| DoD Microsoft Defender Antivirus STIG Computer v2r7 | |
| Data collected on: 1/9/2026 11:17:55 AM | |
| Domain | security.local |
| Owner | SECURITY\Domain Admins |
| Created | 1/9/2026 7:42:02 AM |
| Modified | 1/9/2026 7:42:34 AM |
| User Revisions | 1 (AD), 1 (SYSVOL) |
| Computer Revisions | 1 (AD), 1 (SYSVOL) |
| Unique ID | {B300F726-2E7D-46ED-8E9D-928B95C7A0DE} |
| GPO Status | User settings disabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| None | |||
| Name |
|---|
| NT AUTHORITY\Authenticated Users |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| NT AUTHORITY\Authenticated Users | Read (from Security Filtering) | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| SECURITY\Domain Admins | Edit settings, delete, modify security | No |
| SECURITY\Enterprise Admins | Edit settings, delete, modify security | No |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Configure detection for potentially unwanted applications | Enabled | |||
| Policy | Setting | Comment | ||
| Configure local administrator merge behavior for lists | Enabled | |||
| Control whether or not exclusions are visible to Local Admins | Enabled | |||
| Randomize scheduled task times | Enabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Turn off Auto Exclusions | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Enable EDR in block mode | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Configure the 'Block at First Sight' feature | Enabled | |||
| Join Microsoft MAPS | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Send file samples when further analysis is required | Enabled | |||
| ||||
| Policy | Setting | Comment | ||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Configure Attack Surface Reduction rules | Enabled | |||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Prevent users and apps from accessing dangerous websites | Enabled | |||
| Policy | Setting | Comment | ||
| This settings controls whether Network Protection is allowed to be configured into block or audit mode on Windows Server. | Enabled | |||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Configure extended cloud check | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Enable file hash computation feature | Enabled | |||
| Select cloud protection level | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Convert warn verdict to block | Enabled | |
| Turn on asynchronous inspection | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Configure real-time protection and Security Intelligence Updates during OOBE | Enabled | |
| Turn on script scanning | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Configure whether to report Dynamic Signature dropped events | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Scan excluded files and directories during quick scans | Enabled | |||
| Policy | Setting | Comment | ||
| Scan packed executables | Enabled | |||
| Scan removable drives | Enabled | |||
| Specify the day of the week to run a scheduled scan | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Turn on e-mail scanning | Enabled | |||
| Turn on heuristics | Enabled | |||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Define the number of days before spyware security intelligence is considered out of date | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Define the number of days before virus security intelligence is considered out of date | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Specify the day of the week to check for security intelligence updates | Enabled | |||
| ||||
| Policy | Setting | Comment | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Specify threat alert levels at which default action should not be taken when detected | Enabled | |||||||||||||
| ||||||||||||||
| Policy | Setting | Comment |
|---|---|---|
| Hide the Family options area | Enabled |