You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-endpoint/configure-advanced-scan-types-microsoft-defender-antivirus.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -3,8 +3,8 @@ title: Configure scanning options for Microsoft Defender Antivirus
3
3
description: You can configure Microsoft Defender Antivirus to scan email storage files, back-up or reparse points, network files, and archived files (such as .zip files).
Copy file name to clipboardExpand all lines: defender-endpoint/configure-block-at-first-sight-microsoft-defender-antivirus.md
+14-14Lines changed: 14 additions & 14 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -3,8 +3,8 @@ title: Enable block at first sight to detect malware in seconds
3
3
description: Turn on the block at first sight feature to detect and block malware within seconds.
4
4
ms.service: defender-endpoint
5
5
ms.localizationpriority: high
6
-
author: denisebmsft
7
-
ms.author: deniseb
6
+
author: emmwalshh
7
+
ms.author: ewalsh
8
8
ms.reviewer: marcmcc
9
9
manager: deniseb
10
10
ms.custom: nextgen
@@ -32,7 +32,7 @@ search.appverid: met150
32
32
This article describes an antivirus/antimalware feature known as "block at first sight", and describes how to enable block at first sight for your organization.
33
33
34
34
> [!TIP]
35
-
> This article is intended for enterprise admins and IT Pros who manage security settings for organizations. If you are not an enterprise admin or IT Pro but you have questions about block at first sight, see the [Not an enterprise admin or IT Pro?](#not-an-enterprise-admin-or-it-pro) section.
35
+
> This article is intended for enterprise admins and IT Pros who manage security settings for organizations. If you aren't an enterprise admin or IT Pro but you have questions about block at first sight, see the [Not an enterprise admin or IT Pro?](#not-an-enterprise-admin-or-it-pro) section.
36
36
37
37
## What is "block at first sight"?
38
38
@@ -57,9 +57,9 @@ Microsoft Defender Antivirus uses multiple detection and prevention technologies
57
57
58
58
## A few things to know about block at first sight
59
59
60
-
- Block at first sight can block non-portable executable files (such as JS, VBS, or macros) and executable files, running the [latest Defender antimalware platform](microsoft-defender-antivirus-updates.md) on Windows or Windows Server.
60
+
- Block at first sight can block nonportable executable files (such as JS, VBS, or macros) and executable files, running the [latest Defender antimalware platform](microsoft-defender-antivirus-updates.md) on Windows or Windows Server.
61
61
62
-
- Block at first sight only uses the cloud protection backend for executable files and non-portable executable files that are downloaded from the Internet, or that originate from the Internet zone. A hash value of the `.exe` file is checked via the cloud backend to determine if the file is a previously undetected file.
62
+
- Block at first sight only uses the cloud protection backend for executable files and nonportable executable files that are downloaded from the Internet, or that originate from the Internet zone. A hash value of the `.exe` file is checked via the cloud backend to determine if the file is a previously undetected file.
63
63
64
64
- If the cloud backend is unable to make a determination, Microsoft Defender Antivirus locks the file and uploads a copy to the cloud. The cloud performs more analysis to reach a determination before it either allows the file to run or blocks it in all future encounters, depending on whether it determines the file to be malicious or not a threat.
65
65
@@ -98,7 +98,7 @@ Microsoft Defender Antivirus uses multiple detection and prevention technologies
98
98
3. In the MAPS section, double-click **Configure the 'Block at First Sight' feature**, and set it to **Enabled**, and then select **OK**.
99
99
100
100
> [!IMPORTANT]
101
-
> Setting to **Always prompt (0)**will lower the protection state of the device. Setting to **Never send (2)** means block at first sight will not function.
101
+
> Setting to **Always prompt (0)**lowers the protection state of the device. Setting to **Never send (2)** means block at first sight won't function.
102
102
103
103
4. In the MAPS section, double-click **Send file samples when further analysis is required**, and set it to **Enabled**. Under **Send file samples when further analysis is required**, select **Send all samples**, and then select **OK**.
104
104
@@ -118,13 +118,13 @@ You can confirm that block at first sight is enabled on individual client device
118
118
119
119
> [!NOTE]
120
120
>
121
-
> - If the prerequisite settings are configured and deployed using Group Policy, the settings described in this section will be greyed-out and unavailable for use on individual endpoints.
122
-
> - Changes made through a Group Policy Object must first be deployed to individual endpoints before the setting will be updated in Windows Settings.
121
+
> - If the prerequisite settings are configured and deployed using Group Policy, the settings described in this section are greyed-out and unavailable for use on individual endpoints.
122
+
> - Changes made through a Group Policy Object must first be deployed to individual endpoints before the setting gets updated in Windows Settings.
123
123
124
124
## Turn off block at first sight
125
125
126
126
> [!CAUTION]
127
-
> Turning off block at first sight will lower the protection state of your device(s) and your network. We do not recommend disabling block at first sight protection permanently.
127
+
> Turning off block at first sight lowers the protection state of your devices and your network. We don't recommend disabling block at first sight protection permanently.
128
128
129
129
### Turn off block at first sight with Microsoft Intune
130
130
@@ -144,22 +144,22 @@ You can confirm that block at first sight is enabled on individual client device
144
144
145
145
1. On your Group Policy management computer, open the [Group Policy Management Console](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc731212(v=ws.11)), right-click the Group Policy Object you want to configure, and then select **Edit**.
146
146
147
-
2. Using the **Group Policy Management Editor** go to **Computer configuration** and select **Administrative templates**.
147
+
2. Using the **Group Policy Management Editor**, go to **Computer configuration** and select **Administrative templates**.
148
148
149
149
3. Expand the tree through **Windows components**\>**Microsoft Defender Antivirus**\>**MAPS**.
150
150
151
151
4. Double-click **Configure the 'Block at First Sight' feature** and set the option to **Disabled**.
152
152
153
153
> [!NOTE]
154
-
> Disabling block at first sight does not disable or alter the prerequisite group policies.
154
+
> Disabling block at first sight doesn't disable or alter the prerequisite group policies.
155
155
156
156
## Not an enterprise admin or IT Pro?
157
157
158
-
If you are not an enterprise admin or an IT Pro, but you have questions about block at first sight, this section is for you. Block at first sight is a threat protection feature that detects and blocks malware within seconds. Although there isn't a specific setting called "Block at first sight," the feature is enabled when certain settings are configured on your device.
158
+
If you aren't an enterprise admin or an IT Pro, but you have questions about block at first sight, this section is for you. Block at first sight is a threat protection feature that detects and blocks malware within seconds. Although there isn't a specific setting called "Block at first sight," the feature is enabled when certain settings are configured on your device.
159
159
160
160
### How to manage block at first sight on or off on your own device
161
161
162
-
If you have a personal device that is not managed by an organization, you might be wondering how to turn block at first sight on or off. You can use the Windows Security app to manage block at first sight.
162
+
If you have a personal device that isn't managed by an organization, you might be wondering how to turn block at first sight on or off. You can use the Windows Security app to manage block at first sight.
163
163
164
164
1. On your Windows 10 or Windows 11 computer, open the Windows Security app.
165
165
@@ -174,7 +174,7 @@ If you have a personal device that is not managed by an organization, you might
174
174
- To disable block at first sight, turn off **Cloud-delivered protection** or **Automatic sample submission**.
175
175
176
176
> [!CAUTION]
177
-
> Turning off block at first sight lowers the level of protection for your device. We do not recommend permanently disabling block at first sight.
177
+
> Turning off block at first sight lowers the level of protection for your device. We don't recommend permanently disabling block at first sight.
Copy file name to clipboardExpand all lines: defender-endpoint/configure-notifications-microsoft-defender-antivirus.md
+13-13Lines changed: 13 additions & 13 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,12 +4,12 @@ description: Learn how to configure and customize both standard and other Micros
4
4
ms.service: defender-endpoint
5
5
ms.subservice: ngp
6
6
ms.localizationpriority: medium
7
-
author: denisebmsft
7
+
author: emmwalshh
8
8
ms.topic: conceptual
9
-
ms.author: deniseb
9
+
ms.author: ewalsh
10
10
ms.custom: nextgen
11
11
ms.date: 10/18/2021
12
-
ms.reviewer:
12
+
ms.reviewer: yongrhee
13
13
manager: deniseb
14
14
ms.collection:
15
15
- m365-security
@@ -35,12 +35,12 @@ If you're part of your organization's security team, you can configure how notif
35
35
36
36
## Configure antivirus notifications using Group Policy or the Windows Security app
37
37
38
-
You can configure the display of additional notifications, such as recent threat detection summaries, in the [Windows Security app](microsoft-defender-security-center-antivirus.md) and with Group Policy.
38
+
You can configure the display of more notifications, such as recent threat detection summaries, in the [Windows Security app](microsoft-defender-security-center-antivirus.md) and with Group Policy.
39
39
40
40
> [!NOTE]
41
41
> In Windows 10, version 1607 the feature was called **Enhanced notifications** and was configured under **Windows Settings**\>**Update & security**\>**Windows Defender**. In Group Policy settings for all versions of Windows 10 and Windows 11, the notification feature is called **Enhanced notifications**.
42
42
43
-
### Use Group Policy to disable additional notifications
43
+
### Use Group Policy to disable other notifications
44
44
45
45
1. On your Group Policy management computer, open the [Group Policy Management Console](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc731212(v=ws.11)).
46
46
@@ -52,10 +52,10 @@ You can configure the display of additional notifications, such as recent threat
52
52
53
53
5. Expand the tree to **Windows components**\>**Microsoft Defender Antivirus** > **Reporting**.
54
54
55
-
6. Double-click **Turn off enhanced notifications**, and set the option to **Enabled**. Then select **OK**. This will prevent additional notifications from appearing.
55
+
6. Double-click **Turn off enhanced notifications**, and set the option to **Enabled**. Then select **OK**. This setting prevents more notifications from appearing.
56
56
57
57
> [!IMPORTANT]
58
-
> Disabling additional notifications will not disable critical notifications, such as threat detection and remediation alerts.
58
+
> Disabling other notifications won't disable critical notifications, such as threat detection and remediation alerts.
59
59
60
60
### Use the Windows Security app to disable additional notifications
61
61
@@ -65,20 +65,20 @@ You can configure the display of additional notifications, such as recent threat
65
65
66
66
3. Scroll to the **Notifications** section and select **Change notification settings**.
67
67
68
-
4. Slide the switch to **Off** or **On** to disable or enable additional notifications.
68
+
4. Slide the switch to **Off** or **On** to disable or enable other notifications.
69
69
70
70
> [!IMPORTANT]
71
-
> Disabling additional notifications will not disable critical notifications, such as threat detection and remediation alerts.
71
+
> Disabling other notifications won't disable critical notifications, such as threat detection and remediation alerts.
72
72
73
73
## Configure standard notifications on endpoints using Group Policy
74
74
75
75
You can use Group Policy to:
76
76
77
-
- Display additional, customized text on endpoints when the user needs to perform an action
77
+
- Display more, customized text on endpoints when the user needs to perform an action
78
78
- Hide all notifications on endpoints
79
79
- Hide reboot notifications on endpoints
80
80
81
-
Hiding notifications can be useful in situations where you can't hide the entire Microsoft Defender Antivirus interface. See [Prevent users from seeing or interacting with the Microsoft Defender Antivirus user interface](prevent-end-user-interaction-microsoft-defender-antivirus.md) for more information. Hiding notifications will only occur on endpoints to which the policy has been deployed. Notifications related to actions that must be taken (such as a reboot) will still appear on the [Microsoft Configuration Manager Endpoint Protection monitoring dashboard and reports](/configmgr/protect/deploy-use/monitor-endpoint-protection).
81
+
Hiding notifications can be useful in situations where you can't hide the entire Microsoft Defender Antivirus interface. See [Prevent users from seeing or interacting with the Microsoft Defender Antivirus user interface](prevent-end-user-interaction-microsoft-defender-antivirus.md) for more information. Hiding notifications will only occur on endpoints to which the policy is deployed. Notifications related to actions that must be taken (such as a reboot) will still appear on the [Microsoft Configuration Manager Endpoint Protection monitoring dashboard and reports](/configmgr/protect/deploy-use/monitor-endpoint-protection).
82
82
83
83
To add custom contact information to endpoint notifications, see [Customize the Windows Security app for your organization](/windows/security/threat-protection/windows-defender-security-center/windows-defender-security-center).
84
84
@@ -94,7 +94,7 @@ To add custom contact information to endpoint notifications, see [Customize the
94
94
95
95
5. Double-click **Suppress all notifications** and set the option to **Enabled**.
96
96
97
-
6. Select **OK**. This will prevent additional notifications from appearing.
97
+
6. Select **OK**. This setting prevents more notifications from appearing.
98
98
99
99
### Use Group Policy to hide reboot notifications
100
100
@@ -110,7 +110,7 @@ To add custom contact information to endpoint notifications, see [Customize the
110
110
111
111
5. Double-click **Suppresses reboot notifications** and set the option to **Enabled**.
112
112
113
-
5. Select **OK**. This will prevent additional notifications from appearing.
113
+
5. Select **OK**. This setting prevents more notifications from appearing.
114
114
115
115
> [!TIP]
116
116
> If you're looking for Antivirus related information for other platforms, see:
0 commit comments