Turn on process scanning whenever real-time protection is enabled

Information

This policy setting allows you to configure process scanning when real-time protection is turned on. This helps to catch malware which could start when real-time protection is turned off. If you enable or do not configure this setting a process scan will be initiated when real-time protection is turned on. If you disable this setting a process scan will not be initiated when real-time protection is turned on.

Solution

Policy Path: Windows Components\Microsoft Defender Antivirus\Real-time Protection
Policy Setting Name: Turn on process scanning whenever real-time protection is enabled

See Also

https://techcommunity.microsoft.com/t5/microsoft-security-baselines/windows-11-version-24h2-security-baseline/ba-p/4252801

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3c.1.

Plugin: Windows

Control ID: 32af6d76d1c971dda6f75839fcefcb99f3a71431786fdd79d7022b24949e0ab4