Skip to content

III - Administrative Classified

Rules and Groups employed by this XCCDF Profile

  • SRG-APP-000112

    <GroupDescription></GroupDescription>
    Group
  • Microsoft Defender AV must be configured to not allow local override of monitoring for file and program activity.

    &lt;VulnDiscussion&gt;This policy setting configures a local override for the configuration of monitoring for file and program activity on your com...
    Rule Medium Severity
  • SRG-APP-000112

    <GroupDescription></GroupDescription>
    Group
  • Microsoft Defender AV must be configured to not allow override of monitoring for incoming and outgoing file activity.

    &lt;VulnDiscussion&gt;This policy setting configures a local override for the configuration of monitoring for incoming and outgoing file activity. ...
    Rule Medium Severity
  • SRG-APP-000209

    <GroupDescription></GroupDescription>
    Group
  • Microsoft Defender AV must be configured to not allow override of scanning for downloaded files and attachments.

    &lt;VulnDiscussion&gt;This policy setting configures a local override for the configuration of scanning for all downloaded files and attachments. T...
    Rule Medium Severity
  • SRG-APP-000210

    <GroupDescription></GroupDescription>
    Group
  • Microsoft Defender AV must be configured to not allow override of behavior monitoring.

    &lt;VulnDiscussion&gt;This policy setting configures a local override for the configuration of behavior monitoring. This setting can only be set by...
    Rule Medium Severity
  • SRG-APP-000278

    <GroupDescription></GroupDescription>
    Group
  • Microsoft Defender AV Group Policy settings must take priority over the local preference settings.

    &lt;VulnDiscussion&gt;This policy setting configures a local override for the configuration to turn on real-time protection. This setting can only ...
    Rule Medium Severity
  • SRG-APP-000278

    <GroupDescription></GroupDescription>
    Group
  • Microsoft Defender AV must monitor for incoming and outgoing files.

    &lt;VulnDiscussion&gt;This policy setting allows the configuration of monitoring for incoming and outgoing files without having to turn off monitor...
    Rule Medium Severity
  • SRG-APP-000278

    <GroupDescription></GroupDescription>
    Group
  • Microsoft Defender AV must be configured to monitor for file and program activity.

    &lt;VulnDiscussion&gt;This policy setting allows configuration of monitoring for file and program activity. If this setting is enabled or not confi...
    Rule Medium Severity
  • SRG-APP-000209

    <GroupDescription></GroupDescription>
    Group
  • Microsoft Defender AV must be configured to scan all downloaded files and attachments.

    &lt;VulnDiscussion&gt;This policy setting allows configuration of scanning for all downloaded files and attachments. If this setting is enabled or ...
    Rule Medium Severity
  • SRG-APP-000278

    <GroupDescription></GroupDescription>
    Group
  • Microsoft Defender AV must be configured to always enable real-time protection.

    &lt;VulnDiscussion&gt;This policy setting turns off real-time protection prompts for known malware detection. Microsoft Defender Antivirus alerts ...
    Rule Medium Severity
  • SRG-APP-000210

    <GroupDescription></GroupDescription>
    Group
  • Microsoft Defender AV must be configured to enable behavior monitoring.

    &lt;VulnDiscussion&gt;This policy setting allows configuration of behavior monitoring. If this setting is enabled or not configured, behavior monit...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules