18.10.43.13.4 (L1) Ensure 'Trigger a quick scan after X days without any scans' is set to 'Enabled: 7'

Information

This policy setting configures the number of days after the last scan (of any type) before an aggressive Quick Scan is automatically triggered.

The recommended state for this setting is: Enabled: 7 days.

Antivirus scans should be performed on a regular basis so that malicious software can be detected and remediated before malicious activity occurs.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: 7 days:

Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Antivirus\Scan\Trigger a quick scan after X days without any scans

Note: This Group Policy path is provided by the Group Policy template WindowsDefender.admx/adml that is included with the Microsoft Windows 11 Release 24H2 Administrative Templates (or newer).

Impact:

This setting should have no adverse effect on the system.

See Also

https://workbench.cisecurity.org/benchmarks/21318

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, CSCv7|8.1

Plugin: Windows

Control ID: 90d346dcf6c283284eafc696c634aa82a818843278a51a91e6902557ba046491