STIGQter STIGQter: STIG Summary: Microsoft Defender for Endpoint Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

Microsoft Defender for Endpoint (MDE) must enable File Content Analysis.

DISA Rule

SV-275994r1119724_rule

Vulnerability Number

V-275994

Group Title

SRG-APP-000279

Rule Version

MSDE-00-001250

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Access the MDE portal as a user with at least an MDE Administrator or equivalent role:

1. In the navigation pane, select Settings >> Endpoints >> Automation uploads (under Rules).
2. Set the slide bar for "File Content Analysis" to "On".

Check Contents

Access the MDE portal as a user with at least an MDE Administrator or equivalent role:

1. In the navigation pane, select Settings >> Endpoints >> Automation uploads (under Rules).
2. Verify the slide bar for "File Content Analysis" is set to "On".

If the slide bar for "File Content Analysis" is not set to "On", this is a finding.

Vulnerability Number

V-275994

Documentable

False

Rule Version

MSDE-00-001250

Severity Override Guidance

Access the MDE portal as a user with at least an MDE Administrator or equivalent role:

1. In the navigation pane, select Settings >> Endpoints >> Automation uploads (under Rules).
2. Verify the slide bar for "File Content Analysis" is set to "On".

If the slide bar for "File Content Analysis" is not set to "On", this is a finding.

Check Content Reference

M

Target Key

5693