{"id":30907,"date":"2025-06-19T14:54:00","date_gmt":"2025-06-19T14:54:00","guid":{"rendered":"https:\/\/endusersupports.com\/?p=30907"},"modified":"2026-05-09T07:26:35","modified_gmt":"2026-05-09T07:26:35","slug":"configure-microsoft-defender-antivirus-policy","status":"publish","type":"post","link":"https:\/\/endusersupports.com\/index.php\/2025\/06\/19\/configure-microsoft-defender-antivirus-policy\/","title":{"rendered":"Configure Microsoft Defender Antivirus Policy"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"30907\" class=\"elementor elementor-30907\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-124785b elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"124785b\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-4fbbbb6\" data-id=\"4fbbbb6\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-cb24f92 elementor-widget elementor-widget-text-editor\" data-id=\"cb24f92\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"color: #ffffff;\"><b>Configure\u00a0 Microsoft Defender Antivirus Policy\u00a0<\/b><\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-958de73 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"958de73\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-f7c703a\" data-id=\"f7c703a\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-c8de423 elementor-widget elementor-widget-text-editor\" data-id=\"c8de423\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>A <strong>Microsoft Defender Antivirus policy<\/strong> defines how malware protection is configured and enforced across Windows devices. These policies control real\u2011time protection, cloud\u2011based detection, scanning behavior, exclusions, ransomware protection, and tamper prevention.<\/p><div><p>In modern environments, Defender Antivirus policies are most effectively managed using <strong>Microsoft Intune<\/strong>, ensuring consistent and scalable security across all endpoints.<\/p><\/div><h6>Key Settings in Microsoft Defender Antivirus Policy<\/h6><div><h5>\ud83d\udee1\ufe0f Real\u2011Time Protection<\/h5><ul><li>Monitors files and processes continuously<\/li><li>Blocks malicious behavior instantly<\/li><li><strong>Must remain enabled<\/strong> for baseline security<\/li><\/ul><div><h5>\u2601\ufe0f Cloud\u2011Delivered Protection<\/h5><ul><li>Leverages Microsoft threat intelligence<\/li><li>Detects zero\u2011day and emerging threats<\/li><li>Recommended protection level: <strong>High \/ Advanced<\/strong><\/li><\/ul><div><h5>\ud83d\udd0d Scheduled Scans<\/h5><ul><li><strong>Quick Scan<\/strong> (daily or at logon)<\/li><li><strong>Full Scan<\/strong> (weekly or during maintenance windows)<\/li><li>Prevents performance impact while maintaining coverage<\/li><\/ul><div><h5>\ud83d\udeab Exclusions<\/h5><ul><li>Files<\/li><li>Folders<\/li><li>File extensions<\/li><li>Processes<\/li><\/ul><div><h5>\ud83d\udd10 Tamper Protection<\/h5><ul><li>Prevents users and malware from changing Defender settings<\/li><li>Critical for preventing security bypass<\/li><li>Should always be <strong>enabled in enterprise environments.<\/strong><\/li><\/ul><div><h5>\ud83d\udca5 Ransomware Protection<\/h5><p>Includes:<\/p><ul><li>Controlled Folder Access<\/li><li>Protection for Documents, Desktop, Pictures, and custom folders<\/li><li>Blocks unauthorized app access<\/li><\/ul><div><h5>\ud83e\udde0 Behavior Monitoring<\/h5><ul><li>Detects suspicious activities rather than signatures<\/li><li>Effective against file\u2011less and script\u2011based attacks.<\/li><\/ul><div>Recommended Baseline Configuration (Best Practice).<\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/div><div><p>\u00a0<\/p><div><table><tbody><tr><th>Setting<\/th><th>Recommended Value<\/th><\/tr><tr><td>Real\u2011Time Protection<\/td><td>Enabled<\/td><\/tr><tr><td>Cloud Protection<\/td><td>Enabled<\/td><\/tr><tr><td>Sample Submission<\/td><td>Enabled<\/td><\/tr><tr><td>Tamper Protection<\/td><td>Enabled<\/td><\/tr><tr><td>Weekly Full Scan<\/td><td>Enabled<\/td><\/tr><tr><td>Behavior Monitoring<\/td><td>Enabled<\/td><\/tr><tr><td>ASR Rules<\/td><td>Enabled (Audit \u2192 Block)<\/td><\/tr><tr><td>Ransomware Protection<\/td><td>Enabled<\/td><\/tr><\/tbody><\/table><\/div><h6>Microsoft Defender Antivirus Policy vs Defender for Endpoint Policy<\/h6><div><table><tbody><tr><th>Aspect<\/th><th>Antivirus Policy<\/th><th>MDE Policy<\/th><\/tr><tr><td>Malware prevention<\/td><td>\u2705 Yes<\/td><td>\u2705 Yes<\/td><\/tr><tr><td>EDR &amp; investigation<\/td><td>\u274c No<\/td><td>\u2705 Yes<\/td><\/tr><tr><td>Automated remediation<\/td><td>Limited<\/td><td>Advanced<\/td><\/tr><tr><td>Threat hunting<\/td><td>\u274c No<\/td><td>\u2705 Yes<\/td><\/tr><\/tbody><\/table><\/div><h6>Follow the below steps to create Antivirus Policy.<\/h6><p>Login to Intune, Click on Endpoint Security then Antivirus and Click on New Policy then Select the\u00a0<strong>Microsoft Defender Antivirus.\u00a0<\/strong><img fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter size-full wp-image-30914\" src=\"http:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDE17F1.png\" alt=\"\" width=\"1295\" height=\"665\" srcset=\"https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDE17F1.png 1295w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDE17F1-300x154.png 300w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDE17F1-1024x526.png 1024w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDE17F1-768x394.png 768w\" sizes=\"(max-width: 1295px) 100vw, 1295px\" \/><\/p><p>Enter the Policy Name<\/p><p><img decoding=\"async\" class=\"aligncenter size-full wp-image-30915\" src=\"http:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDC6071.png\" alt=\"\" width=\"906\" height=\"669\" srcset=\"https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDC6071.png 906w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDC6071-300x222.png 300w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDC6071-768x567.png 768w\" sizes=\"(max-width: 906px) 100vw, 906px\" \/><\/p><\/div><p>Select all the required settings as your company standard.<\/p><p><img decoding=\"async\" class=\"aligncenter size-full wp-image-30916\" src=\"http:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MD1C3B1.png\" alt=\"\" width=\"866\" height=\"653\" srcset=\"https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MD1C3B1.png 866w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MD1C3B1-300x226.png 300w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MD1C3B1-768x579.png 768w\" sizes=\"(max-width: 866px) 100vw, 866px\" \/><\/p><p>You can add the tags if need if not can leave it on default.<\/p><p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-30917\" src=\"http:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MD617F1.png\" alt=\"\" width=\"735\" height=\"656\" srcset=\"https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MD617F1.png 735w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MD617F1-300x268.png 300w\" sizes=\"(max-width: 735px) 100vw, 735px\" \/><\/p><p>Select the group Name you can want to deploy the policy.<\/p><p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-30918\" src=\"http:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MD08761.png\" alt=\"\" width=\"1201\" height=\"675\" srcset=\"https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MD08761.png 1201w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MD08761-300x169.png 300w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MD08761-1024x576.png 1024w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MD08761-768x432.png 768w\" sizes=\"(max-width: 1201px) 100vw, 1201px\" \/><\/p><p>No review the policy and Click on next if everything looks ok.<\/p><p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-30919\" src=\"http:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDETUT3-1.png\" alt=\"\" width=\"862\" height=\"666\" srcset=\"https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDETUT3-1.png 862w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDETUT3-1-300x232.png 300w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDETUT3-1-768x593.png 768w\" sizes=\"(max-width: 862px) 100vw, 862px\" \/><\/p><p>When policy is created then search with the name.<\/p><p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-30920\" src=\"http:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDETUT2-1.png\" alt=\"\" width=\"1336\" height=\"570\" srcset=\"https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDETUT2-1.png 1336w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDETUT2-1-300x128.png 300w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDETUT2-1-1024x437.png 1024w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDETUT2-1-768x328.png 768w\" sizes=\"(max-width: 1336px) 100vw, 1336px\" \/><\/p><p>To get the deployment status report, open the policy and check here deployment status.<\/p><p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-30921\" src=\"http:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDETUT4-1.png\" alt=\"\" width=\"753\" height=\"647\" srcset=\"https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDETUT4-1.png 753w, https:\/\/endusersupports.com\/wp-content\/uploads\/2026\/05\/MDETUT4-1-300x258.png 300w\" sizes=\"(max-width: 753px) 100vw, 753px\" \/><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Configure\u00a0 Microsoft Defender Antivirus Policy\u00a0 A Microsoft Defender Antivirus policy defines how malware protection is configured and enforced across Windows devices. These policies control real\u2011time protection, cloud\u2011based detection, scanning behavior, exclusions, ransomware protection, and tamper prevention. In modern environments, Defender Antivirus policies are most effectively managed using Microsoft Intune, ensuring consistent and scalable security across [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":31030,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[19],"tags":[],"class_list":["post-30907","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-defender-for-endpoint"],"views":19,"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/endusersupports.com\/index.php\/wp-json\/wp\/v2\/posts\/30907","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/endusersupports.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/endusersupports.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/endusersupports.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/endusersupports.com\/index.php\/wp-json\/wp\/v2\/comments?post=30907"}],"version-history":[{"count":15,"href":"https:\/\/endusersupports.com\/index.php\/wp-json\/wp\/v2\/posts\/30907\/revisions"}],"predecessor-version":[{"id":31006,"href":"https:\/\/endusersupports.com\/index.php\/wp-json\/wp\/v2\/posts\/30907\/revisions\/31006"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/endusersupports.com\/index.php\/wp-json\/wp\/v2\/media\/31030"}],"wp:attachment":[{"href":"https:\/\/endusersupports.com\/index.php\/wp-json\/wp\/v2\/media?parent=30907"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/endusersupports.com\/index.php\/wp-json\/wp\/v2\/categories?post=30907"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/endusersupports.com\/index.php\/wp-json\/wp\/v2\/tags?post=30907"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}