Information
This policy setting determines how aggressive Microsoft Defender Antivirus will be in blocking and scanning suspicious files. Threat data from this feature is analyzed in real time using, machine learning models, and behavioral analysis.
Options for blocking levels are:
- Default blocking level provides strong detection without increasing the risk of detecting legitimate files.
- Moderate blocking level provides moderate only for high confidence detections
- High blocking level applies a strong level of detection while optimizing client performance (but can also give a greater chance of false positives).
- High + blocking level applies extra protection measures (might affect client performance and increase the chance of false positives).
- Zero tolerance blocking level blocks all unknown executables.
The recommended state for this setting is: Enabled: Moderate blocking level . Configuring this setting to High blocking level, High+ blocking level, or Zero tolerance blocking level also conforms to the benchmark.
Attackers routinely deploy new malware variants that can change faster than signature updates. Enabling cloud protection can close this gap with its ability to detect and block new, unknown, and fast-moving threats.
Solution
To establish the recommended configuration via GP, set the following UI path to Enabled: Moderate blocking level, High blocking level, High+ blocking level, or Zero tolerance blocking level :
Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Antivirus\MpEngine\Select cloud protection level
Note: This Group Policy path is provided by the Group Policy template WindowsDefender.admx/adml that is included with the Microsoft Windows 11 Release 24H2 Administrative Templates (or newer).
Impact:
Although higher protection levels can increase detection of new threats, it can also raise the potential for false positives.
Note: The select cloud protection level feature requires the following Group Policy setting to be configured to function.
- Join Microsoft MAPS must be enabled.