Manage Tamper Protection Intune
In brief
The page now cautions that registry keys are for viewing only and that changing them does not affect whether tamper protection applies to exclusions. It also adds a related-content link.
What Defender admins need to know
Avoid changing these registry keys; such changes will not control tamper protection for exclusions.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
description: Turn tamper protection on or off for your organization in Microsoft Intune.
ms.service: defender-endpoint
ms.localizationpriority: medium
ms.date: 06/16/07/03/2026
ms.topic: how-to
author: limwainstein
ms.author: lwainstein
ms.custom:
- msecd-doc-authoring-
10141016 - nextgen
- admindeeplinkDEFENDER ms.subservice: ngp
Turn tamper protection on (or off) in Microsoft Intune
To create an antivirus policy in Microsoft Intune that turns tamper protection on or off for your devices, see Create an endpoint security policy (opens in a new tab in the Intune documentation). When creating the antivirus policy, use these settings::
- Policy type": Antivirus
- Platform: Windows
You can use a registry key to determine whether the functionality to protect Microsoft Defender Antivirus exclusions is enabled. Use this procedure to view, but not change, tamper protection status.
On a Windows device open Registry Editor. (Read-only mode is fine; you're not editing the registry key.)On a Windows device open Registry Editor. (Read-only mode is fine; you're not editing the registry key.)
To confirm that the device is managed by Intune only or managed by Configuration Manager only, with Sense enabled, check the following registry key values:
Related content
To confirm that the device is managed by Intune only or managed by Configuration Manager only, with Sense enabled, check the following registry key values:
See also
@@ -4,12 +4,12 @@ ms.reviewer: joshbregman, mattcall, pahuijbr, hayhov, oogunrinde description: Turn tamper protection on or off for your organization in Microsoft Intune. ms.service: defender-endpoint ms.localizationpriority: medium-ms.date: 06/16/2026+ms.date: 07/03/2026 ms.topic: how-to author: limwainstein ms.author: lwainstein ms.custom: -- msecd-doc-authoring-1014+- msecd-doc-authoring-1016 - nextgen - admindeeplinkDEFENDER ms.subservice: ngp@@ -67,7 +67,7 @@ Tamper protection helps protect certain [security settings](prevent-changes-to-s ## Turn tamper protection on (or off) in Microsoft Intune -To create an antivirus policy in Microsoft Intune that turns tamper protection on or off for your devices, see <a href="/intune/intune-service/protect/endpoint-security-policy#create-endpoint-security-policies" target="_blank">Create an endpoint security policy</a> (opens in a new tab in the Intune documentation). When creating the policy, use these settings::+To create an antivirus policy in Microsoft Intune that turns tamper protection on or off for your devices, see <a href="/intune/intune-service/protect/endpoint-security-policy#create-endpoint-security-policies" target="_blank">Create an endpoint security policy</a> (opens in a new tab in the Intune documentation). When creating the antivirus policy, use these settings: - **Policy type**": Antivirus - **Platform**: Windows@@ -97,6 +97,9 @@ To learn more about antivirus exclusions, see [Exclusions for Microsoft Defender You can use a registry key to determine whether the functionality to protect Microsoft Defender Antivirus exclusions is enabled. Use this procedure to view, but not change, tamper protection status. +> [!CAUTION]+> **Do not change the value of the registry keys**. This procedure is for viewing registry values only. Changing keys has no effect on whether tamper protection applies to exclusions.+ 1. On a Windows device open Registry Editor. (Read-only mode is fine; you're not editing the registry key.) 1. To confirm that the device is managed by Intune only or managed by Configuration Manager only, with Sense enabled, check the following registry key values:@@ -123,8 +126,9 @@ You can use a registry key to determine whether the functionality to protect Mic > [!CAUTION] > **Do not change the value of the registry keys**. Use the preceding procedure for information only. Changing keys has no effect on whether tamper protection applies to exclusions. -## See also+## Related content +- [Controlled configuration in Microsoft Defender for Endpoint](secure-controlled-configuration.md) - [Frequently asked questions (FAQs) on tamper protection](faqs-on-tamper-protection.yml) - [Troubleshoot problems with tamper protection](troubleshoot-problems-with-tamper-protection.yml) - [Manage Microsoft Defender for Endpoint on devices with Microsoft Intune](/intune/intune-service/protect/mde-security-integration) 