title | description | ms.service | ms.subservice | ms.localizationpriority | author | ms.author | ms.topic | ms.custom | ms.reviewer | manager | ms.collection | search.appverid | ms.date | |||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Configure Microsoft Defender Antivirus features |
You can configure Microsoft Defender Antivirus features with Intune, Microsoft Configuration Manager, Group Policy, and PowerShell. |
defender-endpoint |
ngp |
medium |
denisebmsft |
deniseb |
conceptual |
nextgen |
yongrhee |
deniseb |
|
met150 |
02/18/2024 |
Applies to:
- Microsoft Defender for Endpoint Plan 1
- Microsoft Defender for Endpoint Plan 2
- Microsoft Defender XDR
- Microsoft Defender Antivirus
Platforms
- Windows
You can configure Microsoft Defender Antivirus with a number of tools, such as:
-
Microsoft Configuration Manager Tenant attach
-
Windows Management Instrumentation (WMI) The following broad categories of features can be configured:
-
Cloud-delivered protection. See Cloud-delivered protection and Microsoft Defender Antivirus
-
Always-on real-time protection, including behavioral, heuristic, and machine learning-based protection. See Configure behavioral, heuristic, and real-time protection.
-
How end users interact with the client on individual endpoints. See the following resources:
Tip
Review Reference topics for management and configuration tools. If you're looking for Antivirus related information for other platforms, see:
- Set preferences for Microsoft Defender for Endpoint on macOS
- Microsoft Defender for Endpoint on Mac
- macOS Antivirus policy settings for Microsoft Defender Antivirus for Intune
- Set preferences for Microsoft Defender for Endpoint on Linux
- Microsoft Defender for Endpoint on Linux
- Configure Defender for Endpoint on Android features
- Configure Microsoft Defender for Endpoint on iOS features
Tip
Performance tip Due to a variety of factors (examples listed below) Microsoft Defender Antivirus, like other antivirus software, can cause performance issues on endpoint devices. In some cases, you might need to tune the performance of Microsoft Defender Antivirus to alleviate those performance issues. Microsoft's Performance analyzer is a PowerShell command-line tool that helps determine which files, file paths, processes, and file extensions might be causing performance issues; some examples are:
- Top paths that impact scan time
- Top files that impact scan time
- Top processes that impact scan time
- Top file extensions that impact scan time
- Combinations – for example:
- top files per extension
- top paths per extension
- top processes per path
- top scans per file
- top scans per file per process
You can use the information gathered using Performance analyzer to better assess performance issues and apply remediation actions. See: Performance analyzer for Microsoft Defender Antivirus.