Forum Discussion

AnalystGuy's avatar
AnalystGuy
Copper Contributor
Sep 28, 2020

What is the Defender ATP equivalent to "gpupdate /force" (force an update of policies on a host)

Hi there,

  When troubleshooting, how does one tell Windows "Go check with Defender ATP headquarters and update your policy right now?".  I'm looking for the equivalent of gpupdate /force to force a refresh of group policy when on-prem, but for for MDATP.

 

Update (sorry for not zeroing in on this): I'm thinking in terms of indicators - e.g. If I go into Settings, add a File indicator, and set it to Alert and Block.  I would hope that this isn't driven solely by the logs on the back-end because the block would come in awfully late.

 

TIA!

7 Replies

  • Thijs Lecomte's avatar
    Thijs Lecomte
    Bronze Contributor
    What kind of policies are you talking about?
    Client policies are pushed through Intune/MEMCM/GPO and the respective command for these tools should be used.

    Otherwise, the MDATP cloud service doesn't push a lot of settings to users
      • Thijs Lecomte's avatar
        Thijs Lecomte
        Bronze Contributor
        For indicators, there isn't anyway to force it AFAIK. It periodically checks for new indicators in the MDATP portal, this shouldn't take long.

        How long of a delay are you experiencing?

Resources