Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
On Windows devices, tamper protection can prevent unauthorized changes to organization-managed Microsoft Defender Antivirus exclusions. Review the requirements for protecting exclusions, and use Registry Editor to verify that protection is active. For an overview of how tamper protection exclusions differ between Windows and macOS, see Tamper protection exclusions.
Requirements for protecting antivirus exclusions
Meet the following requirements:
- Microsoft Defender platform: Devices run platform version
4.18.2211.5(November 2022) or later. See Monthly platform and engine versions. DisableLocalAdminMergesetting: EnableDisableLocalAdminMergeto prevent locally configured settings from merging with organization policies. See DisableLocalAdminMerge.- Device management: Devices are managed only by Intune or only by Configuration Manager, and the Microsoft Defender for Endpoint sensor (Sense) is enabled.
- Antivirus exclusions: Exclusions are managed in Intune or Configuration Manager. See Microsoft Defender Antivirus policy settings for Windows devices. The exclusion protection feature is enabled on devices. See Verify that antivirus exclusions are tamper protected.
Note
If Configuration Manager is the only tool that manages exclusions and all requirements are met, the exclusions are tamper protected. You don't also need to deploy exclusions through Intune.
You don't need to disable tamper protection to apply new exclusion policy settings from Intune or Configuration Manager.
For more information about antivirus exclusions, see Microsoft Defender for Endpoint and Microsoft Defender Antivirus exclusions.
Verify that antivirus exclusions are tamper protected
Use Registry Editor to verify whether Microsoft Defender Antivirus exclusions are tamper protected.
Caution
Don't change the registry values. Use this procedure to view the values only.
Open Registry Editor on a Windows device.
To verify that only Intune or only Configuration Manager manages the device and that the Defender for Endpoint sensor is enabled, check the following registry values:
ManagedDefenderProductTypeinComputer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows DefenderorHKLM\SOFTWARE\Microsoft\Windows Defender.EnrollmentStatusinComputer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SenseCMorHKLM\SOFTWARE\Microsoft\SenseCM.
Use the following table to interpret the values:
ManagedDefenderProductType EnrollmentStatus Description 6Any value The device is managed only with Intune and meets the device-management requirement. 74The device is managed with Configuration Manager and meets the device-management requirement. 73The device is co-managed with Configuration Manager and Intune. This configuration isn't supported for tamper-protected exclusions. A value other than 6or7Any value The device isn't managed only with Intune or only with Configuration Manager. Exclusions aren't tamper protected. To confirm that tamper protection is deployed and exclusions are tamper protected, check the
TPExclusionsvalue inComputer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\FeaturesorHKLM\SOFTWARE\Microsoft\Windows Defender\Features.Use the following table to interpret the value:
TPExclusions Description 1The requirements are met, and exclusions are tamper protected. 0Tamper protection isn't protecting exclusions. If all requirements are met and this state seems incorrect, contact support.