1.18 Ensure 'Turn off routine remediation' is set to 'Disabled'

Information

This policy setting configures whether Microsoft Defender Antivirus automatically takes action on all detected threats. The action to be taken on a particular threat is determined by the combination of the policy-defined action, user-defined action, and the signature-defined action.

The recommended state for this setting is: Disabled.

If this setting is enabled, Microsoft Defender prompts the user to take action on detected threats. Allowing users to choose threat remediation actions is not considered a best practice, as it can lead to inconsistent or unsafe responses.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled :

Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Antivirus\Turn off routine remediation

Note: This Group Policy path is provided by the Group Policy template WindowsDefender.admx/adml that is included with all versions of the Microsoft Windows Administrative Templates.

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/25919

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, CSCv7|8.1

Plugin: Windows

Control ID: a5bd475cd732035ccf4d7ab62ebfb8c4d963ff9430efdbb13e849f3c8a81f02e