Microsoft Defender for Endpoint
Endpoint protection

Manage Tamper Protection Intune

In brief

The page now cautions that registry keys are for viewing only and that changing them does not affect whether tamper protection applies to exclusions. It also adds a related-content link.

What Defender admins need to know

Avoid changing these registry keys; such changes will not control tamper protection for exclusions.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

description: Turn tamper protection on or off for your organization in Microsoft Intune. ms.service: defender-endpoint ms.localizationpriority: medium ms.date: 06/16/07/03/2026 ms.topic: how-to author: limwainstein ms.author: lwainstein ms.custom:

  • msecd-doc-authoring-10141016
  • nextgen
  • admindeeplinkDEFENDER ms.subservice: ngp

Turn tamper protection on (or off) in Microsoft Intune

To create an antivirus policy in Microsoft Intune that turns tamper protection on or off for your devices, see Create an endpoint security policy (opens in a new tab in the Intune documentation). When creating the antivirus policy, use these settings::

  • Policy type": Antivirus
  • Platform: Windows

You can use a registry key to determine whether the functionality to protect Microsoft Defender Antivirus exclusions is enabled. Use this procedure to view, but not change, tamper protection status.

  1. On a Windows device open Registry Editor. (Read-only mode is fine; you're not editing the registry key.)

    1. On a Windows device open Registry Editor. (Read-only mode is fine; you're not editing the registry key.)

    2. To confirm that the device is managed by Intune only or managed by Configuration Manager only, with Sense enabled, check the following registry key values:

    Related content

See also