1.13.7 Ensure 'Specify the scan type to use for a scheduled scan' is set to 'Enabled: Quick Scan (default)' or higher

Information

This policy setting configures the scan type to use during a scheduled scan.

The recommended state for this setting is: Enabled: Quick Scan (default) . Configuring this setting to Full Scan also conforms to the benchmark.

Preforming antivirus scans helps protect systems, data, and users from a wide range of security threats.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: 1 :

Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Antivirus\Scan\Specify the scan type to use for a scheduled scan

Note: This Group Policy path is provided by the Group Policy template WindowsDefender.admx/adml that is included with all versions of the Microsoft Windows Administrative Templates.

Impact:

If Quick Scan is configured, this setting is not expected to negatively impact system performance, as quick scans are designed to be lightweight.

If Full Scan is configured, it might negatively impact the system, as a full scan comprehensively scans every file, folder, running process, and system area on the device.

See Also

https://workbench.cisecurity.org/benchmarks/25919

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, CSCv7|8.1

Plugin: Windows

Control ID: 061a4c94872ff898f0cb9468539a4862def55ad384d7ea883b313c836797c721