--- title: WindowsAdvancedThreatProtection DDF file description: WindowsAdvancedThreatProtection DDF file ms.assetid: 0C62A790-4351-48AF-89FD-7D46C42D13E0 ms.reviewer: manager: dansimp ms.author: dansimp ms.topic: article ms.prod: w10 ms.technology: windows author: manikadhiman ms.date: 12/05/2017 --- # WindowsAdvancedThreatProtection DDF file This topic shows the OMA DM device description framework (DDF) for the **WindowsAdvancedThreatProtection** configuration service provider. DDF files are used only with OMA DM provisioning XML. Looking for the DDF XML files? See [CSP DDF files download](configuration-service-provider-reference.md#csp-ddf-files-download). The XML below is the current version for this CSP. ```xml ]> 1.2 WindowsAdvancedThreatProtection ./Device/Vendor/MSFT Windows Defender Advanced Threat Protection com.microsoft/1.2/MDM/WindowsAdvancedThreatProtection Onboarding Set Windows Defender Advanced Threat Protection Onboarding blob and initiate onboarding to Windows Defender Advanced Threat Protection text/plain HealthState Represents Windows Defender Advanced Threat Protection Health State LastConnected The last successful connection. text/plain SenseIsRunning false Return Windows Defender Advanced Threat Protection service running state text/plain OnboardingState 0 Return Windows Defender Advanced Threat Protection onboarding state: 0 – not onboarded; 1 - onboarded text/plain OrgId Onboarded Org ID. text/plain Configuration Represents Windows Defender Advanced Threat Protection Configuration SampleSharing 1 Return or set Windows Defender Advanced Threat Protection Sample Sharing configuration parameter: 0 - none, 1 - All text/plain TelemetryReportingFrequency 1 Return or set Windows Defender Advanced Threat Protection diagnostic data reporting frequency. Allowed values are: 1 - Normal, 2 - Expedite Telemetry reporting frequency text/plain Offboarding Set Windows Defender Advanced Threat Protection Offboarding blob and initiate offboarding text/plain DeviceTagging Represents Windows Defender Advanced Threat Protection configuration for managing role base access and device tagging Device Tagging Group Device group identifiers Device Group Identifier text/plain Criticality 0 Asset criticality value. 0 - Normal, 1 - Critical. Device Criticality text/plain ``` ## Related topics [Configuration service provider reference](configuration-service-provider-reference.md)