Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

Endpoint Standard: What Permission Rules are needed for Windows Defender?

Endpoint Standard: What Permission Rules are needed for Windows Defender?

Environment

  • Carbon Black Cloud Console: All Versions
  • Endpoint Standard Sensor: All Versions
  • Microsoft Windows Defender

Question

What are the Permissions needed to not scan Windows Defender?

Answer

The following should be added to the Permissions section of the Policies page:
Application at path: *:\ProgramData\Microsoft\Windows Defender\** 
**\Program Files*\Windows Defender*\**
Operation attempt: Performs any operation
Action: Bypass

Additional Notes


Related Content


Was this article helpful? Yes No
84% helpful (5/6)
Article Information
Author:
Creation Date:
‎09-01-2020
Views:
10134
Contributors