Skip to main content

📚🪟💻Compliance - System Security - Defender for Endpoint

What this policy is about 🔍

Microsoft Defender is your first line of defense against malware and threats.

This compliance policy ensures that Defender is installed, up-to-date, and actively protecting the device. An antivirus that's disabled or outdated is as useful as no antivirus at all.


How it works 🛠️

This policy checks three things:

  1. Microsoft Defender Antimalware — Is Defender installed and enabled?
  2. Security intelligence up-to-date — Are the virus definitions current?
  3. Real-time protection — Is active scanning enabled?

All three must pass for the device to be compliant.


🛠️ Compliance Settings

Platform

  • Windows 10 and later

Profile Type

  • Windows 10/11 compliance policy

System Security

SettingValue
Microsoft Defender AntimalwareRequired
Microsoft Defender Antimalware security intelligence up-to-dateRequired
Real-time protectionRequired

⚙️ Actions for Non-Compliance

ActionScheduleMessage TemplateAdditional Recipients
Mark device non-compliant0.25 Days (6 hours)(none)None selected

👥 Group Assignments

✅ Included groups:

  • All Devices

❌ Excluded groups: