18.10.43.8.1 (L2) Ensure 'Convert warn verdict to block' is set to 'Enabled'

Information

This policy setting controls whether Microsoft Defender Antivirus network protection will display a warning, or block network traffic.

The recommended state for this setting is: Enabled

Potentially suspicious network traffic should be blocked until it has been reviewed, and an exception has been granted.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Administrative Templates\Windows Components\Microsoft Defender Antivirus\Network Inspection System\Convert warn verdict to block

Note: This Group Policy path is provided by the Group Policy template WindowsDefender.admx/adml that is included with the Microsoft Windows 11 Release 24H2 Administrative Templates (or newer).

Impact:

Legitimate network traffic could be blocked by Microsoft Defender Antivirus network protection.

See Also

https://workbench.cisecurity.org/benchmarks/21344

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, CSCv7|8.1

Plugin: Windows

Control ID: 9501414e622ec21b0941176f2bdaaf6cf24643a6c8c683c25ac498ebd1993eec