Windows Defender Passive mode

Handian Sudianto 6,106 Reputation points
2023-08-04T04:11:02.7466667+00:00

We need to set defender for endpoint to passive mode and on this article 'https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/microsoft-defender-antivirus-compatibility?view=o365-worldwide' we must onboarded first.

So, i have several question regarding this :

  • We need to turn off the tamper to change to passive mode? If yes, how we can disable tamper protection while the device onboarded to MDM?
  • If passive mode already enable, will all protection such as Behavior Monitor, On Access Protection, Real Time Protection will be disabled?
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. David Broggy 6,371 Reputation points MVP Volunteer Moderator
    2023-08-04T14:13:28.5633333+00:00

    Hi Handian,

    In order to disable tamper protection for a single asset, I would login to the security.microsoft.com portal > devices and disable it for that server.

    If passive mode is enabled, then AV is disabled. All of the features you mentioned depend on AV being enabled:
    User's image

    hope that helps.


  2. Akshay-MSFT 17,961 Reputation points Microsoft Employee Moderator
    2023-09-04T08:32:02.2766667+00:00

    @Handian Sudianto

    To disable passive mode on windows server:

    1. Open Registry Editor, and then navigate to Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection.
    2. Edit (or create) a DWORD entry called ForceDefenderPassiveMode, and specify the following settings:
      • Set the DWORD's value to 0.
           - Under **Base**, select **Hexadecimal**.
        
      Alternatively, you can turn on Microsoft Defender Antivirus by toggling on the Cloud-delivered protection and Real-time protection under the Virus & threat protection settings. Thanks, Akshay Kaushik
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.