Microsoft Defender for Endpoint
Endpoint protection

Detect and block potentially unwanted applications

In brief

The article now includes current links, clearer GPMC navigation and editing steps, a note about updating Administrative Templates when the setting is unavailable, legacy policy-path naming guidance, and Local Group Policy instructions.

What Defender admins need to know

Administrators can more easily locate and configure potentially unwanted application detection as Block or Audit Mode.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Detect and block potentially unwanted applications

Configure PUA protection in Microsoft Edge

The new Microsoft Edgenew Microsoft Edge, which is Chromium-based, blocks potentially unwanted application downloads and associated resource URLs. This feature is provided via Microsoft Defender SmartScreenMicrosoft Defender SmartScreen.

Enable PUA protection in Chromium-based Microsoft Edge

The following table shows the default PUA protection settings for devices that aren't onboarded to Defender for Endpoint:

Scenarios Security intelligence update version PUA protection default setting
Windows 10 or later
Windows Server 2016 or later
older than 1.329.495.0 Disabled (0)
Windows 10 or later
Windows Server 2016 or later
1.329.495.0 or later Audit mode (2)
-------- -------- --------
Windows 10, version 2004 or later
Windows Server 2012 R2 and Windows Server 2016 with the modern unified solution for Windows Server 2016 and 2012 R2
Windows Server 2019 or later
Older than 1.329.495.0 Feature not available
Windows 11, version 22H2 or later 1.329.495.0 or later Available
Windows 10, version 2004 or later
Windows Server 2012 R2 and Windows Server 2016 with the modern unified solution for Windows Server 2016 and 2012 R2
Windows Server 2019 or later
1.329.495.0 or later Feature not available

Perform the following steps to configure PUA protection by using Group Policy:

  1. OnIn Centralized Group Policy, open the Group Policy Management Console (GPMC) on your Group Policy management computer, open the Group Policy Management Console.computer.

  2. SelectIn the GPMC console tree, expand Group Policy ObjectObjects in the forest and domain containing the GPO you want to configure,edit.

  3. Right-click the GPO, and then chooseselect Edit.

  4. In the Group Policy Management Editor, go to Computer configuration and select> Administrative templates.

  5. Expand the tree to > Windows Componentscomponents > Microsoft Defender Antivirus.

  6. Double-click Configure detection for potentially unwanted applications, and set it to Enabled.

  7. In Options, select Block to block potentially unwanted applications, or select Audit Mode to test how the setting works in your environment. Select OK.

  8. Deploy your Group Policy object as you usually do.

Use PowerShell cmdlets to configure PUA protection

  1. In the details pane of Microsoft Defender Antivirus, open the Configure detection for potentially unwanted applications setting. To open the setting, use any of the following methods:

    • Double-click the setting.
    • Right-click the setting, and then select Edit.
    • Select the setting, and then select Action > Edit.
  2. In the setting window that opens, configure the following options:

    1. Select Enabled.
    2. Options section: Select one of the following values:
      • Block: Block potentially unwanted applications.
      • Audit Mode: Test how the setting works in your environment.

    When you're finished, select OK.

Use PowerShell cmdlets to configure PUA protection