Microsoft Defender for Endpoint
Endpoint protection

Specify the cloud protection level

In brief

The article now provides revised GPMC navigation steps, clearer protection-level descriptions, an RSOP caution, and instructions for configuring the setting locally with gpedit.msc.

What Defender admins need to know

Administrators can use the updated paths and procedures when configuring the existing cloud protection setting through centralized or local Group Policy.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Specify the cloud protection level

Cloud protection works together with Microsoft Defender Antivirus to deliver protection to your devices faster than through traditional security intelligence updates. You can configure your level of cloud protection by using Microsoft Intune (recommended) or Group Policy.

Prerequisites

Supported operating systems

Cloud protection level configuration is supported on the following operating systems:

Perform the following steps to specify the level of cloud protection by using Group Policy:

  1. OnIn Centralized Group Policy, open the Group Policy Management Console (GPMC) on your Group Policy management machine, opencomputer.

  2. In the Group Policy Management Console.GPMC console tree, expand Group Policy Objects in the forest and domain containing the GPO you want to edit.

  3. Right-click the Group Policy Object you want to configure,GPO, and then select Edit.

  4. In the Group Policy Management Editor, go to Computer Configurationconfiguration > Administrative templates.

  5. Expand the tree to > Windows Componentscomponents > Microsoft Defender Antivirus > MpEngine.

  6. Double-click the Select cloud protection level setting, and set it to Enabled.

  7. Under Select cloud blocking level

  1. In the details pane of MpEngine, open the Select cloud protection level setting. To open the setting, use any of the following methods:

    • Double-click the setting.
    • Right-click the setting, and then select Edit.
    • Select the setting, and then select Action > Edit.
  2. In the setting window that opens, configure the following options:

    1. Select Enabled.
    2. Under Select cloud blocking level, select one of the following protection levels:
      • Default blocking level provides strong detection without increasing the risk of detecting legitimate files.