1.10.1 Ensure 'Configure monitoring for incoming and outgoing file and program activity' is set to 'Enabled: bi-directional (full on access)'

Information

This policy setting configures monitoring for incoming and outgoing files, without having to turn off monitoring entirely. This setting only applies to NTFS volumes. For any other file system types, full monitoring of file and program activity will be present on those volumes.

The recommended state for this setting is: Enabled: bi-directional (full on access).

Warning: When configured as recommended, the Group Policy Object (GPO) will automatically appear as Disabled after saving. This behavior is expected and indicates the setting was applied correctly.

When running an antivirus solution such as Microsoft Defender Antivirus, it is important to ensure that it is configured to monitor in real-time for suspicious activity.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: bi-directional (full on access) :

Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Antivirus\Real-Time Protection\Configure monitoring for incoming and outgoing file and program activity

Note: This Group Policy path is provided by the Group Policy template WindowsDefender.admx/adml that is included with the Microsoft Windows 11 Release 24H2 Administrative Templates (or newer).

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/25919

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, CSCv7|8.1

Plugin: Windows

Control ID: ca1b7f2d01239e68b4002b3b00b6030daa136b486c77a1a05c91cedfd7d87714