Windows Defender Antivirus Baseline and Exploit Guard
Target Scope
- Applicable Systems: Tier 2 client workstations and member servers.
- Operating Systems: Windows 10 (and above) Enterprise/Professional, Windows Server 2016 (and above).
Implementation Details
- Priority: High
- GPO Path / Registry Location:
- Computer Configuration\Administrative Templates\Windows Components\Windows Defender Antivirus
Rationale
Windows Defender Antivirus is the primary endpoint protection suite on Windows platforms. To establish a robust defense-in-depth posture against modern endpoint threat vectors, the basic protection must be augmented with Exploit Guard, Tamper Protection, SmartScreen, and process isolation.
This submodule contains individual requirement controls for each advanced protective mechanism and configuration parameter within Windows Defender Antivirus.
Legacy Impact & Compatibility
- ASR Administrative Impact: Enabling ASR rules can block legacy administrative scripts or third-party orchestration tools that rely on WMI/PSExec or execute obfuscated administrative wrappers. Extensive audit testing is recommended prior to broad enforcement.
- Office Application Rules: Rules related to Microsoft Office (e.g., blocking child processes) apply only to endpoints where productivity suites are installed. They will have no impact on member servers without Office.
- Sandbox Boot Overhead: Setting
MP_FORCE_USE_SANDBOXrequires a reboot to initialize the scanning process within the AppContainer sandbox. There is negligible performance overhead once initialized. - SmartScreen Impact: Standard users will be blocked from launching unrecognized software. Support staff must assist with authorizing internal or uncertified custom business applications.
- AMSI Provider Signatures: Any third-party antimalware software that registers itself as an AMSI provider must possess a valid, trusted Authenticode signature. Unsigned or self-signed providers will be blocked from loading.
Defender Hardening Requirements
The following Defender Antivirus configurations must be enforced:
- REQ-END-057 - Disable Real-Time Monitoring and Behavior Monitoring Override
- REQ-END-058 - Configure Potentially Unwanted Applications (PUA) Protection
- REQ-END-059 - Prevent Local List Merging and Exclusions Configuration
- REQ-END-060 - Configure Auto Exclusions Configuration
- REQ-END-061 - Prevent MAPS Local Setting Override
- REQ-END-062 - Enable EDR in Block Mode
- REQ-END-063 - Allow Network Protection on Windows Server
- REQ-END-064 - Enable File Hash Computation
- REQ-END-065 - Configure Network Inspection System (NIS) settings
- REQ-END-066 - Configure OOBE Real-Time Protection and Security Intelligence
- REQ-END-067 - Enable Dynamic Signature Dropped Event Reporting
- REQ-END-068 - Configure Quick Scan and Scanning Exclusions
- REQ-END-069 - Configure Scheduled Scan Parameters
- REQ-END-070 - Configure Security Intelligence Update Schedule
- REQ-END-071 - Configure Attack Surface Reduction Rules
- REQ-END-072 - Configure Threat Severity Default Quarantine Actions
- REQ-END-073 - Configure Family Options UI Lockdown
- REQ-END-074 - Configure Tamper Protection
- REQ-END-075 - Configure Sandbox Execution Environment
- REQ-END-076 - Configure AMSI Authenticode Signature Verification
- REQ-END-077 - Configure File Explorer SmartScreen
- REQ-END-078 - Disable OneDrive File Sync
- REQ-END-079 - Enforce Antivirus Scan on Opening Attachments
- REQ-END-203 - Configure Remote Encryption Protection Mode
Sources & Compliance References
- CIS Microsoft Windows 10 Benchmark: Section 18.9 (Windows Defender Antivirus configuration parameters)
- ANSSI Active Directory Hardening Guide: Protective controls baselines on client workstations