Edit

Configure security settings in Microsoft Defender for Endpoint on Linux

Microsoft Defender for Endpoint on Linux includes antivirus, anti-malware protection, endpoint detection, and response capabilities. This article summarizes important security settings to configure and includes links to other resources.

Settings Description
1. Configure static proxy discovery. Configuring a static proxy helps ensure telemetry is submitted and helps avoid network timeouts. Perform this task during and after your Defender for Endpoint installation.

For more information, see Configure Microsoft Defender for Endpoint on Linux for static proxy discovery.
2. Configure your antivirus scans. You can schedule automatic antivirus scans using built-in scheduled scan settings, or by using Anacron or Crontab.

For more information, see the following articles:
3. Configure your security settings and policies. You can use the Microsoft Defender portal (Defender for Endpoint Security Settings Management) or a configuration profile (.json file) to configure Defender for Endpoint on Linux. Or, you can use command line to configure certain settings.

For more information, see the following articles:
4. Configure and validate exclusions (as appropriate) You can exclude certain files, folders, processes, and process-opened files from Defender for Endpoint on Linux. Global exclusions apply to real-time protection (RTP), behavior monitoring (BM), and endpoint detection and response (EDR), thus stopping all associated antivirus detections, EDR alerts, and visibility for the excluded item.

For more information, see Configure and validate exclusions for Microsoft Defender for Endpoint on Linux.
5. Configure the eBPF-based sensor. The extended Berkeley Packet Filter (eBPF) for Microsoft Defender for Endpoint on Linux is automatically enabled for all customers by default for agent versions 101.23082.0006 and later. It provides supplementary event data for Linux operating systems and helps reduce the possibility of conflicts between applications.

For more information, see Use eBPF-based sensor for Microsoft Defender for Endpoint on Linux.
6. Configure Offline Security Intelligence Update (as appropriate) Offline Security Intelligence Update enables you to configure security intelligence updates for Linux servers with limited or no exposure to the internet. You can set up a local hosting server ("mirror server") that can connect to the Microsoft cloud to download the signatures. Other Linux endpoints can pull the updates from your mirror server at a predefined interval.

For more information, see Configure offline security intelligence update for Microsoft Defender for Endpoint on Linux.
7. Deploy updates. Microsoft regularly publishes software updates to improve performance, security, and to deliver new features.

For more information, see Deploy updates for Microsoft Defender for Endpoint on Linux.
8. Configure network protection (Preview) Network protection helps prevent users from using any application to access dangerous domains that might host phishing scams, exploits, and other malicious content on the internet.

For more information, see Network protection for Linux.

Important

If you want to run multiple security solutions side by side, see Considerations for performance, configuration, and support.

You might have already configured mutual security exclusions for devices onboarded to Microsoft Defender for Endpoint. If you still need to set mutual exclusions to avoid conflicts, see Add Microsoft Defender for Endpoint to the exclusion list for your existing solution.

Options for configuring security settings

To configure your security settings in Defender for Endpoint on Linux, you have two main options:

  • Use the Microsoft Defender portal (Defender for Endpoint Security Settings Management)

    or

  • Use a configuration profile

You can use the command line to configure specific settings, gather diagnostics, run scans, and more. For more information, see Linux resources: Configure using command line.

Configure settings with Defender for Endpoint Security Settings Management

You can configure Defender for Endpoint on Linux in the Microsoft Defender portal at (Microsoft Defender portal) using Defender for Endpoint Security Settings Management. For more information, including how to create, edit, and verify security policies, see Use Microsoft Defender for Endpoint Security Settings Management to manage Microsoft Defender Antivirus.

Use a configuration profile to manage security settings

You can configure settings in Defender for Endpoint on Linux through a configuration profile that uses a .json file. After you set up your profile, you can deploy it by using your management tool of choice. Preferences managed by the enterprise take precedence over preferences set locally on the device.

In other words, users in your enterprise aren't able to change preferences that are set through this configuration profile. If exclusions were added through the managed configuration profile, they can only be removed through the managed configuration profile. The command line works for exclusions added locally.

The following configuration profile guidance describes the structure of the Defender for Endpoint on Linux configuration profile, includes a recommended starter profile, and explains how to deploy it.

Configuration profile structure

The configuration profile is a .json file that consists of entries identified by a key (which denotes the name of the preference), followed by a value, which depends on the nature of the preference. Values can be simple (for example, a numerical value) or complex (for example, a nested list of preferences).

Typically, you use a configuration management tool to push a file named mdatp_managed.json to the location /etc/opt/microsoft/mdatp/managed/.

The top level of the configuration profile includes product-wide preferences and entries for subareas of the product, such as Antivirus engine preferences, Cloud-delivered protection preferences, Advanced optional features, and Network protection configurations.

The following recommended configuration profile guidance includes two configuration profile examples:

  • Sample profile to help you get started with recommended settings.
  • Full configuration profile example for organizations who want more granular control over security settings.

To get started, we recommend using the first sample profile for your organization. For more granular control, you can use the full configuration profile example instead.

Sample profile

The following configuration profile helps you take advantage of important protection features in Defender for Endpoint on Linux. The profile includes the following configuration:

  • Enable real-time protection (RTP).
  • Specify how the following threat types are handled:
    • Potentially unwanted applications (PUA) are blocked.
    • Archive bombs (file with a high compression rate) are audited to the product logs.
  • Enable automatic security intelligence updates.
  • Enable cloud-delivered protection.
  • Enable automatic sample submission at safe level.
{
   "antivirusEngine":{
      "enforcementLevel":"real_time",
      "threatTypeSettings":[
         {
            "key":"potentially_unwanted_application",
            "value":"block"
         },
         {
            "key":"archive_bomb",
            "value":"audit"
         }
      ]
   },
   "cloudService":{
      "automaticDefinitionUpdateEnabled":true,
      "automaticSampleSubmissionConsent":"safe",
      "enabled":true,
      "proxy": "<EXAMPLE DO NOT USE> http://proxy.server:port/"
   }
}
Full configuration profile example

The following complete managed configuration example contains entries for all settings described in this article, including antivirus engine, scheduled scan, cloud service, advanced feature, network protection, EDR, and exclusion settings. You can use this profile for advanced scenarios where you want granular control over each setting.

{
"antivirusEngine":{
      "enforcementLevel":"passive",
      "behaviorMonitoring": "disabled",
      "scanAfterDefinitionUpdate":true,
      "scanArchives":true,
      "scanHistoryMaximumItems": 10000,
      "scanResultsRetentionDays": 90,
      "maximumOnDemandScanThreads":2,
      "exclusionsMergePolicy":"merge",
      "allowedThreats":[
         "<EXAMPLE DO NOT USE>EICAR-Test-File (not a virus)"
      ],
      "disallowedThreatActions":[
         "allow",
         "restore"
      ],
      "nonExecMountPolicy":"unmute",
      "unmonitoredFilesystems": ["nfs,fuse"],
      "enableFileHashComputation": false,
      "threatTypeSettingsMergePolicy":"merge",
      "threatTypeSettings":[
         {
            "key":"potentially_unwanted_application",
            "value":"block"
         },
         {
            "key":"archive_bomb",
            "value":"audit"
         }
      ],
      "scanFileModifyPermissions":true,
      "scanFileModifyOwnership":false,
      "scanNetworkSocketEvent":false,
      "offlineDefinitionUpdateUrl": "http://172.22.199.67:8000/linux/production/<EXAMPLE DO NOT USE>",
      "offlineDefinitionUpdateFallbackToCloud":false,
      "offlineDefinitionUpdate":"disabled",
      "scheduledScan": "enabled"
   },
   "scheduledScan":{
      "weeklyConfiguration":{
         "dayOfWeek": 7,
         "scanType": "full",
         "timeOfDay": 180
      },
      "dailyConfiguration":{
         "timeOfDay": 180
      },
      "runScanWhenIdle": true,
      "lowPriorityScheduledScan": true,
      "checkForDefinitionsUpdate": true,
      "ignoreExclusions": false,
      "randomizeScanStartTime": 3
   },
   "cloudService":{
      "enabled":true,
      "diagnosticLevel":"optional",
      "automaticSampleSubmissionConsent":"safe",
      "automaticDefinitionUpdateEnabled":true,
      "proxy": "<EXAMPLE DO NOT USE> http://proxy.server:port/",
      "definitionUpdatesInterval":28800
   },
   "features":{
      "moduleLoad":"disabled",
      "supplementarySensorConfigurations":{
        "enableFilePermissionEvents":"disabled",
        "enableFileOwnershipEvents":"disabled",
        "enableRawSocketEvent":"disabled",
        "enableBootLoaderCalls":"disabled",
        "enableProcessCalls":"disabled",
        "enablePseudofsCalls":"disabled",
        "enableEbpfModuleLoadEvents":"disabled",
        "sendLowfiEvents":"disabled"
      },
      "ebpfSupplementaryEventProvider":"enabled",
      "offlineDefinitionUpdateVerifySig": "disabled"
   },
   "networkProtection":{
      "enforcementLevel":"disabled",
      "disableIcmpInspection":true
   },
   "edr":{
      "groupIds":"GroupIdExample",
      "tags": [
         {
         "key": "GROUP",
         "value": "Tag"
         }
       ]
   },
"exclusionSettings":{
  "exclusions":[
     {
        "$type":"excludedPath",
        "isDirectory":true,
        "path":"/home/*/git<EXAMPLE DO NOT USE>",
        "scopes": [
              "epp"
        ]
     },
     {
        "$type":"excludedPath",
        "isDirectory":true,
        "path":"/run<EXAMPLE DO NOT USE>",
        "scopes": [
              "global"
        ]
     },
     {
        "$type":"excludedPath",
        "isDirectory":false,
        "path":"/var/log/system.log<EXAMPLE DO NOT USE><EXCLUDED IN ALL SCENARIOS>",
        "scopes": [
              "epp", "global"
        ]
     },
     {
        "$type":"excludedFileExtension",
        "extension":".pdf<EXAMPLE DO NOT USE>",
        "scopes": [
              "epp"
        ]
     },
     {
        "$type":"excludedFileName",
        "name":"/bin/cat<EXAMPLE DO NOT USE><NO SCOPE PROVIDED - GLOBAL CONSIDERED>"
     }
  ],
  "mergePolicy":"admin_only"
}
}

Antivirus, antimalware, and EDR settings in Defender for Endpoint on Linux

Whether you use a configuration profile (.json file) or the Microsoft Defender portal (Security Settings Management), you can configure your antivirus, antimalware, and EDR settings in Defender for Endpoint on Linux. The following sections describe where and how to configure your settings.

Antivirus engine preferences

The antivirusEngine section of the configuration profile manages the preferences of the antivirus component of the product.

Description JSON Value Defender portal value
Key antivirusEngine Antivirus Engine
Data type Dictionary (nested preference) Collapsed Section

For descriptions of the dictionary contents and policy properties, see Enforcement level for Microsoft Defender Antivirus, Scan exclusions, Threat type settings, and Exclusion merge policy.

Enforcement level for Microsoft Defender Antivirus

Specifies the enforcement preference of the antivirus engine. There are three values for setting enforcement level:

Important

Only one enforcement level can be configured at a time. You can configure either passive or real-time mode, but not both.

  • Real-time (real_time): Real-time protection (scan files as they're modified) is enabled.

  • On-demand (on_demand): Files are scanned only on demand:

    • Real-time protection is off.
    • Definition updates occur only when a scan starts, even if automaticDefinitionUpdateEnabled is set to true in on-demand mode.
  • Passive (passive): Runs the antivirus engine in passive mode:

    • Real-time protection is off. Microsoft Defender Antivirus doesn't remediate threats.
    • On-demand scanning is on. Scan capabilities are still available on the device.
    • Automatic threat remediation is off. No files are moved and your security administrator is expected to take required action.
    • Security intelligence updates are on. Alerts are available in the security administrator's organization.
    • Definition updates occur only when a scan starts, even if automaticDefinitionUpdateEnabled is set to true.
    • Endpoint detection and response (EDR) is on. The output of the mdatp health command on the device shows engine not loaded for the engine_load_version property. The engine is related to antivirus, not EDR.

To check whether real-time protection is active after applying an enforcement level configuration, run the following command. The command returns true if real-time protection is enabled or false if it's disabled:

mdatp health --field real_time_protection_enabled

Note

  • Available in Defender for Endpoint version 101.10.72 or later.
  • In version 101.23062.0001 or later, the default value is passive. In previous versions, the default was real_time.
  • We also recommended using scheduled scans as per requirement.

Enable or disable behavior monitoring (if RTP is enabled)

Important

This feature works only when the enforcement level is real-time.

Specifies whether behavior monitoring and blocking capability is enabled or disabled on the device.

Description JSON Value Defender portal value
Key behaviorMonitoring Enable behavior monitoring
Data type String Drop down
Possible values disabled (default)
enabled
Not configured
Disabled (Default)
Enabled

Note

Available in Defender for Endpoint version 101.45.00 or later.

Run a scan after definitions are updated

Important

This feature works only when the enforcement level is set to real-time.

Specifies whether to start a process scan after new security intelligence updates are downloaded on the device. Enabling this setting triggers an antivirus scan on the running processes of the device.

Description JSON Value Defender portal value
Key scanAfterDefinitionUpdate Enable Scanning after definition update
Data type Boolean Drop down
Possible values true (default)
false
Not configured
Disabled
Enabled (Default)

Note

Available in Defender for Endpoint version 101.45.00 or later.

Scan archives (on-demand antivirus scans only)

Specifies whether to scan archives during on-demand antivirus scans.

Description JSON Value Defender portal value
Key scanArchives Enable scanning of archives
Data type Boolean Drop down
Possible values true (default)
false
Not configured
Disabled
Enabled (Default)

Note

  • Available in Microsoft Defender for Endpoint version 101.45.00 or later.
  • Archive files are never scanned during RTP. Files in the archive are scanned after you extract them. The scanArchives option forces archive scanning during on-demand scans only.

Degree of parallelism for on-demand scans

Specifies the degree of parallelism for on-demand scans. This setting corresponds to the number of processor threads used by the scan. This setting affects CPU usage and the duration of on-demand scans.

Description JSON Value Defender portal value
Key maximumOnDemandScanThreads maximum on demand scan threads
Data type Integer Toggle Switch & Integer
Possible values 2 (default). Allowed values are integers between 1 and 64. Not Configured (Default toggle off defaults to 2)
Configured (toggle on) and integer between 1 and 64.

Note

Available in Microsoft Defender for Endpoint version 101.45.00 or later.

Exclusion merge policy

Note

We recommend configuring exclusions and the merge policy in exclusionSettings. This approach allows you to configure epp and global scope exclusions with a single mergePolicy. The settings in this section apply only to epp exclusions unless the merge policy in exclusionSettings is admin_only.

Specifies whether to use user-defined exclusions on the device. Valid values are:

  • admin_only: Use only admin-defined exclusions configured by Defender for Endpoint policy. Use this value to prevent users from defining their own exclusions.
  • merge: Use a combination of admin-defined and user-defined exclusions.
Description JSON Value Microsoft Defender portal value
Key exclusionsMergePolicy Exclusions merge
Data type String Drop down
Possible values merge (default)
admin_only
Not configured
merge (Default)
admin_only

Note

Available in Defender for Endpoint version 100.83.73 or later.

Configure scan exclusions

Entities excluded from scans. You specify exclusions as an array of items. Admins can specify as many elements as necessary, in any order. You specify exclusions using full paths, extensions, or file names.

Description JSON Value Microsoft Defender portal value
Key exclusions Scan exclusions
Data type Dictionary (nested preference) Dynamic Properties List

For a description of the dictionary contents, see Type of exclusion, Path to excluded content, Path type (file / directory), File extension excluded from the scan, and Process excluded from the scan.

Type of exclusion

Specifies the type of content excluded from scans.

Description JSON Value Microsoft Defender portal value
Key $type Type
Data type String Drop Down
Possible values excludedPath
excludedFileExtension
excludedFileName
Path
File extension
Process name

Path to excluded content

Exclude content from the scan by full file path.

Description JSON Value Microsoft Defender portal value
Key path Path
Data type String String
Possible values valid paths valid paths
Comments Applicable only if $type is excludedPath Accessed in Edit instance popup

Path type (file / directory)

Specifies whether the path property refers to a file or a directory.

Description JSON Value Microsoft Defender portal value
Key isDirectory Is directory
Data type Boolean Drop down
Possible values false (default)
true
Enabled
Disabled
Comments Applicable only if $type is excludedPath Accessed in Edit instance popup

File extension excluded from the scan

Exclude content from the scan by file extension.

Description JSON Value Microsoft Defender portal value
Key extension File extension
Data type String String
Possible values valid file extensions valid file extensions
Comments Applicable only if $type is excludedFileExtension Accessed in Configure instance popup

Process excluded from the scan

Specifies a process for which all file activity is excluded from scanning. You can specify the process by name (for example, cat) or full path (for example, /bin/cat).

Description JSON Value Microsoft Defender portal value
Key name File name
Data type String String
Possible values any string any string
Comments Applicable only if $type is excludedFileName Accessed in Configure instance popup

Muting nonexec mounts

Specifies the behavior of RTP on mount points marked as noexec. Valid values are:

  • Unmuted (unmute): All mount points are scanned as part of RTP. This value is the default.
  • Muted (mute): Mount points marked as noexec aren't scanned as part of RTP.
    • Database servers can keep database file.
    • File servers can keep data file mount points.
    • Backup can keep data file mount points.
Description JSON Value Microsoft Defender portal value
Key nonExecMountPolicy non execute mount mute
Data type String Drop down
Possible values unmute (default)
mute
Not configured
unmute (Default)
mute

Note

Available in Defender for Endpoint version 101.85.27 or later.

Unmonitor filesystems

Specifies the filesystems that aren't monitored by (are excluded from) RTP. The specified filesystems are still scanned by Quick, Full, and custom scans in Microsoft Defender Antivirus.

When you add or remove a filesystem from the unmonitored list, Microsoft validates the eligibility of the filesystem for monitoring by RTP (removed from the list) or no monitoring by RTP (added to the list).

Description JSON Value Microsoft Defender portal value
Key unmonitoredFilesystems Unmonitored Filesystems
Data type Array of strings Dynamic String List
  • By default, the following filesystems are monitored by RTP:

    • btrfs
    • ecryptfs
    • ext2
    • ext3
    • ext4
    • fuseblk
    • jfs
    • overlay
    • ramfs
    • reiserfs
    • tmpfs
    • udf
    • vfat
    • xfs
  • By default, the following filesystems are unmonitored by RTP:

    • cifs*
    • fuse
    • nfs
    • nfs4*
    • smb*

    These filesystems are also unmonitored by Quick and Full scans, but are scannable by custom scans.

    * Currently, RTP monitoring of this filesystem is in Preview.

To configure the unmonitoredFilesystems setting, add it to the antivirusEngine section of your managed configuration file. Filesystems included in this array are excluded from real-time protection (RTP) monitoring. For example, to remove nfs and nfs4 from the unmonitored list so that RTP monitors them after validation, update the managed config file with the following entry:

{
   "antivirusEngine":{
      "unmonitoredFilesystems": ["cifs","fuse","smb"]
  }
}

To clear the unmonitored filesystems list so that RTP monitors all supported filesystem types, set unmonitoredFilesystems to an empty array. This configuration ensures that no filesystems are excluded from real-time protection monitoring:

{
   "antivirusEngine":{
      "unmonitoredFilesystems": []
  }
}

Configure file hash computation feature

Enables or disables file hash computation for files scanned by Defender for Endpoint. Enabling this feature might affect device performance. For more information, see Create indicators for files.

Description JSON Value Microsoft Defender portal value
Key enableFileHashComputation Enable file hash computation
Data type Boolean Drop down
Possible values false (default)
true
Not configured
Disabled (default)
Enabled

Note

Available in Defender for Endpoint version 101.85.27 or later.

Configure allowed threats

Specifies the names of threats that aren't blocked by Defender for Endpoint. Instead, these threats are allowed to run.

Description JSON Value Microsoft Defender portal value
Key allowedThreats Allowed threats
Data type Array of strings Dynamic String List

Configure disallowed threat actions

Restricts the allowed actions by the device user when threats are detected. The actions included in this list aren't displayed in the user interface.

Description JSON Value Microsoft Defender portal value
Key disallowedThreatActions Disallowed threat actions
Data type Array of strings Dynamic String List
Possible values allow (restricts users from allowing threats)
restore (restricts users from restoring threats from the quarantine)
allow (restricts users from allowing threats)
restore (restricts users from restoring threats from the quarantine)

Note

Available in Defender for Endpoint version 100.83.73 or later.

Threat type settings

Control how certain threat types are handled.

Description JSON Value Microsoft Defender portal value
Key threatTypeSettings Threat type settings
Data type Dictionary (nested preference) Dynamic Properties List

For a description of the dictionary contents, see Threat type and Action to take.

Threat type

Specifies the type of threat.

Description JSON Value Microsoft Defender portal value
Key key Threat type
Data type String Drop down
Possible values potentially_unwanted_application
archive_bomb
potentially_unwanted_application
archive_bomb

Action to take

Specifies the action when the previously specified threats types are detected. Valid values are:

  • Audit: The device isn't protected against this type of threat, but an entry about the threat is logged. This value is the Default.
  • Block: The device is protected against this type of threat and you're notified in the Microsoft Defender portal.
  • Off: The device isn't protected against this type of threat and nothing is logged.
Description JSON Value Microsoft Defender portal value
Key value Action to take
Data type String Drop down
Possible values audit (default)
block
off
audit
block
off

Threat type settings merge policy

Specifies whether to use user-defined threat type settings on the device. Valid values are:

  • admin_only: Use only admin-defined threat type settings. Use this value to prevent users from defining their own threat type settings.
  • merge: Use a combination of admin-defined and user-defined threat type settings.
Description JSON Value Microsoft Defender portal value
Key threatTypeSettingsMergePolicy Threat type settings merge
Data type String Drop down
Possible values merge (default)
admin_only
Not configured
merge (Default)
admin_only

Note

Available in Defender for Endpoint version 100.83.73 or later.

Antivirus scan history retention (in days)

Specify the number of days that results are retained in the scan history on the device. Old scan results are removed from the history. Old quarantined files are also removed from the disk.

Description JSON Value Microsoft Defender portal value
Key scanResultsRetentionDays Scan results retention
Data type String Toggle switch and Integer
Possible values 90 (default). Valid values are 1 to 180 days. Not configured (toggle off; 90-day default)

Configured (toggle on) and allowed value 1 to 180 days.

Note

Available in Defender for Endpoint version 101.04.76 or later.

Maximum number of items in the antivirus scan history

Specify the maximum number of entries to keep in the scan history. Entries include all on-demand scans and all antivirus detections.

Description JSON Value Microsoft Defender portal value
Key scanHistoryMaximumItems Scan history size
Data type String Toggle and Integer
Possible values 10000 (default). Allowed values are from 5000 items to 15000 items. Not configured (toggle off - 10000 default)
Configured (toggle on) and allowed value from 5000 to 15000 items.

Note

Available in Defender for Endpoint version 101.04.76 or later.

Exclusion setting preferences

Note

Global exclusions are available in Defender for Endpoint version 101.24092.0001 or later.

The exclusionSettings section of the configuration profile configures various exclusions for Microsoft Defender for Endpoint for Linux.

Description JSON Value
Key exclusionSettings
Data type Dictionary (nested preference)

For a description of the dictionary contents, see Merge policy, Exclusion merge policy, and Exclusions.

Note

  • Previously configured antivirus exclusions in the antivirusEngine section in managed JSON continue to function.
  • You can specify antivirus exclusions in this section or in the antivirusEngine) section. You should add all other exclusion type in this section, because the exclusionSettings section is designed to centrally host all exclusion types.

Exclusion settings merge policy

The following setting controls how admin-defined and user-defined exclusions are combined.

Exclusion merge policy

Specifies whether to use user-defined exclusions on the device. Valid values are:

  • admin_only: Use only admin-defined exclusions configured by Defender for Endpoint policy. Use this value to prevent users from defining their own exclusions.
  • merge: Use a combination of admin-defined and user-defined exclusions.

This setting applies to exclusions of all scopes.

Description JSON Value
Key mergePolicy
Data type String
Possible values merge (default)
admin_only

Note

Available in Defender for Endpoint version Sept 2023 or later.

Exclusions

Entities excluded from scans. You specify exclusions as an array of items. Admins can specify as many elements as necessary, in any order. You specify exclusions using full paths, extensions, or file names. For each exclusion, you can specify a scope. The default scope is global.

Description JSON Value
Key exclusions
Data type Dictionary (nested preference)

The exclusion dictionary includes entries for type of exclusion, scope of exclusion, path to excluded content, path type (file or directory), file extension, and process name.

Type of exclusion

Specifies the type of content excluded from scans.

Description JSON Value
Key $type
Data type String
Possible values excludedPath
excludedFileExtension
excludedFileName

Scope of exclusion (optional)

Specifies the exclusion scope of excluded content. Valid values are:

  • epp
  • global

If you don't specify an exclusion scope in managed configuration, the value global is used.

Note

Previously configured antivirus exclusions under antivirusEngine in managed JSON continue to function with the scope epp because they were in the antivirusEngine section.

Description JSON Value
Key scopes
Data type Set of strings
Possible values epp
global

Note

Previously applied exclusions using (mdatp_managed.json) or by CLI are unaffected. The scope for these exclusions is epp because they were in the antivirusEngine section.

Path to excluded content

Exclude content from scans by full file path.

Description JSON Value
Key path
Data type String
Possible values valid paths
Comments Applicable only if $type is excludedPath.
Wildcards aren't supported if the exclusion has a global scope.

Path type (file / directory)

Specifies whether the path property refers to a file or a directory.

Note

The File path must already exist if you add a file exclusion with global scope.

Description JSON Value
Key isDirectory
Data type Boolean
Possible values false (default)
true
Comments Applicable only if $type is excludedPath.
Wildcards aren't supported if the exclusion has a global scope.

File extension excluded from the scan

Exclude content from scans by file extension.

Description JSON Value
Key extension
Data type String
Possible values valid file extensions
Comments Applicable only if $type is excludedFileExtension.
Not supported if the exclusion has a global scope.

Process excluded from the scan

Exclude all file activity by a process from scans. Valid values are:

  • Process name. For example, cat.
  • Full path. For example, /bin/cat.
Description JSON Value
Key name
Data type String
Possible values any string
Comments Applicable only if $type is excludedFileName.
Wildcards and process names aren't supported if the exclusion has a global scope.
You need to provide the full path.

Advanced scan options

You can configure the following settings to enable certain advanced scanning features.

Important

Enabling these features might affect device performance. We recommended the default values unless recommended otherwise by Microsoft Support.

Configure scanning of file modify permissions events

Specifies whether Defender for Endpoint scans files when their permissions changed to set the executed bits.

Note

This setting is meaningful only when enableFilePermissionEvents is enabled. For more information, see Configure monitoring of file modify permissions events.

Description JSON Value Microsoft Defender portal value
Key scanFileModifyPermissions Not available
Data type Boolean n/a
Possible values false (default)
true
n/a

Note

Available in Defender for Endpoint version 101.23062.0010 or later.

Configure scanning of file modify ownership events

Specifies whether Defender for Endpoint scans files with changed ownership.

Note

This setting is meaningful only when enableFileOwnershipEvents is enabled. For more information, see Configure monitoring of file modify ownership events.

Description JSON Value Microsoft Defender portal value
Key scanFileModifyOwnership Not available
Data type Boolean n/a
Possible values false (default)
true
n/a

Note

Available in Defender for Endpoint version 101.23062.0010 or later.

Configure scanning of raw socket events

Specifies whether Defender for Endpoint scans network socket events. For example:

  • Creating raw sockets / packet sockets.
  • Setting socket options.

Note

  • This setting is meaningful only when Behavior Monitoring is enabled.
  • This setting is meaningful only when enableRawSocketEvent is enabled. For more information, see Configure monitoring of raw socket events.
Description JSON Value Microsoft Defender portal value
Key scanNetworkSocketEvent Not available
Data type Boolean n/a
Possible values false (default)
true
n/a

Note

Available in Defender for Endpoint version 101.23062.0010 or later.

Scheduled scan preferences (preview)

The scheduledScan section of the configuration profile configures built-in scheduled antivirus scans. To enable scheduled scans, set antivirusEngine.scheduledScan to "enabled".

Note

Available in Defender for Endpoint version 101.26032.0000 or later.

Description JSON Value
Key scheduledScan
Data type Dictionary (nested preference)

For a description of the scheduled scan dictionary contents, see Enable scheduled scans, Weekly scan configuration, Daily scan configuration, and Advanced scheduled scan settings.

For the full details on scheduled scan configuration, including how to use Security Settings Management policies and the command line, see Schedule antivirus scans on Linux (preview).

Enable scheduled scans

Specifies whether scheduled scans are enabled.

Description JSON Value
Key antivirusEngine.scheduledScan
Data type String
Possible values disabled (default)
enabled

Weekly scan configuration

Configures a weekly scan with a specific day, time, and scan type.

Description JSON Value
Key weeklyConfiguration
Data type Dictionary (nested preference)
Day of the week

Specifies the day the weekly scan runs.

Description JSON Value
Key dayOfWeek
Data type Integer
Possible values 0 (disabled, default)
17 (Sunday–Saturday)
8 (every day)
Scan type (weekly)

Specifies the scan type for weekly scans.