This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Download Microsoft Edge
More info about Internet Explorer and Microsoft Edge
Microsoft Defender for Endpoint Plan 1
Microsoft Defender for Endpoint Plan 2
Microsoft Defender Antivirus
Platforms
Windows
We recommend using
Microsoft Intune
to manage Microsoft Defender Antivirus settings for your organization. However, you can use
Group Policy
to configure and manage some settings for Microsoft Defender Antivirus.
Important
If
tamper protection
is enabled in your organization, any changes made to
tamper-protected settings
are ignored. In addition, you cannot turn off tamper protection by using Group Policy.
If you must make changes to a device and those changes are blocked by tamper protection, we recommend using
troubleshooting mode
to temporarily disable tamper protection on the device. Note that after troubleshooting mode ends, any changes made to tamper-protected settings are reverted to their configured state.
In general, you can use the following procedure to configure or change some settings for Microsoft Defender Antivirus.
On your Group Policy management machine, open the
Group Policy Management Console
, right-click the Group Policy Object (GPO) you want to configure and click
Edit
.
Using the
Group Policy Management Editor
go to
Computer configuration
.
Click
Administrative templates
.
Expand the tree to
Windows components
>
Microsoft Defender Antivirus
.
Expand the section (referred to as
Location
in the table in this topic) that contains the setting you want to configure, double-click the setting to open it, and make configuration changes.
Deploy the updated GPO as you normally do
.
Group Policy settings and resources
The following table lists commonly used Group Policy settings that are available in Windows 10.
For the most current settings, see get the latest ADMX files in your central store to access the correct policy options. See
How to create and manage the Central Store for Group Policy Administrative Templates in Windows
and download the latest files.
Client interface
Enable headless UI mode
Prevent users from seeing or interacting with the Microsoft Defender Antivirus user interface
Client interface
Display additional text to clients when they need to perform an action
Configure the notifications that appear on endpoints
Client interface
Suppress all notifications
Configure the notifications that appear on endpoints
Client interface
Suppresses reboot notifications
Configure the notifications that appear on endpoints
Exclusions
Extension Exclusions
Configure and validate exclusions in Microsoft Defender Antivirus scans
Exclusions
Path Exclusions
Configure and validate exclusions in Microsoft Defender Antivirus scans
Exclusions
Process Exclusions
Configure and validate exclusions in Microsoft Defender Antivirus scans
Exclusions
Turn off Auto Exclusions
Configure and validate exclusions in Microsoft Defender Antivirus scans
Configure the "Block at First Sight" feature
Enable block at first sight
Join Microsoft MAPS
Enable cloud-delivered protection
Send file samples when further analysis is required
Enable cloud-delivered protection
Configure local setting override for reporting to Microsoft MAPS
Prevent or allow users to locally modify policy settings
MpEngine
Configure extended cloud check
Configure the cloud block timeout period
MpEngine
Select cloud protection level
Specify the cloud-delivered protection level
Network inspection system
Specify additional definition sets for network traffic inspection
Not used (deprecated)
Network inspection system
Turn on definition retirement
Not used (deprecated)
Network inspection system
Turn on protocol recognition
Not used (deprecated)
Quarantine
Configure local setting override for the removal of items from Quarantine folder
Prevent or allow users to locally modify policy settings
Quarantine
Configure removal of items from Quarantine folder
Configure remediation for Microsoft Defender Antivirus scans
Real-time protection
Configure local setting override for monitoring file and program activity on your computer
Prevent or allow users to locally modify policy settings
Real-time protection
Configure local setting override for monitoring for incoming and outgoing file activity
Prevent or allow users to locally modify policy settings
Real-time protection
Configure local setting override for scanning all downloaded files and attachments
Prevent or allow users to locally modify policy settings
Real-time protection
Configure local setting override for turn on behavior monitoring
Prevent or allow users to locally modify policy settings
Real-time protection
Configure local setting override to turn on real-time protection
Prevent or allow users to locally modify policy settings
Real-time protection
Define the maximum size of downloaded files and attachments to be scanned
Enable and configure Microsoft Defender Antivirus always-on protection and monitoring
Real-time protection
Monitor file and program activity on your computer
Enable and configure Microsoft Defender Antivirus always-on protection and monitoring
Real-time protection
Scan all downloaded files and attachments
Enable and configure Microsoft Defender Antivirus always-on protection and monitoring
Real-time protection
Turn off real-time protection
Enable and configure Microsoft Defender Antivirus always-on protection and monitoring
Real-time protection
Turn on behavior monitoring
Enable and configure Microsoft Defender Antivirus always-on protection and monitoring
Real-time protection
Turn on process scanning whenever real-time protection is enabled
Enable and configure Microsoft Defender Antivirus always-on protection and monitoring
Real-time protection
Turn on raw volume write notifications
Enable and configure Microsoft Defender Antivirus always-on protection and monitoring
Real-time protection
Configure monitoring for incoming and outgoing file and program activity
Enable and configure Microsoft Defender Antivirus always-on protection and monitoring
Remediation
Configure local setting override for the time of day to run a scheduled full scan to complete remediation
Prevent or allow users to locally modify policy settings
Remediation
Specify the day of the week to run a scheduled full scan to complete remediation
Configure scheduled Microsoft Defender Antivirus scans
Remediation
Specify the time of day to run a scheduled full scan to complete remediation
Configure scheduled Microsoft Defender Antivirus scans
Reporting
Turn off enhanced notifications
Configure the notifications that appear on endpoints
Turn off Microsoft Defender Antivirus
Not used. If you're using or planning to use a non-Microsoft antivirus product, see
Microsoft Defender Antivirus compatibility with other security products
.
Define addresses to bypass proxy server
Configure device proxy and Internet connectivity settings
Define proxy autoconfig (.pac) for connecting to the network
Configure device proxy and Internet connectivity settings
Define proxy server for connecting to the network
Configure device proxy and Internet connectivity settings
Configure local administrator merge behavior for lists
Prevent or allow users to locally modify policy settings
Allow antimalware service to start up with normal priority
Configure remediation for Microsoft Defender Antivirus scans
Allow antimalware service to remain running always
Configure remediation for Microsoft Defender Antivirus scans
Turn off routine remediation
Configure remediation for Microsoft Defender Antivirus scans
Randomize scheduled task times
Configure scheduled scans for Microsoft Defender Antivirus
Allow users to pause scan
Prevent users from seeing or interacting with the Microsoft Defender Antivirus user interface
(Not supported on Windows 10)
Check for the latest virus and spyware definitions before running a scheduled scan
Manage event-based forced updates
Define the number of days after which a catch-up scan is forced
Manage updates for endpoints that are out of date
Turn on catch up full scan
Manage updates for endpoints that are out of date
Turn on catch up quick scan
Manage updates for endpoints that are out of date
Configure local setting override for maximum percentage of CPU utilization
Prevent or allow users to locally modify policy settings
Configure local setting override for schedule scan day
Prevent or allow users to locally modify policy settings
Configure local setting override for scheduled quick scan time
Prevent or allow users to locally modify policy settings
Configure local setting override for scheduled scan time
Prevent or allow users to locally modify policy settings
Configure local setting override for the scan type to use for a scheduled scan
Prevent or allow users to locally modify policy settings
Create a system restore point
Configure remediation for Microsoft Defender Antivirus scans
Turn on removal of items from scan history folder
Configure remediation for Microsoft Defender Antivirus scans
Turn on heuristics
Enable and configure Microsoft Defender Antivirus always-on protection and monitoring
Turn on e-mail scanning
Configure scanning options in Microsoft Defender Antivirus
Turn on reparse point scanning
Configure scanning options in Microsoft Defender Antivirus
Run full scan on mapped network drives
Configure scanning options in Microsoft Defender Antivirus
Scan archive files
Configure scanning options in Microsoft Defender Antivirus
Scan network files
Configure scanning options in Microsoft Defender Antivirus
Scan packed executables
Configure scanning options in Microsoft Defender Antivirus
Scan scripts
Configure scanning options in Microsoft Defender Antivirus
Also see
Defender/AllowScriptScanning
.
Scan removable drives
Configure scanning options in Microsoft Defender Antivirus
Specify the maximum depth to scan archive files
Configure scanning options in Microsoft Defender Antivirus
Specify the maximum percentage of CPU utilization during a scan
Configure scanning options in Microsoft Defender Antivirus
Specify the maximum size of archive files to be scanned
Configure scanning options in Microsoft Defender Antivirus
Specify the day of the week to run a scheduled scan
Configure scheduled scans for Microsoft Defender Antivirus
Specify the interval to run quick scans per day
Configure scheduled scans for Microsoft Defender Antivirus
Specify the scan type to use for a scheduled scan
Configure scheduled scans for Microsoft Defender Antivirus
Specify the time for a daily quick scan
Configure scheduled scans for Microsoft Defender Antivirus
Specify the time of day to run a scheduled scan
Configure scheduled scans for Microsoft Defender Antivirus
Start the scheduled scan only when computer is on but not in use
Configure scheduled scans for Microsoft Defender Antivirus
Security intelligence updates
Allow security intelligence updates from Microsoft Update
Manage updates for mobile devices and virtual machines (VMs)
Security intelligence updates
Allow security intelligence updates when running on battery power
Manage updates for mobile devices and virtual machines (VMs)
Security intelligence updates
Allow notifications to disable definitions-based reports to Microsoft MAPS
Manage event-based forced updates
Security intelligence updates
Allow real-time security intelligence updates based on reports to Microsoft MAPS
Manage event-based forced updates
Security intelligence updates
Check for the latest virus and spyware definitions on startup
Manage event-based forced updates
Security intelligence updates
Define file shares for downloading security intelligence updates
Manage Microsoft Defender Antivirus protection and security intelligence updates
Security intelligence updates
Define the number of days after which a catch up security intelligence update is required
Manage updates for endpoints that are out of date
Security intelligence updates
Define the number of days before spyware definitions are considered out of date
Manage updates for endpoints that are out of date
Security intelligence updates
Define the number of days before virus definitions are considered out of date
Manage updates for endpoints that are out of date
Security intelligence updates
Define the order of sources for downloading security intelligence updates
Manage Microsoft Defender Antivirus protection and security intelligence updates
Security intelligence updates
Initiate security intelligence update on startup
Manage event-based forced updates
Security intelligence updates
Specify the day of the week to check for security intelligence updates
Manage when protection updates should be downloaded and applied
Security intelligence updates
Specify the interval to check for security intelligence updates
Manage when protection updates should be downloaded and applied
Security intelligence updates
Specify the time to check for security intelligence updates
Manage when protection updates should be downloaded and applied
Security intelligence updates
Turn on scan after Security intelligence update
Configure scheduled scans for Microsoft Defender Antivirus
Threats
Specify threat alert levels at which default action should not be taken when detected
Configure remediation for Microsoft Defender Antivirus scans
Threats
Specify threats upon which default action should not be taken when detected
Configure remediation for Microsoft Defender Antivirus scans
If you're looking for Antivirus related information for other platforms, see:
Set preferences for Microsoft Defender for Endpoint on macOS
Microsoft Defender for Endpoint on Mac
macOS Antivirus policy settings for Microsoft Defender Antivirus for Intune
Set preferences for Microsoft Defender for Endpoint on Linux
Microsoft Defender for Endpoint on Linux
Configure Defender for Endpoint on Android features
Configure Microsoft Defender for Endpoint on iOS features
Performance tip
Due to a variety of factors (examples listed below) Microsoft Defender Antivirus, like other antivirus software, can cause performance issues on endpoint devices. In some cases, you might need to tune the performance of Microsoft Defender Antivirus to alleviate those performance issues. Microsoft's
Performance analyzer
is a PowerShell command-line tool that helps determine which files, file paths, processes, and file extensions might be causing performance issues; some examples are:
Top paths that impact scan time
Top files that impact scan time
Top processes that impact scan time
Top file extensions that impact scan time
Combinations – for example:
top files per extension
top paths per extension
top processes per path
top scans per file
top scans per file per process
You can use the information gathered using Performance analyzer to better assess performance issues and apply remediation actions.
See:
Performance analyzer for Microsoft Defender Antivirus
.
See also
Performance analyzer for Microsoft Defender Antivirus
Reference topics for management and configuration tools
Microsoft Defender Antivirus in Windows 10