Skip to content

Commit e7fad01

Browse files
committed
Antivirus policy main article
1 parent 995d812 commit e7fad01

2 files changed

Lines changed: 17 additions & 45 deletions

File tree

memdocs/intune/fundamentals/whats-new.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -66,7 +66,7 @@ You can use RSS to be notified when this page is updated. For more information,
6666

6767
#### New profile templates and settings structure for endpoint security policies<!-- 13742640 -->
6868

69-
We’ve begun to release new [endpoint security profile templates](../intune/protect/endpoint-security-policy.md) that use the settings format as found in the Settings Catalog. Each new profile template includes the same settings as the older profile it replaces, while bringing the following improvements:
69+
We’ve begun to release new [endpoint security profile templates](../intune/protect/endpoint-security-policy.md) , while bringing the following improvements:
7070

7171
- **Setting names match the Windows CSP name**: Each setting name in the new profiles use the same name as the CSP that the setting configures. However, in the Intune UI we’ve added spaces to that name to make the setting name easier to read. For example, a setting in the Intune UI that’s named *Allow USB Connection* configures the CSP named [AllowUSBConnection](/windows/client-management/mdm/policy-csp-connectivity#connectivity-allowusbconnection).
7272

memdocs/intune/protect/endpoint-security-antivirus-policy.md

Lines changed: 16 additions & 44 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ keywords:
77
author: brenduns
88
ms.author: brenduns
99
manager: dougeby
10-
ms.date: 11/02/2021
10+
ms.date: 04/04/2022
1111
ms.topic: reference
1212
ms.service: microsoft-intune
1313
ms.subservice: protect
@@ -32,14 +32,12 @@ ms.reviewer: mattcall
3232

3333
Intune Endpoint security Antivirus policies can help security admins focus on managing the discrete group of antivirus settings for managed devices.
3434

35-
Antivirus policy includes several profiles. Each profile contains only the settings that are relevant for Microsoft Defender for Endpoint antivirus for macOS, Windows 10/11, or for the user experience in the Windows Security app on Windows 10/11 devices.
35+
Antivirus policy includes several profiles. Each profile contains only the settings that are relevant for Microsoft Defender for Endpoint antivirus for macOS and Windows devices, or for the user experience in the Windows Security app on Windows devices.
3636

3737
You'll find the antivirus policies under **Manage** in the Endpoint security node of the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431).
3838

39-
Antivirus policies include the same settings as *endpoint protection* or *device restriction* profiles for [device configuration](../configuration/device-profile-create.md) policy. However, those policy types include additional categories of settings that are unrelated to Antivirus. The additional settings can complicate the task of configuring Antivirus workload. Additionally, the settings found in the Antivirus policy for macOS aren't available through the other policy types. The macOS Antivirus profile replaces the need to configure the settings by using `.plist` files.
39+
Antivirus policies include the same settings as found *endpoint protection* or *device restriction* templates for [device configuration](../configuration/device-profile-create.md) policy. However, those policy types include additional categories of settings that are unrelated to Antivirus. The additional settings can complicate the task of configuring Antivirus workload. Additionally, the settings found in the Antivirus policy for macOS aren't available through the other policy types. The macOS Antivirus profile replaces the need to configure the settings by using `.plist` files.
4040

41-
>[!Note]
42-
> The Security Management for Microsoft Defender for Endpoint added an additional platform **Windows 10, Windows 11, and Windows Server (Preview)**. This new platform applies to both devices enrolled through Microsoft Intune as well as Microsoft Defender for Endpoint.
4341

4442
## Prerequisites for antivirus policy
4543

@@ -49,12 +47,8 @@ Antivirus policies include the same settings as *endpoint protection* or *device
4947
- Any supported version of macOS
5048
- For Intune to manage antivirus settings on a device, Microsoft Defender for Endpoint must be installed on that device. See. [Microsoft Defender for Endpoint for macOS](/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-atp-mac) (In the Microsoft Defender for Endpoint documentation)
5149

52-
- **Windows 10 and later**
53-
- No additional prerequisites are required.
54-
55-
- **Windows 10, Windows 11, and Windows Server (Preview)**
56-
- No additional prerequisites are required.
57-
50+
- **Windows 10, Windows 11, and Windows Server**
51+
- No additional prerequisites are required.
5852

5953
**Support for Configuration Manager clients**:
6054

@@ -114,9 +108,15 @@ The following profiles are supported for devices you manage with Intune:
114108

115109
When you use [Microsoft Defender for Endpoint for Mac](/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-atp-mac), you can configure and deploy Antivirus settings to your managed macOS devices through Intune instead of configuring those settings by use of `.plist` files.
116110

117-
**Windows 10**:
111+
**Windows 10, 11, and Windows Server**:
112+
113+
> [!NOTE]
114+
> Beginning in April 2022, the *Windows 10 and later* platform is replaced by the *Windows 10, Windows 11, and Windows Server* platform. Profiles for this new platform use the settings format as found in the Settings Catalog. Each new profile template for this new platform includes the same settings as the older profile template it replaces. With this change you can no longer create new versions of the old profiles. Your existing instances of the old profile remain available to use and edit.
115+
116+
- Platform: **Windows 10, Windows 11, and Windows Server**
117+
Profiles for this platform can be used with devices enrolled with Intune, and devices managed through [Security Management for Microsoft Defender for Endpoint](../protect/mde-security-integration.md).
118+
118119

119-
- Platform: **Windows 10 profiles**
120120

121121
- Profile: **Microsoft Defender Antivirus** - Manage [Antivirus policy settings](../protect/antivirus-microsoft-defender-settings-windows.md) for Windows 10/11.
122122

@@ -140,34 +140,6 @@ The following profiles are supported for devices you manage with Intune:
140140

141141
The Windows security app is used by a number of Windows security features to provide notifications about the health and security of the machine. Security app notifications include firewalls, antivirus products, Windows Defender SmartScreen, and others.
142142

143-
- Platform: **Windows 10, Windows 11, and Windows Server (Preview)**
144-
145-
- Profile: **Microsoft Defender Antivirus (Preview)** - Manage [Antivirus policy settings](../protect/antivirus-microsoft-defender-settings-windows.md) for Windows 10/11.
146-
147-
Defender Antivirus is the next-generation protection component of Microsoft Defender for Endpoint. Next-generation protection brings together technologies like machine learning and cloud infrastructure to protect devices in your enterprise organization.
148-
149-
The *Microsoft Defender Antivirus* profile is a separate instance of the antivirus settings that are found in the *Device Restriction profile* for Device Configuration policy.
150-
151-
Unlike the antivirus settings in a *Device Restriction profile*, you can use these settings to with devices that are co-managed. To use these settings, the [co-management workload slider](/configmgr/comanage/how-to-switch-workloads) for Endpoint Protection must be set to Intune.
152-
153-
The settings in this profile apply to devices that are enrolled to Endpoint Manager with **Intune or Microsoft Defender for Endpoint**.
154-
155-
To setup security management for MDE, see [Manage Microsoft Defender for Endpoint on devices with Microsoft Endpoint Manager](../protect/mde-security-integration.md).
156-
157-
**Windows Server:**
158-
159-
- Platform: **Windows 10, Windows 11, and Windows Server (Preview)**
160-
161-
- Profile: **Microsoft Defender Antivirus (Preview)** - Manage [Antivirus policy settings](../protect/antivirus-microsoft-defender-settings-windows.md) for Windows 10/11.
162-
163-
Defender Antivirus is the next-generation protection component of Microsoft Defender for Endpoint. Next-generation protection brings together technologies like machine learning and cloud infrastructure to protect devices in your enterprise organization.
164-
165-
The *Microsoft Defender Antivirus* profile is a separate instance of the antivirus settings that are found in the *Device Restriction profile* for Device Configuration policy.
166-
167-
The settings in this profile apply to devices that are enrolled to Endpoint Manager with **Microsoft Defender for Endpoint**.
168-
169-
To setup security management for MDE, see [Manage Microsoft Defender for Endpoint on devices with Microsoft Endpoint Manager](../protect/mde-security-integration.md).
170-
171143
### Devices managed by Configuration Manager
172144

173145
[!INCLUDE [antivirus policy prerequisites](../includes/tenant-attach-antivirus-prerequisites.md)]
@@ -192,9 +164,9 @@ The following settings support policy merge:
192164

193165
[Microsoft Defender Antivirus policies](../protect/antivirus-microsoft-defender-settings-windows.md)
194166

195-
- **Defender Processes To Exclude** - CSP: [Defender/ExcludedProcesses](/windows/client-management/mdm/policy-csp-defender#defender-excludedprocesses)
196-
- **File extensions to exclude from scans and real-time protection** - CSP: [Defender/ExcludedExtensions](/windows/client-management/mdm/policy-csp-defender#defender-excludedextensions)
197-
- **Defender Files And Folders To Exclude** - CSP: [Defender/ExcludedPaths](/windows/client-management/mdm/policy-csp-defender#defender-excludedpaths)
167+
- **Excluded Processes** - CSP: [Defender/ExcludedProcesses](/windows/client-management/mdm/policy-csp-defender#defender-excludedprocesses)
168+
- **Excluded Extensions** - CSP: [Defender/ExcludedExtensions](/windows/client-management/mdm/policy-csp-defender#defender-excludedextensions)
169+
- **Excluded Paths** - CSP: [Defender/ExcludedPaths](/windows/client-management/mdm/policy-csp-defender#defender-excludedpaths)
198170

199171
## Antivirus policy reports
200172

0 commit comments

Comments
 (0)