Skip to content

Commit a5cc755

Browse files
Merge branch 'main' into v-smandalika-9664381-B3
2 parents bca859b + 1192132 commit a5cc755

File tree

71 files changed

+223
-202
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

71 files changed

+223
-202
lines changed

defender-endpoint/adv-tech-of-mdav.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,9 @@
11
---
22
title: Advanced technologies at the core of Microsoft Defender Antivirus
33
description: Microsoft Defender Antivirus engines and advanced technologies
4-
author: YongRhee-MSFT
5-
ms.author: yongrhee
4+
author: emmwalshh
5+
ms.author: ewalsh
6+
ms.reviewer: yongrhee
67
manager: deniseb
78
ms.service: defender-endpoint
89
ms.topic: overview

defender-endpoint/analyzer-feedback.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,8 +4,9 @@ description: Provide feedback on the Microsoft Defender for Endpoint client anal
44
ms.service: defender-endpoint
55
f1.keywords:
66
- NOCSH
7-
ms.author: deniseb
8-
author: denisebmsft
7+
ms.author: ewalsh
8+
author: emmwalshh
9+
ms.reviewer: yongrhee
910
ms.localizationpriority: medium
1011
manager: deniseb
1112
audience: ITPro

defender-endpoint/behavior-monitor-macos.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
---
22
title: Behavior Monitoring in Microsoft Defender Antivirus on macOS
33
description: Behavior Monitoring in Microsoft Defender Antivirus on macOS
4-
author: denisebmsft
5-
ms.author: deniseb
4+
author: emmwalshh
5+
ms.author: ewalsh
66
manager: deniseb
77
ms.service: defender-endpoint
88
ms.topic: overview

defender-endpoint/behavior-monitor.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,9 @@
11
---
22
title: Behavior monitoring in Microsoft Defender Antivirus
33
description: Learn about Behavior monitoring in Microsoft Defender Antivirus and Defender for Endpoint.
4-
author: YongRhee-MSFT
5-
ms.author: yongrhee
4+
author: emmwalshh
5+
ms.author: ewalsh
6+
ms.reviewer: yongrhee
67
manager: deniseb
78
audience: ITPro
89
ms.topic: conceptual

defender-endpoint/client-behavioral-blocking.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
---
22
title: Client behavioral blocking
33
description: Client behavioral blocking is part of behavioral blocking and containment capabilities at Microsoft Defender for Endpoint
4-
author: denisebmsft
5-
ms.author: deniseb
4+
author: emmwalshh
5+
ms.author: ewalsh
66
manager: deniseb
77
ms.reviewer: shwetaj
88
audience: ITPro

defender-endpoint/cloud-protection-microsoft-defender-antivirus.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,8 +3,8 @@ title: Cloud protection and Microsoft Defender Antivirus
33
description: Learn about cloud protection and Microsoft Defender Antivirus
44
ms.service: defender-endpoint
55
ms.localizationpriority: medium
6-
author: denisebmsft
7-
ms.author: deniseb
6+
author: emmwalshh
7+
ms.author: ewalsh
88
ms.reviewer: mkaminska
99
manager: deniseb
1010
ms.custom: nextgen

defender-endpoint/common-exclusion-mistakes-microsoft-defender-antivirus.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -3,10 +3,10 @@ title: Common mistakes to avoid when defining exclusions
33
description: Avoid common mistakes when defining exclusions for Microsoft Defender Antivirus scans.
44
ms.service: defender-endpoint
55
ms.localizationpriority: medium
6-
author: denisebmsft
7-
ms.author: deniseb
6+
author: emmwalshh
7+
ms.author: ewalsh
88
ms.custom: nextgen
9-
ms.reviewer:
9+
ms.reviewer: yongrhee
1010
manager: deniseb
1111
ms.subservice: ngp
1212
ms.topic: conceptual

defender-endpoint/configure-advanced-scan-types-microsoft-defender-antivirus.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,8 +3,8 @@ title: Configure scanning options for Microsoft Defender Antivirus
33
description: You can configure Microsoft Defender Antivirus to scan email storage files, back-up or reparse points, network files, and archived files (such as .zip files).
44
ms.service: defender-endpoint
55
ms.localizationpriority: medium
6-
author: denisebmsft
7-
ms.author: deniseb
6+
author: emmwalshh
7+
ms.author: ewalsh
88
ms.custom: nextgen
99
ms.reviewer: pahuijbr
1010
manager: deniseb

defender-endpoint/configure-block-at-first-sight-microsoft-defender-antivirus.md

Lines changed: 14 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -3,8 +3,8 @@ title: Enable block at first sight to detect malware in seconds
33
description: Turn on the block at first sight feature to detect and block malware within seconds.
44
ms.service: defender-endpoint
55
ms.localizationpriority: high
6-
author: denisebmsft
7-
ms.author: deniseb
6+
author: emmwalshh
7+
ms.author: ewalsh
88
ms.reviewer: marcmcc
99
manager: deniseb
1010
ms.custom: nextgen
@@ -32,7 +32,7 @@ search.appverid: met150
3232
This article describes an antivirus/antimalware feature known as "block at first sight", and describes how to enable block at first sight for your organization.
3333

3434
> [!TIP]
35-
> This article is intended for enterprise admins and IT Pros who manage security settings for organizations. If you are not an enterprise admin or IT Pro but you have questions about block at first sight, see the [Not an enterprise admin or IT Pro?](#not-an-enterprise-admin-or-it-pro) section.
35+
> This article is intended for enterprise admins and IT Pros who manage security settings for organizations. If you aren't an enterprise admin or IT Pro but you have questions about block at first sight, see the [Not an enterprise admin or IT Pro?](#not-an-enterprise-admin-or-it-pro) section.
3636
3737
## What is "block at first sight"?
3838

@@ -57,9 +57,9 @@ Microsoft Defender Antivirus uses multiple detection and prevention technologies
5757
5858
## A few things to know about block at first sight
5959

60-
- Block at first sight can block non-portable executable files (such as JS, VBS, or macros) and executable files, running the [latest Defender antimalware platform](microsoft-defender-antivirus-updates.md) on Windows or Windows Server.
60+
- Block at first sight can block nonportable executable files (such as JS, VBS, or macros) and executable files, running the [latest Defender antimalware platform](microsoft-defender-antivirus-updates.md) on Windows or Windows Server.
6161

62-
- Block at first sight only uses the cloud protection backend for executable files and non-portable executable files that are downloaded from the Internet, or that originate from the Internet zone. A hash value of the `.exe` file is checked via the cloud backend to determine if the file is a previously undetected file.
62+
- Block at first sight only uses the cloud protection backend for executable files and nonportable executable files that are downloaded from the Internet, or that originate from the Internet zone. A hash value of the `.exe` file is checked via the cloud backend to determine if the file is a previously undetected file.
6363

6464
- If the cloud backend is unable to make a determination, Microsoft Defender Antivirus locks the file and uploads a copy to the cloud. The cloud performs more analysis to reach a determination before it either allows the file to run or blocks it in all future encounters, depending on whether it determines the file to be malicious or not a threat.
6565

@@ -98,7 +98,7 @@ Microsoft Defender Antivirus uses multiple detection and prevention technologies
9898
3. In the MAPS section, double-click **Configure the 'Block at First Sight' feature**, and set it to **Enabled**, and then select **OK**.
9999

100100
> [!IMPORTANT]
101-
> Setting to **Always prompt (0)** will lower the protection state of the device. Setting to **Never send (2)** means block at first sight will not function.
101+
> Setting to **Always prompt (0)** lowers the protection state of the device. Setting to **Never send (2)** means block at first sight won't function.
102102
103103
4. In the MAPS section, double-click **Send file samples when further analysis is required**, and set it to **Enabled**. Under **Send file samples when further analysis is required**, select **Send all samples**, and then select **OK**.
104104

@@ -118,13 +118,13 @@ You can confirm that block at first sight is enabled on individual client device
118118

119119
> [!NOTE]
120120
>
121-
> - If the prerequisite settings are configured and deployed using Group Policy, the settings described in this section will be greyed-out and unavailable for use on individual endpoints.
122-
> - Changes made through a Group Policy Object must first be deployed to individual endpoints before the setting will be updated in Windows Settings.
121+
> - If the prerequisite settings are configured and deployed using Group Policy, the settings described in this section are greyed-out and unavailable for use on individual endpoints.
122+
> - Changes made through a Group Policy Object must first be deployed to individual endpoints before the setting gets updated in Windows Settings.
123123
124124
## Turn off block at first sight
125125

126126
> [!CAUTION]
127-
> Turning off block at first sight will lower the protection state of your device(s) and your network. We do not recommend disabling block at first sight protection permanently.
127+
> Turning off block at first sight lowers the protection state of your devices and your network. We don't recommend disabling block at first sight protection permanently.
128128
129129
### Turn off block at first sight with Microsoft Intune
130130

@@ -144,22 +144,22 @@ You can confirm that block at first sight is enabled on individual client device
144144

145145
1. On your Group Policy management computer, open the [Group Policy Management Console](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc731212(v=ws.11)), right-click the Group Policy Object you want to configure, and then select **Edit**.
146146

147-
2. Using the **Group Policy Management Editor** go to **Computer configuration** and select **Administrative templates**.
147+
2. Using the **Group Policy Management Editor**, go to **Computer configuration** and select **Administrative templates**.
148148

149149
3. Expand the tree through **Windows components** \> **Microsoft Defender Antivirus** \> **MAPS**.
150150

151151
4. Double-click **Configure the 'Block at First Sight' feature** and set the option to **Disabled**.
152152

153153
> [!NOTE]
154-
> Disabling block at first sight does not disable or alter the prerequisite group policies.
154+
> Disabling block at first sight doesn't disable or alter the prerequisite group policies.
155155
156156
## Not an enterprise admin or IT Pro?
157157

158-
If you are not an enterprise admin or an IT Pro, but you have questions about block at first sight, this section is for you. Block at first sight is a threat protection feature that detects and blocks malware within seconds. Although there isn't a specific setting called "Block at first sight," the feature is enabled when certain settings are configured on your device.
158+
If you aren't an enterprise admin or an IT Pro, but you have questions about block at first sight, this section is for you. Block at first sight is a threat protection feature that detects and blocks malware within seconds. Although there isn't a specific setting called "Block at first sight," the feature is enabled when certain settings are configured on your device.
159159

160160
### How to manage block at first sight on or off on your own device
161161

162-
If you have a personal device that is not managed by an organization, you might be wondering how to turn block at first sight on or off. You can use the Windows Security app to manage block at first sight.
162+
If you have a personal device that isn't managed by an organization, you might be wondering how to turn block at first sight on or off. You can use the Windows Security app to manage block at first sight.
163163

164164
1. On your Windows 10 or Windows 11 computer, open the Windows Security app.
165165

@@ -174,7 +174,7 @@ If you have a personal device that is not managed by an organization, you might
174174
- To disable block at first sight, turn off **Cloud-delivered protection** or **Automatic sample submission**.
175175

176176
> [!CAUTION]
177-
> Turning off block at first sight lowers the level of protection for your device. We do not recommend permanently disabling block at first sight.
177+
> Turning off block at first sight lowers the level of protection for your device. We don't recommend permanently disabling block at first sight.
178178
179179
## See also
180180

defender-endpoint/configure-cloud-block-timeout-period-microsoft-defender-antivirus.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,8 +3,8 @@ title: Configure the Microsoft Defender Antivirus cloud block timeout period
33
description: You can configure how long Microsoft Defender Antivirus will block a file from running while waiting for a cloud determination.
44
ms.service: defender-endpoint
55
ms.localizationpriority: medium
6-
author: denisebmsft
7-
ms.author: deniseb
6+
author: emmwalshh
7+
ms.author: ewalsh
88
ms.custom: nextgen
99
ms.reviewer: yongrhee
1010
manager: deniseb

0 commit comments

Comments
 (0)