Sep 28 2020 11:27 AM - edited Sep 28 2020 04:53 PM
Hi there,
When troubleshooting, how does one tell Windows "Go check with Defender ATP headquarters and update your policy right now?". I'm looking for the equivalent of gpupdate /force to force a refresh of group policy when on-prem, but for for MDATP.
Update (sorry for not zeroing in on this): I'm thinking in terms of indicators - e.g. If I go into Settings, add a File indicator, and set it to Alert and Block. I would hope that this isn't driven solely by the logs on the back-end because the block would come in awfully late.
TIA!
Sep 28 2020 11:47 AM
Sep 28 2020 12:01 PM
@AnalystGuy If you're setting your Defender ATP configuration with Group Policy (Computer | Policies | Administrative Templates | Windows Components | Windows Components | Microsoft Defender Antivirus) then you've already said the answer, which is gpupdate /target:computer /force.
If you're using Intune, then this page might be of interest: https://oofhours.com/2019/09/28/forcing-an-mdm-sync-from-a-windows-10-client/
Sep 28 2020 04:53 PM
My apologies @Thijs Lecomte - perfectly legit question; see my updated post, above
Oct 05 2020 12:14 AM
Oct 05 2020 06:58 PM
45 mins to an hour on a couple of tests
Oct 05 2020 10:37 PM
Jul 19 2021 01:23 PM