22.24 (L2) Ensure 'Enable Convert Warn To Block' is set to 'Warn verdicts are converted to block'

Information

This policy setting controls whether Microsoft Defender Antivirus network protection will display a warning, or block network traffic.

The recommended state for this setting is: Warn verdicts are converted to block

Potentially suspicious network traffic should be blocked until it has been reviewed, and an exception has been granted.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Warn verdicts are converted to block

Defender\Enable Convert Warn To Block

Impact:

Legitimate network traffic could be blocked by Microsoft Defender Antivirus network protection.

See Also

https://workbench.cisecurity.org/benchmarks/21719

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, CSCv7|8.1

Plugin: Windows

Control ID: 1c7790ce39159a609ee9613f983d3385bf149f7aba4b5932cf4ed6ee66a9e267