{"id":30868,"date":"2025-06-08T13:04:00","date_gmt":"2025-06-08T13:04:00","guid":{"rendered":"https:\/\/endusersupports.com\/?p=30868"},"modified":"2026-05-03T14:50:24","modified_gmt":"2026-05-03T14:50:24","slug":"how-to-create-exclusion-policy-in-defender-for-endpoint","status":"publish","type":"post","link":"https:\/\/endusersupports.com\/index.php\/2025\/06\/08\/how-to-create-exclusion-policy-in-defender-for-endpoint\/","title":{"rendered":"How to create exclusion policy in Defender for endpoint"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"30868\" class=\"elementor elementor-30868\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-1e2ba8f elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"1e2ba8f\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-bbe8970\" data-id=\"bbe8970\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-717acc2 elementor-widget elementor-widget-text-editor\" data-id=\"717acc2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"color: #ffffff;\"><b>\u00a0How to create exclusion in Defender for Endpoint<\/b><\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-ecf1f94 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"ecf1f94\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-98bb6ab\" data-id=\"98bb6ab\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-d89d762 elementor-drop-cap-yes elementor-drop-cap-view-default elementor-widget elementor-widget-text-editor\" data-id=\"d89d762\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;drop_cap&quot;:&quot;yes&quot;}\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h6>What is Exclusions<\/h6><ol><li>Exclusions used to exclude Extensions, Process, and Paths from the Microsoft Defender Scans.<\/li><li>Exclusions apply to <b><a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/security\/defender-endpoint\/scheduled-catch-up-scans-microsoft-defender-antivirus?view=o365-worldwide\">scheduled scans<\/a><\/b>,\u00a0<b><a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/security\/defender-endpoint\/run-scan-microsoft-defender-antivirus?view=o365-worldwide\">on-demand scans<\/a><\/b>, and\u00a0<b><a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/security\/defender-endpoint\/configure-real-time-protection-microsoft-defender-antivirus?view=o365-worldwide\">always-on real-time protection<\/a><\/b><a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/security\/defender-endpoint\/configure-real-time-protection-microsoft-defender-antivirus?view=o365-worldwide\"> and <\/a><b><a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/security\/defender-endpoint\/configure-real-time-protection-microsoft-defender-antivirus?view=o365-worldwide\">monitoring<\/a><\/b>.<\/li><li>Exclusions for process-opened files only apply to real-time protection.<\/li><li>You should always evaluate the risks that are associated with implementing exclusions, and you should only exclude files that you are confident are not malicious.<\/li><\/ol><h6>Exclusions Types<\/h6><p><img fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter wp-image-30869\" src=\"http:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/Exclusions-300x121.png\" alt=\"\" width=\"600\" height=\"241\" srcset=\"https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/Exclusions-300x121.png 300w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/Exclusions-768x308.png 768w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/Exclusions.png 829w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/p><h6>Wildcards in Exclusions<\/h6><table width=\"1209\"><tbody><tr><td width=\"199\"><p><b>Wildcard<\/b><\/p><\/td><td width=\"487\"><p><b>Where <\/b><\/p><\/td><td width=\"523\"><p><b>Examples<\/b><\/p><\/td><\/tr><tr><td rowspan=\"3\" width=\"199\"><p>* (asterisk)<\/p><\/td><td width=\"487\"><p>File Extension<\/p><\/td><td width=\"523\"><p>\u00a0C:\\MyData\\*.txt\u00a0<br \/>\u00a0Includes\u00a0C:\\MyData\\notes.txt<\/p><\/td><\/tr><tr><td width=\"487\"><p>Folder name<\/p><\/td><td width=\"523\"><p>\u00a0C:\\somepath\\*\\Data <br \/>\u00a0Includes any file in C:\\somepath\\Archives\\Data <br \/>\u00a0and its subfolders, and C:\\somepath\\Authorized\\Data\u00a0<\/p><p>\u00a0and its subfolders<\/p><\/td><\/tr><tr><td width=\"487\"><p>\u00a0In folder exclusions &#8211; Use multiple * with\u00a0\u00a0 folder slashes \\ to indicate multiple nested folders.<\/p><\/td><td width=\"523\"><p>\u00a0C:\\Serv\\*\\*\\Backup <br \/>\u00a0Includes any file in C:\\Serv\\Primary\\Denied\\Backup <br \/>\u00a0and its subfolders, and C:\\Serv\\Secondary\\Allowed\\Backup <br \/>\u00a0and its subfolders<\/p><\/td><\/tr><\/tbody><\/table><table style=\"height: 353px;\" width=\"965\"><tbody><tr><td width=\"245\"><p><b>Wildcard<\/b><\/p><\/td><td width=\"414\"><p><b>Where <\/b><\/p><\/td><td width=\"561\"><p><b>Examples<\/b><\/p><\/td><\/tr><tr><td rowspan=\"3\" width=\"245\"><p>? (question mark)<\/p><\/td><td width=\"414\"><p>File Extension<\/p><\/td><td width=\"561\"><p>\u00a0C:\\MyData\\my?.zip<br \/>\u00a0<b>Includes<\/b>\u00a0C:\\MyData\\my1.zip<\/p><\/td><\/tr><tr><td width=\"414\"><p>Folder name<\/p><\/td><td width=\"561\"><p>\u00a0C:\\somepath\\?\\Data <br \/>\u00a0Includes any file in C:\\somepath\\P\\Data <br \/>\u00a0and its subfolders<\/p><\/td><\/tr><tr><td width=\"414\"><p>In folder exclusions &#8211; Use multiple * with folder slashes \\ to indicate multiple nested folders.<\/p><\/td><td width=\"561\"><p>\u00a0C:\\somepath\\test0?\\Data <br \/>\u00a0Includes any file in C:\\somepath\\test01\\Data <br \/>\u00a0and its subfolders<\/p><\/td><\/tr><\/tbody><\/table><table style=\"height: 961px;\" width=\"966\"><tbody><tr><td width=\"441\"><p><b>System Environment variable<\/b><\/p><\/td><td width=\"706\"><p><b>Redirects to this<\/b><\/p><\/td><\/tr><tr><td width=\"441\"><p>%APPDATA%<\/p><\/td><td width=\"706\"><p>C:\\Windows\\system32\\config\\systemprofile\\Appdata\\Roaming<\/p><\/td><\/tr><tr><td width=\"441\"><p>%APPDATA%\\Microsoft<\/p><\/td><td width=\"706\"><p>C:\\Windows\\System32\\config\\systemprofile\\AppData\\Roaming\\Microsoft<\/p><\/td><\/tr><tr><td width=\"441\"><p>%LOCALAPPDATA%<\/p><\/td><td width=\"706\"><p>C:\\Windows\\System32\\config\\systemprofile\\AppData\\Local<\/p><\/td><\/tr><tr><td width=\"441\"><p>%ProgramData%<\/p><\/td><td width=\"706\"><p>C:\\ProgramData<\/p><\/td><\/tr><tr><td width=\"441\"><p>%ProgramFiles%<\/p><\/td><td width=\"706\"><p>C:\\Program Files<\/p><\/td><\/tr><tr><td width=\"441\"><p>%ProgramFiles%\\Common Files<\/p><\/td><td width=\"706\"><p>C:\\Program Files\\Common Files<\/p><\/td><\/tr><tr><td width=\"441\"><p>%ProgramFiles(x86)%<\/p><\/td><td width=\"706\"><p>C:\\Program Files (x86)<\/p><\/td><\/tr><tr><td width=\"441\"><p>%SystemDrive%<\/p><\/td><td width=\"706\"><p>C:<\/p><\/td><\/tr><tr><td width=\"441\"><p>%SystemDrive%\\Program Files<\/p><\/td><td width=\"706\"><p>C:\\Program Files<\/p><\/td><\/tr><tr><td width=\"441\"><p>%SystemRoot%<\/p><\/td><td width=\"706\"><p>C:\\Windows<\/p><\/td><\/tr><tr><td width=\"441\"><p>%windir%<\/p><\/td><td width=\"706\"><p>C:\\Windows<\/p><\/td><\/tr><tr><td width=\"441\"><p>%windir%\\Fonts<\/p><\/td><td width=\"706\"><p>C:\\Windows\\Fonts<\/p><\/td><\/tr><tr><td width=\"441\"><p>%ALLUSERSPROFILE%<\/p><\/td><td width=\"706\"><p>C:\\ProgramData<\/p><\/td><\/tr><tr><td width=\"441\"><p>%PUBLIC%<\/p><\/td><td width=\"706\"><p>C:\\Users\\Public<\/p><\/td><\/tr><tr><td width=\"441\"><p>%USERPROFILE%<\/p><\/td><td width=\"706\"><p>C:\\Windows\\system32\\config\\systemprofile<\/p><\/td><\/tr><\/tbody><\/table><p><strong>Steps to create Exclusion policy<\/strong><\/p><p>Follow the below steps to create exclusion policy.<\/p><p>Login to Intune and Click on <strong>Endpoint Security\u00a0<\/strong>then <strong>Antivirus <\/strong>and now click on <strong>Create Policy <\/strong>as showing in screenshot.\u00a0<\/p><p><img decoding=\"async\" class=\"aligncenter wp-image-30873 size-full\" src=\"http:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDETUT4.png\" alt=\"\" width=\"1329\" height=\"643\" srcset=\"https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDETUT4.png 1329w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDETUT4-300x145.png 300w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDETUT4-1024x495.png 1024w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDETUT4-768x372.png 768w\" sizes=\"(max-width: 1329px) 100vw, 1329px\" \/><\/p><p>Enter the Exclusion policy name.<\/p><p><img decoding=\"async\" class=\"aligncenter size-full wp-image-30874\" src=\"http:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MD4EDA1.png\" alt=\"\" width=\"900\" height=\"652\" srcset=\"https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MD4EDA1.png 900w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MD4EDA1-300x217.png 300w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MD4EDA1-768x556.png 768w\" sizes=\"(max-width: 900px) 100vw, 900px\" \/><\/p><p>Enter the exclusions details.<\/p><p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-30876\" src=\"http:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDETUT3.png\" alt=\"\" width=\"797\" height=\"658\" srcset=\"https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDETUT3.png 797w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDETUT3-300x248.png 300w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDETUT3-768x634.png 768w\" sizes=\"(max-width: 797px) 100vw, 797px\" \/><\/p><p>Select the group name where you want to deploy the policy.<\/p><p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-30877\" src=\"http:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDEFBA1.png\" alt=\"\" width=\"1286\" height=\"654\" srcset=\"https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDEFBA1.png 1286w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDEFBA1-300x153.png 300w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDEFBA1-1024x521.png 1024w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDEFBA1-768x391.png 768w\" sizes=\"(max-width: 1286px) 100vw, 1286px\" \/><\/p><p>Now review the policy and validate that everything looks OK and click on create.<\/p><p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-30878\" src=\"http:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MD2AE91.png\" alt=\"\" width=\"1012\" height=\"654\" srcset=\"https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MD2AE91.png 1012w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MD2AE91-300x194.png 300w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MD2AE91-768x496.png 768w\" sizes=\"(max-width: 1012px) 100vw, 1012px\" \/><\/p><p>Check the exclusion policy created.<\/p><p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-30879\" src=\"http:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDETUT2.png\" alt=\"\" width=\"1270\" height=\"642\" srcset=\"https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDETUT2.png 1270w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDETUT2-300x152.png 300w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDETUT2-1024x518.png 1024w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDETUT2-768x388.png 768w\" sizes=\"(max-width: 1270px) 100vw, 1270px\" \/><\/p><p>Open the policy and check the deployment status.<\/p><p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-30880\" src=\"http:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDETUT1.png\" alt=\"\" width=\"777\" height=\"660\" srcset=\"https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDETUT1.png 777w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDETUT1-300x255.png 300w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDETUT1-768x652.png 768w\" sizes=\"(max-width: 777px) 100vw, 777px\" \/><\/p><p>Validate that Exclusions is applied on device.<\/p><p>Open PowerShell with admin and use the below command.<\/p><blockquote><p>\u00a0<i>$<\/i><i>WDAVprefs<\/i><i> = <\/i><i>Get-<\/i><i>MpPreference<\/i><\/p><p>\u00a0<i>$<\/i><i>WDAVprefs.ExclusionExtension<\/i><\/p><p>\u00a0<i>$<\/i><i>WDAVprefs.ExclusionPath<\/i><\/p><\/blockquote><p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-30882\" src=\"http:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/Exclusion-Validation.png\" alt=\"\" width=\"557\" height=\"190\" srcset=\"https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/Exclusion-Validation.png 557w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/Exclusion-Validation-300x102.png 300w\" sizes=\"(max-width: 557px) 100vw, 557px\" \/><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>\u00a0How to create exclusion in Defender for Endpoint What is Exclusions Exclusions used to exclude Extensions, Process, and Paths from the Microsoft Defender Scans. Exclusions apply to scheduled scans,\u00a0on-demand scans, and\u00a0always-on real-time protection and monitoring. Exclusions for process-opened files only apply to real-time protection. You should always evaluate the risks that are associated with implementing [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[19],"tags":[],"class_list":["post-30868","post","type-post","status-publish","format-standard","hentry","category-defender-for-endpoint"],"views":12,"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/endusersupports.com\/index.php\/wp-json\/wp\/v2\/posts\/30868","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/endusersupports.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/endusersupports.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/endusersupports.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/endusersupports.com\/index.php\/wp-json\/wp\/v2\/comments?post=30868"}],"version-history":[{"count":27,"href":"https:\/\/endusersupports.com\/index.php\/wp-json\/wp\/v2\/posts\/30868\/revisions"}],"predecessor-version":[{"id":30906,"href":"https:\/\/endusersupports.com\/index.php\/wp-json\/wp\/v2\/posts\/30868\/revisions\/30906"}],"wp:attachment":[{"href":"https:\/\/endusersupports.com\/index.php\/wp-json\/wp\/v2\/media?parent=30868"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/endusersupports.com\/index.php\/wp-json\/wp\/v2\/categories?post=30868"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/endusersupports.com\/index.php\/wp-json\/wp\/v2\/tags?post=30868"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}