Check: WNDF-AV-000069
Microsoft Defender Antivirus STIG:
WNDF-AV-000069
(in version v2 r6)
Title
Microsoft Defender AV must disable auto exclusions. (Cat II impact)
Discussion
Custom exclusions apply to scheduled scans, on-demand scans, and always-on real-time protection and monitoring. Exclusions for process-opened files only apply to real-time protection.
Check Content
Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Exclusions >> Turn off Auto Exclusions is set to "Disabled"; otherwise, this is a finding. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows Defender\Exclusions Criteria: If the value "DisableAutoExclusions" is REG_DWORD = 0, this is not a finding. If the value is 1, this is a finding.
Fix Text
Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> Exclusions >> Turn off Auto Exclusions to "Disabled". Click "OK". Click "Apply".
Additional Identifiers
Rule ID: SV-278673r1144069_rule
Vulnerability ID: V-278673
Group Title: SRG-APP-000210
Expert Comments
CCIs
| Number | Definition |
|---|---|
| CCI-001170 |
Prevents the automatic execution of mobile code in organization-defined software applications. |
Controls
| Number | Title |
|---|---|
| SC-18(4) |
Prevent Automatic Execution |