Information
This policy setting configures monitoring for incoming and outgoing files, without having to turn off monitoring entirely. This setting only applies to NTFS volumes. For any other file system types, full monitoring of file and program activity will be present on those volumes.
The recommended state for this setting is: Enabled: bi-directional (full on access).
Warning: When configured as recommended, the Group Policy Object (GPO) will automatically appear as Disabled after saving. This behavior is expected and indicates the setting was applied correctly.
When running an antivirus solution such as Microsoft Defender Antivirus, it is important to ensure that it is configured to monitor in real-time for suspicious activity.
Solution
To establish the recommended configuration via GP, set the following UI path to Enabled: bi-directional (full on access) :
Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Antivirus\Real-Time Protection\Configure monitoring for incoming and outgoing file and program activity
Note: This Group Policy path is provided by the Group Policy template WindowsDefender.admx/adml that is included with the Microsoft Windows 11 Release 24H2 Administrative Templates (or newer).
Impact:
None - this is the default behavior.