Defender - prevent users from switching off protection

Vítězslav Žurek 1 Reputation point
2023-05-24T11:56:07.1833333+00:00

Hello, seems like on some of our servers the Virus & threat protection and App & browser control were switched off. I didn't find eventid 1121 in security eventlog because it's too short unfortunately, so I have no clue if someone clicked in Windows Security and switched it off or how it happened.

Image

I have seen it off only on w2k22 servers but I didn't check all yet.

I was asked to see if there is a way to prevent this from happening so these controls remain ON.

Seems like there is no such settings in GPO. Is there another way?

Windows for business | Windows Server | User experience | Other
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Reza-Ameri 17,341 Reputation points Volunteer Moderator
    2023-05-24T17:00:51.17+00:00

    Yes, there is policy, if you navigate to:

    Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Antivirus

    And then select Turn off Microsoft Defender Antivirus and set it as Disabled and this disable the turn off option which mean it will be forced to be on and user couldn't turn it off.

    Have a look at:

    https://learn.microsoft.com/en-us/mem/intune/user-help/turn-on-defender-windows

    0 comments No comments

  2. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.