Forum Discussion
Nigel_Ward
Apr 03, 2022Copper Contributor
Microsoft Defender for Endpoint
I'm currently trying to implement MDE to replace existing EDR solution. Policies and test group have been created. MS test powershell does generate the appropriate alert. But Windows Defender A...
Nigel_Ward
Apr 03, 2022Copper Contributor
No errors here
Jonhed
Apr 04, 2022Iron Contributor
Do you have any GPO settings that disable defender antivirus?
GPO will take precedence over Intune policies.
GPO will take precedence over Intune policies.
- Nigel_WardApr 09, 2022Copper ContributorI found this did the job.
https://www.varonis.com/blog/windows-defender-turned-off-by-group-policy
Run ‘regedit’
Navigate through the tree to HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows Defender.
Delete DisableAntiSpyware in the right pane.
Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection.
Delete DisableRealtimeMonitoring in the right pane.