Defender ATP GPO
Configuring Defender ATP with GPO¶
Microsoft Defender ATP (Advanced Threat Protection) provides advanced endpoint security capabilities, including threat detection, investigation, and response. Integrating Defender ATP with Group Policy Objects (GPO) allows administrators to centrally enforce security baselines, monitor endpoint behavior, and automate response actions across managed Windows devices. This section outlines how to deploy and configure Defender ATP using GPO.
1. Enabling Defender ATP via GPO¶
Before configuring Defender ATP policies, ensure the service is installed and running on target devices. Defender ATP (now Microsoft Defender for Endpoint) is not included by default in Windows 10/11, Windows Server 2016, or Windows Server 2019. It must be deployed via the Microsoft 365 Defender portal.
Prerequisites:
- A valid Microsoft 365 Defender subscription.
- Defender for Endpoint service enabled for the tenant.
- GPO linked to the organizational unit (OU) containing target devices.
Steps to configure Defender ATP via GPO:
1. Open the Group Policy Management Console (GPMC).
2. Create a new GPO or edit an existing one, then link it to the target OU.
3. Navigate to:
Computer Configuration > Administrative Templates > Microsoft Defender ATP > Defender ATP settings
4. Enable the following policies:
- Enable Microsoft Defender ATP: Ensures the service is active.
- Allow Microsoft Defender ATP to collect data: Enables telemetry and threat intelligence.
- Allow Microsoft Defender ATP to use cloud protection: Enables cloud-based threat detection.
Example PowerShell command to verify GPO application:
2. Configuring Protection and Monitoring Policies¶
Defender ATP policies can enforce real-time protection, cloud protection, and network protection settings.
Real-Time Protection:
- Policy Path: Computer Configuration > Administrative Templates > Microsoft Defender ATP > Real-time protection
- Key Settings:
- Enable real-time protection: Blocks malicious files in real time.
- Exclude paths: Add directories to exclude from scans (e.g., C:\Program Files\ for legitimate software).
Cloud Protection:
- Policy Path: Computer Configuration > Administrative Templates > Microsoft Defender ATP > Cloud protection
- Key Settings:
- Enable cloud protection: Uses Microsoft’s threat intelligence database.
- Cloud protection scan interval: Set the frequency for cloud-based scans (default: 24 hours).
Network Protection:
- Policy Path: Computer Configuration > Administrative Templates > Microsoft Defender ATP > Network protection
- Key Settings:
- Enable network protection: Detects and blocks malicious network activity.
- Allow network protection to use cloud-based protection: Enhances detection with Microsoft’s cloud database.
Example GPO setting for cloud protection scan interval:
[Registry Item]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Cloud Protection]
"ScanIntervalInMinutes"=dword:000003E8
**Maps to GPO policy**: "Cloud protection scan interval" (sets scan frequency)
Example GPO setting for network protection configuration:
[Registry Item]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Network Protection]
"EnableNetworkProtection"=dword:00000001
"AllowCloudBasedProtection"=dword:00000001
**Maps to GPO policies**: "Enable network protection" and "Allow network protection to use cloud-based protection"
3. Setting Up Alerts and Response Actions¶
Defender ATP can trigger alerts and automated responses based on predefined rules. Configure these via GPO to enforce monitoring and remediation policies.
Alert Thresholds:
- Policy Path: Computer Configuration > Administrative Templates > Microsoft Defender ATP > Alerts
- Key Settings:
- Enable alert thresholds: Define conditions for generating alerts (e.g., number of suspicious processes).
- Alert threshold duration: Set the time window for alert triggers (e.g., 1 hour).
Automated Response Actions:
- Policy Path: Computer Configuration > Administrative Templates > Microsoft Defender ATP > Automated response
- Key Settings:
- Enable automated response: Automatically isolate or remediate threats.
- Isolate suspicious processes: Quarantines processes matching known malicious patterns.
Example GPO setting for alert thresholds:
[Registry Item]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Alerts]
"AlertThreshold"=dword:00000005
"AlertThresholdDuration"=dword:00000060
**Maps to GPO policy**: "Alert threshold" and "Alert threshold duration" (defines alert conditions)
4. Troubleshooting GPO Configuration¶
If Defender ATP policies are not applying correctly:
1. Verify GPO linking and enforcement using gpresult /H report.html.
2. Check the Event Viewer for errors under Windows Defender ATP.
3. Ensure the Microsoft Defender ATP service is running (msdefenderatp service).
4. Use Get-MpPreference in PowerShell to confirm local Microsoft Defender Antivirus settings match GPO configurations.
Key takeaways¶
- Use GPO to centrally enable and configure Defender ATP for real-time protection, cloud-based detection, and network monitoring.
- Adjust alert thresholds and response actions via GPO to align with organizational security policies.
- Validate GPO application and Defender ATP status regularly using tools like
gpresultandGet-MpPreference. - Combine GPO with Microsoft 365 Defender portal settings for comprehensive endpoint security.