18.10.43.17 (L1) Ensure 'Control whether exclusions are visible to local users' is set to 'Enabled'

Information

This policy setting controls whether Microsoft Defender Antivirus exclusions are visible to local users on the system.

The recommended state for this setting is: Enabled

Only administrators should be able to view and manage Microsoft Defender Antivirus exclusions.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Antivirus\Control whether exclusions are visible to local users

Note: This Group Policy path is provided by the Group Policy template WindowsDefender.admx/adml that is included with the Microsoft Windows 11 Release 24H2 Administrative Templates (or newer).

Impact:

Local users will not be able to view Microsoft Defender Antivirus exclusions.

See Also

https://workbench.cisecurity.org/benchmarks/21994

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, CSCv7|8.1

Plugin: Windows

Control ID: f5cb9998050e539438d08b749c17de981e0746facb18118b37614130aa91e804