Microsoft Defender for Endpoint
Email and collaboration

Configure remediation for Microsoft Defender Antivirus detections

In brief

The article adds specific steps for configuring Microsoft Defender Antivirus remediation settings through Intune and the Microsoft Defender portal, including policy type, platform, template, and configuration settings.

What Defender admins need to know

Administrators can use the documented navigation and policy selections when configuring threat remediation settings.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Configure remediation for Microsoft Defender Antivirus detections

When Microsoft Defender Antivirus runs a scan, it attempts to remediate or remove threats that are detected. Remediation actions can include removing a file, sending it to quarantine, or allowing it to remain. This article includes information and links to resources about specifying what actions should be taken when threats are detected on devices. You can choose from several methods, such as:

Configure remediation options using Intune

[!INCLUDE intune-recommended-separate-product (opens]

To configure remediation actions in aMicrosoft Intune, use an endpoint security Antivirus policy. For detailed instructions, see Create endpoint security policies or Modify existing policies (links open new tabtabs in the Intune documentation).

When creatingyou create the policy, use these specific settings:

When you create or modify the policy, use these specific settings on the Configuration settings: tab:

  • In the Threat security default action section, configure the available settings:
    • Remediation action for High severity threats
    • Remediation action for Severe threats
    • Remediation action for Low severity threats
      • Other procedures exist to respond to detected threats.
      • Compensating security controls are deployed.

      Use standard remediation actions (Clean, Quarantine, Remove,(Clean, Quarantine, Remove, or Block)Block) in all other environments.

For more information about antivirus policies in Intune, see Antivirus policy for endpoint security in Intune.

Configure remediation options using Configuration Managerin the Microsoft Defender portal

If you're using Configuration Manager,your organization manages endpoint security policies in the Microsoft Defender portal, use a Microsoft Defender Antivirus policy to configure remediation actions.

For detailed instructions, see Create an endpoint security policy or Edit an endpoint security policy (links open new tabs).

When you create the following articles:policy on the Windows policies tab of the Endpoint security policies page in the Defender portal at https://security.microsoft.com/policy-inventory?osPlatform=Windows, use these specific settings:

When you create or modify the policy, use the same remediation action settings described in Configure remediation options using Intune on the Configuration settings tab.

Configure remediation options using Group PolicyConfiguration Manager

For instructions to create and deploy an antimalware policy, see Endpoint Protection antimalware policies in Configuration Manager.

Configure the following settings in the antimalware policy:

  • Default Actions Settings: For each threat severity level, select one of the following remediation actions:
    • Recommended: Use the following stepsaction recommended in the malware definition file.
    • Quarantine: Quarantine the detected malware without removing it.
    • Remove: Remove the detected malware.
    • Allow: Don't remove or quarantine the detected malware.
  • Threat Overrides Settings: For Threat name and override action, select Set to configure the remediation options in Group Policy:
    1. Onaction for a specific threat ID.

Configure remediation options using Group Policy

Use the following steps to configure remediation options in Group Policy:

  1. In Centralized Group Policy, open the Group Policy Management Console (GPMC) on your Group Policy management computer, opencomputer.

  2. In the Group Policy Management Console, and edit theGPMC console tree, expand Group Policy ObjectObjects in the forest and domain containing the GPO you want to configure.edit.

  3. Right-click the GPO, and then select Edit.

  4. In the Group Policy Management Editor, go to Computer configuration and then select> Administrative templates.

  5. Expand the tree to > Windows components > Microsoft Defender Antivirus.

  6. Using the following table, edit the policy as needed.

    SettingDescriptionDefault setting (if not configured)
    Scan
    Create a system restore point.
    A system restore point is created each day before cleaning or scanning is attempted.Disabled
    Scan
    Turn on removal of items from scan history folder.
    Specify how many days items should be kept in the scan history.30 days
    Root
    Turn off routine remediation.
    Specify whether Microsoft Defender Antivirus automatically remediates threats, or whether to prompt the user.Disabled. Threats are remediated automatically.
    Quarantine
    Configure removal of items from Quarantine folder.
    Specify how many days items should be kept in quarantine before being removed.90 days
    Threats > Specify threats upon which default action shouldn't be taken when detected.Specify how specific threats (using their threat ID) should be remediated. You can specify whether the specific threat should be quarantined, removed, or ignored.Not applicable
    Threats > Specify threat alert levels at which default action shouldn't be taken when detected.Every threat that is detected by Microsoft Defender Antivirus is assigned a threat level:
    • 1: Low
    • 2: Medium
    • 4: High
    • 5: Severe
    Use this setting to specify how threats for each level are remediated. Valid values are:
    • 2: Quarantine
    • 3: Remove
    • 6: Ignore
    • 11: None
    Warning: The actions Ignore (6) and None (11) don't remediate detected threats. Ignore (6) suppresses ongoing detection events, while None (11) continues to generate alerts and Protection History entries. Don't configure either action when tamper protection is enabled
    1. In the details pane of Microsoft Defender Antivirus, use the following table to select the location and setting you want to configure.

      Subfolder Setting Description Default setting (if not configured)
      n/a Turn off routine remediation. Specify whether Microsoft Defender Antivirus automatically remediates threats, or whether to prompt the user. Disabled. Threats are remediated automatically.
      Quarantine Configure removal of items from Quarantine folder. Specify how many days items should be kept in quarantine before being removed. 90 days
      Scan Create a system restore point. A system restore point is created each day before cleaning or scanning is attempted. Disabled
      Scan Turn on removal of items from scan history folder. Specify how many days items should be kept in the scan history. 30 days
      Threats Specify threat alert levels at which default action shouldn't be taken when detected. Every threat that is detected by Microsoft Defender Antivirus is assigned a threat level:
      • 1: Low
      • 2: Medium
      • 4: High
      • 5: Severe
      Use this setting to specify how threats for each level are remediated. Valid values are:
      • 2: Quarantine
      • 3: Remove
      • 6: Ignore
      • 11: None
      Warning: The actions Ignore (6) and None (11) don't remediate detected threats. Ignore (6) suppresses ongoing detection events, while None (11) continues to generate alerts and Protection History entries. Don't configure either action when tamper protection is enabled. Use these actions only in specialized environments (for example, industrial control systems or critical infrastructure) where Automatic remediation isn't practical for operations, other procedures exist to respond to detected threats, or compensating security controls are deployed. Use standard remediation actions (Quarantine (2) or Remove (3)) in all other environments.
      Not applicablen/a
      ThreatsSpecify threats upon which default action shouldn't be taken when detected.Specify how specific threats (using their threat ID) should be remediated. You can specify whether the specific threat should be quarantined, removed, or ignored.n/a
    2. In the details pane of the selected location, open the setting. To open and configure a setting, use any of the following methods:

      • Double-click the setting.
      • Right-click the setting, and then select Edit.
      • Select the setting, and then select Action > Edit.
    3. In the setting window that opens, configure the setting, and then select OK.

      Repeat this step as many times as necessary.

    Configure remediation options using PowerShell or WMI

    You can also useRun the Set-MpPreference PowerShell cmdlet or MSFT_MpPreference WMI classcommands in an elevated PowerShell session (a PowerShell window you opened by selecting Run as administrator).

    Configure default actions by threat severity

    The following example quarantines low and moderate severity threats and removes high and severe threats:

    Set-MpPreference -LowThreatDefaultAction Quarantine -ModerateThreatDefaultAction Quarantine -HighThreatDefaultAction Remove -SevereThreatDefaultAction Remove
    

    Configure the default action for a specific threat

    Replace <threat-ID> with the numeric threat ID. The following command quarantines the specified threat:

    Set-MpPreference -ThreatIDDefaultAction_Ids <threat-ID> -ThreatIDDefaultAction_Actions Quarantine
    

    To configure multiple threats, specify comma-separated lists of threat IDs and corresponding actions. Each action applies to configure the threat default-actionID in the same position in the other list.

    Configure quarantine and scan history retention

    The following example keeps items in quarantine for 90 days and items in scan history for 30 days:

    Set-MpPreference -QuarantinePurgeItemsAfterDelay 90 -ScanPurgeItemsAfterDelay 30
    

    Specify 0 to keep items indefinitely.

    Turn on system restore point creation

    The following command allows Microsoft Defender Antivirus to create a system restore point before cleaning or scanning:

    Set-MpPreference -DisableRestorePoint $false
    

    For detailed syntax, available remediation settings.actions, and parameter information, see Set-MpPreference.

    See also