The default period that the file is blocked is 10 seconds. If you're a security administrator, you can specify more time to wait before the file is allowed to run. Extending the cloud block timeout period can help ensure there is enough time to receive a proper determination from the Microsoft Defender Antivirus cloud service.
Prerequisites to use the extended cloud block timeout
Block at first sight and its prerequisites must be enabled before you can specify an extended timeout period.
Specify the extended timeout period using Microsoft Defender for Endpoint Security settings management
To specify the cloud block timeout period with Microsoft Defender for Endpoint Security settings management:
Select Endpoint security, and then under Manage, choose Antivirus.
Select (or create) an antivirus policy.
In the Configuration settings section, scroll down to Cloud Extended Timeout and specify the timeout, in seconds, from 0 to 50 seconds. Whatever you specify is added to the default 10 seconds.
Right-click the Group Policy Object you want to configure and then select Edit.
In the Group Policy Management Editor, go to Computer configuration, and then select Administrative templates.
Expand the tree to Windows components > Microsoft Defender Antivirus > MpEngine.
Double-click Configure extended cloud check and ensure the option is enabled.
Specify the extra amount of time to prevent the file from running while waiting for a cloud determination. Specify the extra time, in seconds, from 1 second to 50 seconds. Whatever you specify is added to the default 10 seconds.
Select OK.
Tip
If you're looking for Antivirus related information for other platforms, see:
Discover how to leverage Microsoft Defender for Cloud through the Azure portal to ensure the security of your Azure services and workloads, offering continuous threat detection and prevention.
Plan and execute an endpoint deployment strategy, using essential elements of modern management, co-management approaches, and Microsoft Intune integration.