Share via

Exploit Protection Settings

Anonymous
2018-04-30T21:12:55+00:00

How or where can  I find a clear explanation/description of the correct at least what the default settings are for my Windows Defender Exploit Protection.  I do not know enough to know what is wrong but something is not right.  If I had a guide/roadmap of how the settings should be correctly configured for protecting my home computer it would be a great help.

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

Answer accepted by question author

Reza-Ameri 45,816 Reputation points Volunteer Moderator
2018-05-01T15:30:06+00:00

Open Windows Defender Security Center and click on App & browser control and there find Exploit protection settingsand you could change settings for Exploit protection from there.

Was this answer helpful?

3 people found this answer helpful.
0 comments No comments

Answer accepted by question author

Anonymous
2018-05-01T15:57:54+00:00

The Exploit Protection settings are preconfigured; and home users should generally just leave them alone:

The Use default configuration for each of the mitigation settings indicates our recommendation for a base level of protection for everyday usage for home users. Enterprise deployments should consider the protection required for their individual needs and may need to modify configuration away from the defaults.

https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-exploit-guard/customize-exploit-protection

https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-exploit-guard/exploit-protection-exploit-guard 

The preconfigured applications have been optimized by Microsoft – and adding customizations for other apps requires both a rationale and an understanding of the potential consequences, since haphazardly changing the default settings for an app can easily render it dysfunctional.

It’s ironic that these application mitigations are exposed in the Windows Defender Security Center interface, while the safe and simple Windows Defender configuration options are only available via the PowerShell Set-MpPreference command line:

https://docs.microsoft.com/en-us/powershell/module/defender/set-mppreference?view=win10-ps

The Set-MpPreference cmdlet now also includes the parameters for Attack Surface Reduction and Block at First Sight:

https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/windows-defender-detection-rate/09e71b77-e9d3-418f-9746-cd529235ed14

GreginMich

Was this answer helpful?

2 people found this answer helpful.
0 comments No comments

0 additional answers

Sort by: Most helpful