Check: WNDF-AV-000073
Microsoft Defender Antivirus STIG:
WNDF-AV-000073
(in versions v2 r7 through v2 r6)
Title
Microsoft Defender AV must set cloud protection level to High. (Cat II impact)
Discussion
Cloud protection in Microsoft Defender Antivirus delivers accurate, real-time, and intelligent protection. Cloud protection should be enabled by default.
Check Content
Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> MpEngine >> Select cloud protection level is set to "Enabled". Verify the policy value for "Select cloud blocking level" is set to "High blocking level"; otherwise, this is a finding. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows Defender\MpEngine Criteria: If the value "MpCloudBlockLevel" is REG_DWORD = 2, this is not a finding. If the value is other than 2, this is a finding.
Fix Text
Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> MpEngine >> Select cloud protection level to "Enabled". Set policy value "Select cloud blocking level" to "High blocking level". Click "OK". Click "Apply".
Additional Identifiers
Rule ID: SV-278863r1144086_rule
Vulnerability ID: V-278863
Group Title: SRG-APP-000210
Expert Comments
CCIs
| Number | Definition |
|---|---|
| CCI-001170 |
Prevents the automatic execution of mobile code in organization-defined software applications. |
Controls
| Number | Title |
|---|---|
| SC-18(4) |
Prevent Automatic Execution |