Information
This policy setting configures the behavior of samples sent to Microsoft for submission when opt-in for MAPS telemetry is set.
The recommended state for this setting is: Enabled: Send safe samples or Enabled: Send all samples.
For the Block at First Sight feature to function properly, the Send file samples when further analysis is required setting must be configured as prescribed.
Solution
To establish the recommended configuration via GP, set the following UI path to Enabled: Send safe samples or Enabled: Send all samples :
Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Antivirus\MAPS\Send file samples when further analysis is required
Note: This Group Policy path is provided by the Group Policy template WindowsDefender.admx/adml that is included with the Microsoft Windows 8.1 & Server 2012 R2 Administrative Templates (or newer).
Impact:
Submitting samples carries a small risk that sensitive information may be inadvertently included.