Information
This policy setting configures whether to report Dynamic Signature dropped events. Dynamic Signature events are Microsoft Defender Antivirus log events that relate to cloud-delivered, on-demand threat signatures that Microsoft pushes to endpoints outside of the normal scheduled signature update cycle.
The recommended state for this setting is: Enabled.
Microsoft Defender Antivirus logs Dynamic Signature dropped events when it blocks or removes a file using a dynamically delivered signature, but the signature is not fully processed or applied and is subsequently discarded. This may indicate an issue with signature updates or with the system's ability to properly receive or handle dynamic signatures.
Solution
To establish the recommended configuration via GP, set the following UI path to Enabled :
Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Antivirus\Reporting\Configure whether to report Dynamic Signature dropped events
Note: This Group Policy path is provided by the Group Policy template WindowsDefender.admx/adml that is included with the Microsoft Windows 8.1 & Server 2012 R2 Administrative Templates (or newer).
Impact:
Enabling dynamic signature dropped events will generate additional events when this feature is enabled.