Configure scanning options for Microsoft Defender Antivirus - Microsoft Defender for Endpoint (2024)

  • Article

Applies to:

  • Microsoft Defender for Endpoint Plan 1
  • Microsoft Defender for Endpoint Plan 2
  • Microsoft Defender Antivirus

Platforms

  • Windows

Use Microsoft Intune to configure scanning options

For more information, see Configure device restriction settings in Microsoft Intune and Microsoft Defender Antivirus device restriction settings for Windows 10 in Intune.

Use Microsoft Configuration Manager to configure scanning options

For details on configuring Microsoft Configuration Manager (current branch), see How to create and deploy antimalware policies: Scan settings.

Use Group Policy to configure scanning options

Tip

Download the Group Policy Reference Spreadsheet, which lists the policy settings for computer and user configurations that are included in the Administrative template files delivered with for Windows. You can configure refer to the spreadsheet when you edit Group Policy Objects.

Here are the most recent versions:

  • Group Policy Settings Reference Spreadsheet for Windows 10 May 2020 Update (2004)
  • Group Policy Settings Reference Spreadsheet for Windows 11 October 2021 Update (21H2)
  1. On your Group Policy management computer, open the Group Policy Management Console.

  2. Right-click the Group Policy Object you want to configure, and then select Edit.

  3. In the Group Policy Management Editor go to Computer configuration and click Administrative templates.

  4. Expand the tree to Windows components > Microsoft Defender Antivirus, and then select a location (refer to Settings and locations in this article).

  5. Edit the policy object.

  6. Click OK, and repeat for any other settings.

Settings and locations

Policy item and locationDefault setting
(if not configured)
PowerShell Set-MpPreference parameter
or WMI property for MSFT_MpPreference class
Email scanning
Scan > Turn on e-mail scanning
See Email scanning limitations (in this article)
Disabled-DisableEmailScanning
Script scanningEnabledThis policy setting allows you to configure script scanning. If you enable or do not configure this setting, script scanning is enabled.

See Defender/AllowScriptScanning

Scan reparse points
Scan > Turn on reparse point scanning
DisabledNot available
See Reparse points
Scan mapped network drives
Scan > Run full scan on mapped network drives
Disabled-DisableScanningMappedNetworkDrivesForFullScan
Scan archive files (such as .zip or .rar files).
Scan > Scan archive files
Enabled-DisableArchiveScanning

The extensions exclusion list will take precedence over this setting.

Scan files on the network
Scan > Scan network files
Disabled-DisableScanningNetworkFiles
Scan packed executables
Scan > Scan packed executables
EnabledNot available

Scan packed executables were removed from the following templates:
- Administrative Templates (.admx) for Windows 11 2022 Update (22H2)
- Administrative Templates (.admx) for Windows 11 October 2021 Update (21H2)

Scan removable drives during full scans only
Scan > Scan removable drives
Disabled-DisableRemovableDriveScanning
Specify the level of subfolders within an archive folder to scan

Scan > Specify the maximum depth to scan archive files

0Not available
Specify the maximum CPU load (as a percentage) during a scan.

Scan > Specify the maximum percentage of CPU utilization during a scan

50-ScanAvgCPULoadFactor

The maximum CPU load is not a hard limit, but is guidance for the scanning engine to not exceed the maximum on average. Manual scans ignore this setting and run without any CPU limits.

Specify the maximum size (in kilobytes) of archive files that should be scanned.
Scan > Specify the maximum size of archive files to be scanned
No limitNot available

The default value of 0 applies no limit

Configure low CPU priority for scheduled scans
Scan > Configure low CPU priority for scheduled scans
DisabledNot available

Note

If real-time protection is turned on, files are scanned before they are accessed and executed. The scanning scope includes all files, including files on mounted removable media, such as USB drives. If the device performing the scan has real-time protection or on-access protection turned on, the scan also includes network shares.

Use PowerShell to configure scanning options

For more information on how to use PowerShell with Microsoft Defender Antivirus, see the following articles:

  • Manage Microsoft Defender Antivirus with PowerShell cmdlets
  • Microsoft Defender Antivirus cmdlets

Use WMI to configure scanning options

See Windows Defender WMIv2 APIs.

Email scanning limitations

Email scanning enables scanning of email files used by Outlook and other mail clients during on-demand and scheduled scans. Embedded objects within email (such as attachments and archived files) are also scanned. The following file format types can be scanned and remediated:

  • DBX
  • MBX
  • MIME

PST files used by Outlook 2003 or older (where the archive type is set to non-unicode) are also scanned, but Microsoft Defender Antivirus cannot remediate threats that are detected inside PST files.

If Microsoft Defender Antivirus detects a threat inside an email message, the following information is displayed to assist you in identifying the compromised email so you can remediate the threat manually:

  • Email subject
  • Attachment name

Scanning mapped network drives

On any OS, only the network drives that are mapped at system level, are scanned. User-level mapped network drives aren't scanned. User-level mapped network drives are those that a user maps in their session manually and using their own credentials.

Tip

Do you want to learn more? Engage with the Microsoft Security community in our Tech Community: Microsoft Defender for Endpoint Tech Community.

Configure scanning options for Microsoft Defender Antivirus - Microsoft Defender for Endpoint (2024)
Top Articles
Grade Retention, Help Your Child Cope with Getting Held Back
Here’s what Realtors are saying about the N.J. real estate market
Yogabella Babysitter
Chicago Neighborhoods: Lincoln Square & Ravenswood - Chicago Moms
Occupational therapist
Online Reading Resources for Students & Teachers | Raz-Kids
Ixl Elmoreco.com
biBERK Business Insurance Provides Essential Insights on Liquor Store Risk Management and Insurance Considerations
Washington Poe en Tilly Bradshaw 1 - Brandoffer, M.W. Craven | 9789024594917 | Boeken | bol
5 high school volleyball stars of the week: Sept. 17 edition
fort smith farm & garden - craigslist
Find Such That The Following Matrix Is Singular.
Pekin Soccer Tournament
Unterwegs im autonomen Freightliner Cascadia: Finger weg, jetzt fahre ich!
Ukc Message Board
SF bay area cars & trucks "chevrolet 50" - craigslist
Wsop Hunters Club
R. Kelly Net Worth 2024: The King Of R&B's Rise And Fall
UMvC3 OTT: Welcome to 2013!
Dark Entreaty Ffxiv
Prep Spotlight Tv Mn
Greensboro sit-in (1960) | History, Summary, Impact, & Facts
1145 Barnett Drive
Page 2383 – Christianity Today
Ticket To Paradise Showtimes Near Cinemark Mall Del Norte
Mynahealthcare Login
Marlene2995 Pagina Azul
Tomb Of The Mask Unblocked Games World
Ihs Hockey Systems
Emuaid Max First Aid Ointment 2 Ounce Fake Review Analysis
FREE Houses! All You Have to Do Is Move Them. - CIRCA Old Houses
Taktube Irani
Devargasfuneral
Strange World Showtimes Near Regal Edwards West Covina
Blue Beetle Movie Tickets and Showtimes Near Me | Regal
Today's Final Jeopardy Clue
Sams La Habra Gas Price
State Legislatures Icivics Answer Key
Hell's Kitchen Valley Center Photos Menu
Craigslist Boats Dallas
Dinar Detectives Cracking the Code of the Iraqi Dinar Market
Sdn Fertitta 2024
Frigidaire Fdsh450Laf Installation Manual
Citizens Bank Park - Clio
2013 Honda Odyssey Serpentine Belt Diagram
Random Animal Hybrid Generator Wheel
Aloha Kitchen Florence Menu
Meet Robert Oppenheimer, the destroyer of worlds
A Man Called Otto Showtimes Near Cinemark Greeley Mall
Costco Gas Price Fort Lauderdale
What Are Routing Numbers And How Do You Find Them? | MoneyTransfers.com
Latest Posts
Article information

Author: Msgr. Refugio Daniel

Last Updated:

Views: 6470

Rating: 4.3 / 5 (54 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: Msgr. Refugio Daniel

Birthday: 1999-09-15

Address: 8416 Beatty Center, Derekfort, VA 72092-0500

Phone: +6838967160603

Job: Mining Executive

Hobby: Woodworking, Knitting, Fishing, Coffee roasting, Kayaking, Horseback riding, Kite flying

Introduction: My name is Msgr. Refugio Daniel, I am a fine, precious, encouraging, calm, glamorous, vivacious, friendly person who loves writing and wants to share my knowledge and understanding with you.