Turn on definition retirement

This policy setting allows you to configure definition retirement for network protection against exploits of known vulnerabilities. Definition retirement checks to see if a computer has the required security updates necessary to protect it against a particular vulnerability. If the system is not vulnerable to the exploit detected by a definition then that definition is “retired”. If all definitions for a given protocal are retired then that protocol is no longer parsed. Enabling this feature helps to improve performance. On a computer that is up-to-date with all the latest security updates network protection will have no impact on network performance. If you enable or do not configure this setting definition retirement will be enabled. If you disable this setting definition retirement will be disabled.

Randomize scheduled task times

This policy setting allows you to enable or disable randomization of the scheduled scan start time and the scheduled definition update start time. This setting is used to distribute the resource impact of scanning. For example it could be used in guest virtual machines sharing a host to prevent multiple guest virtual machines from undertaking a disk-intensive operation at the same time. If you enable or do not configure this setting scheduled tasks will begin at a random time within an interval of 30 minutes before and after the specified start time. If you disable this setting scheduled tasks will begin at the specified start time.

Allow antimalware service to remain running always

This policy setting allows you to configure whether or not the antimalware service remains running when antivirus and antispyware definitions are disabled. It is recommended that this setting remain disabled. If you enable this setting the antimalware service will always remain running even if both antivirus and antispyware definitions are disabled. If you disable or do not configure this setting the antimalware service will be stopped when both antivirus and antispyware definitions are disabled. If the computer is restarted the service will be started if it is set to Automatic startup. After the service has started there will be a check to see if antivirus and antispyware definitions are enabled. If at least one is enabled the service will remain running. If both are disabled the service will be stopped.

Extension Exclusions

This policy setting allows you specify a list of file types that should be excluded from scheduled custom and real-time scanning. File types should be added under the Options for this setting. Each entry must be listed as a name value pair where the name should be a string representation of the file type extension (such as “obj” or “lib”). The value is not used and it is recommended that this be set to 0.

Path Exclusions

This policy setting allows you to disable scheduled and real-time scanning for files under the paths specified or for the fully qualified resources specified. Paths should be added under the Options for this setting. Each entry must be listed as a name value pair where the name should be a string representation of a path or a fully qualified resource name. As an example a path might be defined as: “c: -> Windows” to exclude all files in this directory. A fully qualified resource name might be defined as: “C: -> Windows -> App. exe”. The value is not used and it is recommended that this be set to 0.

Prohibit access of the Windows Connect Now wizards

This policy setting prohibits access to Windows Connect Now (WCN) wizards. If you enable this policy setting the wizards are turned off and users have no access to any of the wizard tasks. All the configuration related tasks including “Set up a wireless router or access point” and “Add a wireless device” are disabled. If you disable or do not configure this policy setting users can access the wizard tasks including “Set up a wireless router or access point” and “Add a wireless device. ” The default for this policy setting allows users to access all WCN wizards.

Configuration of wireless settings using Windows Connect Now

This policy setting allows the configuration of wireless settings using Windows Connect Now (WCN). The WCN Registrar enables the discovery and configuration of devices over Ethernet (UPnP) over In-band 802. 11 Wi-Fi through the Windows Portable Device API (WPD) and via USB Flash drives. Additional options are available to allow discovery and configuration over a specific medium. If you enable this policy setting additional choices are available to turn off the operations over a specific medium. If you disable this policy setting operations are disabled over all media. If you do not configure this policy setting operations are enabled over all media. The default for this policy setting allows operations over all media.

Turn off Windows Defender

This policy setting turns off Windows Defender. If you enable this policy setting Windows Defender does not run and computers are not scanned for malware or other potentially unwanted software. If you disable or do not configure this policy setting by default Windows Defender runs and computers are scanned for malware and other potentially unwanted software.