Microsoft Defender for Endpoint
Endpoint protection

Evaluate Microsoft Defender Antivirus with security policies

In brief

The article was retitled and restructured to cover evaluating Microsoft Defender Antivirus and Windows protection features through endpoint security policies in the Defender portal. It now provides clearer prerequisites, including onboarding and security settings management requirements, and notes that Intune enrollment is not required.

What Defender admins need to know

Administrators should use the revised prerequisites and policy-configuration steps when evaluating Defender Antivirus; no mandatory administrator action is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Evaluate Microsoft Defender Antivirus by usingwith endpoint security policies

Use endpoint security policies in the Microsoft Defender for Endpoint security settings management

This article explains howportal to use Microsoft Defender for Endpoint Security Settings Management (Endpoint security policies) to configure, activate,configure and test key protection features in Microsoft Defender Antivirus (MDAV) and Microsoft Defender Exploit Guard (Microsoft Defender EG).Windows protection features. The features covered includeevaluation includes real-time protection, cloud-delivered protection, network protection, attack surface reduction (ASR) rules, and tamper protection.

Prerequisites

These procedures require Before you begin, make sure you have:

Use EndpointConfigure evaluation policies

Create separate endpoint security policies to evaluatefor Microsoft Defender Antivirus featuressettings, ASR rules, and tamper protection. For the complete steps to create, assign, save, edit, and verify policies, see Create an endpoint security policy and Edit an endpoint security policy.

The following guidance describes the Microsoft Defender for Endpoint Security Settings Management (Endpoint security policies) settings that configure the Microsoft Defender Antivirus protection features you should use during your evaluation.

MDAV indicates a detection through standard Windows notifications. You can also review detections in the MDAV app. To review scan results in the MDAV app, see review Microsoft Defender Antivirus scan results.

The Windows event log also records detection and engine events. For a list of event IDs and their corresponding actions, see Review event logs and error codes to troubleshoot issues with Microsoft Defender Antivirus.

Configure Microsoft Defender Antivirus settings

To configure the options that you mustantivirus evaluation settings, use to test the protection features, do the following steps:

  1. In the a Microsoft Defender portal at https://security.microsoft.com, go toAntivirus policy.

    When you create the policy on the EndpointsWindows policies > Configuration management > Endpoint security policies. Or, to go directly totab of the Endpoint security policies page,page in the Defender portal at https://security.microsoft.com/policy-inventory?osPlatform=Windows, use https://security.microsoft.com/policy-inventory Windows policies.

  2. On the Endpoint security policies page, verify the Windows policies tab is selected, and then select Create new policy

  3. On the Create a new policy flyout that opens, configure the followingthese specific settings:

    • Select a platform: Select Windows.
    • Select template: Select Microsoft Defender Antivirus.

    Select Create policy.

  4. TheWhen you create a new policy wizard opens. Onor modify the Basics page,policy, configure the following settings:

    • Name: Enter a unique name for the policy.
    • Description: Enter an optional description.

    Select Next

  5. Onevaluation settings on the Configuration settings page, configure the settings in the Defender section as described in the following tables:tab:

    • Real-time Protection:

      Setting Value
      Allow Realtime Monitoring Allowed. Turns on and runs the real-time monitoring service. (Default)service (default).
      Real Time Scan Direction Monitor all files (bi-directional) (default). (Default)
      Allow Behavior Monitoring Allowed. Turns on real-time behavior monitoring (Default)(default).
      Allow On Access Protection Allowed. (Default)Allowed (default).
      PUA Protection PUA Protection on. Detected items are blocked. They will showappear in history along with other threats.
    • Cloud protection features:

      Setting Value
      Allow Cloud Protection Allowed. Turns on Cloud Protection. (Default)cloud protection (default).
      Cloud Block Level High
      Cloud Extended Time-outTimeout Configured, 50
      Submit Samples Consent Send all samples automatically

      Standard security intelligence updates can take hours to prepare and deliver. OurMicrosoft cloud-delivered protection service can deliver updated protection against emerging threats in seconds. For more information, see Use next-gen technologies in Microsoft Defender Antivirus through cloud-delivered protection.

    • Scans:

      Setting Value
      Allow Email Scanning Allowed. Turns on email scanning.
      Allow scanning of all downloaded files and attachments Allowed. (Default)Allowed (default).
      Allow Script Scanning Allowed. (Default)Allowed (default).
      Allow Archive Scanning Allowed. Scans the archive files. (Default)files (default).
      Allow Scanning Network Files Allowed. Scans network files. (Default)files (default).
      Allow Full Scan Removable Drive Scanning Allowed. Scans removable drives.
    • Network Protection:

      Setting Value
      Enable Network Protection Enabled (block mode)
      Allow Network Protection Down Level Network protection will be enabled downlevel.
      Allow Datagram Processing On Win Server Datagram processing on Windows Server is enabled.disabled (default).
      Disable DNS over TCP parsing DNS over TCP parsing is enabled (Default)(default).
      Disable HTTP parsing HTTP parsing is enabled (Default)(default).
      Disable SSH parsing SSH parsing is enabled (Default)(default).
      Disable TLS parsing TLS parsing is enabled (Default)(default).
    • Security Intelligence updates:

      Setting Value
      Signature Update Interval Configured, 4
      Signature Update Fallback Order
      1. Select Add for as many fallback sources as you want to specify.
      2. Enter one of the following values in each box in the order you want:
        • InternalDefinitionUpdateServer: Your own WSUS server with Microsoft Defender Antivirus updates allowed.
        • MicrosoftUpdateServer: Microsoft Update.
        • MMPC: https://www.microsoft.com/wdsi/definitions


      To remove a fallback source (populated or empty), select the check box next to the box, and then select Remove.
    • Local administrator AV:

      DisablePrevent local administrator AVadministrators from changing Microsoft Defender Antivirus settings such as exclusions, and setexclusions. Manage the policies from the Microsoftsettings through Defender for Endpoint Security Settings Management as described in the following table:security settings management.

      Setting Value
      Disable Local Admin Merge Disable Local Admin Merge
    • Threat severity default action:

      Setting Value
      Remediation action for High severity threats Quarantine. Move files to quarantine.
      Remediation action for Severe threats Quarantine. Move files to quarantine.
      Remediation action for Low severity threats Quarantine. Move files to quarantine.
      Remediation action for Moderate severity threats Quarantine. Move files to quarantine.
    • Quarantine options:

      Setting Value
      Days to Retain Cleaned Malware Configured, 60
      Allow User UI Access Allowed. LetLets users access UI. (Default)the UI (default).

    Configure attack surface reduction rules

    To configure the ASR rule evaluation settings, use an Attack Surface Reduction Rules policy. For more information about ASR rules, see ASR rules.

    For information about the available rule actions, see Modes for ASR rules.

    When you're finished create the policy on the Configuration settings page, select Next.

  6. On the Assignments page, click in the box and select from the following values:

    • All users or All devices.
    • When you find and select one or more available groups, you can use the Target type value on the group entry to to Include or Exclude the group members.

    When you're finished on the Assignments page, select Next.

  7. On the Review + create page, review your settings. Select Back or select the page name to make changes.

    When you're finished on the Review + create page, select Save.

When the policy creation is complete, you're taken to the details page of the new policy.

Select Endpoint securityWindows policies at the toptab of the page to return to the Endpoint security policies page wherein the new policy is listed with the Policy type value Microsoft Defender Antivirus.

Attack surface reduction rules

To enable attack surface reduction (ASR) rules using the endpoint security policies, do the following steps:

  1. In the Microsoft Defender portal at https://security.microsoft.comhttps://security.microsoft.com/policy-inventory?osPlatform=Windows, go to Endpoints > Configuration management > Endpoint security policies. Or, to go directly to the Endpoint security policies page, use https://security.microsoft.com/policy-inventory Windows policies.

  2. On the Endpoint security policies page, verify the Windows policies tab is selected, and then select Create new policy

  3. On the Create a new policy flyout that opens, configure the followingthese specific settings:

    • Select a platform: Select Windows.
    • Select template: Select Attack Surface Reduction Rules.

    Select Create policy.

  4. TheWhen you create a new policy wizard opens. Onor modify the Basics page,policy, configure the following settings:

    • Name: Enter a unique name for the policy.
    • Description: Enter an optional description.

    Select Next

  5. Onevaluation settings on the Configuration settings page, configure the settings based on the following recommendations:tab:

    Setting Value
    Block executable content from email client and webmail BlockAudit
    Block Adobe Reader from creating child processes BlockAudit
    Block execution of potentially obfuscated scripts BlockAudit
    Block abuse of exploited vulnerable signed drivers (Device) BlockAudit
    Block Win32 API calls from Office macros BlockAudit
    Block executable files from running unless they meet a prevalence, age, or trusted list criterion BlockAudit
    Block Office communication application from creating child processes BlockAudit
    Block all Office applications from creating child processes BlockAudit
    Block use of copied or impersonated system tools BlockAudit
    Block JavaScript or VBScript from launching downloaded executable content BlockAudit
    Block credential stealing from the Windows local security authority subsystem BlockAudit
    Block Webshell creation for Servers BlockAudit
    Block Office applications from creating executable content BlockAudit
    Block untrusted and unsigned processes that run from USB BlockAudit
    Block Office applications from injecting code into other processes BlockAudit
    Block persistence through WMI event subscription BlockAudit
    Use advanced protection against ransomware BlockAudit
    Block process creations originating from PSExec and WMI commands Block (If you have Configuration Manager (formerly SCCM), or other management tools that use WMI you might need to set this to Audit instead of Block)
    Block rebooting machine in Safe Mode BlockAudit
    Enable Controlled Folder Access EnabledAudit Mode
  1. On the Assignments page, click in the box and select from the following values:

    • All users or All devices.
    • When you find and select one or more available groups, you can use the Target type value on the group entry to to Include or Exclude the group members.

    When you're finished on the Assignments page, select Next.

  2. On the Review + create page, review your settings. Select Back or select the page name to make changes.

    When you're finished on the Review + create page, select Save.

When the policy creation is complete, you're taken to the details page of the new policy.

Select Endpoint security policies at the top of the page to return to the Endpoint security policies page where the new policy is listed with the Policy type value Attack surface reduction rules.

Enable Tamper Protection

To enable Tamper Protection by using endpoint security policies, complete the following steps:

  1. Sign in to Microsoft Defender XDR

  2. Go toReview the audit events before you enable ASR rules or controlled folder access in block mode. For more information, see Test your ASR rules deployment.

Configure tamper protection

To configure tamper protection, use a Endpoints > Configuration management > Windows Security Experience policy.

When you create the policy on the Windows policies tab of the Endpoint security policies > page in the Defender portal at https://security.microsoft.com/policy-inventory?osPlatform=Windows, use these specific settings:

  • Select platform: Select Windows policies > Create new policy.
  • Select template: Select Windows 10, Windows 11, and Windows Server from the Select Platform drop-down list.

  • Select Security Experience from.

When you create or modify the Select Template drop-down list.

  • Select Create policy. The Create a new policy page appears.

  • On the Basics page, enter a name and description for the profile in the Name and Description fields, respectively.

  • Select Next.

  • Onpolicy, use this specific setting on the Configuration settings page, expand the groups of settings, and then select the settings that you want to manage with this profile.

  • Set the policies for the chosen groups of settings by configuring them as described in the following table:tab:

    DescriptionSetting SettingValue
    TamperProtectionTamper Protection (Device) OnTamper Protection (On)
  • Check the Cloud Protection network connectivity

    Cloud Protection (also known as the Microsoft Active Protection Service, or MAPS) is a feature of

    Validate Microsoft Defender Antivirus thatprotection

    Use the following procedures to verify cloud connectivity and update versions on the evaluation devices.

    Check cloud protection network connectivity

    Cloud protection uses cloud-based machine learning and analysis to provide faster threat detection. The device must be able to reach the cloudMicrosoft cloud-delivered protection service over the network for this feature to work correctly.

    Verify that Cloud Protection network connectivity is working during your penetration testing.The following procedure applies to Windows 10 or later and Windows Server 2019 or later.

    Prerequisite: OpenRun the following commands in an elevated Command Prompt as an administrator (select(a Command Prompt window you opened by selecting Run as administrator) before running the following commands.:

    For more information, see Configure and manage Microsoft Defender Antivirus with the MpCmdRun command-line tool.

    Check the platform update version

    The latest "Platform Update" version Production channel (GA) is available in Microsoft Update Catalog.

    To check which "Platform Update" version you have installed, runRun the following command in an elevated PowerShell usingsession to display the privileges of an administrator:Microsoft Defender Antivirus platform version installed on the device:

    Get-MPComputerStatus | Format-Table AMProductVersion
    

    Compare the output with the latest production channel version in the Microsoft Update Catalog.

    Check the Security Intelligence Updatesecurity intelligence update version

    The latest "Security Intelligence Update" version is available in Latest security intelligence updates for Microsoft Defender Antivirus and other Microsoft anti-malware - Microsoft Security Intelligence.

    To check which "Security Intelligence Update" version you have installed, runRun the following command in an elevated PowerShell usingsession to display the privileges of an administrator:security intelligence version installed on the device:

    Get-MPComputerStatus | Format-Table AntivirusSignatureVersion
    

    Compare the output with the Security intelligence update version on the Microsoft Defender Antivirus security intelligence and product updates page.

    Check the Engine Update version

    The latest scan "engine update" version is available in Latest security intelligence updates for Microsoft Defender Antivirus and other Microsoft anti-malware - Microsoft Security Intelligence.

    To check which "Engine Update" version you have installed, runRun the following command in an elevated PowerShell usingsession to display the privileges of an administrator:Microsoft Defender Antivirus engine version installed on the device:

    Get-MPComputerStatus | Format-Table AMEngineVersion
    

    Compare the output with the Engine version on the Microsoft Defender Antivirus security intelligence and product updates page.

    If you find that your settings aren't taking effect, you might have a conflict. For information on how to resolve conflicts, see Troubleshoot Microsoft Defender Antivirus settings.

    For False Negatives (FNs) submissions

    A false negative (FN) occurs when

    Submit missed detections

    If Microsoft Defender Antivirus doesn't detect a malicious file or activity that is actually malicious. If you encounter a missed detection during your evaluation, submit the undetected file to Microsoft for analysis so that protection can be updated.

    For information on how to make FN submissions, see:analysis: