Information
This policy setting configures monitoring for file and program activity.
The recommended state for this setting is: Enabled.
Attackers routinely deploy new malware variants that can change faster than signature updates. Enabling this setting ensures that file and program activity are continually monitored.
Solution
To establish the recommended configuration via GP, set the following UI path to Enabled :
Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Antivirus\Real-Time Protection\Monitor file and program activity on your computer
Note: This Group Policy path is provided by the Group Policy template WindowsDefender.admx/adml that is included with the Microsoft Windows 8.1 & Server 2012 R2 Administrative Templates (or newer).
Impact:
None - this is the default behavior.