Extension Exclusions

This policy setting allows you specify a list of file types that should be excluded from scheduled custom and real-time scanning. File types should be added under the Options for this setting. Each entry must be listed as a name value pair where the name should be a string representation of the file type extension (such as “obj” or “lib”). The value is not used and it is recommended that this be set to 0.

Allow antimalware service to remain running always

This policy setting allows you to configure whether or not the antimalware service remains running when antivirus and antispyware definitions are disabled. It is recommended that this setting remain disabled. If you enable this setting the antimalware service will always remain running even if both antivirus and antispyware definitions are disabled. If you disable or do not configure this setting the antimalware service will be stopped when both antivirus and antispyware definitions are disabled. If the computer is restarted the service will be started if it is set to Automatic startup. After the service has started there will be a check to see if antivirus and antispyware definitions are enabled. If at least one is enabled the service will remain running. If both are disabled the service will be stopped.

Randomize scheduled task times

This policy setting allows you to enable or disable randomization of the scheduled scan start time and the scheduled definition update start time. This setting is used to distribute the resource impact of scanning. For example it could be used in guest virtual machines sharing a host to prevent multiple guest virtual machines from undertaking a disk-intensive operation at the same time. If you enable or do not configure this setting scheduled tasks will begin at a random time within an interval of 30 minutes before and after the specified start time. If you disable this setting scheduled tasks will begin at the specified start time.

Define proxy server for connecting to the network

This policy setting allows you to configure the named proxy that should be used when the client attempts to connect to the network for definition updates and MAPS reporting. If the named proxy fails or if there is no proxy specified the following settings will be used (in order):1. Internet Explorer proxy settings2. Autodetect3. NoneIf you enable this setting the proxy will be set to the specified URL. If you disable or do not configure this setting the proxy will be set according to the order specified above.

Define addresses to bypass proxy server

This policy if defined will prevent antimalware from using the configured proxy server when communicating with the specified IP addresses. The address value should be entered as a valid URL. If you enable this setting the proxy server will be bypassed for the specified addresses. If you disable or do not configure this setting the proxy server will not be bypassed for the specified addresses.

Turn off routine remediation

This policy setting allows you to configure whether Windows Defender automatically takes action on all detected threats. The action to be taken on a particular threat is determined by the combination of the policy-defined action user-defined action and the signature-defined action. If you enable this policy setting Windows Defender does not automatically take action on the detected threats but prompts users to choose from the actions available for each threat. If you disable or do not configure this policy setting Windows Defender automatically takes action on all detected threats after a nonconfigurable delay of approximately ten minutes.

Configure local administrator merge behavior for lists

This policy setting controls whether or not complex list settings configured by a local administrator are merged with Group Policy settings. This setting applies to lists such as threats and Exclusions. If you enable or do not configure this setting unique items defined in Group Policy and in preference settings configured by the local administrator will be merged into the resulting effective policy. In the case of conflicts Group policy Settings will override preference settings. If you disable this setting only items defined by Group Policy will be used in the resulting effective policy. Group Policy settings will override preference settings configured by the local administrator.

Turn off Windows Defender

This policy setting turns off Windows Defender. If you enable this policy setting Windows Defender does not run and computers are not scanned for malware or other potentially unwanted software. If you disable or do not configure this policy setting by default Windows Defender runs and computers are scanned for malware and other potentially unwanted software.

Configuration of wireless settings using Windows Connect Now

This policy setting allows the configuration of wireless settings using Windows Connect Now (WCN). The WCN Registrar enables the discovery and configuration of devices over Ethernet (UPnP) over In-band 802. 11 Wi-Fi through the Windows Portable Device API (WPD) and via USB Flash drives. Additional options are available to allow discovery and configuration over a specific medium. If you enable this policy setting additional choices are available to turn off the operations over a specific medium. If you disable this policy setting operations are disabled over all media. If you do not configure this policy setting operations are enabled over all media. The default for this policy setting allows operations over all media.