Enable EDR in block mode

Information

This policy setting enables or disables EDR in block mode (also known as 'passive remediation'). EDR in block mode is recommended for devices running Microsoft Defender Antivirus in passive mode. Available with platform release: 4.18.2202.X

The data type is integer

Supported values:

1: Turn EDR in block mode on

0: Turn EDR in block mode off

Solution

Policy Path: Windows Components\Microsoft Defender Antivirus\Features
Policy Setting Name: Enable EDR in block mode

See Also

https://techcommunity.microsoft.com/t5/microsoft-security-baselines/windows-11-version-24h2-security-baseline/ba-p/4252801