1.15.1 Ensure 'Specify threat alert levels at which default action should not be taken when detected' is set to 'Enabled'

Information

This policy setting configures which automatic remediation action Microsoft Defender Antivirus will take for each threat alert level detection.

The recommended state for this setting is: Enabled.

By default, Defender uses the action embedded in each threat's malware signature (clean, quarantine, remove, etc.). Configuring this setting ensures the same action is always taken, regardless of how Microsoft classifies a specific threat.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Antivirus\Threats\Specify threat alert levels at which default action should not be taken when detected

Note: This Group Policy section is provided by the Group Policy template WindowsDefender.admx/adml that is included with all versions of the Microsoft Windows Administrative Templates.

Impact:

If tamper protection is enabled in the environment, this setting is ignored because tamper protection enforces its own default action.

See Also

https://workbench.cisecurity.org/benchmarks/25919

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, CSCv7|8.1

Plugin: Windows

Control ID: 4dbbcbc83731c6258f9c47f513554b8ace2fe533caeb7fc9ad4d1c9de9dda4d6