From deb26fb920b840ca6c12912fe5e6b5be2c4d11cd Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Mon, 27 Jan 2020 14:24:17 -0800 Subject: [PATCH 01/27] Update TOC.md --- windows/security/threat-protection/TOC.md | 18 +++++++++--------- 1 file changed, 9 insertions(+), 9 deletions(-) diff --git a/windows/security/threat-protection/TOC.md b/windows/security/threat-protection/TOC.md index 3d8409c878..7c3a3c157a 100644 --- a/windows/security/threat-protection/TOC.md +++ b/windows/security/threat-protection/TOC.md @@ -44,7 +44,7 @@ #### [Attack surface reduction](microsoft-defender-atp/attack-surface-reduction.md) #### [Network firewall](windows-firewall/windows-firewall-with-advanced-security.md) -### [Next generation protection](windows-defender-antivirus/windows-defender-antivirus-in-windows-10.md) +### [Next-generation protection](windows-defender-antivirus/windows-defender-antivirus-in-windows-10.md) #### [Better together: Windows Defender Antivirus and Microsoft Defender ATP](windows-defender-antivirus/why-use-microsoft-antivirus.md) ### [Endpoint detection and response]() @@ -187,7 +187,7 @@ ##### [Controlled folder access](microsoft-defender-atp/evaluate-controlled-folder-access.md) ##### [Attack surface reduction](microsoft-defender-atp/evaluate-attack-surface-reduction.md) ##### [Network firewall](windows-firewall/evaluating-windows-firewall-with-advanced-security-design-examples.md) -##### [Evaluate next generation protection](windows-defender-antivirus/evaluate-windows-defender-antivirus.md) +##### [Evaluate next-generation protection](windows-defender-antivirus/evaluate-windows-defender-antivirus.md) ### [Access the Windows Defender Security Center Community Center](microsoft-defender-atp/community.md) @@ -231,7 +231,7 @@ -### [Configure next generation protection]() +### [Configure next-generation protection]() #### [Configure Windows Defender Antivirus features](windows-defender-antivirus/configure-windows-defender-antivirus-features.md) #### [Utilize Microsoft cloud-delivered protection](windows-defender-antivirus/utilize-microsoft-cloud-protection-windows-defender-antivirus.md) @@ -315,13 +315,13 @@ ##### [Run and review the results of an offline scan](windows-defender-antivirus/windows-defender-offline.md) ##### [Restore quarantined files](windows-defender-antivirus/restore-quarantined-files-windows-defender-antivirus.md) -#### [Manage next generation protection in your business]() +#### [Manage next-generation protection in your business]() ##### [Management overview](windows-defender-antivirus/configuration-management-reference-windows-defender-antivirus.md) ##### [Use Microsoft Intune and System Center Configuration Manager to manage next generation protection](windows-defender-antivirus/use-intune-config-manager-windows-defender-antivirus.md) -##### [Use Group Policy settings to manage next generation protection](windows-defender-antivirus/use-group-policy-windows-defender-antivirus.md) -##### [Use PowerShell cmdlets to manage next generation protection](windows-defender-antivirus/use-powershell-cmdlets-windows-defender-antivirus.md) -##### [Use Windows Management Instrumentation (WMI) to manage next generation protection](windows-defender-antivirus/use-wmi-windows-defender-antivirus.md) -##### [Use the mpcmdrun.exe command line tool to manage next generation protection](windows-defender-antivirus/command-line-arguments-windows-defender-antivirus.md) +##### [Use Group Policy settings to manage next-generation protection](windows-defender-antivirus/use-group-policy-windows-defender-antivirus.md) +##### [Use PowerShell cmdlets to manage next-generation protection](windows-defender-antivirus/use-powershell-cmdlets-windows-defender-antivirus.md) +##### [Use Windows Management Instrumentation (WMI) to manage next-generation protection](windows-defender-antivirus/use-wmi-windows-defender-antivirus.md) +##### [Use the mpcmdrun.exe command line tool to manage next-generation protection](windows-defender-antivirus/command-line-arguments-windows-defender-antivirus.md) ### [Microsoft Defender Advanced Threat Protection for Mac](microsoft-defender-atp/microsoft-defender-atp-mac.md) @@ -573,7 +573,7 @@ #### [Network protection](microsoft-defender-atp/troubleshoot-np.md) #### [Attack surface reduction rules](microsoft-defender-atp/troubleshoot-asr.md) -### [Troubleshoot next generation protection](windows-defender-antivirus/troubleshoot-windows-defender-antivirus.md) +### [Troubleshoot next-generation protection](windows-defender-antivirus/troubleshoot-windows-defender-antivirus.md) From 1eff95103c3ce25e74da2df1c3a32b08ad723ed3 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Mon, 27 Jan 2020 14:53:15 -0800 Subject: [PATCH 02/27] new article about FP/FN in WDAV --- windows/security/threat-protection/TOC.md | 1 + .../antivirus-false-positives-negatives.md | 25 +++++++++++++++++++ 2 files changed, 26 insertions(+) create mode 100644 windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md diff --git a/windows/security/threat-protection/TOC.md b/windows/security/threat-protection/TOC.md index 7c3a3c157a..44d2dfed8d 100644 --- a/windows/security/threat-protection/TOC.md +++ b/windows/security/threat-protection/TOC.md @@ -316,6 +316,7 @@ ##### [Restore quarantined files](windows-defender-antivirus/restore-quarantined-files-windows-defender-antivirus.md) #### [Manage next-generation protection in your business]() +##### [Handle false positives/negatives in Windows Defender Antivirus](windows-defender-antivirus/antivirus-false-positives-negatives.md) ##### [Management overview](windows-defender-antivirus/configuration-management-reference-windows-defender-antivirus.md) ##### [Use Microsoft Intune and System Center Configuration Manager to manage next generation protection](windows-defender-antivirus/use-intune-config-manager-windows-defender-antivirus.md) ##### [Use Group Policy settings to manage next-generation protection](windows-defender-antivirus/use-group-policy-windows-defender-antivirus.md) diff --git a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md new file mode 100644 index 0000000000..595435124f --- /dev/null +++ b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md @@ -0,0 +1,25 @@ +--- +title: Handling false positives/negatives in Windows Defender Antivirus +description: Did Windows Defender Antivirus miss or wrongly detect something? Find out what you can do. +keywords: Windows Defender Antivirus, false positives, false negatives, exclusions +search.product: eADQiWindows 10XVcnh +ms.pagetype: security +ms.prod: w10 +ms.mktglfcycl: manage +ms.sitesec: library +ms.pagetype: security +ms.localizationpriority: medium +author: denisebmsft +ms.author: deniseb +ms.custom: nextgen +ms.date: 01/27/2020 +ms.reviewer: +manager: dansimp +--- + +# Handling false positives/negatives in Windows Defender Antivirus + +**Applies to:** + +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) + From 7624f226dec37a3750d3d22a8fdd4a45a96d1bf3 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Mon, 27 Jan 2020 14:58:43 -0800 Subject: [PATCH 03/27] Update antivirus-false-positives-negatives.md --- .../antivirus-false-positives-negatives.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md index 595435124f..ff06518411 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md +++ b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md @@ -23,3 +23,5 @@ manager: dansimp - [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +As you probably already know, Windows Defender Antivirus is designed to keep your PC safe with built-in, trusted antivirus protection. With Windows Defender Antivirus, you get comprehensive, ongoing, and real-time protection against software threats like viruses, malware and spyware across email, apps, the cloud and the web. But what do you do if something was missed or wrongly detected as malware? You can report it to Microsoft for analysis. + From 7700b0274b0aaa762cfa0815775593839f9069c8 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Mon, 27 Jan 2020 15:26:25 -0800 Subject: [PATCH 04/27] Update antivirus-false-positives-negatives.md --- .../antivirus-false-positives-negatives.md | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md index ff06518411..489dd382e2 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md +++ b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md @@ -23,5 +23,14 @@ manager: dansimp - [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) -As you probably already know, Windows Defender Antivirus is designed to keep your PC safe with built-in, trusted antivirus protection. With Windows Defender Antivirus, you get comprehensive, ongoing, and real-time protection against software threats like viruses, malware and spyware across email, apps, the cloud and the web. But what do you do if something was missed or wrongly detected as malware? You can report it to Microsoft for analysis. +Windows Defender Antivirus is designed to keep your PC safe with built-in, trusted antivirus protection. With Windows Defender Antivirus, you get comprehensive, ongoing, and real-time protection against software threats like viruses, malware and spyware across email, apps, the cloud and the web. + +But what if something gets detected wrongly as malware, or something is missed? We call these false positives and false negatives, and there are some steps you can take to deal with these things. + +## Report a false positive/negative to Microsoft + +1. Review the [submission guidelines](../intelligence/submission-guide.md). +2. Submit your file here: [https://www.microsoft.com/wdsi/filesubmission/](https://www.microsoft.com/wdsi/filesubmission/). + +## Define an exclusion From 55e1b6935b51060eb3d8ab35c445b50a1a9718a7 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Mon, 27 Jan 2020 15:37:53 -0800 Subject: [PATCH 05/27] Update antivirus-false-positives-negatives.md --- .../antivirus-false-positives-negatives.md | 17 +++++++++++++---- 1 file changed, 13 insertions(+), 4 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md index 489dd382e2..4c352ce500 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md +++ b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md @@ -25,12 +25,21 @@ manager: dansimp Windows Defender Antivirus is designed to keep your PC safe with built-in, trusted antivirus protection. With Windows Defender Antivirus, you get comprehensive, ongoing, and real-time protection against software threats like viruses, malware and spyware across email, apps, the cloud and the web. -But what if something gets detected wrongly as malware, or something is missed? We call these false positives and false negatives, and there are some steps you can take to deal with these things. +But what if something gets detected wrongly as malware, or something is missed? We call these false positives and false negatives, and there are some steps you can take to deal with these things. You can submit a file to Microsoft for analysis, and potentially, define an exclusion in your Windows Defender Antivirus settings. -## Report a false positive/negative to Microsoft +## Submit a file to Microsoft for analysis 1. Review the [submission guidelines](../intelligence/submission-guide.md). -2. Submit your file here: [https://www.microsoft.com/wdsi/filesubmission/](https://www.microsoft.com/wdsi/filesubmission/). +2. [Submit your file or sample](https://www.microsoft.com/wdsi/filesubmission). -## Define an exclusion +> [!TIP] +> We recommend signing in at the submission portal so you can track the results of your submissions. +## Define an exclusion on a Windows device + +When you define an exclusion for Windows Defender Antivirus, you configure your antivirus to skip that item. + +1. On your Windows 10 device, open the Windows Security app. +2. Select **Virus & threat protection** > **Virus & threat protection settings**. +3. Under **Exclusions**, select **Add or remove exclusions**. +4. Select **+ Add an exclusion**, and specify its type (**File**, **Folder**, **File type**, or **Process**.) \ No newline at end of file From ae77ae6c88ff13eebabe582741fd0068c18f5a9b Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Mon, 27 Jan 2020 15:42:57 -0800 Subject: [PATCH 06/27] Update antivirus-false-positives-negatives.md --- .../antivirus-false-positives-negatives.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md index 4c352ce500..22f22eb666 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md +++ b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md @@ -25,7 +25,7 @@ manager: dansimp Windows Defender Antivirus is designed to keep your PC safe with built-in, trusted antivirus protection. With Windows Defender Antivirus, you get comprehensive, ongoing, and real-time protection against software threats like viruses, malware and spyware across email, apps, the cloud and the web. -But what if something gets detected wrongly as malware, or something is missed? We call these false positives and false negatives, and there are some steps you can take to deal with these things. You can submit a file to Microsoft for analysis, and potentially, define an exclusion in your Windows Defender Antivirus settings. +But what if something gets detected wrongly as malware, or something is missed? We call these false positives and false negatives, and there are some steps you can take to deal with these things. You can [submit a file to Microsoft for analysis](#submit-a-file-to-microsoft-for-analysis), and potentially, [define an exclusion](#define-an-exclusion-on-a-windows-device) in your Windows Defender Antivirus settings. ## Submit a file to Microsoft for analysis From 87dabf7055bdf25b4d91a599e34ad46a12120d95 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Wed, 29 Jan 2020 15:48:58 -0800 Subject: [PATCH 07/27] Update antivirus-false-positives-negatives.md --- .../antivirus-false-positives-negatives.md | 23 +++++++++++++++---- 1 file changed, 19 insertions(+), 4 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md index 22f22eb666..a6dc1e50c2 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md +++ b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md @@ -12,7 +12,7 @@ ms.localizationpriority: medium author: denisebmsft ms.author: deniseb ms.custom: nextgen -ms.date: 01/27/2020 +ms.date: 01/29/2020 ms.reviewer: manager: dansimp --- @@ -25,7 +25,10 @@ manager: dansimp Windows Defender Antivirus is designed to keep your PC safe with built-in, trusted antivirus protection. With Windows Defender Antivirus, you get comprehensive, ongoing, and real-time protection against software threats like viruses, malware and spyware across email, apps, the cloud and the web. -But what if something gets detected wrongly as malware, or something is missed? We call these false positives and false negatives, and there are some steps you can take to deal with these things. You can [submit a file to Microsoft for analysis](#submit-a-file-to-microsoft-for-analysis), and potentially, [define an exclusion](#define-an-exclusion-on-a-windows-device) in your Windows Defender Antivirus settings. +But what if something gets detected wrongly as malware, or something is missed? We call these false positives and false negatives. Fortunately, there are some steps you can take to deal with these things. You can: +- [Submit a file to Microsoft for analysis](#submit-a-file-to-microsoft-for-analysis); +- [Create an "Allow" indicator](#create-an-allow-indicator); or +- [Define an exclusion on an individual device](#define-an-exclusion-on-a-windows-device) in your Windows Defender Antivirus settings. ## Submit a file to Microsoft for analysis @@ -35,11 +38,23 @@ But what if something gets detected wrongly as malware, or something is missed? > [!TIP] > We recommend signing in at the submission portal so you can track the results of your submissions. -## Define an exclusion on a Windows device +## Create an "Allow" indicator + +If a file, IP address, URL, or domain is treated as malware on a device, even though it's safe, you can create an "Allow" indicator. This indicator tells Windows Defender Antivirus (and Microsoft Defender Advanced Threat Protection) that the item is safe. + +To set up your "Allow" indicator, follow the guidance in [Manage indicators](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/manage-indicators). + +## Define an exclusion on an individual Windows device When you define an exclusion for Windows Defender Antivirus, you configure your antivirus to skip that item. 1. On your Windows 10 device, open the Windows Security app. 2. Select **Virus & threat protection** > **Virus & threat protection settings**. 3. Under **Exclusions**, select **Add or remove exclusions**. -4. Select **+ Add an exclusion**, and specify its type (**File**, **Folder**, **File type**, or **Process**.) \ No newline at end of file +4. Select **+ Add an exclusion**, and specify its type (**File**, **Folder**, **File type**, or **Process**.) + +## Related articles + +[What is Microsoft Defender Advanced Threat Protection?](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-advanced-threat-protection) + +[Microsoft Threat Protection](https://docs.microsoft.com/microsoft-365/security/mtp/microsoft-threat-protection) \ No newline at end of file From 48d0c9edfdc26c113e1375f71995024581853d93 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Wed, 29 Jan 2020 15:59:07 -0800 Subject: [PATCH 08/27] Update antivirus-false-positives-negatives.md --- .../antivirus-false-positives-negatives.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md index a6dc1e50c2..f04cb9e76c 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md +++ b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md @@ -1,5 +1,5 @@ --- -title: Handling false positives/negatives in Windows Defender Antivirus +title: What to do with false positives/negatives in Windows Defender Antivirus description: Did Windows Defender Antivirus miss or wrongly detect something? Find out what you can do. keywords: Windows Defender Antivirus, false positives, false negatives, exclusions search.product: eADQiWindows 10XVcnh @@ -17,7 +17,7 @@ ms.reviewer: manager: dansimp --- -# Handling false positives/negatives in Windows Defender Antivirus +# What to do with false positives/negatives in Windows Defender Antivirus **Applies to:** From 06ba43601c76119b5d4d68b3b7125cac4e2112bd Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Wed, 29 Jan 2020 16:15:25 -0800 Subject: [PATCH 09/27] Update antivirus-false-positives-negatives.md --- .../antivirus-false-positives-negatives.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md index f04cb9e76c..d2f4a1c9b5 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md +++ b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md @@ -28,7 +28,7 @@ Windows Defender Antivirus is designed to keep your PC safe with built-in, trust But what if something gets detected wrongly as malware, or something is missed? We call these false positives and false negatives. Fortunately, there are some steps you can take to deal with these things. You can: - [Submit a file to Microsoft for analysis](#submit-a-file-to-microsoft-for-analysis); - [Create an "Allow" indicator](#create-an-allow-indicator); or -- [Define an exclusion on an individual device](#define-an-exclusion-on-a-windows-device) in your Windows Defender Antivirus settings. +- [Define an exclusion on an individual Windows device](#define-an-exclusion-on-an-individual-windows-device) in your Windows Defender Antivirus settings. ## Submit a file to Microsoft for analysis From 0200844f9e3c1e5905c5bab049c8f4a31ea3af95 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Wed, 29 Jan 2020 16:17:38 -0800 Subject: [PATCH 10/27] fixing build report errors --- ...ix-a-powershell-scripts-for-surface-hub.md | 6 ++-- mdop/appv-v5/app-v-50-prerequisites.md | 36 +++++++++---------- 2 files changed, 21 insertions(+), 21 deletions(-) diff --git a/devices/surface-hub/appendix-a-powershell-scripts-for-surface-hub.md b/devices/surface-hub/appendix-a-powershell-scripts-for-surface-hub.md index 8196982606..7b44ff3d38 100644 --- a/devices/surface-hub/appendix-a-powershell-scripts-for-surface-hub.md +++ b/devices/surface-hub/appendix-a-powershell-scripts-for-surface-hub.md @@ -617,7 +617,7 @@ try { catch { PrintError "Some dependencies are missing" - PrintError "Please install the Windows PowerShell Module for Lync Online. For more information go to http://www.microsoft.com/download/details.aspx?id=39366" + PrintError "Please install the Windows PowerShell Module for Lync Online. For more information go to https://www.microsoft.com/download/details.aspx?id=39366" PrintError "Please install the Azure Active Directory module for PowerShell from https://go.microsoft.com/fwlink/p/?linkid=236297" CleanupAndFail } @@ -1104,7 +1104,7 @@ if ($fSfbIsOnline) } catch { - CleanupAndFail "To verify Skype for Business in online tenants you need the Lync Online Connector module from http://www.microsoft.com/download/details.aspx?id=39366" + CleanupAndFail "To verify Skype for Business in online tenants you need the Lync Online Connector module from https://www.microsoft.com/download/details.aspx?id=39366" } } else @@ -1518,7 +1518,7 @@ if ($online) catch { PrintError "Some dependencies are missing" - PrintError "Please install the Windows PowerShell Module for Lync Online. For more information go to http://www.microsoft.com/download/details.aspx?id=39366" + PrintError "Please install the Windows PowerShell Module for Lync Online. For more information go to https://www.microsoft.com/download/details.aspx?id=39366" PrintError "Please install the Azure Active Directory module for PowerShell from https://go.microsoft.com/fwlink/p/?linkid=236297" CleanupAndFail } diff --git a/mdop/appv-v5/app-v-50-prerequisites.md b/mdop/appv-v5/app-v-50-prerequisites.md index 1d1dcd7770..60a2900438 100644 --- a/mdop/appv-v5/app-v-50-prerequisites.md +++ b/mdop/appv-v5/app-v-50-prerequisites.md @@ -100,8 +100,8 @@ The following table lists the installation prerequisites for the App-V 5.0 clien

Software requirements

@@ -158,8 +158,8 @@ The following table lists the installation prerequisites for the App-V 5.0 Remot

Software requirements

@@ -221,12 +221,12 @@ If the system requirements of a locally installed application exceed the require

Software requirements

    -
  • Visual C++ Redistributable Packages for Visual Studio 2013 (http://www.microsoft.com/download/details.aspx?id=40784)

    +
  • Visual C++ Redistributable Packages for Visual Studio 2013 (https://www.microsoft.com/download/details.aspx?id=40784)

    This prerequisite is required only if you have installed Hotfix Package 4 for Application Virtualization 5.0 SP2.

  • -
  • Microsoft .NET Framework 4 (Full Package) (http://www.microsoft.com/download/details.aspx?id=17718)

    +
  • Microsoft .NET Framework 4 (Full Package) (https://www.microsoft.com/download/details.aspx?id=17718)

  • -
  • Windows PowerShell 3.0 (http://www.microsoft.com/download/details.aspx?id=34595)

    +
  • Windows PowerShell 3.0 (https://www.microsoft.com/download/details.aspx?id=34595)

  • Download and install KB2533623 (http://support.microsoft.com/kb/2533623)

  • @@ -292,8 +292,8 @@ The installation of the App-V 5.0 server on a computer that runs any previous ve

    Management Server

    @@ -339,7 +339,7 @@ The installation of the App-V 5.0 server on a computer that runs any previous ve

    The App-V 5.0 server components are dependent but they have varying requirements and installation options that must be deployed. Use the following information to prepare your environment to run the App-V 5.0 management database.

    @@ -355,7 +355,7 @@ The installation of the App-V 5.0 server on a computer that runs any previous ve

    Reporting Server

      -
    • Microsoft .NET Framework 4 (Full Package) (http://www.microsoft.com/download/details.aspx?id=17718)

    • +
    • Microsoft .NET Framework 4 (Full Package) (https://www.microsoft.com/download/details.aspx?id=17718)

    • Microsoft Visual C++ 2010 SP1 Redistributable Package (x86)(https://go.microsoft.com/fwlink/?LinkId=267110)

    • Note

      To help reduce the risk of unwanted or malicious data being sent to the reporting server, you should restrict access to the Reporting Web Service per your corporate security policy.

      @@ -380,7 +380,7 @@ The installation of the App-V 5.0 server on a computer that runs any previous ve

      The App-V 5.0 server components are dependent but they have varying requirements and installation options that must be deployed. Use the following information to prepare your environment to run the App-V 5.0 reporting database.

      @@ -396,7 +396,7 @@ The installation of the App-V 5.0 server on a computer that runs any previous ve

      Publishing Server

        -
      • Microsoft .NET Framework 4 (Full Package) (http://www.microsoft.com/download/details.aspx?id=17718)

      • +
      • Microsoft .NET Framework 4 (Full Package) (https://www.microsoft.com/download/details.aspx?id=17718)

      • Microsoft Visual C++ 2010 SP1 Redistributable Package (x86)(https://go.microsoft.com/fwlink/?LinkId=267110)

      • Windows Web Server with the IIS role with the following features: Common HTTP Features (static content and default document), Application Development (ASP.NET, .NET Extensibility, ISAPI Extensions and ISAPI Filters), Security (Windows Authentication, Request Filtering), Security (Windows Authentication, Request Filtering), Management Tools (IIS Management Console)

      • 64-bit ASP.NET registration

      • From fbee1a68caf1c25b7e9f9d107d0f3bddcafa962a Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Wed, 29 Jan 2020 16:18:45 -0800 Subject: [PATCH 11/27] fixing build report errors --- mdop/appv-v5/app-v-50-prerequisites.md | 8 ++++---- ...own-issues-in-the-mbam-international-release-mbam-1.md | 2 +- mdop/mbam-v2/mbam-20-privacy-statement-mbam-2.md | 2 +- 3 files changed, 6 insertions(+), 6 deletions(-) diff --git a/mdop/appv-v5/app-v-50-prerequisites.md b/mdop/appv-v5/app-v-50-prerequisites.md index 60a2900438..e90a62583c 100644 --- a/mdop/appv-v5/app-v-50-prerequisites.md +++ b/mdop/appv-v5/app-v-50-prerequisites.md @@ -109,7 +109,7 @@ The following table lists the installation prerequisites for the App-V 5.0 clien
        -
      • Download and install KB2533623 (http://support.microsoft.com/kb/2533623)

        +
      • Download and install KB2533623 (https://support.microsoft.com/kb/2533623)

        Important

        You can download and install the previous KB article. However, it may have been replaced with a more recent version.

        @@ -228,7 +228,7 @@ If the system requirements of a locally installed application exceed the require

      • Windows PowerShell 3.0 (https://www.microsoft.com/download/details.aspx?id=34595)

      • -
      • Download and install KB2533623 (http://support.microsoft.com/kb/2533623)

        +
      • Download and install KB2533623 (https://support.microsoft.com/kb/2533623)

      • For computers running Microsoft Windows Server 2008 R2 SP1, download and install KB2533623 (https://go.microsoft.com/fwlink/?LinkId=286102)

        @@ -254,7 +254,7 @@ The following prerequisites are already installed for computers that run Windows - Windows PowerShell 3.0 -- Download and install [KB2533623](https://support.microsoft.com/kb/2533623) (http://support.microsoft.com/kb/2533623) +- Download and install [KB2533623](https://support.microsoft.com/kb/2533623) (https://support.microsoft.com/kb/2533623) **Important** You can still download install the previous KB. However, it may have been replaced with a more recent version. @@ -301,7 +301,7 @@ The installation of the App-V 5.0 server on a computer that runs any previous ve
      • Windows Web Server with the IIS role enabled and the following features: Common HTTP Features (static content and default document), Application Development (ASP.NET, .NET Extensibility, ISAPI Extensions and ISAPI Filters), Security (Windows Authentication, Request Filtering), Management Tools (IIS Management Console).

      • -
      • Download and install KB2533623 (http://support.microsoft.com/kb/2533623)

        +
      • Download and install KB2533623 (https://support.microsoft.com/kb/2533623)

        Important

        You can still download install the previous KB. However, it may have been replaced with a more recent version.

        diff --git a/mdop/mbam-v1/known-issues-in-the-mbam-international-release-mbam-1.md b/mdop/mbam-v1/known-issues-in-the-mbam-international-release-mbam-1.md index 965278e188..d365a7ce2c 100644 --- a/mdop/mbam-v1/known-issues-in-the-mbam-international-release-mbam-1.md +++ b/mdop/mbam-v1/known-issues-in-the-mbam-international-release-mbam-1.md @@ -36,7 +36,7 @@ If you are using a certificate for authentication between MBAM servers, after up ### MBAM Svclog File Filling Disk Space -If you have followed Knowledge Base article 2668170, [http://support.microsoft.com/kb/2668170](https://go.microsoft.com/fwlink/?LinkID=247277), you might have to repeat the KB steps after you install this update. +If you have followed Knowledge Base article 2668170, [https://support.microsoft.com/kb/2668170](https://go.microsoft.com/fwlink/?LinkID=247277), you might have to repeat the KB steps after you install this update. **Workaround**: None. diff --git a/mdop/mbam-v2/mbam-20-privacy-statement-mbam-2.md b/mdop/mbam-v2/mbam-20-privacy-statement-mbam-2.md index 2c93b51293..1d8f677dab 100644 --- a/mdop/mbam-v2/mbam-20-privacy-statement-mbam-2.md +++ b/mdop/mbam-v2/mbam-20-privacy-statement-mbam-2.md @@ -92,7 +92,7 @@ Incorrectly editing the registry may severely damage your system. Before making Important Information: Enterprise customers can use Group Policy to configure how Microsoft Error Reporting behaves on their PCs. Configuration options include the ability to turn off Microsoft Error Reporting. If you are an administrator and wish to configure Group Policy for Microsoft Error Reporting, technical details are available on [TechNet](https://technet.microsoft.com/library/cc709644.aspx). -Additional information on how to modify enable and disable error reporting is available at this support article: [(http://support.microsoft.com/kb/188296)](https://support.microsoft.com/kb/188296). +Additional information on how to modify enable and disable error reporting is available at this support article: [(https://support.microsoft.com/kb/188296)](https://support.microsoft.com/kb/188296). ### Microsoft Update From 7562c72d8cef686febf6f1900736dfb4e6413b2e Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Wed, 29 Jan 2020 16:19:45 -0800 Subject: [PATCH 12/27] fixing build report errors --- devices/hololens/hololens1-start.md | 2 +- .../mdm/certificate-authentication-device-enrollment.md | 2 +- .../mdm/federated-authentication-device-enrollment.md | 2 +- windows/client-management/mdm/mobile-device-enrollment.md | 2 +- .../mdm/on-premise-authentication-device-enrollment.md | 2 +- 5 files changed, 5 insertions(+), 5 deletions(-) diff --git a/devices/hololens/hololens1-start.md b/devices/hololens/hololens1-start.md index 466fc431b2..b6775ce7ee 100644 --- a/devices/hololens/hololens1-start.md +++ b/devices/hololens/hololens1-start.md @@ -28,7 +28,7 @@ Before you get started, make sure you have the following available: **A Microsoft account or a work account**. You'll also need to use a Microsoft account (or a work account, if your organization owns the device) to sign in to HoloLens. If you don't have a Microsoft account, go to [account.microsoft.com](http://account.microsoft.com) and set one up for free. -**A safe, well-lit space with no tripping hazards**. [Health and safety info](http://go.microsoft.com/fwlink/p/?LinkId=746661). +**A safe, well-lit space with no tripping hazards**. [Health and safety info](https://go.microsoft.com/fwlink/p/?LinkId=746661). **The optional comfort accessories** that came with your HoloLens, to help you get the most comfortable fit. [More on fit and comfort](https://support.microsoft.com/help/12632/hololens-fit-your-hololens). diff --git a/windows/client-management/mdm/certificate-authentication-device-enrollment.md b/windows/client-management/mdm/certificate-authentication-device-enrollment.md index 042efca28b..dd72081354 100644 --- a/windows/client-management/mdm/certificate-authentication-device-enrollment.md +++ b/windows/client-management/mdm/certificate-authentication-device-enrollment.md @@ -15,7 +15,7 @@ ms.date: 06/26/2017 # Certificate authentication device enrollment -This section provides an example of the mobile device enrollment protocol using certificate authentication policy. For details about the Microsoft mobile device enrollment protocol for Windows 10, see [\[MS-MDE2\]: Mobile Device Enrollment Protocol Version 2]( http://go.microsoft.com/fwlink/p/?LinkId=619347). +This section provides an example of the mobile device enrollment protocol using certificate authentication policy. For details about the Microsoft mobile device enrollment protocol for Windows 10, see [\[MS-MDE2\]: Mobile Device Enrollment Protocol Version 2]( https://go.microsoft.com/fwlink/p/?LinkId=619347). > **Note**  To set up devices to use certificate authentication for enrollment, you should create a provisioning package. For more information about provisioning packages, see [Build and apply a provisioning package](https://msdn.microsoft.com/library/windows/hardware/dn916107). diff --git a/windows/client-management/mdm/federated-authentication-device-enrollment.md b/windows/client-management/mdm/federated-authentication-device-enrollment.md index 12af80dacf..e8ad3c9cd8 100644 --- a/windows/client-management/mdm/federated-authentication-device-enrollment.md +++ b/windows/client-management/mdm/federated-authentication-device-enrollment.md @@ -19,7 +19,7 @@ This section provides an example of the mobile device enrollment protocol using The <AuthenticationServiceURL> element the discovery response message specifies web authentication broker page start URL. -For details about the Microsoft mobile device enrollment protocol for Windows 10, see [\[MS-MDE2\]: Mobile Device Enrollment Protocol Version 2]( http://go.microsoft.com/fwlink/p/?LinkId=619347). +For details about the Microsoft mobile device enrollment protocol for Windows 10, see [\[MS-MDE2\]: Mobile Device Enrollment Protocol Version 2]( https://go.microsoft.com/fwlink/p/?LinkId=619347). ## In this topic diff --git a/windows/client-management/mdm/mobile-device-enrollment.md b/windows/client-management/mdm/mobile-device-enrollment.md index 3b50e8d5cf..38e128bd28 100644 --- a/windows/client-management/mdm/mobile-device-enrollment.md +++ b/windows/client-management/mdm/mobile-device-enrollment.md @@ -34,7 +34,7 @@ The enrollment process includes the following steps: ## Enrollment protocol -There are a number of changes made to the enrollment protocol to better support a variety of scenarios across all platforms. For detailed information about the mobile device enrollment protocol, see [\[MS-MDM\]: Mobile Device Management Protocol](https://go.microsoft.com/fwlink/p/?LinkId=619346) and [\[MS-MDE2\]: Mobile Device Enrollment Protocol Version 2]( http://go.microsoft.com/fwlink/p/?LinkId=619347). +There are a number of changes made to the enrollment protocol to better support a variety of scenarios across all platforms. For detailed information about the mobile device enrollment protocol, see [\[MS-MDM\]: Mobile Device Management Protocol](https://go.microsoft.com/fwlink/p/?LinkId=619346) and [\[MS-MDE2\]: Mobile Device Enrollment Protocol Version 2]( https://go.microsoft.com/fwlink/p/?LinkId=619347). The enrollment process involves the following steps: diff --git a/windows/client-management/mdm/on-premise-authentication-device-enrollment.md b/windows/client-management/mdm/on-premise-authentication-device-enrollment.md index fc1667fcc2..22c3ac4fbe 100644 --- a/windows/client-management/mdm/on-premise-authentication-device-enrollment.md +++ b/windows/client-management/mdm/on-premise-authentication-device-enrollment.md @@ -14,7 +14,7 @@ ms.date: 06/26/2017 # On-premises authentication device enrollment -This section provides an example of the mobile device enrollment protocol using on-premises authentication policy. For details about the Microsoft mobile device enrollment protocol for Windows 10, see [\[MS-MDE2\]: Mobile Device Enrollment Protocol Version 2]( http://go.microsoft.com/fwlink/p/?LinkId=619347). +This section provides an example of the mobile device enrollment protocol using on-premises authentication policy. For details about the Microsoft mobile device enrollment protocol for Windows 10, see [\[MS-MDE2\]: Mobile Device Enrollment Protocol Version 2]( https://go.microsoft.com/fwlink/p/?LinkId=619347). ## In this topic From 282b1e6892b6d16223417078227c0410b4c347a1 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Wed, 29 Jan 2020 16:24:36 -0800 Subject: [PATCH 13/27] Update antivirus-false-positives-negatives.md --- .../antivirus-false-positives-negatives.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md index d2f4a1c9b5..dbb155a0b2 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md +++ b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md @@ -27,7 +27,7 @@ Windows Defender Antivirus is designed to keep your PC safe with built-in, trust But what if something gets detected wrongly as malware, or something is missed? We call these false positives and false negatives. Fortunately, there are some steps you can take to deal with these things. You can: - [Submit a file to Microsoft for analysis](#submit-a-file-to-microsoft-for-analysis); -- [Create an "Allow" indicator](#create-an-allow-indicator); or +- [Create an "Allow" indicator to prevent a false positive from recurring](#create-an-allow-indicator-to-prevent-a-false-positive-from-recurring); or - [Define an exclusion on an individual Windows device](#define-an-exclusion-on-an-individual-windows-device) in your Windows Defender Antivirus settings. ## Submit a file to Microsoft for analysis @@ -38,7 +38,7 @@ But what if something gets detected wrongly as malware, or something is missed? > [!TIP] > We recommend signing in at the submission portal so you can track the results of your submissions. -## Create an "Allow" indicator +## Create an "Allow" indicator to prevent a false positive from recurring If a file, IP address, URL, or domain is treated as malware on a device, even though it's safe, you can create an "Allow" indicator. This indicator tells Windows Defender Antivirus (and Microsoft Defender Advanced Threat Protection) that the item is safe. From 873fffc8725ffb4e3478b424a4864398dae9b6ca Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Wed, 29 Jan 2020 16:25:19 -0800 Subject: [PATCH 14/27] Update antivirus-false-positives-negatives.md --- .../antivirus-false-positives-negatives.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md index dbb155a0b2..ec65351029 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md +++ b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md @@ -28,7 +28,7 @@ Windows Defender Antivirus is designed to keep your PC safe with built-in, trust But what if something gets detected wrongly as malware, or something is missed? We call these false positives and false negatives. Fortunately, there are some steps you can take to deal with these things. You can: - [Submit a file to Microsoft for analysis](#submit-a-file-to-microsoft-for-analysis); - [Create an "Allow" indicator to prevent a false positive from recurring](#create-an-allow-indicator-to-prevent-a-false-positive-from-recurring); or -- [Define an exclusion on an individual Windows device](#define-an-exclusion-on-an-individual-windows-device) in your Windows Defender Antivirus settings. +- [Define an exclusion on an individual Windows device to prevent an item from being scanned](#define-an-exclusion-on-an-individual-windows-device-to-prevent-an-item-from-being-scanned) by Windows Defender Antivirus. ## Submit a file to Microsoft for analysis @@ -44,7 +44,7 @@ If a file, IP address, URL, or domain is treated as malware on a device, even th To set up your "Allow" indicator, follow the guidance in [Manage indicators](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/manage-indicators). -## Define an exclusion on an individual Windows device +## Define an exclusion on an individual Windows device to prevent an item from being scanned When you define an exclusion for Windows Defender Antivirus, you configure your antivirus to skip that item. From cbb1809620df9f4b56e3ecb7b9445e9545116f2d Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Wed, 5 Feb 2020 13:54:12 -0800 Subject: [PATCH 15/27] moved tamper protection image --- .../{ => images}/tamperprotectsecurityrecos.png | Bin 1 file changed, 0 insertions(+), 0 deletions(-) rename windows/security/threat-protection/windows-defender-antivirus/{ => images}/tamperprotectsecurityrecos.png (100%) diff --git a/windows/security/threat-protection/windows-defender-antivirus/tamperprotectsecurityrecos.png b/windows/security/threat-protection/windows-defender-antivirus/images/tamperprotectsecurityrecos.png similarity index 100% rename from windows/security/threat-protection/windows-defender-antivirus/tamperprotectsecurityrecos.png rename to windows/security/threat-protection/windows-defender-antivirus/images/tamperprotectsecurityrecos.png From 9ee841257e55195ca57e8fced373abdb0d2c9b77 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Wed, 5 Feb 2020 13:54:49 -0800 Subject: [PATCH 16/27] Update antivirus-false-positives-negatives.md --- .../antivirus-false-positives-negatives.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md index ec65351029..c8fe54fe39 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md +++ b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md @@ -12,7 +12,7 @@ ms.localizationpriority: medium author: denisebmsft ms.author: deniseb ms.custom: nextgen -ms.date: 01/29/2020 +ms.date: 02/05/2020 ms.reviewer: manager: dansimp --- @@ -51,7 +51,7 @@ When you define an exclusion for Windows Defender Antivirus, you configure your 1. On your Windows 10 device, open the Windows Security app. 2. Select **Virus & threat protection** > **Virus & threat protection settings**. 3. Under **Exclusions**, select **Add or remove exclusions**. -4. Select **+ Add an exclusion**, and specify its type (**File**, **Folder**, **File type**, or **Process**.) +4. Select **+ Add an exclusion**, and specify its type (**File**, **Folder**, **File type**, or **Process**). ## Related articles From ba65ead669a78c0606246faf180826dbac14e0de Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Wed, 5 Feb 2020 14:30:33 -0800 Subject: [PATCH 17/27] WDAV updates --- .../antivirus-false-positives-negatives.md | 13 +++++++++++ ...e-exclusions-windows-defender-antivirus.md | 22 +++++++------------ 2 files changed, 21 insertions(+), 14 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md index c8fe54fe39..b3ec698443 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md +++ b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md @@ -53,6 +53,19 @@ When you define an exclusion for Windows Defender Antivirus, you configure your 3. Under **Exclusions**, select **Add or remove exclusions**. 4. Select **+ Add an exclusion**, and specify its type (**File**, **Folder**, **File type**, or **Process**). +The following table summarizes exclusion types and what happens: + +|Exclusion type |Defined by |What happens | +|---------|---------|---------| +|**File** |Location
        Example: `c:\sample\sample.test` |The specific file is skipped by Windows Defender Antivirus. | +|**Folder** |Location
        Example: `c:\test\sample` |All items in the specified folder are skipped by Windows Defender Antivirus. | +|**File type** |File extension
        Example: `.test` |All files with the `.test` extension anywhere on your device are skipped by Windows Defender Antivirus. | +|**Process** |Executable file path
        Example: `c:\test\process.exe` |The specific process and any files that are opened by that process are skipped by Windows Defender Antivirus. | + +To learn more, see: +- [Configure and validate exclusions based on file extension and folder location](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-antivirus/configure-extension-file-exclusions-windows-defender-antivirus) +- [Configure exclusions for files opened by processes](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-antivirus/configure-process-opened-file-exclusions-windows-defender-antivirus) + ## Related articles [What is Microsoft Defender Advanced Threat Protection?](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-advanced-threat-protection) diff --git a/windows/security/threat-protection/windows-defender-antivirus/configure-exclusions-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/configure-exclusions-windows-defender-antivirus.md index f6da565014..03cf88d610 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/configure-exclusions-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/configure-exclusions-windows-defender-antivirus.md @@ -12,7 +12,7 @@ ms.localizationpriority: medium author: denisebmsft ms.author: deniseb ms.custom: nextgen -ms.date: 09/03/2018 +ms.date: 02/05/2020 ms.reviewer: manager: dansimp --- @@ -23,21 +23,15 @@ manager: dansimp - [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) -You can exclude certain files, folders, processes, and process-opened files from Windows Defender Antivirus scans. - -The exclusions apply to [scheduled scans](scheduled-catch-up-scans-windows-defender-antivirus.md), [on-demand scans](run-scan-windows-defender-antivirus.md), and [always-on real-time protection and monitoring](configure-real-time-protection-windows-defender-antivirus.md). Exclusions for process-opened files only apply to real-time protection. - -Exclusions can be useful to avoid incorrect detections on files or software that are unique or customized to your organization. - -Windows Server 2016 also features automatic exclusions that are defined by the server roles you enable. See the [Windows Defender Antivirus exclusions on Windows Server 2016](configure-server-exclusions-windows-defender-antivirus.md) topic for more information and a list of the automatic exclusions. +You can exclude certain files, folders, processes, and process-opened files from Windows Defender Antivirus scans. Such exclusions apply to [scheduled scans](scheduled-catch-up-scans-windows-defender-antivirus.md), [on-demand scans](run-scan-windows-defender-antivirus.md), and [always-on real-time protection and monitoring](configure-real-time-protection-windows-defender-antivirus.md). Exclusions for process-opened files only apply to real-time protection. >[!WARNING] >Defining exclusions lowers the protection offered by Windows Defender Antivirus. You should always evaluate the risks that are associated with implementing exclusions, and you should only exclude files that you are confident are not malicious. -## In this section +- [Configure and validate exclusions based on file name, extension, and folder location](configure-extension-file-exclusions-windows-defender-antivirus.md). This enables you to exclude files from Windows Defender Antivirus scans based on their file extension, file name, or location. -Topic | Description ----|--- -[Configure and validate exclusions based on file name, extension, and folder location](configure-extension-file-exclusions-windows-defender-antivirus.md) | Exclude files from Windows Defender Antivirus scans based on their file extension, file name, or location -[Configure and validate exclusions for files opened by processes](configure-process-opened-file-exclusions-windows-defender-antivirus.md) | Exclude files from scans that have been opened by a specific process -[Configure Windows Defender Antivirus exclusions on Windows Server](configure-server-exclusions-windows-defender-antivirus.md) | Windows Server 2016 includes automatic exclusions, based on the defined server role. You can also add custom exclusions. +- [Configure and validate exclusions for files opened by processes](configure-process-opened-file-exclusions-windows-defender-antivirus.md). This enables you to exclude files from scans that have been opened by a specific process. + +## Related articles + +[Windows Defender Antivirus exclusions on Windows Server 2016](configure-server-exclusions-windows-defender-antivirus.md) \ No newline at end of file From 8fdbb82c94238db04ab6d8822b5b2d9eee1fab11 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Wed, 5 Feb 2020 14:36:20 -0800 Subject: [PATCH 18/27] added info about exclusions to an article --- ...on-file-exclusions-windows-defender-antivirus.md | 1 + .../windows-defender-security-center-antivirus.md | 13 +++++++++++++ 2 files changed, 14 insertions(+) diff --git a/windows/security/threat-protection/windows-defender-antivirus/configure-extension-file-exclusions-windows-defender-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/configure-extension-file-exclusions-windows-defender-antivirus.md index 9a1559d85e..588354937a 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/configure-extension-file-exclusions-windows-defender-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/configure-extension-file-exclusions-windows-defender-antivirus.md @@ -364,3 +364,4 @@ You can also copy the string into a blank text file and attempt to save it with - [Configure Windows Defender Antivirus exclusions on Windows Server](configure-server-exclusions-windows-defender-antivirus.md) - [Customize, initiate, and review the results of Windows Defender Antivirus scans and remediation](customize-run-review-remediate-scans-windows-defender-antivirus.md) - [Windows Defender Antivirus in Windows 10](windows-defender-antivirus-in-windows-10.md) +- [Handling false positives/negatives](antivirus-false-positives-negatives.md) diff --git a/windows/security/threat-protection/windows-defender-antivirus/windows-defender-security-center-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/windows-defender-security-center-antivirus.md index be4f7240f1..0272945883 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/windows-defender-security-center-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/windows-defender-security-center-antivirus.md @@ -130,6 +130,19 @@ This section describes how to perform some of the most common tasks when reviewi 5. Click the plus icon to choose the type and set the options for each exclusion. +The following table summarizes exclusion types and what happens: + +|Exclusion type |Defined by |What happens | +|---------|---------|---------| +|**File** |Location
        Example: `c:\sample\sample.test` |The specific file is skipped by Windows Defender Antivirus. | +|**Folder** |Location
        Example: `c:\test\sample` |All items in the specified folder are skipped by Windows Defender Antivirus. | +|**File type** |File extension
        Example: `.test` |All files with the `.test` extension anywhere on your device are skipped by Windows Defender Antivirus. | +|**Process** |Executable file path
        Example: `c:\test\process.exe` |The specific process and any files that are opened by that process are skipped by Windows Defender Antivirus. | + +To learn more, see: +- [Configure and validate exclusions based on file extension and folder location](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-antivirus/configure-extension-file-exclusions-windows-defender-antivirus) +- [Configure exclusions for files opened by processes](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-antivirus/configure-process-opened-file-exclusions-windows-defender-antivirus) + ### Review threat detection history in the Windows Defender Security Center app 1. Open the Windows Defender Security Center app by clicking the shield icon in the task bar or  From c6577616b27bec36e2978636a0f12b1d1a94301c Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Wed, 5 Feb 2020 14:37:38 -0800 Subject: [PATCH 19/27] Update windows-defender-security-center-antivirus.md --- .../windows-defender-security-center-antivirus.md | 10 +++------- 1 file changed, 3 insertions(+), 7 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-antivirus/windows-defender-security-center-antivirus.md b/windows/security/threat-protection/windows-defender-antivirus/windows-defender-security-center-antivirus.md index 0272945883..75d23d70dd 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/windows-defender-security-center-antivirus.md +++ b/windows/security/threat-protection/windows-defender-antivirus/windows-defender-security-center-antivirus.md @@ -27,18 +27,14 @@ In Windows 10, version 1703 and later, the Windows Defender app is part of the W Settings that were previously part of the Windows Defender client and main Windows Settings have been combined and moved to the new app, which is installed by default as part of Windows 10, version 1703. > [!IMPORTANT] -> Disabling the Windows Security Center service will not disable Windows Defender AV or [Windows Defender Firewall](https://docs.microsoft.com/windows/access-protection/windows-firewall/windows-firewall-with-advanced-security). These are disabled automatically when a third-party antivirus or firewall product is installed and kept up to date. - -> [!WARNING] -> If you do disable the Windows Security Center service, or configure its associated Group Policy settings to prevent it from starting or running, the Windows Security app may display stale or inaccurate information about any antivirus or firewall products you have installed on the device. +> Disabling the Windows Security Center service will not disable Windows Defender AV or [Windows Defender Firewall](https://docs.microsoft.com/windows/access-protection/windows-firewall/windows-firewall-with-advanced-security). These are disabled automatically when a third-party antivirus or firewall product is installed and kept up to date.
        If you do disable the Windows Security Center service, or configure its associated Group Policy settings to prevent it from starting or running, the Windows Security app may display stale or inaccurate information about any antivirus or firewall products you have installed on the device. >It may also prevent Windows Defender AV from enabling itself if you have an old or outdated third-party antivirus, or if you uninstall any third-party antivirus products you may have previously installed. >This will significantly lower the protection of your device and could lead to malware infection. -See the [Windows Security topic](/windows/threat-protection/windows-defender-security-center/windows-defender-security-center) for more information on other Windows security features that can be monitored in the app. +See the [Windows Security article](/windows/threat-protection/windows-defender-security-center/windows-defender-security-center) for more information on other Windows security features that can be monitored in the app. ->[!NOTE] ->The Windows Security app is a client interface on Windows 10, version 1703 and later. It is not the Microsoft Defender Security Center web portal that is used to review and manage [Microsoft Defender Advanced Threat Protection](../microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md). +The Windows Security app is a client interface on Windows 10, version 1703 and later. It is not the Microsoft Defender Security Center web portal that is used to review and manage [Microsoft Defender Advanced Threat Protection](../microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md). ## Review virus and threat protection settings in the Windows Security app From 9f42299f8f47af1ac38dc8dbb6b0461fb8f456f5 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Wed, 5 Feb 2020 14:42:06 -0800 Subject: [PATCH 20/27] Update antivirus-false-positives-negatives.md --- .../antivirus-false-positives-negatives.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md index b3ec698443..c4a9efffe4 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md +++ b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md @@ -23,7 +23,7 @@ manager: dansimp - [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) -Windows Defender Antivirus is designed to keep your PC safe with built-in, trusted antivirus protection. With Windows Defender Antivirus, you get comprehensive, ongoing, and real-time protection against software threats like viruses, malware and spyware across email, apps, the cloud and the web. +Windows Defender Antivirus is designed to keep your PC safe with built-in, trusted antivirus protection. With Windows Defender Antivirus, you get comprehensive, ongoing, and real-time protection against software threats like viruses, malware and spyware across email, apps, the cloud, and the web. But what if something gets detected wrongly as malware, or something is missed? We call these false positives and false negatives. Fortunately, there are some steps you can take to deal with these things. You can: - [Submit a file to Microsoft for analysis](#submit-a-file-to-microsoft-for-analysis); From 123a9e94c4ad8c84ea4850c1f373e461cb618800 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Wed, 5 Feb 2020 14:46:00 -0800 Subject: [PATCH 21/27] Update antivirus-false-positives-negatives.md --- .../antivirus-false-positives-negatives.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md index c4a9efffe4..be96f51375 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md +++ b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md @@ -57,10 +57,10 @@ The following table summarizes exclusion types and what happens: |Exclusion type |Defined by |What happens | |---------|---------|---------| -|**File** |Location
        Example: `c:\sample\sample.test` |The specific file is skipped by Windows Defender Antivirus. | +|**File** |Location
        Example: `c:\sample\sample.test` |The specified file is skipped by Windows Defender Antivirus. | |**Folder** |Location
        Example: `c:\test\sample` |All items in the specified folder are skipped by Windows Defender Antivirus. | -|**File type** |File extension
        Example: `.test` |All files with the `.test` extension anywhere on your device are skipped by Windows Defender Antivirus. | -|**Process** |Executable file path
        Example: `c:\test\process.exe` |The specific process and any files that are opened by that process are skipped by Windows Defender Antivirus. | +|**File type** |File extension
        Example: `.test` |All files with the specified extension anywhere on your device are skipped by Windows Defender Antivirus. | +|**Process** |Executable file path
        Example: `c:\test\process.exe` |The specified process and any files that are opened by that process are skipped by Windows Defender Antivirus. | To learn more, see: - [Configure and validate exclusions based on file extension and folder location](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-antivirus/configure-extension-file-exclusions-windows-defender-antivirus) From 54b5c9f22444a1a25eea5de635a4e718b6653127 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Wed, 5 Feb 2020 14:50:48 -0800 Subject: [PATCH 22/27] Update prevent-changes-to-security-settings-with-tamper-protection.md --- ...event-changes-to-security-settings-with-tamper-protection.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/windows-defender-antivirus/prevent-changes-to-security-settings-with-tamper-protection.md b/windows/security/threat-protection/windows-defender-antivirus/prevent-changes-to-security-settings-with-tamper-protection.md index 0005561984..b5d731b602 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/prevent-changes-to-security-settings-with-tamper-protection.md +++ b/windows/security/threat-protection/windows-defender-antivirus/prevent-changes-to-security-settings-with-tamper-protection.md @@ -147,7 +147,7 @@ Tamper protection integrates with [Threat & Vulnerability Management](https://do In the results, you can select **Turn on Tamper Protection** to learn more and turn it on. -![Turn on tamper protection](tamperprotectsecurityrecos.png) +![Turn on tamper protection](images/tamperprotectsecurityrecos.png) To learn more about Threat & Vulnerability Management, see [Threat & Vulnerability Management in Microsoft Defender Security Center](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/tvm-dashboard-insights#threat--vulnerability-management-in-microsoft-defender-security-center). From a25aaa8276749d7f0912b3c867dc40c896bb5b21 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Wed, 5 Feb 2020 14:51:33 -0800 Subject: [PATCH 23/27] Update hololens1-start.md --- devices/hololens/hololens1-start.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/devices/hololens/hololens1-start.md b/devices/hololens/hololens1-start.md index b6775ce7ee..f5521a25f4 100644 --- a/devices/hololens/hololens1-start.md +++ b/devices/hololens/hololens1-start.md @@ -6,7 +6,7 @@ ms.prod: hololens author: Teresa-Motiv ms.author: v-tea ms.topic: article -ms.date: 8/12/19 +ms.date: 8/12/2019 manager: jarrettr ms.topic: article ms.localizationpriority: high From 0f520fc888384e812d87a38af5157b2d90c0741c Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Wed, 5 Feb 2020 14:51:49 -0800 Subject: [PATCH 24/27] Update hololens1-start.md --- devices/hololens/hololens1-start.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/devices/hololens/hololens1-start.md b/devices/hololens/hololens1-start.md index f5521a25f4..8cb970020a 100644 --- a/devices/hololens/hololens1-start.md +++ b/devices/hololens/hololens1-start.md @@ -26,7 +26,7 @@ Before you get started, make sure you have the following available: **A Wi-Fi connection**. You'll need to connect your HoloLens to a Wi-Fi network to set it up. The first time you connect, you'll need an open or password-protected network that doesn't require navigating to a website or using certificates to connect. [Learn more about the websites that HoloLens uses](hololens-offline.md). -**A Microsoft account or a work account**. You'll also need to use a Microsoft account (or a work account, if your organization owns the device) to sign in to HoloLens. If you don't have a Microsoft account, go to [account.microsoft.com](http://account.microsoft.com) and set one up for free. +**A Microsoft account or a work account**. You'll also need to use a Microsoft account (or a work account, if your organization owns the device) to sign in to HoloLens. If you don't have a Microsoft account, go to [account.microsoft.com](https://account.microsoft.com) and set one up for free. **A safe, well-lit space with no tripping hazards**. [Health and safety info](https://go.microsoft.com/fwlink/p/?LinkId=746661). From 289354f9114b5f16c329c0c13d2d97e264a4c005 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Wed, 5 Feb 2020 16:20:05 -0800 Subject: [PATCH 25/27] Update antivirus-false-positives-negatives.md --- .../antivirus-false-positives-negatives.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md index be96f51375..b39189a69e 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md +++ b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md @@ -15,6 +15,8 @@ ms.custom: nextgen ms.date: 02/05/2020 ms.reviewer: manager: dansimp +ms.audience: ITPro +ms.topic: article --- # What to do with false positives/negatives in Windows Defender Antivirus From f01fcd00148f608e94fcce6c91ea4a95ecc48612 Mon Sep 17 00:00:00 2001 From: Denise Vangel-MSFT Date: Wed, 5 Feb 2020 16:21:07 -0800 Subject: [PATCH 26/27] Update antivirus-false-positives-negatives.md --- .../antivirus-false-positives-negatives.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md index b39189a69e..6d229cc84b 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md +++ b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md @@ -55,7 +55,7 @@ When you define an exclusion for Windows Defender Antivirus, you configure your 3. Under **Exclusions**, select **Add or remove exclusions**. 4. Select **+ Add an exclusion**, and specify its type (**File**, **Folder**, **File type**, or **Process**). -The following table summarizes exclusion types and what happens: +The following table summarizes exclusion types, how they're defined, and what happens when they're in effect. |Exclusion type |Defined by |What happens | |---------|---------|---------| From aaef29335950a24bdd26238db1525509d803a279 Mon Sep 17 00:00:00 2001 From: Tina Burden Date: Thu, 6 Feb 2020 08:17:33 -0800 Subject: [PATCH 27/27] pencil edit --- .../antivirus-false-positives-negatives.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md index 6d229cc84b..228378515b 100644 --- a/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md +++ b/windows/security/threat-protection/windows-defender-antivirus/antivirus-false-positives-negatives.md @@ -15,7 +15,7 @@ ms.custom: nextgen ms.date: 02/05/2020 ms.reviewer: manager: dansimp -ms.audience: ITPro +audience: ITPro ms.topic: article --- @@ -72,4 +72,4 @@ To learn more, see: [What is Microsoft Defender Advanced Threat Protection?](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/microsoft-defender-advanced-threat-protection) -[Microsoft Threat Protection](https://docs.microsoft.com/microsoft-365/security/mtp/microsoft-threat-protection) \ No newline at end of file +[Microsoft Threat Protection](https://docs.microsoft.com/microsoft-365/security/mtp/microsoft-threat-protection)