18.10.42.5.2 Ensure 'Join Microsoft MAPS' is set to 'Enabled: Advanced'

Information

This policy setting configures Microsoft Active Protection Service (MAPS). Microsoft MAPS is designed to help Microsoft continually update and improve definitions of malware, spyware and other potentially unwanted software and to help Microsoft improve Windows Defender and related technologies.

The recommended state for this setting is: Enabled: Advanced.

Note: In Windows 10 and above, Basic membership is no longer available, so setting the value to 1 Basic, or 2 Advanced, enrolls the device into Advanced membership. For more information, please visit: Turn on cloud protection in Microsoft Defender Antivirus - Microsoft Defender for Endpoint | Microsoft Learn https://learn.microsoft.com/en-us/defender-endpoint/enable-cloud-protection-microsoft-defender-antivirus#methods-to-configure-cloud-protection.

Note #2: This setting originally named Windows Defender Antivirus Cloud Protection Service and then Microsoft Defender Antivirus Cloud Protection Service before it was renamed to Microsoft MAPS.

Cloud protection works with Microsoft Defender Antivirus to provide intelligent, real-time threat detection. Microsoft strongly recommends enabling cloud protection, as several advanced security features in Microsoft Defender for Endpoint rely on it to function properly. To fully take advantage of these protections, including several ASR rules, this setting must be enabled to allow for MAPS reporting.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Advanced :

Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Antivirus\MAPS\Join Microsoft MAPS

Note: This Group Policy path is provided by the Group Policy template WindowsDefender.admx/adml that is included with the Microsoft Windows 8.1 & Server 2012 R2 Administrative Templates (or newer).

Impact:

MAPS will send detailed information about malware and potentially unwanted software, including the full path to the software, and detailed information about how the software has affected the device.

See Also

https://workbench.cisecurity.org/benchmarks/25708

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Windows

Control ID: 286b379b489d8604a4e98e2f8b8dd6eef595b93abd0be495b7e9fc038a19a266