GPO to turn on Reputation Based Protection Windows 10

Anonymous
2020-11-03T14:25:08.757+00:00

Does anyone know which GPO setting is the one to turn this on? I've installed the May 2020 Administrative Templates but cant find it. ![37166-image.png][1] [1]: /api/attachments/37166-image.png?platform=QnA

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,766 questions
{count} votes

Accepted answer
  1. Anonymous
    2020-11-30T17:03:56.317+00:00

    Ok so I tried adding the Edge admin templates and it made no difference. I decided to spend (waste) my time finding this and after much trial and error, I found that it is in fact this: Computer > Policy > Admin > Windows Components > Windows Defender Smartscreen > Explorer > Configure Windows defender Smartscreen Turning this on, enables this setting. I will note that I had to install May and October 2020 admin templates in. May 2020 https://www.microsoft.com/en-us/download/101445 October 2020 https://www.microsoft.com/en-us/download/details.aspx?id=102157 You may have to restart the PC for this to apply - GPUPDATE /FORCE does not apply it ![43716-screenshot-2020-11-30-170204.jpg][1] [1]: /api/attachments/43716-screenshot-2020-11-30-170204.jpg?platform=QnA


8 additional answers

Sort by: Most helpful
  1. Anonymous
    2020-11-30T17:10:10.127+00:00

    I dont have the edge policies applied.

    I turned on that one option and if you flick it off/on it will stay on and grey out to not be configurable. Or, a restart would have forced it on.


  2. Anonymous
    2020-11-30T17:17:01.537+00:00

    Im on 20H2 with Version 87.0.664.47 Edge


  3. Duncan Clay 16 Reputation points
    2021-11-01T20:25:34.52+00:00

    I had a similar problem for Windows Server 2022

    I had the following GPOs set:
    Windows Components/Microsoft Defender Antivirus

    • Configure detection for potentially unwanted applications: Enabled = Block

    This is how it appears in Windows Server 2019
    145598-2019a.jpg
    145438-2019b.jpg

    And this is how it appears in Windows Server 2022
    145583-2022a.jpg
    145549-2022b.jpg
    145576-2022c.jpg

    There is a new setting introduced with Windows Server 2022 for "Block downloads".

    The GPO setting to control that is:
    Windows Components/Microsoft Edge/SmartScreen settings

    • Configure Microsoft Defender SmartScreen to block potentially unwanted apps: Enabled

    App & browser control will then show as fully turned on.

    In summary, the PUA GPO settings are as follows:

    For Windows Server 2016:
    MS Security Guide

    • Turn on Windows Defender protection against Potentially Unwanted Applications

    For Windows Server 2019:
    Windows Components/Microsoft Defender Antivirus

    • Configure detection for potentially unwanted applications: Enabled = Block

    For Windows Server 2022
    Windows Components/Microsoft Edge/SmartScreen settings

    • Configure Microsoft Defender SmartScreen to block potentially unwanted apps: Enabled
    0 comments No comments

  4. wcs1236 1 Reputation point
    2021-11-05T16:00:45.17+00:00

    Thank you for the detailed description and screenshots. Setting the MS Edge Smartscreen in GP worked for me.

    0 comments No comments