Skip to content

No profile (default benchmark)

Rules and Groups employed by this XCCDF Profile

  • SRG-APP-000279

    Group
  • Microsoft Defender AV must be configured to automatically take action on all detected tasks.

    This policy setting allows Microsoft Defender configuration to automatically take action on all detected threats. The action to be taken on a particular threat is determined by the combination of t...
    Rule Medium Severity
  • SRG-APP-000278

    Group
  • Microsoft Defender AV must be configured to run and scan for malware and other potentially unwanted software.

    This policy setting turns off Microsoft Defender Antivirus. If this policy setting is enabled, Microsoft Defender Antivirus does not run and computers are not scanned for malware or other potential...
    Rule High Severity
  • SRG-APP-000278

    Group
  • Microsoft Defender AV must be configured to not exclude files for scanning.

    This policy setting allows disabling of scheduled and real-time scanning for files under the paths specified or for the fully qualified resources specified. Paths should be added under the Options ...
    Rule Medium Severity
  • SRG-APP-000278

    Group
  • Microsoft Defender AV must be configured to not exclude files opened by specified processes.

    This policy setting allows the disabling of scheduled and real-time scanning for any file opened by any of the specified processes. The process itself will not be excluded. To exclude the process, ...
    Rule Medium Severity
  • SRG-APP-000278

    Group
  • Microsoft Defender AV must be configured to enable the Automatic Exclusions feature.

    This setting allows an administrator to specify if Automatic Exclusions feature for Server SKUs should be turned off.
    Rule Medium Severity
  • SRG-APP-000210

    Group
  • Microsoft Defender AV must be configured to disable local setting override for reporting to Microsoft MAPS.

    This policy setting configures a local override for the configuration to join Microsoft MAPS. This setting can only be set by Group Policy. If this setting is enabled, the local preference setting ...
    Rule Medium Severity
  • SRG-APP-000278

    Group
  • Microsoft Defender AV must be configured to check in real time with MAPS before content is run or accessed.

    This feature ensures the device checks in real time with the Microsoft Active Protection Service (MAPS) before allowing certain content to be run or accessed. If this feature is disabled, the check...
    Rule Medium Severity
  • SRG-APP-000210

    Group
  • Microsoft Defender AV must be configured to join Microsoft MAPS.

    This policy setting allows joining Microsoft MAPS. Microsoft MAPS is the online community that helps in choosing how to respond to potential threats. The community also helps stop the spread of new...
    Rule Medium Severity
  • SRG-APP-000210

    Group
  • Microsoft Defender AV must be configured to only send safe samples for MAPS telemetry.

    This policy setting configures behavior of samples submission when opt-in for MAPS telemetry is set. Possible options are: (0x0) Always prompt (0x1) Send safe samples automatically (0x2) Never s...
    Rule Medium Severity
  • SRG-APP-000278

    Group
  • Microsoft Defender AV must be configured for protocol recognition for network protection.

    This policy setting allows the configuration of protocol recognition for network protection against exploits of known vulnerabilities. If this setting is enabled or not configured, protocol recogni...
    Rule Medium Severity
  • SRG-APP-000112

    Group
  • Microsoft Defender AV must be configured to not allow local override of monitoring for file and program activity.

    This policy setting configures a local override for the configuration of monitoring for file and program activity on your computer. This setting can only be set by Group Policy. If this setting is ...
    Rule Medium Severity
  • SRG-APP-000112

    Group
  • Microsoft Defender AV must be configured to not allow override of monitoring for incoming and outgoing file activity.

    This policy setting configures a local override for the configuration of monitoring for incoming and outgoing file activity. This setting can only be set by Group Policy. If this setting is enabled...
    Rule Medium Severity
  • SRG-APP-000209

    Group
  • Microsoft Defender AV must be configured to not allow override of scanning for downloaded files and attachments.

    This policy setting configures a local override for the configuration of scanning for all downloaded files and attachments. This setting can only be set by Group Policy. If this setting is enabled,...
    Rule Medium Severity
  • SRG-APP-000210

    Group
  • Microsoft Defender AV must be configured to not allow override of behavior monitoring.

    This policy setting configures a local override for the configuration of behavior monitoring. This setting can only be set by Group Policy. If this setting is enabled, the local preference setting ...
    Rule Medium Severity
  • SRG-APP-000278

    Group
  • Microsoft Defender AV Group Policy settings must take priority over the local preference settings.

    This policy setting configures a local override for the configuration to turn on real-time protection. This setting can only be set by Group Policy. If this setting is enabled, the local preference...
    Rule Medium Severity
  • SRG-APP-000278

    Group
  • Microsoft Defender AV must monitor for incoming and outgoing files.

    This policy setting allows the configuration of monitoring for incoming and outgoing files without having to turn off monitoring entirely. It is recommended for use on servers that have a lot of in...
    Rule Medium Severity
  • SRG-APP-000278

    Group
  • Microsoft Defender AV must be configured to monitor for file and program activity.

    This policy setting allows configuration of monitoring for file and program activity. If this setting is enabled or not configured, monitoring for file and program activity will be enabled. If this...
    Rule Medium Severity
  • SRG-APP-000209

    Group
  • Microsoft Defender AV must be configured to scan all downloaded files and attachments.

    This policy setting allows configuration of scanning for all downloaded files and attachments. If this setting is enabled or not configured, scanning for all downloaded files and attachments will b...
    Rule Medium Severity
  • SRG-APP-000278

    Group
  • Microsoft Defender AV must be configured to always enable real-time protection.

    This policy setting turns off real-time protection prompts for known malware detection. Microsoft Defender Antivirus alerts when malware or potentially unwanted software attempts to install itself...
    Rule Medium Severity
  • SRG-APP-000210

    Group
  • Microsoft Defender AV must be configured to enable behavior monitoring.

    This policy setting allows configuration of behavior monitoring. If this setting is enabled or not configured, behavior monitoring will be enabled. If this setting is disabled, behavior monitoring ...
    Rule Medium Severity
  • SRG-APP-000278

    Group
  • Microsoft Defender AV must be configured to process scanning when real-time protection is enabled.

    This policy setting allows the configuration of process scanning when real-time protection is turned on. This helps to catch malware, which could start when real-time protection is turned off. If t...
    Rule Medium Severity
  • SRG-APP-000278

    Group
  • Microsoft Defender AV must be configured to scan archive files.

    This policy setting allows the configuration of scans for malicious software and unwanted software in archive files such as .ZIP or .CAB files. If this setting is enabled or not configured, archive...
    Rule Medium Severity
  • SRG-APP-000073

    Group
  • Microsoft Defender AV must be configured to scan removable drives.

    This policy setting allows the management of whether or not to scan for malicious software and unwanted software in the contents of removable drives such as USB flash drives when running a full sca...
    Rule Medium Severity
  • SRG-APP-000277

    Group
  • Microsoft Defender AV must be configured to perform a weekly scheduled scan.

    This policy setting allows specifying the day of the week on which to perform a scheduled scan. The scan can also be configured to run every day or to never run at all. This setting can be configur...
    Rule Medium Severity
  • SRG-APP-000210

    Group
  • Microsoft Defender AV must be configured to turn on e-mail scanning.

    This policy setting allows the configuration of e-mail scanning. When e-mail scanning is enabled, the engine will parse the mailbox and mail files according to their specific format in order to ana...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules