From c741449916f8bae8da2d59f7c9106e63b10cf887 Mon Sep 17 00:00:00 2001 From: Vinay Pamnani <37223378+vinaypamnani-msft@users.noreply.github.com> Date: Fri, 5 May 2023 16:38:41 -0400 Subject: [PATCH] Add tamper protection note to Defender CSP --- windows/client-management/mdm/defender-csp.md | 2 ++ ...icy-csp-admx-microsoftdefenderantivirus.md | 30 +++++++++++++++++++ .../mdm/policy-csp-defender.md | 24 +++++++++++++++ 3 files changed, 56 insertions(+) diff --git a/windows/client-management/mdm/defender-csp.md b/windows/client-management/mdm/defender-csp.md index 7550924275..a036a0332b 100644 --- a/windows/client-management/mdm/defender-csp.md +++ b/windows/client-management/mdm/defender-csp.md @@ -2212,6 +2212,8 @@ Tamper protection helps protect important security features from unwanted change +> [!NOTE] +> Changes to this setting are not applied when [tamper protection](https://go.microsoft.com/fwlink/?LinkId=2236030) is enabled. diff --git a/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus.md b/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus.md index 07eef1894d..0a138841a5 100644 --- a/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus.md +++ b/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus.md @@ -115,6 +115,8 @@ Enabling or disabling this policy may lead to unexpected or unsupported behavior +> [!NOTE] +> Changes to this setting are not applied when [tamper protection](https://go.microsoft.com/fwlink/?LinkId=2236030) is enabled. @@ -244,6 +246,8 @@ Real-time Protection -> Do not enable the "Turn off real-time protection" policy +> [!NOTE] +> Changes to this setting are not applied when [tamper protection](https://go.microsoft.com/fwlink/?LinkId=2236030) is enabled. @@ -366,6 +370,8 @@ Real-time protection consists of always-on scanning with file and process behavi +> [!NOTE] +> Changes to this setting are not applied when [tamper protection](https://go.microsoft.com/fwlink/?LinkId=2236030) is enabled. @@ -426,6 +432,8 @@ This policy setting allows you to configure whether Microsoft Defender Antivirus +> [!NOTE] +> Changes to this setting are not applied when [tamper protection](https://go.microsoft.com/fwlink/?LinkId=2236030) is enabled. @@ -482,6 +490,8 @@ This policy setting allows you specify a list of file types that should be exclu +> [!NOTE] +> To prevent unauthorized changes to exclusions, apply tamper protection. Tamper protection for exclusions only works when [certain conditions](https://go.microsoft.com/fwlink/?linkid=2235765) are met. @@ -538,6 +548,8 @@ This policy setting allows you to disable scheduled and real-time scanning for f +> [!NOTE] +> To prevent unauthorized changes to exclusions, apply tamper protection. Tamper protection for exclusions only works when [certain conditions](https://go.microsoft.com/fwlink/?linkid=2235765) are met. @@ -594,6 +606,8 @@ This policy setting allows you to disable real-time scanning for any file opened +> [!NOTE] +> To prevent unauthorized changes to exclusions, apply tamper protection. Tamper protection for exclusions only works when [certain conditions](https://go.microsoft.com/fwlink/?linkid=2235765) are met. @@ -1577,6 +1591,8 @@ This policy setting allows you to configure behavior monitoring. +> [!NOTE] +> Changes to this setting are not applied when [tamper protection](https://go.microsoft.com/fwlink/?LinkId=2236030) is enabled. @@ -1637,6 +1653,8 @@ This policy setting allows you to configure scanning for all downloaded files an +> [!NOTE] +> Changes to this setting are not applied when [tamper protection](https://go.microsoft.com/fwlink/?LinkId=2236030) is enabled. @@ -1697,6 +1715,8 @@ This policy setting allows you to configure monitoring for file and program acti +> [!NOTE] +> Changes to this setting are not applied when [tamper protection](https://go.microsoft.com/fwlink/?LinkId=2236030) is enabled. @@ -1817,6 +1837,8 @@ This policy setting allows you to configure process scanning when real-time prot +> [!NOTE] +> Changes to this setting are not applied when [tamper protection](https://go.microsoft.com/fwlink/?LinkId=2236030) is enabled. @@ -2540,6 +2562,8 @@ Use this policy setting to specify if you want Microsoft Defender Antivirus enha +> [!NOTE] +> Changes to this setting are not applied when [tamper protection](https://go.microsoft.com/fwlink/?LinkId=2236030) is enabled. @@ -3069,6 +3093,8 @@ This policy setting allows you to configure scans for malicious software and unw +> [!NOTE] +> Changes to this setting are not applied when [tamper protection](https://go.microsoft.com/fwlink/?LinkId=2236030) is enabled. @@ -5551,6 +5577,8 @@ Use this policy setting to specify if you want Microsoft Defender Antivirus noti +> [!NOTE] +> Changes to this setting are not applied when [tamper protection](https://go.microsoft.com/fwlink/?LinkId=2236030) is enabled. @@ -5609,6 +5637,8 @@ If you enable this setting AM UI won't show reboot notifications. +> [!NOTE] +> Changes to this setting are not applied when [tamper protection](https://go.microsoft.com/fwlink/?LinkId=2236030) is enabled. diff --git a/windows/client-management/mdm/policy-csp-defender.md b/windows/client-management/mdm/policy-csp-defender.md index 1f26de308e..77b56fa11d 100644 --- a/windows/client-management/mdm/policy-csp-defender.md +++ b/windows/client-management/mdm/policy-csp-defender.md @@ -46,6 +46,8 @@ This policy setting allows you to configure scans for malicious software and unw +> [!NOTE] +> Changes to this setting are not applied when [tamper protection](https://go.microsoft.com/fwlink/?LinkId=2236030) is enabled. @@ -113,6 +115,8 @@ This policy setting allows you to configure behavior monitoring. +> [!NOTE] +> Changes to this setting are not applied when [tamper protection](https://go.microsoft.com/fwlink/?LinkId=2236030) is enabled. @@ -193,6 +197,8 @@ In Windows 10, Basic membership is no longer available, so setting the value to +> [!NOTE] +> Changes to this setting are not applied when [tamper protection](https://go.microsoft.com/fwlink/?LinkId=2236030) is enabled. @@ -457,6 +463,8 @@ Allows or disallows Windows Defender Intrusion Prevention functionality. +> [!NOTE] +> Changes to this setting are not applied when [tamper protection](https://go.microsoft.com/fwlink/?LinkId=2236030) is enabled. @@ -510,6 +518,8 @@ This policy setting allows you to configure scanning for all downloaded files an +> [!NOTE] +> Changes to this setting are not applied when [tamper protection](https://go.microsoft.com/fwlink/?LinkId=2236030) is enabled. @@ -577,6 +587,8 @@ This policy setting allows you to configure monitoring for file and program acti +> [!NOTE] +> Changes to this setting are not applied when [tamper protection](https://go.microsoft.com/fwlink/?LinkId=2236030) is enabled. @@ -640,6 +652,8 @@ Allows or disallows Windows Defender Realtime Monitoring functionality. +> [!NOTE] +> Changes to this setting are not applied when [tamper protection](https://go.microsoft.com/fwlink/?LinkId=2236030) is enabled. @@ -769,6 +783,8 @@ Allows or disallows Windows Defender Script Scanning functionality. +> [!NOTE] +> Changes to this setting are not applied when [tamper protection](https://go.microsoft.com/fwlink/?LinkId=2236030) is enabled. @@ -1891,6 +1907,8 @@ This policy setting allows you specify a list of file types that should be exclu +> [!NOTE] +> To prevent unauthorized changes to exclusions, apply tamper protection. Tamper protection for exclusions only works when [certain conditions](https://go.microsoft.com/fwlink/?linkid=2235765) are met. @@ -1945,6 +1963,8 @@ This policy setting allows you to disable scheduled and real-time scanning for f +> [!NOTE] +> To prevent unauthorized changes to exclusions, apply tamper protection. Tamper protection for exclusions only works when [certain conditions](https://go.microsoft.com/fwlink/?linkid=2235765) are met. @@ -1999,6 +2019,8 @@ This policy setting allows you to disable real-time scanning for any file opened +> [!NOTE] +> To prevent unauthorized changes to exclusions, apply tamper protection. Tamper protection for exclusions only works when [certain conditions](https://go.microsoft.com/fwlink/?linkid=2235765) are met. @@ -2790,6 +2812,8 @@ Valid remediation action values are: +> [!NOTE] +> Changes to this setting are not applied when [tamper protection](https://go.microsoft.com/fwlink/?LinkId=2236030) is enabled.