Group Policy Management
body { font-size:68%;font-family:MS Shell Dlg; margin:0px,0px,0px,0px; border: 1px solid #666666; background:#F6F6F6; width:100%; word-break:normal; word-wrap:break-word; } .head { font-weight:bold; font-size:160%; font-family:MS Shell Dlg; width:100%; color:#6587DC; background:#E3EAF9; border:1px solid #5582D2; padding-left:8px; height:24px; } .path { margin-left: 10px; margin-top: 10px; margin-bottom:5px;width:100%; } .info { padding-left:10px;width:100%; } table { font-size:100%; width:100%; border:1px solid #999999; } th { border-bottom:1px solid #999999; text-align:left; padding-left:10px; height:24px; } td { background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; } .btn { width:100%; text-align:right; margin-top:16px; } .hdr { font-weight:bold; border:1px solid #999999; text-align:left; padding-top: 4px; padding-left:10px; height:24px; margin-bottom:-1px; width:100%; } .bdy { width:100%; height:182px; display:block; overflow:scroll; z-index:2; background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; border:1px solid #999999; } button { width:6.9em; height:2.1em; font-size:100%; font-family:MS Shell Dlg; margin-right:15px; } @media print { .bdy { display:block; overflow:visible; } button { display:none; } .head { color:#000000; background:#FFFFFF; border:1px solid #000000; } }
Setting Path:
Explanation
No explanation is available for this setting.
Supported On:
Not available
DoD Microsoft Defender Antivirus STIG Computer v2r7
Data collected on: 1/9/2026 11:17:55 AM
General
Details
Domainsecurity.local
OwnerSECURITY\Domain Admins
Created1/9/2026 7:42:02 AM
Modified1/9/2026 7:42:34 AM
User Revisions1 (AD), 1 (SYSVOL)
Computer Revisions1 (AD), 1 (SYSVOL)
Unique ID{B300F726-2E7D-46ED-8E9D-928B95C7A0DE}
GPO StatusUser settings disabled
Links
LocationEnforcedLink StatusPath
None

This list only includes links in the domain of the GPO.
Security Filtering
The settings in this GPO can only apply to the following groups, users, and computers:
Name
NT AUTHORITY\Authenticated Users
Delegation
These groups and users have the specified permission for this GPO
NameAllowed PermissionsInherited
NT AUTHORITY\Authenticated UsersRead (from Security Filtering)No
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSReadNo
NT AUTHORITY\SYSTEMEdit settings, delete, modify securityNo
SECURITY\Domain AdminsEdit settings, delete, modify securityNo
SECURITY\Enterprise AdminsEdit settings, delete, modify securityNo
Computer Configuration (Enabled)
Policies
Administrative Templates
Policy definitions (ADMX files) retrieved from the local computer.
Windows Components/Microsoft Defender Antivirus
PolicySettingComment
Configure detection for potentially unwanted applicationsEnabled
 
PolicySettingComment
Configure local administrator merge behavior for listsEnabled
Control whether or not exclusions are visible to Local AdminsEnabled
Randomize scheduled task timesEnabled
Windows Components/Microsoft Defender Antivirus/Exclusions
PolicySettingComment
Turn off Auto ExclusionsDisabled
Windows Components/Microsoft Defender Antivirus/Features
PolicySettingComment
Enable EDR in block modeEnabled
Windows Components/Microsoft Defender Antivirus/MAPS
PolicySettingComment
Configure the 'Block at First Sight' featureEnabled
Join Microsoft MAPSEnabled
Join Microsoft MAPSAdvanced MAPS
PolicySettingComment
Send file samples when further analysis is requiredEnabled
Send file samples when further analysis is required 
Windows Components/Microsoft Defender Antivirus/Microsoft Defender Exploit Guard/Attack Surface Reduction
PolicySettingComment
Configure Attack Surface Reduction rulesEnabled
Set the state for each ASR rule: 
BE9BA2D9-53EA-4CDC-84E5-9B1EEEE465501
D4F940AB-401B-4EFC-AADC-AD5F3C50688A1
3B576869-A4EC-4529-8536-B80A7769E8991
75668C1F-73B5-4CF0-BB93-3ECF5CB7CC841
D3E037E1-3EB8-44C8-A917-57927947596D1
5BEB7EFE-FD9A-4556-801D-275E5FFC04CC1
92E97FA1-2EDF-4476-BDD6-9DD0B4DDDC7B1
01443614-cd74-433a-b99e-2ecdc07bfc252
7674ba52-37eb-4a4f-a9a1-f0f9a1619a2c1
9e6c4e1f-7d60-472f-ba1a-a39ef669e4b21
b2b3f03d-6a65-4f7b-a9c7-1c7ef74a9ba41
c1db55ab-c21a-4637-bb3f-a12568109d351
d1e49aac-8f56-4280-b9ba-993a6d77406c2
e6db77e5-3df2-4cf1-b95a-636979351e5b2
26190899-1602-49e8-8b27-eb1d0a1ce8691
56a863a9-875e-4185-98a7-b882c64b5ce51
Windows Components/Microsoft Defender Antivirus/Microsoft Defender Exploit Guard/Network Protection
PolicySettingComment
Prevent users and apps from accessing dangerous websitesEnabled
 
PolicySettingComment
This settings controls whether Network Protection is allowed to be configured into block or audit mode on Windows Server.Enabled
Windows Components/Microsoft Defender Antivirus/MpEngine
PolicySettingComment
Configure extended cloud checkEnabled
Specify the extended cloud check time in seconds50
PolicySettingComment
Enable file hash computation featureEnabled
Select cloud protection levelEnabled
Select cloud blocking levelHigh blocking level
Windows Components/Microsoft Defender Antivirus/Network Inspection System
PolicySettingComment
Convert warn verdict to blockEnabled
Turn on asynchronous inspectionEnabled
Windows Components/Microsoft Defender Antivirus/Real-time Protection
PolicySettingComment
Configure real-time protection and Security Intelligence Updates during OOBEEnabled
Turn on script scanningEnabled
Windows Components/Microsoft Defender Antivirus/Reporting
PolicySettingComment
Configure whether to report Dynamic Signature dropped eventsEnabled
Windows Components/Microsoft Defender Antivirus/Scan
PolicySettingComment
Scan excluded files and directories during quick scansEnabled
 
PolicySettingComment
Scan packed executablesEnabled
Scan removable drivesEnabled
Specify the day of the week to run a scheduled scanEnabled
Specify the day of the week to run a scheduled scanEvery Day
PolicySettingComment
Turn on e-mail scanningEnabled
Turn on heuristicsEnabled
Windows Components/Microsoft Defender Antivirus/Security Intelligence Updates
PolicySettingComment
Define the number of days before spyware security intelligence is considered out of dateEnabled
Define the number of days before spyware security intelligence is considered out of date7
PolicySettingComment
Define the number of days before virus security intelligence is considered out of dateEnabled
Define the number of days before virus security intelligence is considered out of date7
PolicySettingComment
Specify the day of the week to check for security intelligence updatesEnabled
Specify the day of the week to check for security intelligence updatesEvery Day
Windows Components/Microsoft Defender Antivirus/Threats
PolicySettingComment
Specify threat alert levels at which default action should not be taken when detectedEnabled
Specify threat alert levels at which default action should not be taken when detected 
52
42
22
12
Windows Components/Windows Security/Family options
PolicySettingComment
Hide the Family options areaEnabled
User Configuration (Disabled)
No settings defined.