Tenant setup 18 β€” Defender for Endpoint configuration

πŸ“˜ Complete tenant-setup cookbook in one PDF This article is part of the series. Full series + screenshots in one document: download PDF . (PDF is currently in Czech.

πŸ“˜ Complete tenant-setup cookbook in one PDF
This article is part of the series. Full series + screenshots in one document: download PDF. (PDF is currently in Czech.)
Microsoft Defender for Endpoint β€” Plan 1 capabilities overview

Last time we covered enrolling devices into Defender for Endpoint. Today we'll get the most out of the AV without it nagging users to death. There are a lot of settings, and most of them you can't comfortably live with on default β€” let's go.

Open Intune β†’ Endpoint security β†’ Antivirus β†’ Create Policy. Platform Windows, profile Microsoft Defender Antivirus. Name it ("Less restrictive AV" or similar) and add a description.

Allow Archive Scanning β€” enables/disables AV scanning of archives like .ZIP and .CAB.
Allow Behavior Monitoring β€” enables/disables real-time behavior monitoring and blocking.
Allow Cloud Protection β€” sends/withholds findings to Microsoft.
Allow Email Scanning β€” enables/disables email scanning.
Allow Full Scan On Mapped Network Drives β€” enables/disables scanning of NAS shares.
Allow scanning of all downloaded files and attachments β€” enables/disables.
Allow Realtime Monitoring β€” enables/disables real-time threat monitoring.
Allow Scanning Network Files β€” enables/disables scanning of files reached over the network. Recommended on; for us it caused noise so we left off.
Allow Script Scanning β€” enables/disables script scanning.
Allow User UI Access β€” enables/disables the local Defender UI.
Avg CPU Load Factor β€” average CPU utilization during scans. Older HW: 20% max. Newer: 30–40%.
Cloud Block Level β€” how aggressive the cloud-side blocker is.
Disable Catchup Full/Quick Scan β€” re-run a missed scan.
Enable Low CPU Priority β€” low priority for scheduled scans.
Enable Network Protection β€” protects against phishing/malware sites. Goal: get from Audit to Block; the journey there is long.

Because there's a lot here and most of it has real impact, I'm splitting this into two parts. Next time: PUA + Threat Severity Default Action. Stay safe!