STIGQter STIGQter: STIG Summary:

Microsoft Defender Antivirus Security Technical Implementation Guide

Version: 2

Release: 9 Benchmark Date: 01 Jul 2026

CheckedNameTitle
SV-213426r961197_ruleMicrosoft Defender AV must be configured to block the Potentially Unwanted Application (PUA) feature.
SV-213427r961197_ruleMicrosoft Defender AV must be configured to automatically take action on all detected tasks.
SV-213428r1192794_ruleMicrosoft Defender AV must be configured to run and scan for malware and other potentially unwanted software.
SV-213429r1207390_ruleMicrosoft Defender AV must be configured to not exclude files for scanning.
SV-213430r1207392_ruleMicrosoft Defender AV must be configured to not exclude files opened by specified processes.
SV-213431r1207394_ruleMicrosoft Defender AV must be configured to enable the Automatic Exclusions feature.
SV-213432r961092_ruleMicrosoft Defender AV must be configured to disable local setting override for reporting to Microsoft MAPS.
SV-213433r1192798_ruleMicrosoft Defender AV must be configured to check in real time with MAPS before content is run or accessed.
SV-213434r1134051_ruleMicrosoft Defender AV must join Microsoft MAPS.
SV-213435r961092_ruleMicrosoft Defender AV must be configured to only send safe samples for MAPS telemetry.
SV-213436r1192799_ruleMicrosoft Defender AV must be configured for protocol recognition for network protection.
SV-213437r960921_ruleMicrosoft Defender AV must be configured to not allow local override of monitoring for file and program activity.
SV-213438r960921_ruleMicrosoft Defender AV must be configured to not allow override of monitoring for incoming and outgoing file activity.
SV-213439r961089_ruleMicrosoft Defender AV must be configured to not allow override of scanning for downloaded files and attachments.
SV-213440r961092_ruleMicrosoft Defender AV must be configured to not allow override of behavior monitoring.
SV-213441r1192800_ruleMicrosoft Defender AV Group Policy settings must take priority over the local preference settings.
SV-213442r1192801_ruleMicrosoft Defender AV must monitor for incoming and outgoing files.
SV-213443r1192802_ruleMicrosoft Defender AV must be configured to monitor for file and program activity.
SV-213444r961089_ruleMicrosoft Defender AV must be configured to scan all downloaded files and attachments.
SV-213445r1192803_ruleMicrosoft Defender AV must be configured to always enable real-time protection.
SV-213446r961092_ruleMicrosoft Defender AV must be configured to enable behavior monitoring.
SV-213447r1192804_ruleMicrosoft Defender AV must be configured to process scanning when real-time protection is enabled.
SV-213448r1192805_ruleMicrosoft Defender AV must be configured to scan archive files.
SV-213449r960852_ruleMicrosoft Defender AV must be configured to scan removable drives.
SV-213450r961191_ruleMicrosoft Defender AV must be configured to perform a weekly scheduled scan.
SV-213451r961092_ruleMicrosoft Defender AV must be configured to turn on e-mail scanning.
SV-213452r1192806_ruleMicrosoft Defender AV spyware definition age must not exceed 7 days.
SV-213453r1192807_ruleMicrosoft Defender AV virus definition age must not exceed 7 days.
SV-213454r961161_ruleMicrosoft Defender AV must be configured to check for definition updates daily.
SV-213455r961086_ruleMicrosoft Defender AV must be configured for automatic remediation action to be taken for threat alert level Severe.
SV-213456r961092_ruleMicrosoft Defender AV must be configured to block executable content from email client and webmail.
SV-213457r961092_ruleMicrosoft Defender AV must be configured block Office applications from creating child processes.
SV-213458r961092_ruleMicrosoft Defender AV must be configured block Office applications from creating executable content.
SV-213459r961092_ruleMicrosoft Defender AV must be configured to block Office applications from injecting into other processes.
SV-213460r961092_ruleMicrosoft Defender AV must be configured to impede JavaScript and VBScript to launch executables.
SV-213461r961092_ruleMicrosoft Defender AV must be configured to block execution of potentially obfuscated scripts.
SV-213462r961092_ruleMicrosoft Defender AV must be configured to block Win32 imports from macro code in Office.
SV-213463r961092_ruleMicrosoft Defender AV must be configured to prevent user and apps from accessing dangerous websites.
SV-213464r961086_ruleMicrosoft Defender AV must be configured for automatic remediation action to be taken for threat alert level High.
SV-213465r961086_ruleMicrosoft Defender AV must be configured for automatic remediation action to be taken for threat alert level Medium.
SV-213466r961086_ruleMicrosoft Defender AV must be configured for automatic remediation action to be taken for threat alert level Low.
SV-278647r1192808_ruleMicrosoft Defender AV must block Adobe Reader from creating child processes.
SV-278648r1192809_ruleMicrosoft Defender AV must block credential stealing from the Windows local security authority subsystem.
SV-278649r1192810_ruleMicrosoft Defender AV must block untrusted and unsigned processes that run from USB.
SV-278650r1192811_ruleMicrosoft Defender AV must use advanced protection against ransomware.
SV-278651r1192812_ruleMicrosoft Defender AV must audit process creations originating from PSExec and WMI commands.
SV-278652r1192813_ruleMicrosoft Defender AV must audit persistence through WMI event subscription.
SV-278653r1192814_ruleMicrosoft Defender AV must audit executable files from running unless they meet a prevalence, age, or trusted list criterion.
SV-278654r1192815_ruleMicrosoft Defender AV must block Office communication application from creating child processes.
SV-278655r1192816_ruleMicrosoft Defender AV must block abuse of exploited vulnerable signed drivers.
SV-278656r1192817_ruleMicrosoft Defender AV must configure local administrator merge behavior for lists.
SV-278658r1207388_ruleMicrosoft Defender AV must control whether exclusions are visible to Local Admins.
SV-278659r1192819_ruleMicrosoft Defender AV must randomize scheduled task times.
SV-278660r1192820_ruleMicrosoft Defender AV must hide the Family options area.
SV-278661r1192821_ruleMicrosoft Defender AV must enable the file hash computation feature.
SV-278662r1192822_ruleMicrosoft Defender AV must enable extended cloud check.
SV-278668r1192823_ruleMicrosoft Defender AV must enable script scanning.
SV-278669r1192824_ruleMicrosoft Defender AV must enable real-time protection and Security Intelligence Updates during OOBE.
SV-278672r1192825_ruleMicrosoft Defender AV must enable network protection to be configured into block or audit mode on Windows Server.
SV-278674r1192826_ruleMicrosoft Defender AV must enable EDR in block mode.
SV-278675r1192827_ruleMicrosoft Defender AV must report Dynamic Signature dropped events.
SV-278676r1192828_ruleMicrosoft Defender AV must scan excluded files and directories during quick scans.
SV-278677r1192829_ruleMicrosoft Defender AV must convert warn verdict to block.
SV-278678r1192830_ruleMicrosoft Defender AV must enable asynchronous inspection.
SV-278679r1192831_ruleMicrosoft Defender AV must scan packed executables.
SV-278680r1192832_ruleMicrosoft Defender AV must enable heuristics.
SV-278863r1192833_ruleMicrosoft Defender AV must set cloud protection level to High.