Proper way to exclude applications or folders from ATP protection

%3CLINGO-SUB%20id%3D%22lingo-sub-909601%22%20slang%3D%22en-US%22%3EProper%20way%20to%20exclude%20applications%20or%20folders%20from%20ATP%20protection%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-909601%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20have%20started%20to%20see%20issues%20creep%20up%20with%20MsSense.exe%20reading%20network%20files%20while%20one%20of%20our%20applications%20is%20trying%20to%20open%20the%20files%20off%20a%20network%20location.%26nbsp%3B%20In%20the%20past%20this%20hasn't%20caused%20issues%20but%20now%20we%20are%20starting%20to%20get%20file%20conflicts%20with%20both%20ATP%20and%20our%20application%20trying%20to%20access%20the%20file%20at%20the%20same%20time.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20know%20you%20can%20add%20exclusions%20to%20Windows%20Defender%20but%20as%20far%20as%20I%20can%20tell%20those%20do%20not%20apply%20to%20ATP.%26nbsp%3B%20The%20closest%20thing%20I%20have%20found%20for%20trying%20to%20exclude%20MsSense.exe%20from%20scanning%20specific%20folders%20or%26nbsp%3Bfiles%26nbsp%3Bis%20automation%20folder%20exclusions%20which%20according%20to%20the%20Microsoft%20docs%20this%20it%20can%20be%20used%20to%20exclude%20folders%20from%20the%20automated%20investigation.%26nbsp%3B%20Not%20sure%20if%20Automated%20investigation%20is%20what%20is%20being%20run%20by%26nbsp%3BMsSense.exe.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECan%20someone%20point%20me%20to%20documentation%20of%20how%20to%20exclude%20a%20folder%20or%20file(s)%20from%20being%20scanned%2Fmonitored%20by%20ATP%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-909601%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExclusions%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1798658%22%20slang%3D%22en-US%22%3ERe%3A%20Proper%20way%20to%20exclude%20applications%20or%20folders%20from%20ATP%20protection%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1798658%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F424725%22%20target%3D%22_blank%22%3E%40Dane_B%3C%2FA%3EHave%20you%20ever%20found%20a%20solution%20for%20your%20issue%3F%20I'm%20experiencing%20the%20same%20thing%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1804146%22%20slang%3D%22en-US%22%3ERe%3A%20Proper%20way%20to%20exclude%20applications%20or%20folders%20from%20ATP%20protection%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1804146%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F490127%22%20target%3D%22_blank%22%3E%40Michiel_Singor%3C%2FA%3E%26nbsp%3BNo%20we%20ended%20up%20working%20with%20MS%20support%20and%20they%20added%20a%20custom%20whitelist%20on%20the%20backend.%26nbsp%3B%20Things%20may%20have%20changed%20since%20then%20though%20I%20dont%20know.%26nbsp%3B%20I%20dont%20use%20ATP%20I%20was%20just%20doing%20research%20as%20we%20are%20a%20software%20vendor%20with%20clients%20that%20use%20it.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1804337%22%20slang%3D%22en-US%22%3ERe%3A%20Proper%20way%20to%20exclude%20applications%20or%20folders%20from%20ATP%20protection%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1804337%22%20slang%3D%22en-US%22%3EMy%20understanding%20was%20that%20exclusions%20should%20be%20managed%20by%20custom%20indicators%20or%20automation%20folder%20exclusions%2C%20but%20would%20appreciate%20if%20others%20in%20the%20community%20can%20shed%20their%20experience%20too.%3C%2FLINGO-BODY%3E
New Contributor

We have started to see issues creep up with MsSense.exe reading network files while one of our applications is trying to open the files off a network location.  In the past this hasn't caused issues but now we are starting to get file conflicts with both ATP and our application trying to access the file at the same time. 

 

I know you can add exclusions to Windows Defender but as far as I can tell those do not apply to ATP.  The closest thing I have found for trying to exclude MsSense.exe from scanning specific folders or files is automation folder exclusions which according to the Microsoft docs this it can be used to exclude folders from the automated investigation.  Not sure if Automated investigation is what is being run by MsSense.exe.

 

Can someone point me to documentation of how to exclude a folder or file(s) from being scanned/monitored by ATP?

6 Replies

@Dane_BHave you ever found a solution for your issue? I'm experiencing the same thing

@Michiel_Singor No we ended up working with MS support and they added a custom whitelist on the backend.  Things may have changed since then though I dont know.  I dont use ATP I was just doing research as we are a software vendor with clients that use it.  

My understanding was that exclusions should be managed by custom indicators or automation folder exclusions, but would appreciate if others in the community can shed their experience too.

Also curious here. The exclusions for the automated response portion does not actually seem to exclude it from scanning that folder. Custom indicators also does not seem to solve the issue for us, as our hashes are not staying the same day to day as we continue to develop items. It's great that Defender AV can actually exclude a folder, but it's becoming troublesome that EDR/ATP is still hitting heavily on those locations. Did anyone here ever find an answer?

@Bennett- We also have the same issue.  We have Microsoft Endpoint Manager with Intune, and we have a TeamCity build server where we call sysinternals handle.exe and we can clearly see that mssense.exe has an open file handle to a *.nupkg in our build pipeline, which causes MSBuild to fail.

 

Here is what I have figured out so far.  Add-MpPreference does nothing to stop this problem from happening.  The following two documentation links support that it won't stop this problem.  However, I can't find documentation explaining how to stop it!

 

https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-process-opened-f...

 

says:

 

The exclusions only apply to always-on real-time protection and monitoring. They don't apply to scheduled or on-demand scans.

Note: We don't have real-time monitoring enabled.

 

Also, see the very top IMPORTANT message on https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-extension-file-e...

Important

Microsoft Defender Antivirus exclusions don't apply to other Microsoft Defender for Endpoint capabilities, including endpoint detection and response (EDR), attack surface reduction (ASR) rules, and controlled folder access. Files that you exclude using the methods described in this article can still trigger EDR alerts and other detections. To exclude files broadly, add them to the Microsoft Defender for Endpoint custom indicators.


Separately, when I run Get-MpComputerStatus in PowerShell, the last QuickScan was two days ago, indicating that Mp is completely separate from Windows Defender ATP.

 

Separately, https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/switch-to-microsoft-defend... appears to be incorrect.  It lists SenseIR.exe as the executable for Windows Server 2019.  We're using Windows Server 2019 Datacenter Edition and the executable giving us fits is MsSense.exe.  Both are in the same directory on our version of Windows.

 

Separately, I added a pull request just now to update the documentation in one area, since for some reason dotnet.exe isn't encouraged to NOT be excluded. https://github.com/MicrosoftDocs/microsoft-365-docs/pull/5320

 

Additional Tags: WDATP, Windows Defender ATP, Advanced Threat Protection Sense

I also think this cannot be coming from ASR (Attack Surface Reduction) feature. The reason is if I remote into the machine with the problem, and run:

 

 

Get-MpPreference | Select AttackSurfaceReductionOnlyExclusions,AttackSurfaceReductionRules_Actions,AttackSurfaceReductionRules_Ids

 

The output is:

AttackSurfaceReductionOnlyExclusions AttackSurfaceReductionRules_Actions AttackSurfaceReductionRules_Ids
------------------------------------ ----------------------------------- -------------------------------