Microsoft Defender for Endpoint
Endpoint protection

Endpoint detection and response in block mode

In brief

The article now provides expanded steps for locating and editing the setting in Group Policy Management Console, including the full navigation path and alternative edit methods. It also documents configuring the setting locally with the Local Group Policy Editor.

What Defender admins need to know

Administrators have clearer centralized and local procedures for configuring EDR in block mode.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Endpoint detection and response in block mode

Enable EDR in block mode

You can use Group Policy to enable EDR in block mode.

  1. OnIn Centralized Group Policy, open the Group Policy Management Console (GPMC) on your Group Policy management computer, opencomputer.

  2. In the Group Policy Management Console.GPMC console tree, expand Group Policy Objects in the forest and domain containing the GPO you want to edit.

  3. Right-click the Group Policy Object you want to configure,GPO, and then select Edit.

  4. In the Group Policy Management Editor, go to Computer configuration and then select> Administrative templates.

  5. Expand the tree to > Windows components > Microsoft Defender Antivirus > Features.

  6. Double-clickIn the details pane of Features, open the Enable EDR in block mode setting. To open the setting, use any of the following methods:

    • Double-click the setting.
    • Right-click the setting, and setthen select Edit.
    • Select the option tosetting, and then select Action > Edit.
  7. In the setting window that opens, select Enabled.

  8. Select, and then select OK.

Requirements for EDR in block mode

See also