# [Threat protection](index.md) ## [Overview]() ### [What is Microsoft Defender Advanced Threat Protection?](microsoft-defender-atp/microsoft-defender-advanced-threat-protection.md) ### [Overview of Microsoft Defender ATP capabilities](microsoft-defender-atp/overview.md) ### [Threat & Vulnerability Management]() #### [Next-generation capabilities](microsoft-defender-atp/next-gen-threat-and-vuln-mgt.md) #### [What's in the dashboard and what it means for my organization](microsoft-defender-atp/tvm-dashboard-insights.md) #### [Exposure score](microsoft-defender-atp/tvm-exposure-score.md) #### [Configuration score](microsoft-defender-atp/configuration-score.md) #### [Security recommendation](microsoft-defender-atp/tvm-security-recommendation.md) #### [Remediation](microsoft-defender-atp/tvm-remediation.md) #### [Software inventory](microsoft-defender-atp/tvm-software-inventory.md) #### [Weaknesses](microsoft-defender-atp/tvm-weaknesses.md) #### [Scenarios](microsoft-defender-atp/threat-and-vuln-mgt-scenarios.md) ### [Attack surface reduction]() #### [Overview of attack surface reduction](microsoft-defender-atp/overview-attack-surface-reduction.md) #### [Hardware-based isolation]() ##### [Hardware-based isolation in Windows 10](microsoft-defender-atp/overview-hardware-based-isolation.md) ##### [Application isolation]() ###### [Application guard overview](windows-defender-application-guard/wd-app-guard-overview.md) ###### [System requirements](windows-defender-application-guard/reqs-wd-app-guard.md) ##### [System integrity](windows-defender-system-guard/system-guard-how-hardware-based-root-of-trust-helps-protect-windows.md) #### [Application control](windows-defender-application-control/windows-defender-application-control.md) #### [Exploit protection](microsoft-defender-atp/exploit-protection.md) #### [Network protection](microsoft-defender-atp/network-protection.md) #### [Controlled folder access](microsoft-defender-atp/controlled-folders.md) #### [Attack surface reduction](microsoft-defender-atp/attack-surface-reduction.md) #### [Network firewall](windows-firewall/windows-firewall-with-advanced-security.md) ### [Next generation protection](windows-defender-antivirus/windows-defender-antivirus-in-windows-10.md) ### [Endpoint detection and response]() #### [Endpoint detection and response overview](microsoft-defender-atp/overview-endpoint-detection-response.md) #### [Security operations dashboard](microsoft-defender-atp/security-operations-dashboard.md) #### [Incidents queue]() ##### [View and organize the Incidents queue](microsoft-defender-atp/view-incidents-queue.md) ##### [Manage incidents](microsoft-defender-atp/manage-incidents.md) ##### [Investigate incidents](microsoft-defender-atp/investigate-incidents.md) #### [Alerts queue]() ##### [View and organize the Alerts queue](microsoft-defender-atp/alerts-queue.md) ##### [Manage alerts](microsoft-defender-atp/manage-alerts.md) ##### [Investigate alerts](microsoft-defender-atp/investigate-alerts.md) ##### [Investigate files](microsoft-defender-atp/investigate-files.md) ##### [Investigate machines](microsoft-defender-atp/investigate-machines.md) ##### [Investigate an IP address](microsoft-defender-atp/investigate-ip.md) ##### [Investigate a domain](microsoft-defender-atp/investigate-domain.md) ###### [Investigate connection events that occur behind forward proxies](microsoft-defender-atp/investigate-behind-proxy.md) ##### [Investigate a user account](microsoft-defender-atp/investigate-user.md) #### [Machines list]() ##### [View and organize the Machines list](microsoft-defender-atp/machines-view-overview.md) ##### [Manage machine group and tags](microsoft-defender-atp/machine-tags.md) #### [Take response actions]() ##### [Take response actions on a machine]() ###### [Response actions on machines](microsoft-defender-atp/respond-machine-alerts.md) ###### [Manage tags](microsoft-defender-atp/respond-machine-alerts.md#manage-tags) ###### [Initiate Automated investigation](microsoft-defender-atp/respond-machine-alerts.md#initiate-automated-investigation) ###### [Initiate Live Response session](microsoft-defender-atp/respond-machine-alerts.md#initiate-live-response-session) ###### [Collect investigation package](microsoft-defender-atp/respond-machine-alerts.md#collect-investigation-package-from-machines) ###### [Run antivirus scan](microsoft-defender-atp/respond-machine-alerts.md#run-windows-defender-antivirus-scan-on-machines) ###### [Restrict app execution](microsoft-defender-atp/respond-machine-alerts.md#restrict-app-execution) ###### [Isolate machines from the network](microsoft-defender-atp/respond-machine-alerts.md#isolate-machines-from-the-network) ####### [Check activity details in Action center](microsoft-defender-atp/respond-machine-alerts.md#check-activity-details-in-action-center) ##### [Take response actions on a file]() ###### [Response actions on files](microsoft-defender-atp/respond-file-alerts.md) ###### [Stop and quarantine files in your network](microsoft-defender-atp/respond-file-alerts.md#stop-and-quarantine-files-in-your-network) ###### [Restore file from quarantine](microsoft-defender-atp/respond-file-alerts.md#restore-file-from-quarantine) ###### [Add indicators to block or allow a file](microsoft-defender-atp/respond-file-alerts.md#add-indicator-to-block-or-allow-a-file) ###### [Check activity details in Action center](microsoft-defender-atp/respond-file-alerts.md#check-activity-details-in-action-center) ###### [Download or collect file](microsoft-defender-atp/respond-file-alerts.md#download-or-collect-file) ###### [Deep analysis](microsoft-defender-atp/respond-file-alerts.md#deep-analysis) ###### [Submit files for analysis](microsoft-defender-atp/respond-file-alerts.md#submit-files-for-analysis) ###### [View deep analysis reports](microsoft-defender-atp/respond-file-alerts.md#view-deep-analysis-reports) ###### [Troubleshoot deep analysis](microsoft-defender-atp/respond-file-alerts.md#troubleshoot-deep-analysis) ##### [Investigate entities using Live response]() ###### [Investigate entities on machines](microsoft-defender-atp/live-response.md) ###### [Live response command examples](microsoft-defender-atp/live-response-command-examples.md) ### [Automated investigation and remediation]() #### [Automated investigation and remediation overview](microsoft-defender-atp/automated-investigations.md) #### [Learn about the automated investigation and remediation dashboard](microsoft-defender-atp/manage-auto-investigation.md) ##### [Manage actions related to automated investigation and remediation](microsoft-defender-atp/auto-investigation-action-center.md) ### [Secure score](microsoft-defender-atp/overview-secure-score.md) ### [Threat analytics](microsoft-defender-atp/threat-analytics.md) ### [Advanced hunting]() #### [Advanced hunting overview](microsoft-defender-atp/overview-hunting.md) #### [Query data using Advanced hunting](microsoft-defender-atp/advanced-hunting.md) #### [Advanced hunting schema reference]() ##### [All tables in the Advanced hunting schema](microsoft-defender-atp/advanced-hunting-reference.md) ##### [AlertEvents table](microsoft-defender-atp/advanced-hunting-alertevents-table.md) ##### [FileCreationEvents table](microsoft-defender-atp/advanced-hunting-filecreationevents-table.md) ##### [ImageLoadEvents table](microsoft-defender-atp/advanced-hunting-imageloadevents-table.md) ##### [LogonEvents table](microsoft-defender-atp/advanced-hunting-logonevents-table.md) ##### [MachineInfo table](microsoft-defender-atp/advanced-hunting-machineinfo-table.md) ##### [MachineNetworkInfo table](microsoft-defender-atp/advanced-hunting-machinenetworkinfo-table.md) ##### [MiscEvents table](microsoft-defender-atp/advanced-hunting-miscevents-table.md) ##### [NetworkCommunicationEvents table](microsoft-defender-atp/advanced-hunting-networkcommunicationevents-table.md) ##### [ProcessCreationEvents table](microsoft-defender-atp/advanced-hunting-processcreationevents-table.md) ##### [RegistryEvents table](microsoft-defender-atp/advanced-hunting-registryevents-table.md) #### [Advanced hunting query language best practices](microsoft-defender-atp/advanced-hunting-best-practices.md) #### [Custom detections]() ##### [Understand custom detection rules](microsoft-defender-atp/overview-custom-detections.md) ##### [Create custom detections rules](microsoft-defender-atp/custom-detection-rules.md) ### [Management and APIs]() #### [Overview of management and APIs](microsoft-defender-atp/management-apis.md) #### [Understand threat intelligence concepts](microsoft-defender-atp/threat-indicator-concepts.md) #### [Managed security service provider support](microsoft-defender-atp/mssp-support.md) ### [Integrations]() #### [Microsoft Defender ATP integrations](microsoft-defender-atp/threat-protection-integration.md) #### [Protect users, data, and devices with conditional access](microsoft-defender-atp/conditional-access.md) #### [Microsoft Cloud App Security integration overview](microsoft-defender-atp/microsoft-cloud-app-security-integration.md) ### [Information protection in Windows overview]() #### [Windows integration](microsoft-defender-atp/information-protection-in-windows-overview.md) #### [Use sensitivity labels to prioritize incident response](microsoft-defender-atp/information-protection-investigation.md) ### [Microsoft Threat Experts](microsoft-defender-atp/microsoft-threat-experts.md) ### [Portal overview](microsoft-defender-atp/portal-overview.md) ### [Microsoft Defender ATP for US Government Community Cloud High customers](microsoft-defender-atp/commercial-gov.md) ## [Get started]() ### [What's new in Microsoft Defender ATP](microsoft-defender-atp/whats-new-in-microsoft-defender-atp.md) ### [Minimum requirements](microsoft-defender-atp/minimum-requirements.md) ### [Validate licensing and complete setup](microsoft-defender-atp/licensing.md) ### [Evaluation lab](microsoft-defender-atp/evaluation-lab.md) ### [Preview features](microsoft-defender-atp/preview.md) ### [Data storage and privacy](microsoft-defender-atp/data-storage-privacy.md) ### [Assign user access to the portal](microsoft-defender-atp/assign-portal-access.md) ### [Evaluate Microsoft Defender ATP]() #### [Attack surface reduction and next-generation capability evaluation]() ##### [Attack surface reduction and nex-generation evaluation overview](microsoft-defender-atp/evaluate-atp.md) ##### [Hardware-based isolation](windows-defender-application-guard/test-scenarios-wd-app-guard.md) ##### [Application control](windows-defender-application-control/audit-windows-defender-application-control-policies.md) ##### [Exploit protection](microsoft-defender-atp/evaluate-exploit-protection.md) ##### [Network Protection](microsoft-defender-atp/evaluate-network-protection.md) ##### [Controlled folder access](microsoft-defender-atp/evaluate-controlled-folder-access.md) ##### [Attack surface reduction](microsoft-defender-atp/evaluate-attack-surface-reduction.md) ##### [Network firewall](windows-firewall/evaluating-windows-firewall-with-advanced-security-design-examples.md) ##### [Evaluate next generation protection](windows-defender-antivirus/evaluate-windows-defender-antivirus.md) ### [Access the Windows Defender Security Center Community Center](microsoft-defender-atp/community.md) ## [Configure and manage capabilities]() ### [Configure attack surface reduction]() #### [Attack surface reduction configuration settings](microsoft-defender-atp/configure-attack-surface-reduction.md) ### [Hardware-based isolation]() #### [System isolation](windows-defender-system-guard/system-guard-secure-launch-and-smm-protection.md) #### [Application isolation]() ##### [Install Windows Defender Application Guard](windows-defender-application-guard/install-wd-app-guard.md) ##### [Application control](windows-defender-application-control/windows-defender-application-control.md) #### [Device control]() ##### [Control USB devices](device-control/control-usb-devices-using-intune.md) ##### [Device Guard]() ###### [Code integrity](device-guard/introduction-to-device-guard-virtualization-based-security-and-windows-defender-application-control.md) ###### [Memory integrity]() ####### [Understand memory integrity](device-guard/memory-integrity.md) ####### [Hardware qualifications](device-guard/requirements-and-deployment-planning-guidelines-for-virtualization-based-protection-of-code-integrity.md) ####### [Enable HVCI](device-guard/enable-virtualization-based-protection-of-code-integrity.md) #### [Exploit protection]() ##### [Enable exploit protection](microsoft-defender-atp/enable-exploit-protection.md) ##### [Import/export configurations](microsoft-defender-atp/import-export-exploit-protection-emet-xml.md) #### [Network protection](microsoft-defender-atp/enable-network-protection.md) #### [Controlled folder access](microsoft-defender-atp/enable-controlled-folders.md) #### [Attack surface reduction controls]() ##### [Enable attack surface reduction rules](microsoft-defender-atp/enable-attack-surface-reduction.md) ##### [Customize attack surface reduction](microsoft-defender-atp/customize-attack-surface-reduction.md) #### [Network firewall](windows-firewall/windows-firewall-with-advanced-security-deployment-guide.md) ### [Configure next generation protection]() #### [Configure Windows Defender Antivirus features](windows-defender-antivirus/configure-windows-defender-antivirus-features.md) #### [Utilize Microsoft cloud-delivered protection](windows-defender-antivirus/utilize-microsoft-cloud-protection-windows-defender-antivirus.md) ##### [Enable cloud-delivered protection](windows-defender-antivirus/enable-cloud-protection-windows-defender-antivirus.md) ##### [Specify the cloud-delivered protection level](windows-defender-antivirus/specify-cloud-protection-level-windows-defender-antivirus.md) ##### [Configure and validate network connections](windows-defender-antivirus/configure-network-connections-windows-defender-antivirus.md) ##### [Prevent security settings changes with tamper protection](windows-defender-antivirus/prevent-changes-to-security-settings-with-tamper-protection.md) ##### [Enable Block at first sight](windows-defender-antivirus/configure-block-at-first-sight-windows-defender-antivirus.md) ##### [Configure the cloud block timeout period](windows-defender-antivirus/configure-cloud-block-timeout-period-windows-defender-antivirus.md) #### [Configure behavioral, heuristic, and real-time protection]() ##### [Configuration overview](windows-defender-antivirus/configure-protection-features-windows-defender-antivirus.md) ##### [Detect and block Potentially Unwanted Applications](windows-defender-antivirus/detect-block-potentially-unwanted-apps-windows-defender-antivirus.md) ##### [Enable and configure always-on protection and monitoring](windows-defender-antivirus/configure-real-time-protection-windows-defender-antivirus.md) #### [Antivirus on Windows Server 2016](windows-defender-antivirus/windows-defender-antivirus-on-windows-server-2016.md) #### [Antivirus compatibility]() ##### [Compatibility charts](windows-defender-antivirus/windows-defender-antivirus-compatibility.md) ##### [Use limited periodic antivirus scanning](windows-defender-antivirus/limited-periodic-scanning-windows-defender-antivirus.md) #### [Deploy, manage updates, and report on antivirus]() ##### [Preparing to deploy](windows-defender-antivirus/deploy-manage-report-windows-defender-antivirus.md) ##### [Deploy and enable antivirus](windows-defender-antivirus/deploy-windows-defender-antivirus.md) ###### [Deployment guide for VDI environments](windows-defender-antivirus/deployment-vdi-windows-defender-antivirus.md) ##### [Report on antivirus protection]() ###### [Review protection status and alerts](windows-defender-antivirus/report-monitor-windows-defender-antivirus.md) ###### [Troubleshoot antivirus reporting in Update Compliance](windows-defender-antivirus/troubleshoot-reporting.md) ##### [Manage updates and apply baselines]() ###### [Learn about the different kinds of updates](windows-defender-antivirus/manage-updates-baselines-windows-defender-antivirus.md) ###### [Manage protection and security intelligence updates](windows-defender-antivirus/manage-protection-updates-windows-defender-antivirus.md) ###### [Manage when protection updates should be downloaded and applied](windows-defender-antivirus/manage-protection-update-schedule-windows-defender-antivirus.md) ###### [Manage updates for endpoints that are out of date](windows-defender-antivirus/manage-outdated-endpoints-windows-defender-antivirus.md) ###### [Manage event-based forced updates](windows-defender-antivirus/manage-event-based-updates-windows-defender-antivirus.md) ###### [Manage updates for mobile devices and VMs](windows-defender-antivirus/manage-updates-mobile-devices-vms-windows-defender-antivirus.md) #### [Customize, initiate, and review the results of scans and remediation]() ##### [Configuration overview](windows-defender-antivirus/customize-run-review-remediate-scans-windows-defender-antivirus.md) ##### [Configure and validate exclusions in antivirus scans]() ###### [Exclusions overview](windows-defender-antivirus/configure-exclusions-windows-defender-antivirus.md) ###### [Configure and validate exclusions based on file name, extension, and folder location](windows-defender-antivirus/configure-extension-file-exclusions-windows-defender-antivirus.md) ###### [Configure and validate exclusions for files opened by processes](windows-defender-antivirus/configure-process-opened-file-exclusions-windows-defender-antivirus.md) ###### [Configure antivirus exclusions Windows Server 2016](windows-defender-antivirus/configure-server-exclusions-windows-defender-antivirus.md) ##### [Configure scanning antivirus options](windows-defender-antivirus/configure-advanced-scan-types-windows-defender-antivirus.md) ##### [Configure remediation for scans](windows-defender-antivirus/configure-remediation-windows-defender-antivirus.md) ##### [Configure scheduled scans](windows-defender-antivirus/scheduled-catch-up-scans-windows-defender-antivirus.md) ##### [Configure and run scans](windows-defender-antivirus/run-scan-windows-defender-antivirus.md) ##### [Review scan results](windows-defender-antivirus/review-scan-results-windows-defender-antivirus.md) ##### [Run and review the results of an offline scan](windows-defender-antivirus/windows-defender-offline.md) #### [Restore quarantined files](windows-defender-antivirus/restore-quarantined-files-windows-defender-antivirus.md) #### [Manage antivirus in your business]() ##### [Management overview](windows-defender-antivirus/configuration-management-reference-windows-defender-antivirus.md) ##### [Use Group Policy settings to configure and manage antivirus](windows-defender-antivirus/use-group-policy-windows-defender-antivirus.md) ##### [Use System Center Configuration Manager and Microsoft Intune to configure and manage antivirus](windows-defender-antivirus/use-intune-config-manager-windows-defender-antivirus.md) ##### [Use PowerShell cmdlets to configure and manage antivirus](windows-defender-antivirus/use-powershell-cmdlets-windows-defender-antivirus.md) ##### [Use Windows Management Instrumentation (WMI) to configure and manage antivirus](windows-defender-antivirus/use-wmi-windows-defender-antivirus.md) ##### [Use the mpcmdrun.exe commandline tool to configure and manage antivirus](windows-defender-antivirus/command-line-arguments-windows-defender-antivirus.md) #### [Manage scans and remediation]() ##### [Management overview](windows-defender-antivirus/customize-run-review-remediate-scans-windows-defender-antivirus.md) ##### [Configure and validate exclusions in antivirus scans]() ###### [Exclusions overview](windows-defender-antivirus/configure-exclusions-windows-defender-antivirus.md) ###### [Configure and validate exclusions based on file name, extension, and folder location](windows-defender-antivirus/configure-extension-file-exclusions-windows-defender-antivirus.md) ###### [Configure and validate exclusions for files opened by processes](windows-defender-antivirus/configure-process-opened-file-exclusions-windows-defender-antivirus.md) ###### [Configure antivirus exclusions on Windows Server 2016](windows-defender-antivirus/configure-server-exclusions-windows-defender-antivirus.md) ##### [Configure scanning options](windows-defender-antivirus/configure-advanced-scan-types-windows-defender-antivirus.md) #### [Configure remediation for scans](windows-defender-antivirus/configure-remediation-windows-defender-antivirus.md) ##### [Configure remediation for scans](windows-defender-antivirus/configure-remediation-windows-defender-antivirus.md) ##### [Configure scheduled scans](windows-defender-antivirus/scheduled-catch-up-scans-windows-defender-antivirus.md) ##### [Configure and run scans](windows-defender-antivirus/run-scan-windows-defender-antivirus.md) ##### [Review scan results](windows-defender-antivirus/review-scan-results-windows-defender-antivirus.md) ##### [Run and review the results of an offline scan](windows-defender-antivirus/windows-defender-offline.md) ##### [Restore quarantined files](windows-defender-antivirus/restore-quarantined-files-windows-defender-antivirus.md) #### [Manage next generation protection in your business]() ##### [Management overview](windows-defender-antivirus/configuration-management-reference-windows-defender-antivirus.md) ##### [Management overview](windows-defender-antivirus/configuration-management-reference-windows-defender-antivirus.md) ##### [Use Microsoft Intune and System Center Configuration Manager to manage next generation protection](windows-defender-antivirus/use-intune-config-manager-windows-defender-antivirus.md) ##### [Use Group Policy settings to manage next generation protection](windows-defender-antivirus/use-group-policy-windows-defender-antivirus.md) ##### [Use PowerShell cmdlets to manage next generation protection](windows-defender-antivirus/use-powershell-cmdlets-windows-defender-antivirus.md) ##### [Use Windows Management Instrumentation (WMI) to manage next generation protection](windows-defender-antivirus/use-wmi-windows-defender-antivirus.md) ##### [Use the mpcmdrun.exe command line tool to manage next generation protection](windows-defender-antivirus/command-line-arguments-windows-defender-antivirus.md) ### [Microsoft Defender Advanced Threat Protection for Mac](windows-defender-antivirus/microsoft-defender-atp-mac.md) #### [Deploy Microsoft Defender Advanced Threat Protection for Mac]() ##### [Microsoft Intune-based deployment](windows-defender-antivirus/microsoft-defender-atp-mac-install-with-intune.md) ##### [JAMF-based deployment](windows-defender-antivirus/microsoft-defender-atp-mac-install-with-jamf.md) ##### [Deployment with a different Mobile Device Management (MDM) system](windows-defender-antivirus/microsoft-defender-atp-mac-install-with-other-mdm.md) ##### [Manual deployment](windows-defender-antivirus/microsoft-defender-atp-mac-install-manually.md) #### [Update Microsoft Defender ATP for Mac](windows-defender-antivirus/microsoft-defender-atp-mac-updates.md) #### [Set preferences for Microsoft Defender ATP for Mac](windows-defender-antivirus/microsoft-defender-atp-mac-preferences.md) #### [Privacy for Microsoft Defender ATP for Mac](windows-defender-antivirus/microsoft-defender-atp-mac-privacy.md) #### [Resources for Microsoft Defender ATP for Mac](windows-defender-antivirus/microsoft-defender-atp-mac-resources.md) ### [Configure Secure score dashboard security controls](microsoft-defender-atp/secure-score-dashboard.md) ### [Configure and manage Microsoft Threat Experts capabilities](microsoft-defender-atp/configure-microsoft-threat-experts.md) ### [Management and API support]() #### [Onboard devices to the service]() ##### [Onboard machines to Microsoft Defender ATP](microsoft-defender-atp/onboard-configure.md) ##### [Onboard previous versions of Windows](microsoft-defender-atp/onboard-downlevel.md) ##### [Onboard Windows 10 machines]() ###### [Onboarding tools and methods](microsoft-defender-atp/configure-endpoints.md) ###### [Onboard machines using Group Policy](microsoft-defender-atp/configure-endpoints-gp.md) ###### [Onboard machines using System Center Configuration Manager](microsoft-defender-atp/configure-endpoints-sccm.md) ###### [Onboard machines using Mobile Device Management tools](microsoft-defender-atp/configure-endpoints-mdm.md) ###### [Onboard machines using a local script](microsoft-defender-atp/configure-endpoints-script.md) ###### [Onboard non-persistent virtual desktop infrastructure (VDI) machines](microsoft-defender-atp/configure-endpoints-vdi.md) ##### [Onboard servers](microsoft-defender-atp/configure-server-endpoints.md) ##### [Onboard non-Windows machines](microsoft-defender-atp/configure-endpoints-non-windows.md) ##### [Onboard machines without Internet access](microsoft-defender-atp/onboard-offline-machines.md) ##### [Run a detection test on a newly onboarded machine](microsoft-defender-atp/run-detection-test.md) ##### [Run simulated attacks on machines](microsoft-defender-atp/attack-simulations.md) ##### [Configure proxy and Internet connectivity settings](microsoft-defender-atp/configure-proxy-internet.md) ##### [Create an onboarding or offboarding notification rule](microsoft-defender-atp/onboarding-notification.md) ##### [Troubleshoot onboarding issues]() ###### [Troubleshoot issues during onboarding](microsoft-defender-atp/troubleshoot-onboarding.md) ###### [Troubleshoot subscription and portal access issues](microsoft-defender-atp/troubleshoot-onboarding-error-messages.md) #### [Microsoft Defender ATP API]() ##### [Microsoft Defender ATP API license and terms](microsoft-defender-atp/api-terms-of-use.md) ##### [Get started with Microsoft Defender ATP APIs]() ###### [Introduction](microsoft-defender-atp/apis-intro.md) ###### [Hello World](microsoft-defender-atp/api-hello-world.md) ###### [Get access with application context](microsoft-defender-atp/exposed-apis-create-app-webapp.md) ###### [Get access with user context](microsoft-defender-atp/exposed-apis-create-app-nativeapp.md) ##### [APIs]() ###### [Supported Microsoft Defender ATP query APIs](microsoft-defender-atp/exposed-apis-list.md) ###### [Advanced Hunting](microsoft-defender-atp/run-advanced-query-api.md) ###### [Alert]() ####### [Alert methods and properties](microsoft-defender-atp/alerts.md) ####### [List alerts](microsoft-defender-atp/get-alerts.md) ####### [Create alert](microsoft-defender-atp/create-alert-by-reference.md) ####### [Update Alert](microsoft-defender-atp/update-alert.md) ####### [Get alert information by ID](microsoft-defender-atp/get-alert-info-by-id.md) ####### [Get alert related domains information](microsoft-defender-atp/get-alert-related-domain-info.md) ####### [Get alert related file information](microsoft-defender-atp/get-alert-related-files-info.md) ####### [Get alert related IPs information](microsoft-defender-atp/get-alert-related-ip-info.md) ####### [Get alert related machine information](microsoft-defender-atp/get-alert-related-machine-info.md) ####### [Get alert related user information](microsoft-defender-atp/get-alert-related-user-info.md) ###### [Machine]() ####### [Machine methods and properties](microsoft-defender-atp/machine.md) ####### [List machines](microsoft-defender-atp/get-machines.md) ####### [Get machine by ID](microsoft-defender-atp/get-machine-by-id.md) ####### [Get machine log on users](microsoft-defender-atp/get-machine-log-on-users.md) ####### [Get machine related alerts](microsoft-defender-atp/get-machine-related-alerts.md) ####### [Add or Remove machine tags](microsoft-defender-atp/add-or-remove-machine-tags.md) ####### [Find machines by IP](microsoft-defender-atp/find-machines-by-ip.md) ###### [Machine Action]() ####### [Machine Action methods and properties](microsoft-defender-atp/machineaction.md) ####### [List Machine Actions](microsoft-defender-atp/get-machineactions-collection.md) ####### [Get Machine Action](microsoft-defender-atp/get-machineaction-object.md) ####### [Collect investigation package](microsoft-defender-atp/collect-investigation-package.md) ####### [Get investigation package SAS URI](microsoft-defender-atp/get-package-sas-uri.md) ####### [Isolate machine](microsoft-defender-atp/isolate-machine.md) ####### [Release machine from isolation](microsoft-defender-atp/unisolate-machine.md) ####### [Restrict app execution](microsoft-defender-atp/restrict-code-execution.md) ####### [Remove app restriction](microsoft-defender-atp/unrestrict-code-execution.md) ####### [Run antivirus scan](microsoft-defender-atp/run-av-scan.md) ####### [Offboard machine](microsoft-defender-atp/offboard-machine-api.md) ####### [Stop and quarantine file](microsoft-defender-atp/stop-and-quarantine-file.md) ####### [Initiate investigation (preview)](microsoft-defender-atp/initiate-autoir-investigation.md) ###### [Indicators]() ####### [Indicators methods and properties](microsoft-defender-atp/ti-indicator.md) ####### [Submit Indicator](microsoft-defender-atp/post-ti-indicator.md) ####### [List Indicators](microsoft-defender-atp/get-ti-indicators-collection.md) ####### [Delete Indicator](microsoft-defender-atp/delete-ti-indicator-by-id.md) ###### [Domain]() ####### [Get domain related alerts](microsoft-defender-atp/get-domain-related-alerts.md) ####### [Get domain related machines](microsoft-defender-atp/get-domain-related-machines.md) ####### [Get domain statistics](microsoft-defender-atp/get-domain-statistics.md) ###### [File]() ####### [File methods and properties](microsoft-defender-atp/files.md) ####### [Get file information](microsoft-defender-atp/get-file-information.md) ####### [Get file related alerts](microsoft-defender-atp/get-file-related-alerts.md) ####### [Get file related machines](microsoft-defender-atp/get-file-related-machines.md) ####### [Get file statistics](microsoft-defender-atp/get-file-statistics.md) ###### [IP]() ####### [Get IP related alerts](microsoft-defender-atp/get-ip-related-alerts.md) ####### [Get IP statistics](microsoft-defender-atp/get-ip-statistics.md) ###### [User]() ####### [User methods](microsoft-defender-atp/user.md) ####### [Get user related alerts](microsoft-defender-atp/get-user-related-alerts.md) ####### [Get user related machines](microsoft-defender-atp/get-user-related-machines.md) ##### [How to use APIs - Samples]() ###### [Microsoft Flow](microsoft-defender-atp/api-microsoft-flow.md) ###### [Power BI](microsoft-defender-atp/api-power-bi.md) ###### [Advanced Hunting using Python](microsoft-defender-atp/run-advanced-query-sample-python.md) ###### [Advanced Hunting using PowerShell](microsoft-defender-atp/run-advanced-query-sample-powershell.md) ###### [Using OData Queries](microsoft-defender-atp/exposed-apis-odata-samples.md) #### [Windows updates (KB) info]() ##### [Get KbInfo collection](microsoft-defender-atp/get-kbinfo-collection.md) #### [Common Vulnerabilities and Exposures (CVE) to KB map]() ##### [Get CVE-KB map](microsoft-defender-atp/get-cvekbmap-collection.md) #### [API for custom alerts (Deprecated)]() ##### [Use the threat intelligence API to create custom alerts (Deprecated)](microsoft-defender-atp/use-custom-ti.md) ##### [Create custom threat intelligence alerts (Deprecated)](microsoft-defender-atp/custom-ti-api.md) ##### [PowerShell code examples (Deprecated)](microsoft-defender-atp/powershell-example-code.md) ##### [Python code examples (Deprecated)](microsoft-defender-atp/python-example-code.md) ##### [Experiment with custom threat intelligence alerts (Deprecated)](microsoft-defender-atp/experiment-custom-ti.md) ##### [Troubleshoot custom threat intelligence issues (Deprecated)](microsoft-defender-atp/troubleshoot-custom-ti.md) #### [Pull detections to your SIEM tools]() ##### [Learn about different ways to pull detections](microsoft-defender-atp/configure-siem.md) ##### [Enable SIEM integration](microsoft-defender-atp/enable-siem-integration.md) ##### [Configure Splunk to pull detections](microsoft-defender-atp/configure-splunk.md) ##### [Configure HP ArcSight to pull detections](microsoft-defender-atp/configure-arcsight.md) ##### [Microsoft Defender ATP detection fields](microsoft-defender-atp/api-portal-mapping.md) ##### [Pull detections using SIEM REST API](microsoft-defender-atp/pull-alerts-using-rest-api.md) ##### [Troubleshoot SIEM tool integration issues](microsoft-defender-atp/troubleshoot-siem.md) #### [Reporting]() ##### [Create and build Power BI reports using Microsoft Defender ATP data](microsoft-defender-atp/powerbi-reports.md) ##### [Threat protection reports](microsoft-defender-atp/threat-protection-reports.md) ##### [Machine health and compliance reports](microsoft-defender-atp/machine-reports.md) #### [Interoperability]() ##### [Partner applications](microsoft-defender-atp/partner-applications.md) #### [Manage machine configuration]() ##### [Ensure your machines are configured properly](microsoft-defender-atp/configure-machines.md) ##### [Monitor and increase machine onboarding](microsoft-defender-atp/configure-machines-onboarding.md) ##### [Increase compliance to the security baseline](microsoft-defender-atp/configure-machines-security-baseline.md) ##### [Optimize ASR rule deployment and detections](microsoft-defender-atp/configure-machines-asr.md) #### [Role-based access control]() ##### [Manage portal access using RBAC](microsoft-defender-atp/rbac.md) ##### [Create and manage roles](microsoft-defender-atp/user-roles.md) ##### [Create and manage machine groups]() ###### [Using machine groups](microsoft-defender-atp/machine-groups.md) ###### [Create and manage machine tags](microsoft-defender-atp/machine-tags.md) #### [Configure managed security service provider (MSSP) support](microsoft-defender-atp/configure-mssp-support.md) ### [Configure Microsoft threat protection integration]() #### [Configure conditional access](microsoft-defender-atp/configure-conditional-access.md) #### [Configure Microsoft Cloud App Security integration](microsoft-defender-atp/microsoft-cloud-app-security-config.md) #### [Configure information protection in Windows](microsoft-defender-atp/information-protection-in-windows-config.md) ### [Configure portal settings]() #### [Set up preferences](microsoft-defender-atp/preferences-setup.md) #### [General]() ##### [Update data retention settings](microsoft-defender-atp/data-retention-settings.md) ##### [Configure alert notifications](microsoft-defender-atp/configure-email-notifications.md) ##### [Enable and create Power BI reports using Windows Defender Security center data](microsoft-defender-atp/powerbi-reports.md) ##### [Enable Secure score security controls](microsoft-defender-atp/enable-secure-score.md) ##### [Configure advanced features](microsoft-defender-atp/advanced-features.md) #### [Permissions]() ##### [Use basic permissions to access the portal](microsoft-defender-atp/basic-permissions.md) ##### [Manage portal access using RBAC](microsoft-defender-atp/rbac.md) ###### [Create and manage roles](microsoft-defender-atp/user-roles.md) ###### [Create and manage machine groups](microsoft-defender-atp/machine-groups.md) ####### [Create and manage machine tags](microsoft-defender-atp/machine-tags.md) #### [APIs]() ##### [Enable Threat intel (Deprecated)](microsoft-defender-atp/enable-custom-ti.md) ##### [Enable SIEM integration](microsoft-defender-atp/enable-siem-integration.md) #### [Rules]() ##### [Manage suppression rules](microsoft-defender-atp/manage-suppression-rules.md) ##### [Manage indicators](microsoft-defender-atp/manage-indicators.md) ##### [Manage automation file uploads](microsoft-defender-atp/manage-automation-file-uploads.md) ##### [Manage automation folder exclusions](microsoft-defender-atp/manage-automation-folder-exclusions.md) #### [Machine management]() ##### [Onboarding machines](microsoft-defender-atp/onboard-configure.md) ##### [Offboarding machines](microsoft-defender-atp/offboard-machines.md) #### [Configure Microsoft Defender Security Center time zone settings](microsoft-defender-atp/time-settings.md) ## [Troubleshoot Microsoft Defender ATP]() ### [Troubleshoot sensor state]() #### [Check sensor state](microsoft-defender-atp/check-sensor-status.md) #### [Fix unhealthy sensors](microsoft-defender-atp/fix-unhealthy-sensors.md) #### [Inactive machines](microsoft-defender-atp/fix-unhealthy-sensors.md#inactive-machines) #### [Misconfigured machines](microsoft-defender-atp/fix-unhealthy-sensors.md#misconfigured-machines) #### [Review sensor events and errors on machines with Event Viewer](microsoft-defender-atp/event-error-codes.md) ### [Troubleshoot Microsoft Defender ATP service issues]() #### [Troubleshoot service issues](microsoft-defender-atp/troubleshoot-mdatp.md) #### [Check service health](microsoft-defender-atp/service-status.md) ### [Troubleshoot live response issues]() #### [Troubleshoot issues related to live response](microsoft-defender-atp/troubleshoot-live-response.md) ### [Troubleshoot attack surface reduction]() #### [Network protection](microsoft-defender-atp/troubleshoot-np.md) #### [Attack surface reduction rules](microsoft-defender-atp/troubleshoot-asr.md) ### [Troubleshoot next generation protection](windows-defender-antivirus/troubleshoot-windows-defender-antivirus.md) ## [Security intelligence](intelligence/index.md) ### [Understand malware & other threats](intelligence/understanding-malware.md) #### [Prevent malware infection](intelligence/prevent-malware-infection.md) #### [Malware names](intelligence/malware-naming.md) #### [Coin miners](intelligence/coinminer-malware.md) #### [Exploits and exploit kits](intelligence/exploits-malware.md) #### [Fileless threats](intelligence/fileless-threats.md) #### [Macro malware](intelligence/macro-malware.md) #### [Phishing](intelligence/phishing.md) #### [Ransomware](intelligence/ransomware-malware.md) #### [Rootkits](intelligence/rootkits-malware.md) #### [Supply chain attacks](intelligence/supply-chain-malware.md) #### [Tech support scams](intelligence/support-scams.md) #### [Trojans](intelligence/trojans-malware.md) #### [Unwanted software](intelligence/unwanted-software.md) #### [Worms](intelligence/worms-malware.md) ### [How Microsoft identifies malware and PUA](intelligence/criteria.md) ### [Submit files for analysis](intelligence/submission-guide.md) ### [Safety Scanner download](intelligence/safety-scanner-download.md) ### [Industry antivirus tests](intelligence/top-scoring-industry-antivirus-tests.md) ### [Industry collaboration programs](intelligence/cybersecurity-industry-partners.md) #### [Virus information alliance](intelligence/virus-information-alliance-criteria.md) #### [Microsoft virus initiative](intelligence/virus-initiative-criteria.md) #### [Coordinated malware eradication](intelligence/coordinated-malware-eradication.md) ### [Information for developers](intelligence/developer-info.md) #### [Software developer FAQ](intelligence/developer-faq.md) #### [Software developer resources](intelligence/developer-resources.md) ## Windows Certifications ### [FIPS 140 Validations](fips-140-validation.md) ### [Common Criteria Certifications](windows-platform-common-criteria.md) ## More Windows 10 security ### [The Windows Security app](windows-defender-security-center/windows-defender-security-center.md) #### [Customize the Windows Security app for your organization](windows-defender-security-center/wdsc-customize-contact-information.md) #### [Hide Windows Security app notifications](windows-defender-security-center/wdsc-hide-notifications.md) #### [Manage Windows Security app in Windows 10 in S mode](windows-defender-security-center/wdsc-windows-10-in-s-mode.md) #### [Virus and threat protection](windows-defender-security-center/wdsc-virus-threat-protection.md) #### [Account protection](windows-defender-security-center/wdsc-account-protection.md) #### [Firewall and network protection](windows-defender-security-center/wdsc-firewall-network-protection.md) #### [App and browser control](windows-defender-security-center/wdsc-app-browser-control.md) #### [Device security](windows-defender-security-center/wdsc-device-security.md) #### [Device performance and health](windows-defender-security-center/wdsc-device-performance-health.md) #### [Family options](windows-defender-security-center/wdsc-family-options.md) ### [SmartScreen](windows-defender-smartscreen/windows-defender-smartscreen-overview.md) #### [SmartScreen Group Policy and mobile device management (MDM) settings](windows-defender-smartscreen/windows-defender-smartscreen-available-settings.md) #### [Set up and use SmartScreen on individual devices](windows-defender-smartscreen/windows-defender-smartscreen-set-individual-device.md) ### [Windows Defender Device Guard: virtualization-based security and WDAC](device-guard/introduction-to-device-guard-virtualization-based-security-and-windows-defender-application-control.md) ### [Control the health of Windows 10-based devices](protect-high-value-assets-by-controlling-the-health-of-windows-10-based-devices.md) ### [Mitigate threats by using Windows 10 security features](overview-of-threat-mitigations-in-windows-10.md) ### [Override Process Mitigation Options to help enforce app-related security policies](override-mitigation-options-for-app-related-security-policies.md) ### [Use Windows Event Forwarding to help with intrusion detection](use-windows-event-forwarding-to-assist-in-intrusion-detection.md) ### [Block untrusted fonts in an enterprise](block-untrusted-fonts-in-enterprise.md) ### [Security auditing](auditing/security-auditing-overview.md) #### [Basic security audit policies](auditing/basic-security-audit-policies.md) ##### [Create a basic audit policy for an event category](auditing/create-a-basic-audit-policy-settings-for-an-event-category.md) ##### [Apply a basic audit policy on a file or folder](auditing/apply-a-basic-audit-policy-on-a-file-or-folder.md) ##### [View the security event log](auditing/view-the-security-event-log.md) ##### [Basic security audit policy settings](auditing/basic-security-audit-policy-settings.md) ###### [Audit account logon events](auditing/basic-audit-account-logon-events.md) ###### [Audit account management](auditing/basic-audit-account-management.md) ###### [Audit directory service access](auditing/basic-audit-directory-service-access.md) ###### [Audit logon events](auditing/basic-audit-logon-events.md) ###### [Audit object access](auditing/basic-audit-object-access.md) ###### [Audit policy change](auditing/basic-audit-policy-change.md) ###### [Audit privilege use](auditing/basic-audit-privilege-use.md) ###### [Audit process tracking](auditing/basic-audit-process-tracking.md) ###### [Audit system events](auditing/basic-audit-system-events.md) #### [Advanced security audit policies](auditing/advanced-security-auditing.md) ##### [Planning and deploying advanced security audit policies](auditing/planning-and-deploying-advanced-security-audit-policies.md) ##### [Advanced security auditing FAQ](auditing/advanced-security-auditing-faq.md) ###### [Which editions of Windows support advanced audit policy configuration](auditing/which-editions-of-windows-support-advanced-audit-policy-configuration.md) ###### [How to list XML elements in \](auditing/how-to-list-xml-elements-in-eventdata.md) ###### [Using advanced security auditing options to monitor dynamic access control objects](auditing/using-advanced-security-auditing-options-to-monitor-dynamic-access-control-objects.md) ####### [Monitor the central access policies that apply on a file server](auditing/monitor-the-central-access-policies-that-apply-on-a-file-server.md) ####### [Monitor the use of removable storage devices](auditing/monitor-the-use-of-removable-storage-devices.md) ####### [Monitor resource attribute definitions](auditing/monitor-resource-attribute-definitions.md) ####### [Monitor central access policy and rule definitions](auditing/monitor-central-access-policy-and-rule-definitions.md) ####### [Monitor user and device claims during sign-in](auditing/monitor-user-and-device-claims-during-sign-in.md) ####### [Monitor the resource attributes on files and folders](auditing/monitor-the-resource-attributes-on-files-and-folders.md) ####### [Monitor the central access policies associated with files and folders](auditing/monitor-the-central-access-policies-associated-with-files-and-folders.md) ####### [Monitor claim types](auditing/monitor-claim-types.md) ###### [Advanced security audit policy settings](auditing/advanced-security-audit-policy-settings.md) ####### [Audit Credential Validation](auditing/audit-credential-validation.md) ####### [Event 4774 S, F: An account was mapped for logon.](auditing/event-4774.md) ####### [Event 4775 F: An account could not be mapped for logon.](auditing/event-4775.md) ####### [Event 4776 S, F: The computer attempted to validate the credentials for an account.](auditing/event-4776.md) ####### [Event 4777 F: The domain controller failed to validate the credentials for an account.](auditing/event-4777.md) ###### [Audit Kerberos Authentication Service](auditing/audit-kerberos-authentication-service.md) ####### [Event 4768 S, F: A Kerberos authentication ticket, TGT, was requested.](auditing/event-4768.md) ####### [Event 4771 F: Kerberos pre-authentication failed.](auditing/event-4771.md) ####### [Event 4772 F: A Kerberos authentication ticket request failed.](auditing/event-4772.md) ###### [Audit Kerberos Service Ticket Operations](auditing/audit-kerberos-service-ticket-operations.md) ####### [Event 4769 S, F: A Kerberos service ticket was requested.](auditing/event-4769.md) ####### [Event 4770 S: A Kerberos service ticket was renewed.](auditing/event-4770.md) ####### [Event 4773 F: A Kerberos service ticket request failed.](auditing/event-4773.md) ###### [Audit Other Account Logon Events](auditing/audit-other-account-logon-events.md) ###### [Audit Application Group Management](auditing/audit-application-group-management.md) ###### [Audit Computer Account Management](auditing/audit-computer-account-management.md) ####### [Event 4741 S: A computer account was created.](auditing/event-4741.md) ####### [Event 4742 S: A computer account was changed.](auditing/event-4742.md) ####### [Event 4743 S: A computer account was deleted.](auditing/event-4743.md) ###### [Audit Distribution Group Management](auditing/audit-distribution-group-management.md) ####### [Event 4749 S: A security-disabled global group was created.](auditing/event-4749.md) ####### [Event 4750 S: A security-disabled global group was changed.](auditing/event-4750.md) ####### [Event 4751 S: A member was added to a security-disabled global group.](auditing/event-4751.md) ####### [Event 4752 S: A member was removed from a security-disabled global group.](auditing/event-4752.md) ####### [Event 4753 S: A security-disabled global group was deleted.](auditing/event-4753.md) ###### [Audit Other Account Management Events](auditing/audit-other-account-management-events.md) ####### [Event 4782 S: The password hash of an account was accessed.](auditing/event-4782.md) ####### [Event 4793 S: The Password Policy Checking API was called.](auditing/event-4793.md) ###### [Audit Security Group Management](auditing/audit-security-group-management.md) ####### [Event 4731 S: A security-enabled local group was created.](auditing/event-4731.md) ####### [Event 4732 S: A member was added to a security-enabled local group.](auditing/event-4732.md) ####### [Event 4733 S: A member was removed from a security-enabled local group.](auditing/event-4733.md) ####### [Event 4734 S: A security-enabled local group was deleted.](auditing/event-4734.md) ####### [Event 4735 S: A security-enabled local group was changed.](auditing/event-4735.md) ####### [Event 4764 S: A group�s type was changed.](auditing/event-4764.md) ####### [Event 4799 S: A security-enabled local group membership was enumerated.](auditing/event-4799.md) ###### [Audit User Account Management](auditing/audit-user-account-management.md) ####### [Event 4720 S: A user account was created.](auditing/event-4720.md) ####### [Event 4722 S: A user account was enabled.](auditing/event-4722.md) ####### [Event 4723 S, F: An attempt was made to change an account's password.](auditing/event-4723.md) ####### [Event 4724 S, F: An attempt was made to reset an account's password.](auditing/event-4724.md) ####### [Event 4725 S: A user account was disabled.](auditing/event-4725.md) ####### [Event 4726 S: A user account was deleted.](auditing/event-4726.md) ####### [Event 4738 S: A user account was changed.](auditing/event-4738.md) ####### [Event 4740 S: A user account was locked out.](auditing/event-4740.md) ####### [Event 4765 S: SID History was added to an account.](auditing/event-4765.md) ####### [Event 4766 F: An attempt to add SID History to an account failed.](auditing/event-4766.md) ####### [Event 4767 S: A user account was unlocked.](auditing/event-4767.md) ####### [Event 4780 S: The ACL was set on accounts which are members of administrators groups.](auditing/event-4780.md) ####### [Event 4781 S: The name of an account was changed.](auditing/event-4781.md) ####### [Event 4794 S, F: An attempt was made to set the Directory Services Restore Mode administrator password.](auditing/event-4794.md) ####### [Event 4798 S: A user's local group membership was enumerated.](auditing/event-4798.md) ####### [Event 5376 S: Credential Manager credentials were backed up.](auditing/event-5376.md) ####### [Event 5377 S: Credential Manager credentials were restored from a backup.](auditing/event-5377.md) ###### [Audit DPAPI Activity](auditing/audit-dpapi-activity.md) ####### [Event 4692 S, F: Backup of data protection master key was attempted.](auditing/event-4692.md) ####### [Event 4693 S, F: Recovery of data protection master key was attempted.](auditing/event-4693.md) ####### [Event 4694 S, F: Protection of auditable protected data was attempted.](auditing/event-4694.md) ####### [Event 4695 S, F: Unprotection of auditable protected data was attempted.](auditing/event-4695.md) ###### [Audit PNP Activity](auditing/audit-pnp-activity.md) ####### [Event 6416 S: A new external device was recognized by the System.](auditing/event-6416.md) ####### [Event 6419 S: A request was made to disable a device.](auditing/event-6419.md) ####### [Event 6420 S: A device was disabled.](auditing/event-6420.md) ####### [Event 6421 S: A request was made to enable a device.](auditing/event-6421.md) ####### [Event 6422 S: A device was enabled.](auditing/event-6422.md) ####### [Event 6423 S: The installation of this device is forbidden by system policy.](auditing/event-6423.md) ####### [Event 6424 S: The installation of this device was allowed, after having previously been forbidden by policy.](auditing/event-6424.md) ###### [Audit Process Creation](auditing/audit-process-creation.md) ####### [Event 4688 S: A new process has been created.](auditing/event-4688.md) ####### [Event 4696 S: A primary token was assigned to process.](auditing/event-4696.md) ###### [Audit Process Termination](auditing/audit-process-termination.md) ####### [Event 4689 S: A process has exited.](auditing/event-4689.md) ###### [Audit RPC Events](auditing/audit-rpc-events.md) ####### [Event 5712 S: A Remote Procedure Call, RPC, was attempted.](auditing/event-5712.md) ###### [Audit Detailed Directory Service Replication](auditing/audit-detailed-directory-service-replication.md) ####### [Event 4928 S, F: An Active Directory replica source naming context was established.](auditing/event-4928.md) ####### [Event 4929 S, F: An Active Directory replica source naming context was removed.](auditing/event-4929.md) ####### [Event 4930 S, F: An Active Directory replica source naming context was modified.](auditing/event-4930.md) ####### [Event 4931 S, F: An Active Directory replica destination naming context was modified.](auditing/event-4931.md) ####### [Event 4934 S: Attributes of an Active Directory object were replicated.](auditing/event-4934.md) ####### [Event 4935 F: Replication failure begins.](auditing/event-4935.md) ####### [Event 4936 S: Replication failure ends.](auditing/event-4936.md) ####### [Event 4937 S: A lingering object was removed from a replica.](auditing/event-4937.md) ###### [Audit Directory Service Access](auditing/audit-directory-service-access.md) ####### [Event 4662 S, F: An operation was performed on an object.](auditing/event-4662.md) ####### [Event 4661 S, F: A handle to an object was requested.](auditing/event-4661.md) ###### [Audit Directory Service Changes](auditing/audit-directory-service-changes.md) ####### [Event 5136 S: A directory service object was modified.](auditing/event-5136.md) ####### [Event 5137 S: A directory service object was created.](auditing/event-5137.md) ####### [Event 5138 S: A directory service object was undeleted.](auditing/event-5138.md) ####### [Event 5139 S: A directory service object was moved.](auditing/event-5139.md) ####### [Event 5141 S: A directory service object was deleted.](auditing/event-5141.md) ###### [Audit Directory Service Replication](auditing/audit-directory-service-replication.md) ####### [Event 4932 S: Synchronization of a replica of an Active Directory naming context has begun.](auditing/event-4932.md) ####### [Event 4933 S, F: Synchronization of a replica of an Active Directory naming context has ended.](auditing/event-4933.md) ###### [Audit Account Lockout](auditing/audit-account-lockout.md) ####### [Event 4625 F: An account failed to log on.](auditing/event-4625.md) ###### [Audit User/Device Claims](auditing/audit-user-device-claims.md) ####### [Event 4626 S: User/Device claims information.](auditing/event-4626.md) ###### [Audit Group Membership](auditing/audit-group-membership.md) ####### [Event 4627 S: Group membership information.](auditing/event-4627.md) ###### [Audit IPsec Extended Mode](auditing/audit-ipsec-extended-mode.md) ###### [Audit IPsec Main Mode](auditing/audit-ipsec-main-mode.md) ###### [Audit IPsec Quick Mode](auditing/audit-ipsec-quick-mode.md) ###### [Audit Logoff](auditing/audit-logoff.md) ####### [Event 4634 S: An account was logged off.](auditing/event-4634.md) ####### [Event 4647 S: User initiated logoff.](auditing/event-4647.md) ###### [Audit Logon](auditing/audit-logon.md) ####### [Event 4624 S: An account was successfully logged on.](auditing/event-4624.md) ####### [Event 4625 F: An account failed to log on.](auditing/event-4625.md) ####### [Event 4648 S: A logon was attempted using explicit credentials.](auditing/event-4648.md) ####### [Event 4675 S: SIDs were filtered.](auditing/event-4675.md) ###### [Audit Network Policy Server](auditing/audit-network-policy-server.md) ###### [Audit Other Logon/Logoff Events](auditing/audit-other-logonlogoff-events.md) ####### [Event 4649 S: A replay attack was detected.](auditing/event-4649.md) ####### [Event 4778 S: A session was reconnected to a Window Station.](auditing/event-4778.md) ####### [Event 4779 S: A session was disconnected from a Window Station.](auditing/event-4779.md) ####### [Event 4800 S: The workstation was locked.](auditing/event-4800.md) ####### [Event 4801 S: The workstation was unlocked.](auditing/event-4801.md) ####### [Event 4802 S: The screen saver was invoked.](auditing/event-4802.md) ####### [Event 4803 S: The screen saver was dismissed.](auditing/event-4803.md) ####### [Event 5378 F: The requested credentials delegation was disallowed by policy.](auditing/event-5378.md) ####### [Event 5632 S, F: A request was made to authenticate to a wireless network.](auditing/event-5632.md) ####### [Event 5633 S, F: A request was made to authenticate to a wired network.](auditing/event-5633.md) ###### [Audit Special Logon](auditing/audit-special-logon.md) ####### [Event 4964 S: Special groups have been assigned to a new logon.](auditing/event-4964.md) ####### [Event 4672 S: Special privileges assigned to new logon.](auditing/event-4672.md) ###### [Audit Application Generated](auditing/audit-application-generated.md) ###### [Audit Certification Services](auditing/audit-certification-services.md) ###### [Audit Detailed File Share](auditing/audit-detailed-file-share.md) ####### [Event 5145 S, F: A network share object was checked to see whether client can be granted desired access.](auditing/event-5145.md) ###### [Audit File Share](auditing/audit-file-share.md) ####### [Event 5140 S, F: A network share object was accessed.](auditing/event-5140.md) ####### [Event 5142 S: A network share object was added.](auditing/event-5142.md) ####### [Event 5143 S: A network share object was modified.](auditing/event-5143.md) ####### [Event 5144 S: A network share object was deleted.](auditing/event-5144.md) ####### [Event 5168 F: SPN check for SMB/SMB2 failed.](auditing/event-5168.md) ###### [Audit File System](auditing/audit-file-system.md) ####### [Event 4656 S, F: A handle to an object was requested.](auditing/event-4656.md) ####### [Event 4658 S: The handle to an object was closed.](auditing/event-4658.md) ####### [Event 4660 S: An object was deleted.](auditing/event-4660.md) ####### [Event 4663 S: An attempt was made to access an object.](auditing/event-4663.md) ####### [Event 4664 S: An attempt was made to create a hard link.](auditing/event-4664.md) ####### [Event 4985 S: The state of a transaction has changed.](auditing/event-4985.md) ####### [Event 5051: A file was virtualized.](auditing/event-5051.md) ####### [Event 4670 S: Permissions on an object were changed.](auditing/event-4670.md) ###### [Audit Filtering Platform Connection](auditing/audit-filtering-platform-connection.md) ####### [Event 5031 F: The Windows Firewall Service blocked an application from accepting incoming connections on the network.](auditing/event-5031.md) ####### [Event 5150: The Windows Filtering Platform blocked a packet.](auditing/event-5150.md) ####### [Event 5151: A more restrictive Windows Filtering Platform filter has blocked a packet.](auditing/event-5151.md) ####### [Event 5154 S: The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections.](auditing/event-5154.md) ####### [Event 5155 F: The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections.](auditing/event-5155.md) ####### [Event 5156 S: The Windows Filtering Platform has permitted a connection.](auditing/event-5156.md) ####### [Event 5157 F: The Windows Filtering Platform has blocked a connection.](auditing/event-5157.md) ####### [Event 5158 S: The Windows Filtering Platform has permitted a bind to a local port.](auditing/event-5158.md) ####### [Event 5159 F: The Windows Filtering Platform has blocked a bind to a local port.](auditing/event-5159.md) ###### [Audit Filtering Platform Packet Drop](auditing/audit-filtering-platform-packet-drop.md) ####### [Event 5152 F: The Windows Filtering Platform blocked a packet.](auditing/event-5152.md) ####### [Event 5153 S: A more restrictive Windows Filtering Platform filter has blocked a packet.](auditing/event-5153.md) ###### [Audit Handle Manipulation](auditing/audit-handle-manipulation.md) ####### [Event 4690 S: An attempt was made to duplicate a handle to an object.](auditing/event-4690.md) ###### [Audit Kernel Object](auditing/audit-kernel-object.md) ####### [Event 4656 S, F: A handle to an object was requested.](auditing/event-4656.md) ####### [Event 4658 S: The handle to an object was closed.](auditing/event-4658.md) ####### [Event 4660 S: An object was deleted.](auditing/event-4660.md) ####### [Event 4663 S: An attempt was made to access an object.](auditing/event-4663.md) ###### [Audit Other Object Access Events](auditing/audit-other-object-access-events.md) ####### [Event 4671: An application attempted to access a blocked ordinal through the TBS.](auditing/event-4671.md) ####### [Event 4691 S: Indirect access to an object was requested.](auditing/event-4691.md) ####### [Event 5148 F: The Windows Filtering Platform has detected a DoS attack and entered a defensive mode; packets associated with this attack will be discarded.](auditing/event-5148.md) ####### [Event 5149 F: The DoS attack has subsided and normal processing is being resumed.](auditing/event-5149.md) ####### [Event 4698 S: A scheduled task was created.](auditing/event-4698.md) ####### [Event 4699 S: A scheduled task was deleted.](auditing/event-4699.md) ####### [Event 4700 S: A scheduled task was enabled.](auditing/event-4700.md) ####### [Event 4701 S: A scheduled task was disabled.](auditing/event-4701.md) ####### [Event 4702 S: A scheduled task was updated.](auditing/event-4702.md) ####### [Event 5888 S: An object in the COM+ Catalog was modified.](auditing/event-5888.md) ####### [Event 5889 S: An object was deleted from the COM+ Catalog.](auditing/event-5889.md) ####### [Event 5890 S: An object was added to the COM+ Catalog.](auditing/event-5890.md) ###### [Audit Registry](auditing/audit-registry.md) ####### [Event 4663 S: An attempt was made to access an object.](auditing/event-4663.md) ####### [Event 4656 S, F: A handle to an object was requested.](auditing/event-4656.md) ####### [Event 4658 S: The handle to an object was closed.](auditing/event-4658.md) ####### [Event 4660 S: An object was deleted.](auditing/event-4660.md) ####### [Event 4657 S: A registry value was modified.](auditing/event-4657.md) ####### [Event 5039: A registry key was virtualized.](auditing/event-5039.md) ####### [Event 4670 S: Permissions on an object were changed.](auditing/event-4670.md) ###### [Audit Removable Storage](auditing/audit-removable-storage.md) ###### [Audit SAM](auditing/audit-sam.md) ####### [Event 4661 S, F: A handle to an object was requested.](auditing/event-4661.md) ###### [Audit Central Access Policy Staging](auditing/audit-central-access-policy-staging.md) ####### [Event 4818 S: Proposed Central Access Policy does not grant the same access permissions as the current Central Access Policy.](auditing/event-4818.md) ###### [Audit Audit Policy Change](auditing/audit-audit-policy-change.md) ####### [Event 4670 S: Permissions on an object were changed.](auditing/event-4670.md) ####### [Event 4715 S: The audit policy, SACL, on an object was changed.](auditing/event-4715.md) ####### [Event 4719 S: System audit policy was changed.](auditing/event-4719.md) ####### [Event 4817 S: Auditing settings on object were changed.](auditing/event-4817.md) ####### [Event 4902 S: The Per-user audit policy table was created.](auditing/event-4902.md) ####### [Event 4906 S: The CrashOnAuditFail value has changed.](auditing/event-4906.md) ####### [Event 4907 S: Auditing settings on object were changed.](auditing/event-4907.md) ####### [Event 4908 S: Special Groups Logon table modified.](auditing/event-4908.md) ####### [Event 4912 S: Per User Audit Policy was changed.](auditing/event-4912.md) ####### [Event 4904 S: An attempt was made to register a security event source.](auditing/event-4904.md) ####### [Event 4905 S: An attempt was made to unregister a security event source.](auditing/event-4905.md) ###### [Audit Authentication Policy Change](auditing/audit-authentication-policy-change.md) ####### [Event 4706 S: A new trust was created to a domain.](auditing/event-4706.md) ####### [Event 4707 S: A trust to a domain was removed.](auditing/event-4707.md) ####### [Event 4716 S: Trusted domain information was modified.](auditing/event-4716.md) ####### [Event 4713 S: Kerberos policy was changed.](auditing/event-4713.md) ####### [Event 4717 S: System security access was granted to an account.](auditing/event-4717.md) ####### [Event 4718 S: System security access was removed from an account.](auditing/event-4718.md) ####### [Event 4739 S: Domain Policy was changed.](auditing/event-4739.md) ####### [Event 4864 S: A namespace collision was detected.](auditing/event-4864.md) ####### [Event 4865 S: A trusted forest information entry was added.](auditing/event-4865.md) ####### [Event 4866 S: A trusted forest information entry was removed.](auditing/event-4866.md) ####### [Event 4867 S: A trusted forest information entry was modified.](auditing/event-4867.md) ###### [Audit Authorization Policy Change](auditing/audit-authorization-policy-change.md) ####### [Event 4703 S: A user right was adjusted.](auditing/event-4703.md) ####### [Event 4704 S: A user right was assigned.](auditing/event-4704.md) ####### [Event 4705 S: A user right was removed.](auditing/event-4705.md) ####### [Event 4670 S: Permissions on an object were changed.](auditing/event-4670.md) ####### [Event 4911 S: Resource attributes of the object were changed.](auditing/event-4911.md) ####### [Event 4913 S: Central Access Policy on the object was changed.](auditing/event-4913.md) ###### [Audit Filtering Platform Policy Change](auditing/audit-filtering-platform-policy-change.md) ###### [Audit MPSSVC Rule-Level Policy Change](auditing/audit-mpssvc-rule-level-policy-change.md) ####### [Event 4944 S: The following policy was active when the Windows Firewall started.](auditing/event-4944.md) ####### [Event 4945 S: A rule was listed when the Windows Firewall started.](auditing/event-4945.md) ####### [Event 4946 S: A change has been made to Windows Firewall exception list. A rule was added.](auditing/event-4946.md) ####### [Event 4947 S: A change has been made to Windows Firewall exception list. A rule was modified.](auditing/event-4947.md) ####### [Event 4948 S: A change has been made to Windows Firewall exception list. A rule was deleted.](auditing/event-4948.md) ####### [Event 4949 S: Windows Firewall settings were restored to the default values.](auditing/event-4949.md) ####### [Event 4950 S: A Windows Firewall setting has changed.](auditing/event-4950.md) ####### [Event 4951 F: A rule has been ignored because its major version number was not recognized by Windows Firewall.](auditing/event-4951.md) ####### [Event 4952 F: Parts of a rule have been ignored because its minor version number was not recognized by Windows Firewall. The other parts of the rule will be enforced.](auditing/event-4952.md) ####### [Event 4953 F: Windows Firewall ignored a rule because it could not be parsed.](auditing/event-4953.md) ####### [Event 4954 S: Windows Firewall Group Policy settings have changed. The new settings have been applied.](auditing/event-4954.md) ####### [Event 4956 S: Windows Firewall has changed the active profile.](auditing/event-4956.md) ####### [Event 4957 F: Windows Firewall did not apply the following rule.](auditing/event-4957.md) ####### [Event 4958 F: Windows Firewall did not apply the following rule because the rule referred to items not configured on this computer.](auditing/event-4958.md) ###### [Audit Other Policy Change Events](auditing/audit-other-policy-change-events.md) ####### [Event 4714 S: Encrypted data recovery policy was changed.](auditing/event-4714.md) ####### [Event 4819 S: Central Access Policies on the machine have been changed.](auditing/event-4819.md) ####### [Event 4826 S: Boot Configuration Data loaded.](auditing/event-4826.md) ####### [Event 4909: The local policy settings for the TBS were changed.](auditing/event-4909.md) ####### [Event 4910: The group policy settings for the TBS were changed.](auditing/event-4910.md) ####### [Event 5063 S, F: A cryptographic provider operation was attempted.](auditing/event-5063.md) ####### [Event 5064 S, F: A cryptographic context operation was attempted.](auditing/event-5064.md) ####### [Event 5065 S, F: A cryptographic context modification was attempted.](auditing/event-5065.md) ####### [Event 5066 S, F: A cryptographic function operation was attempted.](auditing/event-5066.md) ####### [Event 5067 S, F: A cryptographic function modification was attempted.](auditing/event-5067.md) ####### [Event 5068 S, F: A cryptographic function provider operation was attempted.](auditing/event-5068.md) ####### [Event 5069 S, F: A cryptographic function property operation was attempted.](auditing/event-5069.md) ####### [Event 5070 S, F: A cryptographic function property modification was attempted.](auditing/event-5070.md) ####### [Event 5447 S: A Windows Filtering Platform filter has been changed.](auditing/event-5447.md) ####### [Event 6144 S: Security policy in the group policy objects has been applied successfully.](auditing/event-6144.md) ####### [Event 6145 F: One or more errors occurred while processing security policy in the group policy objects.](auditing/event-6145.md) ###### [Audit Sensitive Privilege Use](auditing/audit-sensitive-privilege-use.md) ####### [Event 4673 S, F: A privileged service was called.](auditing/event-4673.md) ####### [Event 4674 S, F: An operation was attempted on a privileged object.](auditing/event-4674.md) ####### [Event 4985 S: The state of a transaction has changed.](auditing/event-4985.md) ###### [Audit Non Sensitive Privilege Use](auditing/audit-non-sensitive-privilege-use.md) ####### [Event 4673 S, F: A privileged service was called.](auditing/event-4673.md) ####### [Event 4674 S, F: An operation was attempted on a privileged object.](auditing/event-4674.md) ####### [Event 4985 S: The state of a transaction has changed.](auditing/event-4985.md) ###### [Audit Other Privilege Use Events](auditing/audit-other-privilege-use-events.md) ####### [Event 4985 S: The state of a transaction has changed.](auditing/event-4985.md) ###### [Audit IPsec Driver](auditing/audit-ipsec-driver.md) ###### [Audit Other System Events](auditing/audit-other-system-events.md) ####### [Event 5024 S: The Windows Firewall Service has started successfully.](auditing/event-5024.md) ####### [Event 5025 S: The Windows Firewall Service has been stopped.](auditing/event-5025.md) ####### [Event 5027 F: The Windows Firewall Service was unable to retrieve the security policy from the local storage. The service will continue enforcing the current policy.](auditing/event-5027.md) ####### [Event 5028 F: The Windows Firewall Service was unable to parse the new security policy. The service will continue with currently enforced policy.](auditing/event-5028.md) ####### [Event 5029 F: The Windows Firewall Service failed to initialize the driver. The service will continue to enforce the current policy.](auditing/event-5029.md) ####### [Event 5030 F: The Windows Firewall Service failed to start.](auditing/event-5030.md) ####### [Event 5032 F: Windows Firewall was unable to notify the user that it blocked an application from accepting incoming connections on the network.](auditing/event-5032.md) ####### [Event 5033 S: The Windows Firewall Driver has started successfully.](auditing/event-5033.md) ####### [Event 5034 S: The Windows Firewall Driver was stopped.](auditing/event-5034.md) ####### [Event 5035 F: The Windows Firewall Driver failed to start.](auditing/event-5035.md) ####### [Event 5037 F: The Windows Firewall Driver detected critical runtime error. Terminating.](auditing/event-5037.md) ####### [Event 5058 S, F: Key file operation.](auditing/event-5058.md) ####### [Event 5059 S, F: Key migration operation.](auditing/event-5059.md) ####### [Event 6400: BranchCache: Received an incorrectly formatted response while discovering availability of content.](auditing/event-6400.md) ####### [Event 6401: BranchCache: Received invalid data from a peer. Data discarded.](auditing/event-6401.md) ####### [Event 6402: BranchCache: The message to the hosted cache offering it data is incorrectly formatted.](auditing/event-6402.md) ####### [Event 6403: BranchCache: The hosted cache sent an incorrectly formatted response to the client.](auditing/event-6403.md) ####### [Event 6404: BranchCache: Hosted cache could not be authenticated using the provisioned SSL certificate.](auditing/event-6404.md) ####### [Event 6405: BranchCache: %2 instances of event id %1 occurred.](auditing/event-6405.md) ####### [Event 6406: %1 registered to Windows Firewall to control filtering for the following: %2.](auditing/event-6406.md) ####### [Event 6407: 1%.](auditing/event-6407.md) ####### [Event 6408: Registered product %1 failed and Windows Firewall is now controlling the filtering for %2.](auditing/event-6408.md) ####### [Event 6409: BranchCache: A service connection point object could not be parsed.](auditing/event-6409.md) ###### [Audit Security State Change](auditing/audit-security-state-change.md) ####### [Event 4608 S: Windows is starting up.](auditing/event-4608.md) ####### [Event 4616 S: The system time was changed.](auditing/event-4616.md) ####### [Event 4621 S: Administrator recovered system from CrashOnAuditFail.](auditing/event-4621.md) ###### [Audit Security System Extension](auditing/audit-security-system-extension.md) ####### [Event 4610 S: An authentication package has been loaded by the Local Security Authority.](auditing/event-4610.md) ####### [Event 4611 S: A trusted logon process has been registered with the Local Security Authority.](auditing/event-4611.md) ####### [Event 4614 S: A notification package has been loaded by the Security Account Manager.](auditing/event-4614.md) ####### [Event 4622 S: A security package has been loaded by the Local Security Authority.](auditing/event-4622.md) ####### [Event 4697 S: A service was installed in the system.](auditing/event-4697.md) ###### [Audit System Integrity](auditing/audit-system-integrity.md) ####### [Event 4612 S: Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits.](auditing/event-4612.md) ####### [Event 4615 S: Invalid use of LPC port.](auditing/event-4615.md) ####### [Event 4618 S: A monitored security event pattern has occurred.](auditing/event-4618.md) ####### [Event 4816 S: RPC detected an integrity violation while decrypting an incoming message.](auditing/event-4816.md) ####### [Event 5038 F: Code integrity determined that the image hash of a file is not valid.](auditing/event-5038.md) ####### [Event 5056 S: A cryptographic self-test was performed.](auditing/event-5056.md) ####### [Event 5062 S: A kernel-mode cryptographic self-test was performed.](auditing/event-5062.md) ####### [Event 5057 F: A cryptographic primitive operation failed.](auditing/event-5057.md) ####### [Event 5060 F: Verification operation failed.](auditing/event-5060.md) ####### [Event 5061 S, F: Cryptographic operation.](auditing/event-5061.md) ####### [Event 6281 F: Code Integrity determined that the page hashes of an image file are not valid.](auditing/event-6281.md) ####### [Event 6410 F: Code integrity determined that a file does not meet the security requirements to load into a process.](auditing/event-6410.md) ###### [Other Events](auditing/other-events.md) ####### [Event 1100 S: The event logging service has shut down.](auditing/event-1100.md) ####### [Event 1102 S: The audit log was cleared.](auditing/event-1102.md) ####### [Event 1104 S: The security log is now full.](auditing/event-1104.md) ####### [Event 1105 S: Event log automatic backup.](auditing/event-1105.md) ####### [Event 1108 S: The event logging service encountered an error while processing an incoming event published from %1.](auditing/event-1108.md) ###### [Appendix A: Security monitoring recommendations for many audit events](auditing/appendix-a-security-monitoring-recommendations-for-many-audit-events.md) ###### [Registry (Global Object Access Auditing)](auditing/registry-global-object-access-auditing.md) ###### [File System (Global Object Access Auditing)](auditing/file-system-global-object-access-auditing.md) ### [Security policy settings](security-policy-settings/security-policy-settings.md) #### [Administer security policy settings](security-policy-settings/administer-security-policy-settings.md) ##### [Network List Manager policies](security-policy-settings/network-list-manager-policies.md) #### [Configure security policy settings](security-policy-settings/how-to-configure-security-policy-settings.md) #### [Security policy settings reference](security-policy-settings/security-policy-settings-reference.md) ##### [Account Policies](security-policy-settings/account-policies.md) ###### [Password Policy](security-policy-settings/password-policy.md) ####### [Enforce password history](security-policy-settings/enforce-password-history.md) ####### [Maximum password age](security-policy-settings/maximum-password-age.md) ####### [Minimum password age](security-policy-settings/minimum-password-age.md) ####### [Minimum password length](security-policy-settings/minimum-password-length.md) ####### [Password must meet complexity requirements](security-policy-settings/password-must-meet-complexity-requirements.md) ####### [Store passwords using reversible encryption](security-policy-settings/store-passwords-using-reversible-encryption.md) ###### [Account Lockout Policy](security-policy-settings/account-lockout-policy.md) ####### [Account lockout duration](security-policy-settings/account-lockout-duration.md) ####### [Account lockout threshold](security-policy-settings/account-lockout-threshold.md) ####### [Reset account lockout counter after](security-policy-settings/reset-account-lockout-counter-after.md) ###### [Kerberos Policy](security-policy-settings/kerberos-policy.md) ####### [Enforce user logon restrictions](security-policy-settings/enforce-user-logon-restrictions.md) ####### [Maximum lifetime for service ticket](security-policy-settings/maximum-lifetime-for-service-ticket.md) ####### [Maximum lifetime for user ticket](security-policy-settings/maximum-lifetime-for-user-ticket.md) ####### [Maximum lifetime for user ticket renewal](security-policy-settings/maximum-lifetime-for-user-ticket-renewal.md) ####### [Maximum tolerance for computer clock synchronization](security-policy-settings/maximum-tolerance-for-computer-clock-synchronization.md) ##### [Audit Policy](security-policy-settings/audit-policy.md) ##### [Security Options](security-policy-settings/security-options.md) ###### [Accounts: Administrator account status](security-policy-settings/accounts-administrator-account-status.md) ###### [Accounts: Block Microsoft accounts](security-policy-settings/accounts-block-microsoft-accounts.md) ###### [Accounts: Guest account status](security-policy-settings/accounts-guest-account-status.md) ###### [Accounts: Limit local account use of blank passwords to console logon only](security-policy-settings/accounts-limit-local-account-use-of-blank-passwords-to-console-logon-only.md) ###### [Accounts: Rename administrator account](security-policy-settings/accounts-rename-administrator-account.md) ###### [Accounts: Rename guest account](security-policy-settings/accounts-rename-guest-account.md) ###### [Audit: Audit the access of global system objects](security-policy-settings/audit-audit-the-access-of-global-system-objects.md) ###### [Audit: Audit the use of Backup and Restore privilege](security-policy-settings/audit-audit-the-use-of-backup-and-restore-privilege.md) ###### [Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings](security-policy-settings/audit-force-audit-policy-subcategory-settings-to-override.md) ###### [Audit: Shut down system immediately if unable to log security audits](security-policy-settings/audit-shut-down-system-immediately-if-unable-to-log-security-audits.md) ###### [DCOM: Machine Access Restrictions in Security Descriptor Definition Language (SDDL) syntax](security-policy-settings/dcom-machine-access-restrictions-in-security-descriptor-definition-language-sddl-syntax.md) ###### [DCOM: Machine Launch Restrictions in Security Descriptor Definition Language (SDDL) syntax](security-policy-settings/dcom-machine-launch-restrictions-in-security-descriptor-definition-language-sddl-syntax.md) ###### [Devices: Allow undock without having to log on](security-policy-settings/devices-allow-undock-without-having-to-log-on.md) ###### [Devices: Allowed to format and eject removable media](security-policy-settings/devices-allowed-to-format-and-eject-removable-media.md) ###### [Devices: Prevent users from installing printer drivers](security-policy-settings/devices-prevent-users-from-installing-printer-drivers.md) ###### [Devices: Restrict CD-ROM access to locally logged-on user only](security-policy-settings/devices-restrict-cd-rom-access-to-locally-logged-on-user-only.md) ###### [Devices: Restrict floppy access to locally logged-on user only](security-policy-settings/devices-restrict-floppy-access-to-locally-logged-on-user-only.md) ###### [Domain controller: Allow server operators to schedule tasks](security-policy-settings/domain-controller-allow-server-operators-to-schedule-tasks.md) ###### [Domain controller: LDAP server signing requirements](security-policy-settings/domain-controller-ldap-server-signing-requirements.md) ###### [Domain controller: Refuse machine account password changes](security-policy-settings/domain-controller-refuse-machine-account-password-changes.md) ###### [Domain member: Digitally encrypt or sign secure channel data (always)](security-policy-settings/domain-member-digitally-encrypt-or-sign-secure-channel-data-always.md) ###### [Domain member: Digitally encrypt secure channel data (when possible)](security-policy-settings/domain-member-digitally-encrypt-secure-channel-data-when-possible.md) ###### [Domain member: Digitally sign secure channel data (when possible)](security-policy-settings/domain-member-digitally-sign-secure-channel-data-when-possible.md) ###### [Domain member: Disable machine account password changes](security-policy-settings/domain-member-disable-machine-account-password-changes.md) ###### [Domain member: Maximum machine account password age](security-policy-settings/domain-member-maximum-machine-account-password-age.md) ###### [Domain member: Require strong (Windows 2000 or later) session key](security-policy-settings/domain-member-require-strong-windows-2000-or-later-session-key.md) ###### [Interactive logon: Display user information when the session is locked](security-policy-settings/interactive-logon-display-user-information-when-the-session-is-locked.md) ###### [Interactive logon: Don't display last signed-in](security-policy-settings/interactive-logon-do-not-display-last-user-name.md) ###### [Interactive logon: Don't display username at sign-in](security-policy-settings/interactive-logon-dont-display-username-at-sign-in.md) ###### [Interactive logon: Do not require CTRL+ALT+DEL](security-policy-settings/interactive-logon-do-not-require-ctrl-alt-del.md) ###### [Interactive logon: Machine account lockout threshold](security-policy-settings/interactive-logon-machine-account-lockout-threshold.md) ###### [Interactive logon: Machine inactivity limit](security-policy-settings/interactive-logon-machine-inactivity-limit.md) ###### [Interactive logon: Message text for users attempting to log on](security-policy-settings/interactive-logon-message-text-for-users-attempting-to-log-on.md) ###### [Interactive logon: Message title for users attempting to log on](security-policy-settings/interactive-logon-message-title-for-users-attempting-to-log-on.md) ###### [Interactive logon: Number of previous logons to cache (in case domain controller is not available)](security-policy-settings/interactive-logon-number-of-previous-logons-to-cache-in-case-domain-controller-is-not-available.md) ###### [Interactive logon: Prompt user to change password before expiration](security-policy-settings/interactive-logon-prompt-user-to-change-password-before-expiration.md) ###### [Interactive logon: Require Domain Controller authentication to unlock workstation](security-policy-settings/interactive-logon-require-domain-controller-authentication-to-unlock-workstation.md) ###### [Interactive logon: Require smart card](security-policy-settings/interactive-logon-require-smart-card.md) ###### [Interactive logon: Smart card removal behavior](security-policy-settings/interactive-logon-smart-card-removal-behavior.md) ###### [Microsoft network client: Digitally sign communications (always)](security-policy-settings/microsoft-network-client-digitally-sign-communications-always.md) ###### [SMBv1 Microsoft network client: Digitally sign communications (always)](security-policy-settings/smbv1-microsoft-network-client-digitally-sign-communications-always.md) ###### [SMBv1 Microsoft network client: Digitally sign communications (if server agrees)](security-policy-settings/smbv1-microsoft-network-client-digitally-sign-communications-if-server-agrees.md) ###### [Microsoft network client: Send unencrypted password to third-party SMB servers](security-policy-settings/microsoft-network-client-send-unencrypted-password-to-third-party-smb-servers.md) ###### [Microsoft network server: Amount of idle time required before suspending session](security-policy-settings/microsoft-network-server-amount-of-idle-time-required-before-suspending-session.md) ###### [Microsoft network server: Attempt S4U2Self to obtain claim information](security-policy-settings/microsoft-network-server-attempt-s4u2self-to-obtain-claim-information.md) ###### [Microsoft network server: Digitally sign communications (always)](security-policy-settings/microsoft-network-server-digitally-sign-communications-always.md) ###### [SMBv1 Microsoft network server: Digitally sign communications (always)](security-policy-settings/smbv1-microsoft-network-server-digitally-sign-communications-always.md) ###### [SMBv1 Microsoft network server: Digitally sign communications (if client agrees)](security-policy-settings/smbv1-microsoft-network-server-digitally-sign-communications-if-client-agrees.md) ###### [Microsoft network server: Disconnect clients when logon hours expire](security-policy-settings/microsoft-network-server-disconnect-clients-when-logon-hours-expire.md) ###### [Microsoft network server: Server SPN target name validation level](security-policy-settings/microsoft-network-server-server-spn-target-name-validation-level.md) ###### [Network access: Allow anonymous SID/Name translation](security-policy-settings/network-access-allow-anonymous-sidname-translation.md) ###### [Network access: Do not allow anonymous enumeration of SAM accounts](security-policy-settings/network-access-do-not-allow-anonymous-enumeration-of-sam-accounts.md) ###### [Network access: Do not allow anonymous enumeration of SAM accounts and shares](security-policy-settings/network-access-do-not-allow-anonymous-enumeration-of-sam-accounts-and-shares.md) ###### [Network access: Do not allow storage of passwords and credentials for network authentication](security-policy-settings/network-access-do-not-allow-storage-of-passwords-and-credentials-for-network-authentication.md) ###### [Network access: Let Everyone permissions apply to anonymous users](security-policy-settings/network-access-let-everyone-permissions-apply-to-anonymous-users.md) ###### [Network access: Named Pipes that can be accessed anonymously](security-policy-settings/network-access-named-pipes-that-can-be-accessed-anonymously.md) ###### [Network access: Remotely accessible registry paths](security-policy-settings/network-access-remotely-accessible-registry-paths.md) ###### [Network access: Remotely accessible registry paths and subpaths](security-policy-settings/network-access-remotely-accessible-registry-paths-and-subpaths.md) ###### [Network access: Restrict anonymous access to Named Pipes and Shares](security-policy-settings/network-access-restrict-anonymous-access-to-named-pipes-and-shares.md) ###### [Network access: Restrict clients allowed to make remote calls to SAM](security-policy-settings/network-access-restrict-clients-allowed-to-make-remote-sam-calls.md) ###### [Network access: Shares that can be accessed anonymously](security-policy-settings/network-access-shares-that-can-be-accessed-anonymously.md) ###### [Network access: Sharing and security model for local accounts](security-policy-settings/network-access-sharing-and-security-model-for-local-accounts.md) ###### [Network security: Allow Local System to use computer identity for NTLM](security-policy-settings/network-security-allow-local-system-to-use-computer-identity-for-ntlm.md) ###### [Network security: Allow LocalSystem NULL session fallback](security-policy-settings/network-security-allow-localsystem-null-session-fallback.md) ###### [Network security: Allow PKU2U authentication requests to this computer to use online identities](security-policy-settings/network-security-allow-pku2u-authentication-requests-to-this-computer-to-use-online-identities.md) ###### [Network security: Configure encryption types allowed for Kerberos Win7 only](security-policy-settings/network-security-configure-encryption-types-allowed-for-kerberos.md) ###### [Network security: Do not store LAN Manager hash value on next password change](security-policy-settings/network-security-do-not-store-lan-manager-hash-value-on-next-password-change.md) ###### [Network security: Force logoff when logon hours expire](security-policy-settings/network-security-force-logoff-when-logon-hours-expire.md) ###### [Network security: LAN Manager authentication level](security-policy-settings/network-security-lan-manager-authentication-level.md) ###### [Network security: LDAP client signing requirements](security-policy-settings/network-security-ldap-client-signing-requirements.md) ###### [Network security: Minimum session security for NTLM SSP based (including secure RPC) clients](security-policy-settings/network-security-minimum-session-security-for-ntlm-ssp-based-including-secure-rpc-clients.md) ###### [Network security: Minimum session security for NTLM SSP based (including secure RPC) servers](security-policy-settings/network-security-minimum-session-security-for-ntlm-ssp-based-including-secure-rpc-servers.md) ###### [Network security: Restrict NTLM: Add remote server exceptions for NTLM authentication](security-policy-settings/network-security-restrict-ntlm-add-remote-server-exceptions-for-ntlm-authentication.md) ###### [Network security: Restrict NTLM: Add server exceptions in this domain](security-policy-settings/network-security-restrict-ntlm-add-server-exceptions-in-this-domain.md) ###### [Network security: Restrict NTLM: Audit incoming NTLM traffic](security-policy-settings/network-security-restrict-ntlm-audit-incoming-ntlm-traffic.md) ###### [Network security: Restrict NTLM: Audit NTLM authentication in this domain](security-policy-settings/network-security-restrict-ntlm-audit-ntlm-authentication-in-this-domain.md) ###### [Network security: Restrict NTLM: Incoming NTLM traffic](security-policy-settings/network-security-restrict-ntlm-incoming-ntlm-traffic.md) ###### [Network security: Restrict NTLM: NTLM authentication in this domain](security-policy-settings/network-security-restrict-ntlm-ntlm-authentication-in-this-domain.md) ###### [Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers](security-policy-settings/network-security-restrict-ntlm-outgoing-ntlm-traffic-to-remote-servers.md) ###### [Recovery console: Allow automatic administrative logon](security-policy-settings/recovery-console-allow-automatic-administrative-logon.md) ###### [Recovery console: Allow floppy copy and access to all drives and folders](security-policy-settings/recovery-console-allow-floppy-copy-and-access-to-all-drives-and-folders.md) ###### [Shutdown: Allow system to be shut down without having to log on](security-policy-settings/shutdown-allow-system-to-be-shut-down-without-having-to-log-on.md) ###### [Shutdown: Clear virtual memory pagefile](security-policy-settings/shutdown-clear-virtual-memory-pagefile.md) ###### [System cryptography: Force strong key protection for user keys stored on the computer](security-policy-settings/system-cryptography-force-strong-key-protection-for-user-keys-stored-on-the-computer.md) ###### [System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing](security-policy-settings/system-cryptography-use-fips-compliant-algorithms-for-encryption-hashing-and-signing.md) ###### [System objects: Require case insensitivity for non-Windows subsystems](security-policy-settings/system-objects-require-case-insensitivity-for-non-windows-subsystems.md) ###### [System objects: Strengthen default permissions of internal system objects (e.g. Symbolic Links)](security-policy-settings/system-objects-strengthen-default-permissions-of-internal-system-objects.md) ###### [System settings: Optional subsystems](security-policy-settings/system-settings-optional-subsystems.md) ###### [System settings: Use certificate rules on Windows executables for Software Restriction Policies](security-policy-settings/system-settings-use-certificate-rules-on-windows-executables-for-software-restriction-policies.md) ###### [User Account Control: Admin Approval Mode for the Built-in Administrator account](security-policy-settings/user-account-control-admin-approval-mode-for-the-built-in-administrator-account.md) ###### [User Account Control: Allow UIAccess applications to prompt for elevation without using the secure desktop](security-policy-settings/user-account-control-allow-uiaccess-applications-to-prompt-for-elevation-without-using-the-secure-desktop.md) ###### [User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode](security-policy-settings/user-account-control-behavior-of-the-elevation-prompt-for-administrators-in-admin-approval-mode.md) ###### [User Account Control: Behavior of the elevation prompt for standard users](security-policy-settings/user-account-control-behavior-of-the-elevation-prompt-for-standard-users.md) ###### [User Account Control: Detect application installations and prompt for elevation](security-policy-settings/user-account-control-detect-application-installations-and-prompt-for-elevation.md) ###### [User Account Control: Only elevate executables that are signed and validated](security-policy-settings/user-account-control-only-elevate-executables-that-are-signed-and-validated.md) ###### [User Account Control: Only elevate UIAccess applications that are installed in secure locations](security-policy-settings/user-account-control-only-elevate-uiaccess-applications-that-are-installed-in-secure-locations.md) ###### [User Account Control: Run all administrators in Admin Approval Mode](security-policy-settings/user-account-control-run-all-administrators-in-admin-approval-mode.md) ###### [User Account Control: Switch to the secure desktop when prompting for elevation](security-policy-settings/user-account-control-switch-to-the-secure-desktop-when-prompting-for-elevation.md) ###### [User Account Control: Virtualize file and registry write failures to per-user locations](security-policy-settings/user-account-control-virtualize-file-and-registry-write-failures-to-per-user-locations.md) ##### [Advanced security audit policy settings](security-policy-settings/secpol-advanced-security-audit-policy-settings.md) ##### [User Rights Assignment](security-policy-settings/user-rights-assignment.md) ###### [Access Credential Manager as a trusted caller](security-policy-settings/access-credential-manager-as-a-trusted-caller.md) ###### [Access this computer from the network](security-policy-settings/access-this-computer-from-the-network.md) ###### [Act as part of the operating system](security-policy-settings/act-as-part-of-the-operating-system.md) ###### [Add workstations to domain](security-policy-settings/add-workstations-to-domain.md) ###### [Adjust memory quotas for a process](security-policy-settings/adjust-memory-quotas-for-a-process.md) ###### [Allow log on locally](security-policy-settings/allow-log-on-locally.md) ###### [Allow log on through Remote Desktop Services](security-policy-settings/allow-log-on-through-remote-desktop-services.md) ###### [Back up files and directories](security-policy-settings/back-up-files-and-directories.md) ###### [Bypass traverse checking](security-policy-settings/bypass-traverse-checking.md) ###### [Change the system time](security-policy-settings/change-the-system-time.md) ###### [Change the time zone](security-policy-settings/change-the-time-zone.md) ###### [Create a pagefile](security-policy-settings/create-a-pagefile.md) ###### [Create a token object](security-policy-settings/create-a-token-object.md) ###### [Create global objects](security-policy-settings/create-global-objects.md) ###### [Create permanent shared objects](security-policy-settings/create-permanent-shared-objects.md) ###### [Create symbolic links](security-policy-settings/create-symbolic-links.md) ###### [Debug programs](security-policy-settings/debug-programs.md) ###### [Deny access to this computer from the network](security-policy-settings/deny-access-to-this-computer-from-the-network.md) ###### [Deny log on as a batch job](security-policy-settings/deny-log-on-as-a-batch-job.md) ###### [Deny log on as a service](security-policy-settings/deny-log-on-as-a-service.md) ###### [Deny log on locally](security-policy-settings/deny-log-on-locally.md) ###### [Deny log on through Remote Desktop Services](security-policy-settings/deny-log-on-through-remote-desktop-services.md) ###### [Enable computer and user accounts to be trusted for delegation](security-policy-settings/enable-computer-and-user-accounts-to-be-trusted-for-delegation.md) ###### [Force shutdown from a remote system](security-policy-settings/force-shutdown-from-a-remote-system.md) ###### [Generate security audits](security-policy-settings/generate-security-audits.md) ###### [Impersonate a client after authentication](security-policy-settings/impersonate-a-client-after-authentication.md) ###### [Increase a process working set](security-policy-settings/increase-a-process-working-set.md) ###### [Increase scheduling priority](security-policy-settings/increase-scheduling-priority.md) ###### [Load and unload device drivers](security-policy-settings/load-and-unload-device-drivers.md) ###### [Lock pages in memory](security-policy-settings/lock-pages-in-memory.md) ###### [Log on as a batch job](security-policy-settings/log-on-as-a-batch-job.md) ###### [Log on as a service](security-policy-settings/log-on-as-a-service.md) ###### [Manage auditing and security log](security-policy-settings/manage-auditing-and-security-log.md) ###### [Modify an object label](security-policy-settings/modify-an-object-label.md) ###### [Modify firmware environment values](security-policy-settings/modify-firmware-environment-values.md) ###### [Perform volume maintenance tasks](security-policy-settings/perform-volume-maintenance-tasks.md) ###### [Profile single process](security-policy-settings/profile-single-process.md) ###### [Profile system performance](security-policy-settings/profile-system-performance.md) ###### [Remove computer from docking station](security-policy-settings/remove-computer-from-docking-station.md) ###### [Replace a process level token](security-policy-settings/replace-a-process-level-token.md) ###### [Restore files and directories](security-policy-settings/restore-files-and-directories.md) ###### [Shut down the system](security-policy-settings/shut-down-the-system.md) ###### [Synchronize directory service data](security-policy-settings/synchronize-directory-service-data.md) ###### [Take ownership of files or other objects](security-policy-settings/take-ownership-of-files-or-other-objects.md) ### [Windows security guidance for enterprises](windows-security-configuration-framework/windows-security-compliance.md) #### [Windows security baselines](windows-security-configuration-framework/windows-security-baselines.md) ##### [Security Compliance Toolkit](windows-security-configuration-framework/security-compliance-toolkit-10.md) ##### [Get support](windows-security-configuration-framework/get-support-for-security-baselines.md) #### [Windows security configuration framework](windows-security-configuration-framework/windows-security-configuration-framework.md) ##### [Level 1 enterprise basic security](windows-security-configuration-framework/level-1-enterprise-basic-security.md) ##### [Level 2 enterprise enhanced security](windows-security-configuration-framework/level-2-enterprise-enhanced-security.md) ##### [Level 3 enterprise high security](windows-security-configuration-framework/level-3-enterprise-high-security.md) ##### [Level 4 enterprise dev/ops workstation](windows-security-configuration-framework/level-4-enterprise-devops-security.md) ##### [Level 5 enterprise administrator workstation](windows-security-configuration-framework/level-5-enterprise-administrator-security.md) ### [MBSA removal and alternatives](mbsa-removal-and-guidance.md) ### [Windows 10 Mobile security guide](windows-10-mobile-security-guide.md) ## [Change history for Threat protection](change-history-for-threat-protection.md)