22.27 (L1) Ensure 'Hide Exclusions From Local Users' is set to 'Enabled'

Information

This policy setting controls whether Microsoft Defender Antivirus exclusions are visible to local users on the system.

The recommended state for this setting is: If you enable this setting, local users will no longer be able to see the exclusion list in Windows Security App or via PowerShell.

Note: As of the publication of this Benchmark, the setting configuration state in Intune is the sentence above after

The recommended state for this setting is:

and not

Enabled

as the title states. This was done to keep title length to a minimum.

Only administrators should be able to view and manage Microsoft Defender Antivirus exclusions.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to If you enable this setting, local users will no longer be able to see the exclusion list in Windows Security App or via PowerShell.

Defender\Hide Exclusions From Local Users

Impact:

Local users will not be able to view Microsoft Defender Antivirus exclusions.

See Also

https://workbench.cisecurity.org/benchmarks/21767

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, CSCv7|8.1

Plugin: Windows

Control ID: 57508a2b911f17dae475ec12cb3675726ec42b59e61d9e186626dcfb9f99b1e6