Skip to content

Microsoft Defender Antivirus Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000279

    Group
  • Microsoft Defender AV must be configured to block the Potentially Unwanted Application (PUA) feature.

    After enabling this feature, PUA protection blocking takes effect on endpoint clients after the next signature update or computer restart. Signature updates take place daily under typical circumsta...
    Rule High Severity
  • Microsoft Defender AV must be configured to automatically take action on all detected tasks.

    This policy setting allows Microsoft Defender configuration to automatically take action on all detected threats. The action to be taken on a particular threat is determined by the combination of t...
    Rule Medium Severity
  • Microsoft Defender AV must be configured to run and scan for malware and other potentially unwanted software.

    This policy setting turns off Microsoft Defender Antivirus. If this policy setting is enabled, Microsoft Defender Antivirus does not run and computers are not scanned for malware or other potential...
    Rule High Severity
  • Microsoft Defender AV must be configured to check in real time with MAPS before content is run or accessed.

    This feature ensures the device checks in real time with the Microsoft Active Protection Service (MAPS) before allowing certain content to be run or accessed. If this feature is disabled, the check...
    Rule Medium Severity
  • Microsoft Defender AV must be configured to not allow override of monitoring for incoming and outgoing file activity.

    This policy setting configures a local override for the configuration of monitoring for incoming and outgoing file activity. This setting can only be set by Group Policy. If this setting is enabled...
    Rule Medium Severity
  • Microsoft Defender AV Group Policy settings must take priority over the local preference settings.

    This policy setting configures a local override for the configuration to turn on real-time protection. This setting can only be set by Group Policy. If this setting is enabled, the local preference...
    Rule Medium Severity
  • Microsoft Defender AV must monitor for incoming and outgoing files.

    This policy setting allows the configuration of monitoring for incoming and outgoing files without having to turn off monitoring entirely. It is recommended for use on servers that have a lot of in...
    Rule Medium Severity
  • Microsoft Defender AV must be configured to always enable real-time protection.

    This policy setting turns off real-time protection prompts for known malware detection. Microsoft Defender Antivirus alerts when malware or potentially unwanted software attempts to install itself...
    Rule Medium Severity
  • Microsoft Defender AV must be configured to process scanning when real-time protection is enabled.

    This policy setting allows the configuration of process scanning when real-time protection is turned on. This helps to catch malware, which could start when real-time protection is turned off. If t...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules