18.10.43.4.1 (L1) Ensure 'Enable EDR in block mode' is set to 'Enabled'

Information

This policy setting controls whether Microsoft Defender Antivirus Endpoint Detection and Response (EDR) is enabled in block mode (passive remediation).

The recommended state for this setting is: Enabled

Note: EDR in block mode is only available in Microsoft Defender for Endpoint Plan 2.

Note #2: This setting is available with Microsoft Defender Antivirus platform release v4.18.2202.X and newer.

When Microsoft Defender Antivirus is not the primary antivirus product and is running in passive mode, EDR in block mode provides added protection against malicious artifacts.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Antivirus\Features\Enable EDR in block mode

Note: This Group Policy path is provided by the Group Policy template WindowsDefender.admx/adml that is included with the Microsoft Windows 11 Release 24H2 Administrative Templates (or newer).

Impact:

If Microsoft Defender Antivirus is running EDR will be enabled in block mode. If the system does not have Microsoft Defender Antivirus installed and running, then this setting will have no effect.

See Also

https://workbench.cisecurity.org/benchmarks/21318

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, CSCv7|8.1

Plugin: Windows

Control ID: fe2942fa8a863a183eb202f46f51e2e7750861e83db142080a54ca550e59ad55