Microsoft Defender for Endpoint
Endpoint protection

Use network protection to help prevent connections to malicious or suspicious sites

In brief

The article updates Group Policy Management Console navigation, expands the steps for enabling **Convert warn verdict to block**, adds Local Group Policy Editor guidance, and refreshes supporting links and page metadata.

What Defender admins need to know

Administrators configuring network protection have clearer, updated procedures to follow; no configuration change is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Use network protection to help prevent connections to malicious or suspicious sites

Overview of network protection

Network protection helps protect devices by preventing connections to malicious or suspicious sites. Examples of dangerous domains are domains that host phishing scams, malicious downloads, tech scams, or other malicious content. Network protection expands the scope of Microsoft Defender SmartScreenMicrosoft Defender SmartScreen to block all outbound HTTP(S) traffic that attempts to connect to poor-reputation sources (based on the domain or hostname).

Network protection extends the protection in Web protection to the operating system level, and is a core component for Web Content Filtering (WCF). It provides the web protection functionality found in Microsoft Edge to other supported browsers and nonbrowser applications. Network protection also provides visibility and blocking of indicators of compromise (IOCs) when used with Endpoint detection and response. For example, network protection works with your custom indicators to block specific domains or host names.

The following table summarizes network protection areas of coverage:

Feature Microsoft Edge Non-Microsoft browsers Nonbrowser processes
(for example, PowerShell)
Web Threat Protection SmartScreen must be enabled Network protection must be in block mode Network protection must be in block mode
Custom Indicators SmartScreen must be enabled Network protection must be in block mode Network protection must be in block mode
Web Content Filtering SmartScreen must be enabled Network protection must be in block mode Not supported
Network protection also requires Microsoft Defender Antivirus with real-time protection enabled.
Windows version Microsoft Defender Antivirus
Windows 10 version 1709 or later, Windows 11, Windows Server 1803 or later Make sure that Microsoft Defender Antivirus real-time protection, behavior monitoring, and cloud-delivered protection are enabled (active)
Windows Server 2012 R2 and Windows Server 2016 using the modern unified solution Platform update version 4.18.2001.x.x or newer

Use CSP to enable Convert warn verdict to block

By enabling this setting, network protection blocks network traffic instead of displaying a warning.

  1. OnIn Centralized Group Policy, open the Group Policy Management Console (GPMC) on your Group Policy management computer, opencomputer.

  2. In the Group Policy Management Console.GPMC console tree, expand Group Policy Objects in the forest and domain containing the GPO you want to edit.

  3. Right-click the Group Policy Object you want to configure,GPO, and then select Edit.

  4. In the Group Policy Management Editor, go to Computer configuration and then select> Administrative templates.

  5. Expand the tree to > Windows components > Microsoft Defender Antivirus > Network inspection system.

  6. Double-clickIn the details pane of Network inspection system, open the Convert warn verdict to block setting. To open the setting, use any of the following methods:

    • Double-click the setting.
    • Right-click the setting, and setthen select Edit.
    • Select the option tosetting, and then select Action > Edit.
  7. In the setting window that opens, select Enabled.

  8. Select, and then select OK.

Block experience

This procedure enables network protection to improve performance by switching from real-time inspection to asynchronous inspection.

  1. On

    Block experience

    This procedure enables network protection to improve performance by switching from real-time inspection to asynchronous inspection.

    1. In Centralized Group Policy, open the Group Policy Management Console (GPMC) on your Group Policy management computer, opencomputer.

    2. In the Group Policy Management Console.GPMC console tree, expand Group Policy Objects in the forest and domain containing the GPO you want to edit.

    3. Right-click the Group Policy Object you want to configure,GPO, and then select Edit.

    4. In the Group Policy Management Editor,Editor, go to Computer configuration, and then select > Administrative templates.

    5. Expand the tree to > Windows components > Microsoft Defender Antivirus > Network inspection system.

    6. Double-clickIn the details pane of Network inspection system, open the Turn on asynchronous inspection, setting. To open the setting, use any of the following methods:

      • Double-click the setting.
      • Right-click the setting, and then setselect Edit.
      • Select the option tosetting, and then select EnabledAction > Edit.

      • Select OK.

    Use Microsoft Defender Antivirus Powershell to enable Turn on asynchronous inspection