1.15.2 Ensure 'Specify threat alert levels at which default action should not be taken when detected' is set to 'Enabled: Medium: 2 or 3'

Information

This policy setting configures which automatic remediation action Microsoft Defender Antivirus will take for each threat alert level detection.

Valid threat alert levels are:

- 1 = Low
- 2 = Medium
- 4 = High
- 5 = Severe

Valid remediation action values are:

- 2 = Quarantine
- 3 = Remove
- 6 = Ignore

Threat alert levels are added under 'options' for this setting. Each entry must be listed as a name value pair. The name defines a threat alert level, and the value contains the action ID for the remediation action that should be taken.

The recommended state for this setting is: Enabled with (value name) 2 and (value) 2 . Configuring this setting to Enabled with (value name) 2 and (value) 3 also conforms to the benchmark.

By default, Defender uses the action embedded in each threat's malware signature (clean, quarantine, remove, etc.). Configuring this setting ensures the same action is always taken, regardless of how Microsoft classifies a specific threat.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled with (value name) 2 and (value) 2 or Enabled with (value name) 2 and (value) 3 :

Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Antivirus\Threats\Specify threat alert levels at which default action should not be taken when detected

Note: This Group Policy section is provided by the Group Policy template WindowsDefender.admx/adml that is included with all versions of the Microsoft Windows Administrative Templates.

Impact:

If tamper protection is enabled in the environment, this setting is ignored because tamper protection enforces its own default action. In this case an exception to this recommendation will be needed.

See Also

https://workbench.cisecurity.org/benchmarks/25919

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, CSCv7|8.1

Plugin: Windows

Control ID: 975602c967d51e855d48909eec36dd48f325c39c2c873392cf96cb80abfe8554