Edit

Enable and configure Microsoft Defender Antivirus always-on protection

Always-on protection in Microsoft Defender Antivirus uses real-time protection, behavior monitoring, and heuristics to detect suspicious and malicious activity. Security administrators can use Microsoft Intune or Group Policy to configure these capabilities on Windows devices. Review the supported operating systems before you begin.

Note

Tamper protection helps keep always-on protection and other security settings from being changed. As a result, when tamper protection is enabled, any changes made to tamper-protected settings are ignored. To temporarily change tamper-protected settings for testing or diagnostics, use troubleshooting mode. After troubleshooting mode ends, the settings return to their configured values. To make permanent changes, update the policy in the management tool that configures the device.

If a file containing a threat is added to an Azure file share, the file isn't remediated immediately. Real-time protection detects the threat when a user opens the file.

Prerequisites

Supported operating systems

The following operating systems support always-on protection:

  • Windows

To use the Intune procedure, enroll Windows devices in Intune.

Configure always-on protection settings in Microsoft Intune

Microsoft Intune is the recommended tool for configuring and distributing Defender for Endpoint features to devices. However, Intune is a separate product that isn't part of Defender for Endpoint, and it isn't included in all subscriptions. To use Intune, you need a subscription that includes it, or you can buy it separately as a standalone subscription or add-on. If you don't have Intune, you can use any of the other methods in this article. For more information, see Microsoft Intune licensing.

You can configure always-on protection settings in a Microsoft Intune endpoint security antivirus policy. For more information about creating and assigning antivirus policies, see Antivirus policy for endpoint security in Intune.

To create a new policy and manage antivirus settings with Intune, see Create an endpoint security policy (opens in a new tab in the Intune documentation). When creating a new policy for Windows, choose the following options:

  • Platform: Select Windows.
  • Profile: Select Microsoft Defender Antivirus.
  • Configuration settings: In the Defender section, configure the following settings:
    • Allow Real-Time Monitoring: Select Allowed.
    • Allow On Access Protection: Select Allowed.
    • Real Time Scan Direction: Select Monitor all files (bi-directional).
    • Allow behavior monitoring: Select Allowed.

To edit an existing policy for Windows devices, see Modify existing policies (opens in a new tab in the Intune documentation):

  1. On the Summary tab of the Endpoint security | Antivirus page, select the policy.
  2. Find the Configuration settings section in the Properties section:
    • Expand Defender to see the current settings.
    • Select Edit next to Configuration settings to update the settings.
  3. Configure Allow Real-Time Monitoring, Allow On Access Protection, Real Time Scan Direction, and Allow behavior monitoring by using the values listed for a new policy.

The Microsoft Defender Antivirus profile doesn't include a separate setting for heuristics. Heuristics are part of real-time protection. For descriptions of all available Windows settings, options, defaults, recommendations, and CSP mappings, see Configure Microsoft Defender Antivirus using Microsoft Intune.

Configure always-on protection settings in Group Policy

You can use Group Policy to manage some Microsoft Defender Antivirus settings. If tamper protection is enabled in your organization, any changes made to tamper-protected settings are ignored. You can't turn off tamper protection by using Group Policy.

To temporarily change tamper-protected settings for testing or diagnostics, use troubleshooting mode. After troubleshooting mode ends, the settings return to their configured values. To make permanent changes, use a management tool that supports changes to tamper-protected settings, such as Intune.

The following procedure applies to Windows devices.

  1. In Centralized Group Policy, open the Group Policy Management Console (GPMC) on your Group Policy management computer.

  2. In the GPMC console tree, expand Group Policy Objects in the forest and domain containing the Group Policy Object (GPO) you want to edit.

  3. Right-click the GPO, and then select Edit.

  4. In the Group Policy Management Editor, go to Computer configuration > Administrative templates > Windows components > Microsoft Defender Antivirus.

  5. In the details pane of Microsoft Defender Antivirus, the folders used to configure always-on protection are:

    To open and configure a setting, use any of the following methods:

    • Double-click the setting.
    • Right-click the setting, and then select Edit.
    • Select the setting, and then select Action > Edit.

Tip

You can also configure Group Policy locally on individual devices by using the Local Group Policy Editor (gpedit.msc). Navigate to the same path: Computer configuration > Administrative templates > Windows components > Microsoft Defender Antivirus.

Configure the settings as described in the following subsections.

Configure real-time protection settings in Group Policy

If a setting described in this article isn't available in Group Policy Management Editor, update the Administrative Templates in your Group Policy Central Store. The Central Store isn't updated automatically. For instructions, see How to create and manage the Central Store for Group Policy Administrative Templates in Windows.

Configure the following policies to turn on real-time and behavior monitoring:

Policy Value
Turn off real-time protection Disabled
Configure monitoring for incoming and outgoing file and program activity Enabled, bi-directional (full on-access)
Turn on behavior monitoring Enabled
Monitor file and program activity on your computer Enabled
  1. Go to Microsoft Defender Antivirus > Real-time Protection.
  2. In the details pane of Real-time Protection, select a policy setting to view its description and supported options in the help pane. For a list of the settings and links to related guidance, see Group Policy settings and resources.
  3. Open each policy setting in the table, configure the specified value, and then select OK.

Turn on heuristics in Group Policy

Enable the heuristics policy in the Scan folder:

  1. Go to Microsoft Defender Antivirus > Scan.
  2. In the details pane of Scan, open Turn on heuristics.
  3. Select Enabled, and then select OK.

Disable real-time protection in Group Policy

Warning

Disabling real-time protection drastically reduces the protection on your endpoints and isn't recommended. If tamper protection is enabled, you can't turn off real-time protection by using Group Policy. To turn off real-time protection temporarily for testing or diagnostics, use troubleshooting mode. After troubleshooting mode ends, real-time protection returns to its configured value.

To disable real-time protection by using Group Policy:

  1. Go to Microsoft Defender Antivirus > Real-time Protection.
  2. In the details pane of Real-time Protection, open Turn off real-time protection.
  3. Select Enabled, and then select OK.

Other platforms

If you're looking for antivirus-related information for other platforms, see: