Microsoft Defender Antivirus Security Technical Implementation Guide
Rules, Groups, and Values defined within the XCCDF Benchmark
-
SRG-APP-000112
Group -
SRG-APP-000278
Group -
SRG-APP-000278
Group -
Microsoft Defender AV must be configured to monitor for file and program activity.
This policy setting allows configuration of monitoring for file and program activity. If this setting is enabled or not configured, monitoring for file and program activity will be enabled. If this...Rule Medium Severity -
SRG-APP-000209
Group -
Microsoft Defender AV must be configured to scan all downloaded files and attachments.
This policy setting allows configuration of scanning for all downloaded files and attachments. If this setting is enabled or not configured, scanning for all downloaded files and attachments will b...Rule Medium Severity -
SRG-APP-000278
Group -
SRG-APP-000210
Group -
Microsoft Defender AV must be configured to enable behavior monitoring.
This policy setting allows configuration of behavior monitoring. If this setting is enabled or not configured, behavior monitoring will be enabled. If this setting is disabled, behavior monitoring ...Rule Medium Severity -
SRG-APP-000278
Group -
SRG-APP-000278
Group -
Microsoft Defender AV must be configured to scan archive files.
This policy setting allows the configuration of scans for malicious software and unwanted software in archive files such as .ZIP or .CAB files. If this setting is enabled or not configured, archive...Rule Medium Severity -
SRG-APP-000073
Group -
Microsoft Defender AV must be configured to scan removable drives.
This policy setting allows the management of whether or not to scan for malicious software and unwanted software in the contents of removable drives such as USB flash drives when running a full sca...Rule Medium Severity -
SRG-APP-000277
Group -
SRG-APP-000210
Group -
Microsoft Defender AV must be configured to turn on e-mail scanning.
This policy setting allows the configuration of e-mail scanning. When e-mail scanning is enabled, the engine will parse the mailbox and mail files according to their specific format in order to ana...Rule Medium Severity -
SRG-APP-000276
Group -
SRG-APP-000210
Group -
SRG-APP-000261
Group -
Microsoft Defender AV must be configured to check for definition updates daily.
This policy setting allows specifying the day of the week on which to check for definition updates. The check can also be configured to run every day or to never run at all. This setting can be con...Rule Medium Severity -
SRG-APP-000207
Group -
Microsoft Defender AV must be configured for automatic remediation action to be taken for threat alert level Severe.
This policy setting allows the customization of which automatic remediation action will be taken for each threat alert level. Threat alert levels should be added under the Options for this setting....Rule Medium Severity -
SRG-APP-000210
Group -
Microsoft Defender AV must be configured to block executable content from email client and webmail.
This rule blocks the following file types from being run or launched from an email seen in either Microsoft Outlook or webmail (such as Gmail.com or Outlook.com): Executable files (such as .exe, .d...Rule Medium Severity -
SRG-APP-000210
Group -
SRG-APP-000210
Group -
SRG-APP-000210
Group -
SRG-APP-000210
Group -
SRG-APP-000207
Group -
SRG-APP-000207
Group -
SRG-APP-000207
Group
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.