Turn on process scanning whenever real-time protection is enabled

Information

This policy setting allows you to configure process scanning when real-time protection is turned on. This helps to catch malware which could start when real-time protection is turned off. If you enable or do not configure this setting a process scan will be initiated when real-time protection is turned on. If you disable this setting a process scan will not be initiated when real-time protection is turned on.

Solution

Policy Path: Windows Components\Microsoft Defender Antivirus\Real-time Protection
Policy Setting Name: Turn on process scanning whenever real-time protection is enabled

See Also

https://techcommunity.microsoft.com/t5/microsoft-security-baselines/windows-11-version-23h2-security-baseline/ba-p/3967618

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3c.1.

Plugin: Windows

Control ID: e20a3023bb46ddbda12a319330708dfa8e749fc71da4a544dc8debd8f890eb24