1.5.4 Ensure 'Send file samples when further analysis is required' is set to 'Enabled: Send safe samples automatically' or higher

Information

This policy setting configures the behavior of samples sent to Microsoft for submission when opt-in for MAPS telemetry is set.

The recommended state for this setting is: Enabled: Send safe samples or Enabled: Send all samples.

For the Block at First Sight feature to function properly, the Send file samples when further analysis is required setting must be configured as prescribed.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Send safe samples or Enabled: Send all samples :

Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Antivirus\MAPS\Send file samples when further analysis is required

Note: This Group Policy path is provided by the Group Policy template WindowsDefender.admx/adml that is included with the Microsoft Windows 8.1 & Server 2012 R2 Administrative Templates (or newer).

Impact:

Submitting samples carries a small risk that sensitive information may be inadvertently included.

See Also

https://workbench.cisecurity.org/benchmarks/25919

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, CSCv7|8.1

Plugin: Windows

Control ID: fc131b96de095c953423fce3d25baacbdb7471c195839cd62c90a66f51543a27