Information
This policy setting configures how aggressively Remote Encryption Prevention Protection blocks malicious IP addresses.
The recommended state for this setting is: Enabled: Medium or higher. Configuring this setting to High also conforms to the benchmark.
This feature can help reduce the likelihood of users visiting malicious websites.
Solution
To establish the recommended configuration via GP, set the following UI path to Enabled: Medium or higher:
Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Antivirus\Remediation\Behavioral Network Blocks\Remote Encryption Protection\Configure how aggressively Remote Encryption Protection blocks threats
Note: This Group Policy path is provided by the Group Policy template WindowsDefender.admx/adml that is included with the Microsoft Windows 11 Release 24H2 Administrative Templates (or newer).
Impact:
Legitimate websites could be blocked by Remote Encryption Prevention Protection. When set to Medium, blocks will occur when the confidence level is above 99%. When set to High, blocks will occur when confidence level is above 90%.