2023-12-30 23:54:28 -05:00
|
|
|
# Microsoft Defender Antivirus
|
|
|
|
|
2024-01-07 03:30:05 -05:00
|
|
|
**MAPS and features dependent on it disabled using this policy. It is quite invasive so I will only enable it for certain OUs.**
|
2024-01-04 08:40:19 -05:00
|
|
|
|
2024-01-06 06:43:40 -05:00
|
|
|
`Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Antivirus`
|
2023-12-30 23:54:28 -05:00
|
|
|
|
2023-12-31 00:40:58 -05:00
|
|
|
## MAPS
|
|
|
|
|
|
|
|
`Computer Configuration\Administrative Templates\Windows Components\Microsoft Defender Antivirus\MAPS`
|
2024-01-07 03:30:05 -05:00
|
|
|
- Join Microsoft MAPS -> Enabled -> Disabled
|
2024-01-04 08:40:19 -05:00
|
|
|
|
|
|
|
## Controlled Folder Access
|
|
|
|
|
|
|
|
`Computer Configuration\Administrative Templates\Windows Components\Microsoft Defender Antivirus\Microsoft Defender Exploit Guard\Controlled Folder Access`
|
2023-12-31 00:40:58 -05:00
|
|
|
|
2024-01-04 08:40:19 -05:00
|
|
|
- Configure Controlled folder access -> Enabled -> Block
|
2023-12-30 23:54:28 -05:00
|
|
|
|
2024-01-04 08:40:19 -05:00
|
|
|
## MpEngine
|
2023-12-30 23:54:28 -05:00
|
|
|
|
2024-01-04 08:40:19 -05:00
|
|
|
`Computer Configuration\Administrative Templates\Windows Components\Microsoft Defender Antivirus\MpEngine`
|
|
|
|
|
|
|
|
- Enable file hash computation feature -> Enabled
|
|
|
|
|
|
|
|
## Quarantine
|
|
|
|
|
|
|
|
`Computer Configuration\Administrative Templates\Windows Components\Microsoft Defender Antivirus\Quarantine`
|
|
|
|
|
|
|
|
- Configure local settings override for the removal of items from Quarantine folder -> Enabled
|
|
|
|
- Configure removal of items from Quarantine folder -> 1 day
|
|
|
|
|
|
|
|
## Scan
|
|
|
|
|
|
|
|
`Computer Configuration\Administrative Templates\Windows Components\Microsoft Defender Antivirus\Scan`
|
|
|
|
|
|
|
|
- Scan for the latest virus and spyware security intelligence before running a scheduled scan -> Enabled
|
|
|
|
- Turn on catch-up quick scan -> Enabled
|
|
|
|
|
|
|
|
## Security Intelligence Updates
|
2023-12-30 23:54:28 -05:00
|
|
|
|
2024-01-04 08:40:19 -05:00
|
|
|
- Check for the latest virus and spyware security intelligence on startup -> Enabled
|