| author | limwainstein |
|---|---|
| ms.author | lwainstein |
| ms.date | 02/24/2026 |
| ms.topic | include |
| ms.service | defender-endpoint |
Select the tab for information about exclusions for that operating system.
The specific exclusions to configure depend on which version of Windows your endpoints or devices are running, and are listed in the following table.
| OS | Exclusions |
|---|---|
| Windows 11 Windows 10, version 1803 or later (See Windows 10 release information) Windows 10, version 1703 or 1709 with KB4493441 installed Windows Server 2025 Azure Stack HCI OS, version 23H2 and later Windows Server 2022 Windows Server 2019 Windows Server, version 1803 Windows Server 2016 running the modern unified solution Windows Server 2012 R2 running the modern unified solution |
EDR exclusions: C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exeC:\Program Files\Windows Defender Advanced Threat Protection\SenseCncProxy.exeC:\Program Files\Windows Defender Advanced Threat Protection\SenseSampleUploader.exeC:\Program Files\Windows Defender Advanced Threat Protection\SenseIR.exeC:\Program Files\Windows Defender Advanced Threat Protection\SenseCM.exeC:\Program Files\Windows Defender Advanced Threat Protection\SenseNdr.exeC:\Program Files\Windows Defender Advanced Threat Protection\Classification\SenseCE.exeC:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\DataCollectionC:\Program Files\Windows Defender Advanced Threat Protection\SenseTVM.exeC:\Program Files\Windows Defender Advanced Threat Protection\SenseTracer.exeC:\Program Files\Windows Defender Advanced Threat Protection\SenseDlpProcessor.exe Registry path: HKLM\SOFTWARE\Microsoft\Windows Advanced Threat Protection\* Antivirus exclusions: C:\Program Files\Windows Defender\MsMpEng.exeC:\Program Files\Windows Defender\NisSrv.exeC:\Program Files\Windows Defender\ConfigSecurityPolicy.exeC:\Program Files\Windows Defender\MpCmdRun.exeC:\Program Files\Windows Defender\MpDefenderCoreService.exeC:\ProgramData\Microsoft\Windows Defender\Platform\4.18.*\MsMpEng.exeC:\ProgramData\Microsoft\Windows Defender\Platform\4.18.*\NisSrv.exeC:\ProgramData\Microsoft\Windows Defender\Platform\4.18.*\ConfigSecurityPolicy.exeC:\ProgramData\Microsoft\Windows Defender\Platform\4.18.*\MpCopyAccelerator.exeC:\ProgramData\Microsoft\Windows Defender\Platform\4.18.*\MpCmdRun.exeC:\ProgramData\Microsoft\Windows Defender\Platform\4.18.*\MpDefenderCoreService.exeC:\ProgramData\Microsoft\Windows Defender\Platform\4.18.*\mpextms.exe Endpoint Data Loss Prevention (Endpoint DLP) exclusions: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.*\MpDlpService.exeC:\ProgramData\Microsoft\Windows Defender\Platform\4.18.*\MpDlpCmd.exeC:\ProgramData\Microsoft\Windows Defender\Platform\4.18.*\MipDlp.exeC:\ProgramData\Microsoft\Windows Defender\Platform\4.18.*\DlpUserAgent.exe |
| Windows Server 2016 or Windows Server 2012 R2 running the modern unified solution | The following additional exclusions are required after updating the Sense EDR component using KB5005292: C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Platform\*\MsSense.exe C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Platform\*\SenseCnCProxy.exe C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Platform\*\SenseIR.exe C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Platform\*\SenseCE.exe C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Platform\*\SenseSampleUploader.exe C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Platform\*\SenseCM.exe C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\DataCollectionC:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Platform\*\SenseTVM.exe |
| Windows 8.1 Windows 7 Windows Server 2008 R2 SP1 | C:\Program Files\Microsoft Monitoring Agent\Agent\Health Service State\Monitoring Host Temporary Files 6\45\MsSenseS.exe ( Monitoring Host Temporary Files 6\45 can be different numbered subfolders.) C:\Program Files\Microsoft Monitoring Agent\Agent\AgentControlPanel.exeC:\Program Files\Microsoft Monitoring Agent\Agent\HealthService.exeC:\Program Files\Microsoft Monitoring Agent\Agent\HSLockdown.exeC:\Program Files\Microsoft Monitoring Agent\Agent\MOMPerfSnapshotHelper.exeC:\Program Files\Microsoft Monitoring Agent\Agent\MonitoringHost.exeC:\Program Files\Microsoft Monitoring Agent\Agent\TestCloudConnection.exe |
For macOS devices, the following table lists processes to exclude in your non-Microsoft antivirus/antimalware solution:
| Process | Location |
|---|---|
wdavdaemon_enterpriseEDR engine |
/Library/Application Support/Microsoft/Defender/ |
wdavdaemon_unprivilegedAntivirus engine |
/Library/Application Support/Microsoft/Defender/ |
telemetryd_v1Telemetry daemon for EDR |
/Library/Application Support/Microsoft/Defender/ |
NetextNetwork extension |
/Library/SystemExtensions/*/com.microsoft.wdav.netext.systemextension/Contents/MacOS/ |
Epsext Endpoint security extension |
/Library/SystemExtensions/*/com.microsoft.wdav.epsext.systemextension/Contents/MacOS/ |
msupdateMicrosoft AutoUpdate update tool |
/Library/Application\ Support/Microsoft/MAU2.0/Microsoft\ AutoUpdate.app/Contents/MacOS |
For Linux servers, the following table lists processes to exclude in your non-Microsoft antivirus/antimalware solution:
| Process | Location |
|---|---|
wdavdaemonCore daemon (service). Uses FANotify for both antimalware and EDR purposes (TALPA on older RHEL). |
/opt/microsoft/mdatp/sbin/ |
wdavdaemon enterpriseEDR engine. Used for enrichment. |
/opt/microsoft/mdatp/sbin/ |
wdavdaemon unprivilegedAntivirus engine |
/opt/microsoft/mdatp/sbin/ |
crashpad_handlerCollects crash dumps |
/opt/microsoft/mdatp/sbin/ |
mdatp Command line utility |
/opt/microsoft/mdatp/sbin/Wdavdaemonclient |
mde_netfilter Packet filter for Network protection, also used for response capabilities |
/opt/microsoft/mde_netfilter/sbin |