XenMobile

Defender device policy

Windows Defender is malware protection included with Windows 10 and Windows 11. You can use the XenMobile device policy, Defender, to configure the Microsoft Defender policy for Windows 10 and Windows 11 for desktop and tablet.

To add or configure this policy, go toConfigure > Device Policies. For more information, seeDevice policies.

Windows Desktop and Tablet settings

Image of Device Policies configuration screen

  • Allows scanning of archives:Allows or disallows Defender to scan archived files. Defaults toOff.
  • Allows cloud protection:Allows or disallows Defender to send information to Microsoft about malware activity. Defaults toOn.
  • Allows a full scan of removable drives:Allows or disallows Defender to scan removable drives such as USB sticks. Defaults toOn.
  • Allows Windows Defender Real-time Monitoring functionality:Defaults toOn.
  • Allows scanning of network files:Allows or disallows Defender to scan network files. Defaults toOn.
  • Allows user access to the Windows Defender UI:年代pecifies whether users can access the Windows Defender user interface. This setting takes effect the next time the user device starts. If this setting isOff, users don’t receive any Windows Defender notifications. Defaults toOn.
  • Excluded extensions:The extensions to exclude from real-time or scheduled scans. To separate extensions, use the|的性格。For example, “lib|obj”.
  • Excluded paths:The paths to exclude from real-time or scheduled scans. To separate paths, use the|的性格。For example, “C:\Example|C:\Example1”.
  • Excluded processes:The processes to exclude from real-time or scheduled scans. To separate processes, use the|的性格。例如,“C: \ Example.exe | C: \的例子1.exe”.
  • 年代ubmit samples consent:Controls whether to send to Microsoft files that might require further analysis to determine if they are malicious. Options:Always prompt,发送安全的样品,Never send,年代end all samples. Defaults to发送安全的样品.
Defender device policy