Information
This policy setting configures whether Microsoft Defender Antivirus scans for malicious software and unwanted software in archive files such as .ZIP or .CAB files.
The recommended state for this setting is: Enabled.
Archive files such as .zip, .rar, .7z, and .iso are a common and effective way threat actors hide malware, bypass basic defenses, and to delay detection.
Solution
To establish the recommended configuration via GP, set the following UI path to Enabled :
Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Antivirus\Scan\Scan archive files
Note: This Group Policy path is provided by the Group Policy template WindowsDefender.admx/adml that is included with the Microsoft Windows 11 Release 24H2 Administrative Templates (or newer).
Impact:
None - this is the default behavior.