You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
:::image type="content" source="./media/endpoint-security-policies.png" alt-text="Managing Endpoint security policies in the Microsoft Defender portal":::
54
+
:::image type="content" source="./media/endpoint-security-policies.png" alt-text="Managing Endpoint security policies in the Microsoft Defender portal" lightbox="./media/endpoint-security-policies.png":::
55
55
56
56
The following list provides a brief description of each endpoint security policy type:
57
57
@@ -109,14 +109,14 @@ To verify that you have successfully created a policy, select a policy name from
109
109
110
110
> [!NOTE]
111
111
> It can take up to 90 minutes for a policy to reach a device. To speed up the process, for devices Managed by Defender for Endpoint, you can select **Policy sync** from the actions menu so that it's applied in approximately 10 minutes.
The policy page displays details that summarize the status of the policy. You can view a policy's status, which devices it is applied to, and assigned groups.
115
116
116
117
During an investigation, you can also view the **Security policies** tab in the device page to view the list of policies that are being applied to a particular device. For more information, see [Investigating devices](investigate-machines.md#security-policies).
117
118
118
-
119
-
:::image type="content" source="./media/security-policies-list.png" alt-text="Security policies tab with list of policies":::
119
+
:::image type="content" source="./media/security-policies-list.png" alt-text="Security policies tab with list of policies" lightbox="./media/security-policies-list.png":::
120
120
121
121
## Antivirus policies for Windows and Windows Server
122
122
@@ -131,14 +131,10 @@ During an investigation, you can also view the **Security policies** tab in the
131
131
|PUA Protection|PUA Protection on|
132
132
133
133
For more information, see:
134
-
135
-
[Advanced technologies at the core of Microsoft Defender Antivirus](/defender-endpoint/adv-tech-of-mdav)
136
-
137
-
[Enable and configure Microsoft Defender Antivirus always-on protection](/defender-endpoint/configure-real-time-protection-microsoft-defender-antivirus)
138
-
139
-
[Behavior monitoring in Microsoft Defender Antivirus](/defender-endpoint/behavior-monitor)
140
-
141
-
[Detect and block potentially unwanted applications](/defender-endpoint/detect-block-potentially-unwanted-apps-microsoft-defender-antivirus)
134
+
-[Advanced technologies at the core of Microsoft Defender Antivirus](/defender-endpoint/adv-tech-of-mdav)
135
+
-[Enable and configure Microsoft Defender Antivirus always-on protection](/defender-endpoint/configure-real-time-protection-microsoft-defender-antivirus)
136
+
-[Behavior monitoring in Microsoft Defender Antivirus](/defender-endpoint/behavior-monitor)
137
+
-[Detect and block potentially unwanted applications](/defender-endpoint/detect-block-potentially-unwanted-apps-microsoft-defender-antivirus)
142
138
143
139
1.**Cloud protection features**:
144
140
@@ -165,9 +161,7 @@ Standard security intelligence updates can take hours to prepare and deliver; ou
165
161
|Archive Max Depth | Not configured|
166
162
|Archive Max Size | Not configured|
167
163
168
-
For more information, see:
169
-
170
-
[Configure Microsoft Defender Antivirus scanning options](/defender-endpoint/configure-advanced-scan-types-microsoft-defender-antivirus)
164
+
For more information, see [Configure Microsoft Defender Antivirus scanning options](/defender-endpoint/configure-advanced-scan-types-microsoft-defender-antivirus).
171
165
172
166
**Security Intelligence updates**:
173
167
@@ -187,10 +181,8 @@ For more information, see:
187
181
> 'MMPC' is Microsoft Defender security intelligence center (WDSI formerly Microsoft Malware Protection Center) https://www.microsoft.com/en-us/wdsi/definitions.
188
182
189
183
For more information, see:
190
-
191
-
[Microsoft Defender Antivirus security intelligence and product updates](/defender-endpoint/microsoft-defender-antivirus-updates)
192
-
193
-
[Update channels for security intelligence updates](/defender-endpoint/manage-gradual-rollout)
184
+
-[Microsoft Defender Antivirus security intelligence and product updates](/defender-endpoint/microsoft-defender-antivirus-updates)
185
+
-[Update channels for security intelligence updates](/defender-endpoint/manage-gradual-rollout)
194
186
195
187
**Engine updates**:
196
188
@@ -247,10 +239,8 @@ For more information, see [Manage the gradual rollout process for Microsoft Defe
247
239
> And for Windows Servers, on Saturday's at 1:00 AM. (60)
248
240
249
241
For more information, see:
250
-
251
-
[Configure scheduled quick or full Microsoft Defender Antivirus scans](/defender-endpoint/schedule-antivirus-scans)
252
-
253
-
[Microsoft Defender Antivirus full scan considerations and best practices](/defender-endpoint/mdav-scan-best-practices)
242
+
-[Configure scheduled quick or full Microsoft Defender Antivirus scans](/defender-endpoint/schedule-antivirus-scans)
243
+
-[Microsoft Defender Antivirus full scan considerations and best practices](/defender-endpoint/mdav-scan-best-practices)
254
244
255
245
**Threat severity default action**:
256
246
@@ -285,10 +275,8 @@ Disable local administrator AV settings such as exclusions, and set the policies
285
275
|Excluded Processes | Add as needed for working around false positives (FPs) and/or troubleshooting high cpu utilizations in MsMpEng.exe|
286
276
287
277
For more information, see:
288
-
289
-
[Prevent or allow users to locally modify Microsoft Defender Antivirus policy settings](/defender-endpoint/configure-local-policy-overrides-microsoft-defender-antivirus)
290
-
291
-
[Configure custom exclusions for Microsoft Defender Antivirus](/defender-endpoint/configure-exclusions-microsoft-defender-antivirus)
278
+
-[Prevent or allow users to locally modify Microsoft Defender Antivirus policy settings](/defender-endpoint/configure-local-policy-overrides-microsoft-defender-antivirus)
279
+
-[Configure custom exclusions for Microsoft Defender Antivirus](/defender-endpoint/configure-exclusions-microsoft-defender-antivirus)
292
280
293
281
**Microsoft Defender Core service:**
294
282
@@ -383,9 +371,7 @@ For more information, see [Attack surface reduction rules deployment overview](/
383
371
| -------- | -------- |
384
372
| TamperProtection (Device) | On|
385
373
386
-
For more information, see:
387
-
388
-
[Protect security settings with tamper protection](/defender-endpoint/prevent-changes-to-security-settings-with-tamper-protection)
374
+
For more information, see [Protect security settings with tamper protection](/defender-endpoint/prevent-changes-to-security-settings-with-tamper-protection).
389
375
390
376
#### Check the Cloud Protection network connectivity
391
377
@@ -398,7 +384,7 @@ cd "C:\Program Files\Windows Defender"
398
384
MpCmdRun.exe -ValidateMapsConnection
399
385
```
400
386
401
-
For more information [Use the cmdline tool to validate cloud-delivered protection](/defender-endpoint/configure-network-connections-microsoft-defender-antivirus).
387
+
For more information, see[Use the cmdline tool to validate cloud-delivered protection](/defender-endpoint/configure-network-connections-microsoft-defender-antivirus).
0 commit comments