1.14.1 Ensure 'Specify the interval to check for security intelligence updates' is set to 'Enabled: 4' or fewer, but not '0'

Information

This policy setting configures an interval at which to check for security intelligence updates. Security intelligence updates are the continuously updated packages that Microsoft Defender Antivirus uses to recognize, classify, and block the latest malware, spyware, unwanted software, and potentially harmful behaviors.

The recommended state for this setting is: Enabled: 4 or fewer, but not 0.

Note: The time value is represented as the number of hours between update checks. Valid values range from 1 (every hour) to 24 (once per day).

A malware scan is only as effective as the threat definitions it uses. Running a scan with outdated intelligence significantly reduces detection accuracy and can create a false sense of security.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: 4 or fewer, but not 0 :

Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Antivirus\Security Intelligence Updates\Specify the interval to check for security intelligence updates

Note: This Group Policy path is provided by the Group Policy template WindowsDefender.admx/adml that is included with the Microsoft Windows 8.1 and Server 2012 R2 Administrative Templates (or newer).

Impact:

Checking for updated security intelligence can add a small amount of overhead to system.

See Also

https://workbench.cisecurity.org/benchmarks/25919

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, CSCv7|8.1

Plugin: Windows

Control ID: fffaa63a225ead724f301252195d1dd4c22a198eddd774468c417ec738ac7c4d