Windows Defender Program Is Blocked By Group Policy

On

If you keep receiving a message This app is turned off by group policy when you are trying to access Windows Defender security application, you might be dealing with malware or virus. Determine why a program is blocked by Windows Defender SmartScreen. The problem is, it is running fine on his machine, i.e. It is not blocked by Windows Defender. Basically he don't know what to do as it is working for him. Browse other questions tagged windows security windows-10 group-policy windows-defender or ask your own question.

Policy-->

How To Turn On Windows Defender

Applies to:

You can use Group Policy to configure and manage Windows Defender Antivirus on your endpoints.

In general, you can use the following procedure to configure or change Windows Defender Antivirus group policy settings:

  1. On your Group Policy management machine, open the Group Policy Management Console, right-click the Group Policy Object (GPO) you want to configure and click Edit.

  2. In the Group Policy Management Editor go to Computer configuration.

  3. Click Administrative templates.

  4. Expand the tree to Windows components > Windows Defender Antivirus.

  5. Expand the section (referred to as Location in the table in this topic) that contains the setting you want to configure, double-click the setting to open it, and make configuration changes.

  6. Deploy the updated GPO as you normally do.

The following table in this topic lists the Group Policy settings available in Windows 10, version 1703, and provides links to the appropriate topic in this documentation library (where applicable).

LocationSettingDocumented in topic
Client interfaceEnable headless UI modePrevent users from seeing or interacting with the Windows Defender Antivirus user interface
Client interfaceDisplay additional text to clients when they need to perform an actionConfigure the notifications that appear on endpoints
Client interfaceSuppress all notificationsConfigure the notifications that appear on endpoints
Client interfaceSuppresses reboot notificationsConfigure the notifications that appear on endpoints
ExclusionsExtension ExclusionsConfigure and validate exclusions in Windows Defender Antivirus scans
ExclusionsPath ExclusionsConfigure and validate exclusions in Windows Defender Antivirus scans
ExclusionsProcess ExclusionsConfigure and validate exclusions in Windows Defender Antivirus scans
ExclusionsTurn off Auto ExclusionsConfigure and validate exclusions in Windows Defender Antivirus scans
MAPSConfigure the 'Block at First Sight' featureEnable block at first sight
MAPSJoin Microsoft MAPSEnable cloud-delivered protection
MAPSSend file samples when further analysis is requiredEnable cloud-delivered protection
MAPSConfigure local setting override for reporting to Microsoft MAPSPrevent or allow users to locally modify policy settings
MpEngineConfigure extended cloud checkConfigure the cloud block timeout period
MpEngineSelect cloud protection levelSpecify the cloud-delivered protection level
Network inspection systemSpecify additional definition sets for network traffic inspectionNot used
Network inspection systemTurn on definition retirementNot used
Network inspection systemTurn on protocol recognitionNot used
QuarantineConfigure local setting override for the removal of items from Quarantine folderPrevent or allow users to locally modify policy settings
QuarantineConfigure removal of items from Quarantine folderConfigure remediation for Windows Defender Antivirus scans
Real-time protectionConfigure local setting override for monitoring file and program activity on your computerPrevent or allow users to locally modify policy settings
Real-time protectionConfigure local setting override for monitoring for incoming and outgoing file activityPrevent or allow users to locally modify policy settings
Real-time protectionConfigure local setting override for scanning all downloaded files and attachmentsPrevent or allow users to locally modify policy settings
Real-time protectionConfigure local setting override for turn on behavior monitoringPrevent or allow users to locally modify policy settings
Real-time protectionConfigure local setting override to turn on real-time protectionPrevent or allow users to locally modify policy settings
Real-time protectionDefine the maximum size of downloaded files and attachments to be scannedEnable and configure Windows Defender Antivirus always-on protection and monitoring
Real-time protectionMonitor file and program activity on your computerEnable and configure Windows Defender Antivirus always-on protection and monitoring
Real-time protectionScan all downloaded files and attachmentsEnable and configure Windows Defender Antivirus always-on protection and monitoring
Real-time protectionTurn off real-time protectionEnable and configure Windows Defender Antivirus always-on protection and monitoring
Real-time protectionTurn on behavior monitoringEnable and configure Windows Defender Antivirus always-on protection and monitoring
Real-time protectionTurn on process scanning whenever real-time protection is enabledEnable and configure Windows Defender Antivirus always-on protection and monitoring
Real-time protectionTurn on raw volume write notificationsEnable and configure Windows Defender Antivirus always-on protection and monitoring
Real-time protectionConfigure monitoring for incoming and outgoing file and program activityEnable and configure Windows Defender Antivirus always-on protection and monitoring
RemediationConfigure local setting override for the time of day to run a scheduled full scan to complete remediationPrevent or allow users to locally modify policy settings
RemediationSpecify the day of the week to run a scheduled full scan to complete remediationConfigure scheduled Windows Defender Antivirus scans
RemediationSpecify the time of day to run a scheduled full scan to complete remediationConfigure scheduled Windows Defender Antivirus scans
ReportingConfigure Watson eventsNot used
ReportingConfigure Windows software trace preprocessor componentsNot used
ReportingConfigure WPP tracing levelNot used
ReportingConfigure time out for detections in critically failed stateNot used
ReportingConfigure time out for detections in non-critical failed stateNot used
ReportingConfigure time out for detections in recently remediated stateNot used
ReportingConfigure time out for detections requiring additional actionNot used
ReportingTurn off enhanced notificationsConfigure the notifications that appear on endpoints
RootTurn off Windows Defender AntivirusNot used (This setting must be set to Not configured to ensure any installed third-party antivirus apps work correctly)
RootDefine addresses to bypass proxy serverNot used
RootDefine proxy auto-config (.pac) for connecting to the networkNot used
RootDefine proxy server for connecting to the networkNot used
RootConfigure local administrator merge behavior for listsPrevent or allow users to locally modify policy settings
RootAllow antimalware service to startup with normal priorityConfigure remediation for Windows Defender Antivirus scans
RootAllow antimalware service to remain running alwaysConfigure remediation for Windows Defender Antivirus scans
RootTurn off routine remediationConfigure remediation for Windows Defender Antivirus scans
RootRandomize scheduled task timesConfigure scheduled scans for Windows Defender Antivirus
ScanAllow users to pause scanPrevent users from seeing or interacting with the Windows Defender Antivirus user interface
ScanCheck for the latest virus and spyware definitions before running a scheduled scanManage event-based forced updates
ScanDefine the number of days after which a catch-up scan is forcedManage updates for endpoints that are out of date
ScanTurn on catch up full scanManage updates for endpoints that are out of date
ScanTurn on catch up quick scanManage updates for endpoints that are out of date
ScanConfigure local setting override for maximum percentage of CPU utilizationPrevent or allow users to locally modify policy settings
ScanConfigure local setting override for schedule scan dayPrevent or allow users to locally modify policy settings
ScanConfigure local setting override for scheduled quick scan timePrevent or allow users to locally modify policy settings
ScanConfigure local setting override for scheduled scan timePrevent or allow users to locally modify policy settings
ScanConfigure local setting override for the scan type to use for a scheduled scanPrevent or allow users to locally modify policy settings
ScanCreate a system restore pointConfigure remediation for Windows Defender Antivirus scans
ScanTurn on removal of items from scan history folderConfigure remediation for Windows Defender Antivirus scans
ScanTurn on heuristicsEnable and configure Windows Defender Antivirus always-on protection and monitoring
ScanTurn on e-mail scanningConfigure scanning options in Windows Defender Antivirus
ScanTurn on reparse point scanningConfigure scanning options in Windows Defender Antivirus
ScanRun full scan on mapped network drivesConfigure scanning options in Windows Defender Antivirus
ScanScan archive filesConfigure scanning options in Windows Defender Antivirus
ScanScan network filesConfigure scanning options in Windows Defender Antivirus
ScanScan packed executablesConfigure scanning options in Windows Defender Antivirus
ScanScan removable drivesConfigure scanning options in Windows Defender Antivirus
ScanSpecify the maximum depth to scan archive filesConfigure scanning options in Windows Defender Antivirus
ScanSpecify the maximum percentage of CPU utilization during a scanConfigure scanning options in Windows Defender Antivirus
ScanSpecify the maximum size of archive files to be scannedConfigure scanning options in Windows Defender Antivirus
ScanSpecify the day of the week to run a scheduled scanConfigure scheduled scans for Windows Defender Antivirus
ScanSpecify the interval to run quick scans per dayConfigure scheduled scans for Windows Defender Antivirus
ScanSpecify the scan type to use for a scheduled scanConfigure scheduled scans for Windows Defender Antivirus
ScanSpecify the time for a daily quick scanConfigure scheduled scans for Windows Defender Antivirus
ScanSpecify the time of day to run a scheduled scanConfigure scheduled scans for Windows Defender Antivirus
ScanStart the scheduled scan only when computer is on but not in useConfigure scheduled scans for Windows Defender Antivirus
Security intelligence updatesAllow definition updates from Microsoft UpdateManage updates for mobile devices and virtual machines (VMs)
Security intelligence updatesAllow definition updates when running on battery powerManage updates for mobile devices and virtual machines (VMs)
Security intelligence updatesAllow notifications to disable definitions based repots to Microsoft MAPSManage event-based forced updates
Security intelligence updatesAllow real-time definition updates based on reports to Microsoft MAPSManage event-based forced updates
Security intelligence updatesCheck for the latest virus and spyware definitions on startupManage event-based forced updates
Security intelligence updatesDefine file shares for downloading definition updatesManage Windows Defender Antivirus protection and definition updates
Security intelligence updatesDefine the number of days after which a catch up definition update is requiredManage updates for endpoints that are out of date
Security intelligence updatesDefine the number of days before spyware definitions are considered out of dateManage updates for endpoints that are out of date
Security intelligence updatesDefine the number of days before virus definitions are considered out of dateManage updates for endpoints that are out of date
Security intelligence updatesDefine the order of sources for downloading definition updatesManage Windows Defender Antivirus protection and definition updates
Security intelligence updatesInitiate definition update on startupManage event-based forced updates
Security intelligence updatesSpecify the day of the week to check for definition updatesManage when protection updates should be downloaded and applied
Security intelligence updatesSpecify the interval to check for definition updatesManage when protection updates should be downloaded and applied
Security intelligence updatesSpecify the time to check for definition updatesManage when protection updates should be downloaded and applied
Security intelligence updatesTurn on scan after Security intelligence updateConfigure scheduled scans for Windows Defender Antivirus
ThreatsSpecify threat alert levels at which default action should not be taken when detectedConfigure remediation for Windows Defender Antivirus scans
ThreatsSpecify threats upon which default action should not be taken when detectedConfigure remediation for Windows Defender Antivirus scans
Windows defender is disabled by grou…

Related topics