Information
This policy setting ensures that a recognized antispyware solution is active and registered with the Windows Security Center (WSC) on Windows devices. When set to require, Intune verifies that antispyware software is present and reporting an active status to WSC. Microsoft Defender Antivirus provides integrated antispyware capabilities and is recognized by this check; qualifying third-party antispyware solutions registered with WSC are also accepted.
The recommended state for this setting is: Require.
Spyware and adware represent a class of threats that may not always be classified by antivirus engines, focusing instead on credential theft, surveillance, unauthorized data collection, and persistent presence on the endpoint. Active antispyware protection adds detection coverage for these behaviors, reducing the risk of undetected information exfiltration, session hijacking, and persistent footholds established by stalkerware or commercial spyware tools. Compliance verification ensures the protective layer is active at every device check-in.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
To establish the recommended configuration from Microsoft Intune Admin Center:
- Navigate to Endpoint security > Compliance policies.
- Create or edit a Compliance policy.
- Under System Security\Device Security, set Antispyware to Require.
Impact:
Devices where antispyware is absent, stopped, or not reporting to Windows Security Center will be marked non-compliant. On modern Windows 10 and Windows 11 systems, Microsoft Defender Antivirus satisfies both the Antivirus and Antispyware compliance checks simultaneously.
Note: Third-party antispyware-only products must be registered with WSC. Solutions that do not integrate with WSC will fail this check regardless of their functional status.