Windows Defender Exploit Guard should be enabled on machines - False Positive

Ron de Frates 20 Reputation points
2025-06-29T23:41:35.82+00:00

I configured my VM running Win11 Enterprise as follows, but am still getting flagged for this.

Note: I installed the Guest Configuration extension on this same server (see last screen shot).

Thanks

User's image

User's image

User's image

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

2 answers

Sort by: Most helpful
  1. Ron de Frates 20 Reputation points
    2025-07-01T22:21:13.2766667+00:00

    I was able to resolve this by enabling Controlled Folder via the Group Policy Management Editor interface. I originally used the PowerShell Command per https://learn.microsoft.com/en-us/defender-endpoint/enable-controlled-folders?WT.mc_id=Portal-Microsoft_Azure_Security:

    Set-MpPreference -EnableControlledFolderAccess Enabled

    This did not work per the documentation, so I had to set this manually as follows:

    User's image


  2. Ron de Frates 20 Reputation points
    2025-07-03T18:23:13.44+00:00

    I'm still getting "Windows Defender Exploit Guard should be enabled on machines" despite:

    1. enabling Controlled Folder
    2. Guest Configuration extension has been provisioned successfully
    3. ASR rules

    Please advise.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.