect.- - **Quarantine** - Moves files to quarantine.- - **Remove** - Removes files from system.- - **Allow** - enables the file and doesn't take other actions.- - **User defined** - The device user makes the decision on which action to take.- - **Block** - Blocks file execution.- - Changes to this setting aren't applied if tamper protection is enabled.- ### Allow Network Protection Down Level - CSP: [AllowNetworkProtectionDownLevel](/windows/client-management/mdm/defender-csp#configurationallownetworkprotectiondownlevel)+CSP: [AllowNetworkProtectionDownLevel](/windows/client-management/mdm/defender-csp#configurationallownetworkprotectiondownlevel) - This setting determines whether Network Protection is allowed to be configured into block or audit mode on Windows downlevel of RS3. If false, the value of EnableNetworkProtection is ignored.+Use this setting to control whether network protection can use block or audit mode on Windows versions earlier than RS3. When this setting is disabled, the **Enable Network Protection** value is ignored. - - **Not configured** - The setting reverts to the system default which is to network protection is disabled downlevel.- - **Enabled** - Network protection is enabled downlevel.- - **Disabled** - Network protection is disabled downlevel.+- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus disables network protection on earlier Windows versions.+- **Enabled**: Network protection is enabled on earlier Windows versions.+- **Disabled**: Network protection is disabled on earlier Windows versions. ### Allow Datagram Processing On Win Server - CSP: [AllowDatagramProcessingOnWinServer](/windows/client-management/mdm/defender-csp#configurationallowdatagramprocessingonwinserver)+CSP: [AllowDatagramProcessingOnWinServer](/windows/client-management/mdm/defender-csp#configurationallowdatagramprocessingonwinserver)++Use this setting to control whether network protection can enable datagram processing on Windows Server. When this setting is disabled, the **Disable Datagram Processing** value is ignored, and datagram inspection is disabled. - This setting determines whether Network Protection can enable datagram processing on Windows Server. If set to false, the value of DisableDatagramProcessing is ignored, and datagram inspection is disabled by default.+- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus disables datagram processing on Windows Server.+- **Enabled**: Datagram processing is enabled on Windows Server.+- **Disabled**: Datagram processing is disabled on Windows Server. - - **Not configured** - The setting reverts to the system default, meaning, datagram processing on Windows Server is disabled.- - **Enabled** - Datagram processing on Windows Server is enabled.- - **Disabled** - Datagram processing on Windows Server is disabled.+### Disable Dns Over Tcp Parsing -### Disable Dns Over Tcp Parsing +CSP: [DisableDnsOverTcpParsing](/windows/client-management/mdm/defender-csp#configurationdisablednsovertcpparsing) - CSP: [DisableDnsOverTcpParsing](/windows/client-management/mdm/defender-csp#configurationdisablednsovertcpparsing)+Use this setting to disable DNS over TCP parsing for network protection. - This setting disables DNS over TCP Parsing for Network Protection.+- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus enables DNS over TCP parsing.+- **Enabled**: DNS over TCP parsing is disabled.+- **Disabled**: DNS over TCP parsing is enabled. - - **Not configured** - The setting reverts to the system default, meaning, DNS over TCP parsing is enabled.- - **Enabled** - DNS over TCP parsing is disabled.- - **Disabled** - DNS over TCP parsing is enabled.- ### Disable Http Parsing - CSP: [DisableHttpParsing](/windows/client-management/mdm/defender-csp#configurationdisablehttpparsing)+CSP: [DisableHttpParsing](/windows/client-management/mdm/defender-csp#configurationdisablehttpparsing) - This setting disables HTTP Parsing for Network Protection.+Use this setting to disable HTTP parsing for network protection. - - **Not configured** - The setting reverts to the system default, meaning, HTTP parsing is enabled.- - **Enabled** - HTTP parsing is disabled.- - **Disabled** - HTTP parsing is enabled.+- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus enables HTTP parsing.+- **Enabled**: HTTP parsing is disabled.+- **Disabled**: HTTP parsing is enabled. ### Disable Ssh Parsing - CSP: [DisableSshParsing](/windows/client-management/mdm/defender-csp#configurationdisablesshparsing)+CSP: [DisableSshParsing](/windows/client-management/mdm/defender-csp#configurationdisablesshparsing) - This setting disables SSH Parsing for Network Protection.+Use this setting to disable Secure Shell (SSH) parsing for network protection. - - **Not configured** - The setting reverts to the system default (SSH parsing is enabled).- - **Enabled** - SSH parsing is disabled.- - **Disabled** - SSH parsing is enabled.+- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus enables SSH parsing.+- **Enabled**: SSH parsing is disabled.+- **Disabled**: SSH parsing is enabled. -### Disable Tls Parsing +### Disable Tls Parsing - CSP: [DisableTlsParsing](/windows/client-management/mdm/defender-csp#configurationdisabletlsparsing)+CSP: [DisableTlsParsing](/windows/client-management/mdm/defender-csp#configurationdisabletlsparsing) - This setting disables TLS Parsing for Network Protection.+Use this setting to disable Transport Layer Security (TLS) parsing for network protection. - - **Not configured** - The setting reverts to the system default, meaning, TLS parsing is enabled.- - **Enabled** - TLS parsing is disabled.- - **Disabled** - TLS parsing is enabled.+- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus enables TLS parsing.+- **Enabled**: TLS parsing is disabled.+- **Disabled**: TLS parsing is enabled. ### Engine Updates Channel - CSP: [EngineUpdatesChannel](/windows/client-management/mdm/defender-csp#configurationengineupdateschannel)+CSP: [EngineUpdatesChannel](/windows/client-management/mdm/defender-csp#configurationengineupdateschannel) - Enable this policy to specify when devices receive Microsoft Defender engine updates during the monthly gradual rollout.+Use this setting to specify when devices receive Microsoft Defender Antivirus engine updates during the monthly gradual rollout. - - **Not configured** - The setting reverts to the system default, meaning, the device stays up to date automatically during the gradual release cycle. Suitable for most devices.- - **Beta Channel** - Devices set to this channel are the first to receive new updates. Select Beta Channel to participate in identifying and reporting issues to Microsoft. Devices in the Windows Insider Program are subscribed to this channel by default. For use in (manual) test environments only and a limited number of devices.- - **Current Channel (Preview)** - Devices set to this channel is offered updates earliest during the monthly gradual release cycle. Suggested for pre-production/validation environments.- - **Current Channel (Staged)** - Devices is offered updates after the monthly gradual release cycle. Suggested to apply to a small, representative part of your production population (~10%).- - **Current Channel (Broad)** - Devices is offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in your production population (~10-100%).- - **Critical - Time delay** - Devices are offered updates with a 48-hour delay. Suggested for critical environments only.+- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus keeps devices up to date automatically during the gradual rollout. This option is suitable for most devices.+- **Beta Channel**: Devices receive updates first. Use this channel on a limited number of test devices to identify and report issues to Microsoft. Devices in the Windows Insider Program use this channel by default.+- **Current Channel (Preview)**: Devices receive updates early in the monthly gradual rollout. This channel is recommended for preproduction or validation environments.+- **Current Channel (Staged)**: Devices receive updates after the early rollout stages. Apply this channel to a small, representative group of production devices, such as 10%.+- **Current Channel (Broad)**: Devices receive updates after the gradual rollout is complete. Apply this channel broadly to production devices.+- **Critical - Time delay**: Devices receive updates after a 48-hour delay. Use this channel only for critical environments. -### Metered Connection Updates +### Metered Connection Updates - CSP: [MeteredConnectionUpdates](/windows/client-management/mdm/defender-csp#configurationmeteredconnectionupdates)+CSP: [MeteredConnectionUpdates](/windows/client-management/mdm/defender-csp#configurationmeteredconnectionupdates) - This setting enables managed devices to update through metered connections.+Use this setting to control whether managed devices can get updates through metered connections. - - **Not configured** - The setting reverts to the system default (not allowed).- - **Allowed** - managed devices update through metered connections.- - **Not allowed** - managed devices won't update through metered connections.+- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus doesn't allow updates through metered connections.+- **Allowed**: Managed devices can get updates through metered connections.+- **Not allowed**: Managed devices can't get updates through metered connections. ### Platform Updates Channel - CSP: [EngineUpdatesChannel](/windows/client-management/mdm/defender-csp#configurationplatformupdateschannel)+CSP: [PlatformUpdatesChannel](/windows/client-management/mdm/defender-csp#configurationplatformupdateschannel) - Enable this policy to specify when devices receive Microsoft Defender platform updates during the monthly gradual rollout.+Use this setting to specify when devices receive Microsoft Defender Antivirus platform updates during the monthly gradual rollout. - - **Not configured** - The setting reverts to the system default, meaning, the device stays up to date automatically during the gradual release cycle. Suitable for most devices.- - **Beta Channel** - Devices set to this channel is the first to receive new updates. Select Beta Channel to participate in identifying and reporting issues to Microsoft. Devices in the Windows Insider Program are subscribed to this channel by default. For use in (manual) test environments only and a limited number of devices.- - **Current Channel (Preview)** - Devices set to this channel is offered updates earliest during the monthly gradual release cycle. Suggested for pre-production/validation environments.- - **Current Channel (Staged)** - Devices is offered updates after the monthly gradual release cycle. Suggested to apply to a small, representative part of your production population (~10%).- - **Current Channel (Broad)** - Devices is offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in your production population (~10-100%).- - **Critical - Time delay** - Devices are offered updates with a 48-hour delay. Suggested for critical environments only.+- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus keeps devices up to date automatically during the gradual rollout. This option is suitable for most devices.+- **Beta Channel**: Devices receive updates first. Use this channel on a limited number of test devices to identify and report issues to Microsoft. Devices in the Windows Insider Program use this channel by default.+- **Current Channel (Preview)**: Devices receive updates early in the monthly gradual rollout. This channel is recommended for preproduction or validation environments.+- **Current Channel (Staged)**: Devices receive updates after the early rollout stages. Apply this channel to a small, representative group of production devices, such as 10%.+- **Current Channel (Broad)**: Devices receive updates after the gradual rollout is complete. Apply this channel broadly to production devices.+- **Critical - Time delay**: Devices receive updates after a 48-hour delay. Use this channel only for critical environments. ### Security Intelligence Updates Channel- CSP: [SecurityIntelligenceUpdatesChannel](/windows/client-management/mdm/defender-csp#configurationsecurityintelligenceupdateschannel) - Enable this policy to specify when devices receive Microsoft Defender security intelligence updates during the daily gradual rollout.+CSP: [SecurityIntelligenceUpdatesChannel](/windows/client-management/mdm/defender-csp#configurationsecurityintelligenceupdateschannel) - - **Not configured** - Microsoft will either assign the device to Current Channel (Broad) or a beta channel early in the gradual release cycle. The channel selected by Microsoft might be one that receives updates early during the gradual release cycle, which might not be suitable for devices in a production or critical environment.- - **Current Channel (Staged)** - Same as Current Channel (Broad).- - **Current Channel (Broad)** - Devices is offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in all populations, including production.+Use this setting to specify when devices receive Microsoft Defender Antivirus security intelligence updates during the daily gradual rollout.++- **Not configured**: The policy doesn't set a value. By default, Microsoft assigns the device to **Current Channel (Broad)** or to a beta channel early in the gradual rollout. A beta channel might not be suitable for production or critical devices.+- **Current Channel (Staged)**: Use the same rollout timing as **Current Channel (Broad)**.+- **Current Channel (Broad)**: Devices receive updates after the gradual rollout is complete. Apply this channel broadly, including to production devices. ### Randomize Schedule Task Times- CSP: [RandomizeScheduleTaskTimes](/windows/client-management/mdm/defender-csp#configurationrandomizescheduletasktimes) - In Microsoft Defender Antivirus, randomize the start time of the scan to any interval from 0 to 23 hours. This can be useful in virtual machines or VDI deployments.+CSP: [RandomizeScheduleTaskTimes](/windows/client-management/mdm/defender-csp#configurationrandomizescheduletasktimes)++Use this setting to randomize scan start times across an interval from 0 through 23 hours. Randomization can help distribute resource use in virtual machine or virtual desktop infrastructure (VDI) deployments. - - **Not configured** - The setting reverts to the system default (scheduled tasks are randomized).- - **Widen or narrow the randomization period for scheduled scans. Specify a randomization window of between 1 and 23 hours by using the setting SchedulerRandomizationTime**- - **Scheduled tasks won't be randomized**+- **Not configured**: The policy doesn't set a value. By default, Microsoft Defender Antivirus randomizes scheduled tasks.+- **Widen or narrow the randomization period for scheduled scans (Default)**: Use **Scheduler Randomization Time** to specify a randomization window from 1 through 23 hours.+- **Scheduled tasks won't be randomized**: Scheduled tasks run without randomization. -### Scheduler Randomization Time +### Scheduler Randomization Time - CSP: [SchedulerRandomizationTime](/windows/client-management/mdm/defender-csp#configurationschedulerrandomizationtime)+CSP: [SchedulerRandomizationTime](/windows/client-management/mdm/defender-csp#configurationschedulerrandomizationtime) - This setting enables you to configure the scheduler randomization in hours. The randomization interval is [1 - 23] hours.+Use this setting to configure the scheduler randomization interval in hours.++- **Not configured**: The policy doesn't set a value. By default, the Microsoft Defender Antivirus randomization interval is four hours.+- **[1-23]**: Scheduled tasks are randomized across the specified number of hours. - - **Not configured** - The setting reverts to the system default (4 hours).- - **[1-23]** - The randomization interval is defined by the value specified in the policy.- ### Disable Core Service ECS Integration- CSP: [DisableCoreServiceECSIntegration](/windows/client-management/mdm/defender-csp#configurationdisablecoreserviceecsintegration) - Turn off ECS integration for Defender core service.+CSP: [DisableCoreServiceECSIntegration](/windows/client-management/mdm/defender-csp#configurationdisablecoreserviceecsintegration)++Use this setting to control Experimentation and Configuration Service (ECS) integration for the Defender core service. - - **Not configured** - The setting reverts to the system default, meaning, the Defender core service uses ECS.- - **The Defender core service will use the Experimentation and Configuration Service (ECS) to rapidly deliver critical, org-specific fixes**.- - **The Defender core service stops using the Experimentation and Configuration Service (ECS). Fixes will continue to be delivered through security intelligence updates.**+- **Not configured**: The policy doesn't set a value. By default, the Defender core service uses ECS.+- **The Defender core service will use the Experimentation and Configuration Service (ECS) to rapidly deliver critical, org-specific fixes**: ECS integration is enabled.+- **The Defender core service stops using the Experimentation and Configuration Service (ECS). Fixes will continue to be delivered through security intelligence updates.**: ECS integration is disabled. ### Disable Core Service Telemetry - CSP: [DisableCoreServiceTelemetry](/windows/client-management/mdm/defender-csp#configurationdisablecoreservicetelemetry)+CSP: [DisableCoreServiceTelemetry](/windows/client-management/mdm/defender-csp#configurationdisablecoreservicetelemetry) - Turn off OneDsCollector telemetry for the Defender core service.+Use this setting to control OneDsCollector telemetry for the Defender core service. - - **Not configured** - The setting reverts to the system default, meaning, the Defender core service uses the OneDsCollector framework.- - **The Defender core service will use the OneDsCollector framework to rapidly collect telemetry**.- - **The Defender core service stops using the OneDsCollector framework to rapidly collect telemetry, impacting Microsoft's ability to quickly recognize and address poor performance, false positives, and other problems**.- -> [!TIP]-> Need help? See [Manage endpoint security in Microsoft Intune](/intune/intune-service/protect/endpoint-security).+- **Not configured**: The policy doesn't set a value. By default, the Defender core service uses the OneDsCollector framework.+- **The Defender core service will use the OneDsCollector framework to rapidly collect telemetry**: OneDsCollector telemetry is enabled.+- **The Defender core service stops using the OneDsCollector framework to rapidly collect telemetry, impacting Microsoft's ability to quickly recognize and address poor performance, false positives, and other problems**: OneDsCollector telemetry is disabled. > [!TIP]-> If you're looking for Antivirus related information for other platforms, see:-> - [Set preferences for Microsoft Defender for Endpoint on macOS](mac-preferences.md)-> - [Microsoft Defender for Endpoint on Mac](microsoft-defender-endpoint-mac.md)-> - [macOS Antivirus policy settings for Microsoft Defender Antivirus for Intune](/intune/intune-service/protect/antivirus-microsoft-defender-settings-macos)-> - [Set preferences for Microsoft Defender for Endpoint on Linux](linux-preferences.md)-> - [Microsoft Defender for Endpoint on Linux](microsoft-defender-endpoint-linux.md)-> - [Configure Defender for Endpoint on Android features](android-configure.md)-> - [Configure Microsoft Defender for Endpoint on iOS features](ios-configure-features.md)+>+> - For help managing endpoint security policies, see [Manage endpoint security in Microsoft Intune](/intune/intune-service/protect/endpoint-security).+>+> - For Microsoft Defender Antivirus information for other platforms, see:+> - [Set preferences for Microsoft Defender for Endpoint on macOS](mac-preferences.md)+> - [Microsoft Defender for Endpoint on Mac](microsoft-defender-endpoint-mac.md)+> - [macOS Antivirus policy settings for Microsoft Defender Antivirus for Intune](/intune/intune-service/protect/antivirus-microsoft-defender-settings-macos)+> - [Set preferences for Microsoft Defender for Endpoint on Linux](linux-preferences.md)+> - [Microsoft Defender for Endpoint on Linux](microsoft-defender-endpoint-linux.md)+> - [Configure Defender for Endpoint on Android features](android-configure.md)+> - [Configure Microsoft Defender for Endpoint on iOS features](ios-configure-features.md)+>+> - Microsoft Defender Antivirus, like other antivirus software, can affect endpoint performance. Use the Microsoft Defender Antivirus performance analyzer to identify files, paths, processes, and file extensions that might cause performance problems. The analyzer reports:+> - Top paths that affect scan time+> - Top files that affect scan time+> - Top processes that affect scan time+> - Top file extensions that affect scan time+> - Combinations, for example:+> - Top files per extension+> - Top paths per extension+> - Top processes per path+> - Top scans per file+> - Top scans per file per process+>+> Use the results to assess performance issues and select remediation actions. For more information, see [Performance analyzer for Microsoft Defender Antivirus](tune-performance-defender-antivirus.md). <a name="related-articles"></a> ## Related content@@ -623,21 +661,3 @@ This policy setting controls the level of intensity that Microsoft Defender Anti - [Performance analyzer for Microsoft Defender Antivirus](tune-performance-defender-antivirus.md) - [Reference articles for management and configuration tools](configuration-management-reference-microsoft-defender-antivirus.md) - [Microsoft Defender Antivirus in Windows 10](microsoft-defender-antivirus-windows.md)--> [!TIP]-> **Performance tip** Due to various factors, Microsoft Defender Antivirus, like other antivirus software, can cause performance issues on endpoint devices. In some cases, you might need to tune the performance of Microsoft Defender Antivirus to address these issues. Microsoft's **Performance analyzer** is a PowerShell command-line tool that helps identify which files, file paths, processes, and file extensions might be causing performance problems. Some examples include:-> -> - Top paths that affect scan time-> - Top files that affect scan time-> - Top processes that affect scan time-> - Top file extensions that affect scan time-> - Combinations – for example:-> - top files per extension-> - top paths per extension-> - top processes per path-> - top scans per file-> - top scans per file per process->-> You can use the information gathered using Performance analyzer to better assess performance issues and apply remediation actions.-> See: [Performance analyzer for Microsoft Defender Antivirus](tune-performance-defender-antivirus.md).- 