Information
This policy setting controls whether Microsoft Defender Antivirus exclusions are visible to local users on the system.
The recommended state for this setting is: If you enable this setting, local users will no longer be able to see the exclusion list in Windows Security App or via PowerShell.
Note: As of the publication of this Benchmark, the setting configuration state in Intune is the sentence above after
The recommended state for this setting is:
and not
Enabled
as the title states. This was done to keep title length to a minimum.
Only administrators should be able to view and manage Microsoft Defender Antivirus exclusions.
Solution
To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to If you enable this setting, local users will no longer be able to see the exclusion list in Windows Security App or via PowerShell.
Defender\Hide Exclusions From Local Users
Impact:
Local users will not be able to view Microsoft Defender Antivirus exclusions.