Microsoft Defender for Endpoint
Endpoint protection

Prevent Changes To Security Settings With Tamper Protection

In brief

The documentation introduces controlled configuration as a capability built on tamper protection and notes that the existing tamper protection setting in management experiences is being renamed to controlled configuration.

What Defender admins need to know

Administrators should expect the updated setting name and review the linked controlled configuration guidance.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

description: Use tamper protection to prevent malicious apps from changing important security settings. ms.service: defender-endpoint ms.localizationpriority: medium ms.date: 06/16/07/08/2026 ms.topic: how-to author: limwainstein ms.author: lwainstein ms.custom:

  • msecd-doc-authoring-10141016
  • nextgen
  • admindeeplinkDEFENDER ms.subservice: ngp

Tamper protection is part of anti-tampering capabilities that include standard protection attack surface reduction (ASR) rules. Tamper protection is an important part of built-in protection.

Prerequisites

Supported operating systems

Tamper protection is available for devices that are running one of the following versions of Windows:operating systems:

  • Windows
  • macOS
  • Automatic actions are taken on detected threats.
  • Notifications are visible in the Windows Security app on Windows devices.
  • Archived files are scanned.
  • Exclusions can't be modified or added (see Tamper protection for antivirus exclusions).

As of signature release 1.383.1159.0, due to confusion around the default value for "Allow Scanning Network Files", tamper protection no longer locks this setting to its default value. In managed environments, the default value is enabled.

  • If you must make changes to a device and those changes are blocked by tamper protection, you can use troubleshooting mode to temporarily disable tamper protection on the device.
    • You can use Intune, Microsoft Defender for Endpoint or Configuration Manager to exclude devices from tamper protection.

Tamper protection doesn't prevent you from viewing your security settings. And, tamper protection doesn't affect how non-Microsoft antivirus apps register with the Windows Security app. If your organization is using Defender for Endpoint, individual users can't change the tamper protection setting; in those cases, your security team manages tamper protection. You can configure or manage tamper protection using the Microsoft Defender portal, Microsoft Intune, Configuration Manager,Microsoft Defender portal, Microsoft Intune, Configuration Manager, or the Windows Security app. For more information, see How do I configure or manage tamper protection?Windows Security app.

| Use the Windows Security app. | Turn tamper protection on (or off) on an individual device that isn't managed by a security team (such as devices for home use). See Manage tamper protection on an individual device.

This method doesn't override tamper protection settings that are set in the Microsoft Defender portal, Intune, or Configuration Manager, and it isn't intended to be used by organizations. |

Protect Microsoft Defender Antivirus exclusions

Related content