| MSFT Windows 11 24H2 - Defender Antivirus | |
| Data collected on: 9/30/2024 5:55:34 AM | |
| Domain | security.local |
| Owner | SECURITY\Domain Admins |
| Created | 12/12/2019 5:55:52 AM |
| Modified | 9/27/2024 1:08:52 PM |
| User Revisions | 1 (AD), 1 (SYSVOL) |
| Computer Revisions | 35 (AD), 35 (SYSVOL) |
| Unique ID | {048EDF92-475E-4360-A38B-025342E2D833} |
| GPO Status | User settings disabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| MSFT Clients | No | Enabled | security.local/MSFT Clients |
| SCT Windows 11 Client | No | Enabled | security.local/SCT Windows 11 Client |
| Name |
|---|
| NT AUTHORITY\Authenticated Users |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| NT AUTHORITY\Authenticated Users | Read (from Security Filtering) | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| SECURITY\Domain Admins | Edit settings, delete, modify security | No |
| SECURITY\Enterprise Admins | Edit settings, delete, modify security | No |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Configure detection for potentially unwanted applications | Enabled | |||
| Policy | Setting | Comment | ||
| Configure local administrator merge behavior for lists | Disabled | |||
| Control whether exclusions are visible to local users | Enabled | |||
| Control whether or not exclusions are visible to Local Admins | Enabled | |||
| Turn off routine remediation | Disabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Enable EDR in block mode | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Configure the 'Block at First Sight' feature | Enabled | |||
| Join Microsoft MAPS | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Send file samples when further analysis is required | Enabled | |||
| ||||
| Policy | Setting | Comment | ||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Configure Attack Surface Reduction rules | Enabled | |||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Prevent users and apps from accessing dangerous websites | Enabled | |||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Configure extended cloud check | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Select cloud protection level | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Convert warn verdict to block | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Configure monitoring for incoming and outgoing file and program activity | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Configure real-time protection and Security Intelligence Updates during OOBE | Enabled | |||
| Monitor file and program activity on your computer | Enabled | |||
| Scan all downloaded files and attachments | Enabled | |||
| Turn off real-time protection | Disabled | |||
| Turn on behavior monitoring | Enabled | |||
| Turn on process scanning whenever real-time protection is enabled | Enabled | |||
| Turn on script scanning | Enabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Configure whether to report Dynamic Signature dropped events | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Scan excluded files and directories during quick scans | Enabled | |||
| Policy | Setting | Comment | ||
| Scan packed executables | Enabled | |||
| Scan removable drives | Enabled | |||