oeltayeb.com · Defender Toolkit

Checklist

Defender Antivirus troubleshooting checklist

Based on the article: Defender Antivirus settings not applying from Intune: a troubleshooting checklist · 5 min read

An Intune antivirus policy that reports success while Get-MpPreference on the device says something else is one of the more confusing Defender problems, because several layers can quietly override or hide a setting. In this post I'll walk through a checklist that narrows it down: how the device is managed, whether policies conflict, what actually reached the device, and which Defender behaviours change the result.

Symptoms to confirm

  • The antivirus policy shows Succeeded, Conflict, Error or Not applicable in Intune, but the setting isn't in effect on the device.
  • Get-MpPreference returns a different value from the one you configured, or shows no exclusions at all.
  • Exclusions that admins added locally have stopped working.
  • A policy that turns off real-time or cloud protection for testing has no effect.
  • The policy works on some devices, such as cloud-native laptops, but not on co-managed PCs or servers.

Likely causes

  • The wrong management channel. Co-managed devices follow Configuration Manager unless the Endpoint Protection workload points to Intune. Devices managed through Defender for Endpoint security settings management only pick up policies assigned to device groups.
  • Conflicting Intune policies. In antivirus policies only three settings merge across policies: excluded paths, extensions and processes. Anything else conflicts when two policies disagree, and a conflict can leave the device with no value at all.
  • Another tool writes the same setting. Group Policy, Configuration Manager or local scripts. Microsoft notes that MDMWinsOverGP doesn't apply to the Defender CSP.
  • Defender isn't the active antivirus. On Windows clients with a third-party product, Defender runs in passive mode if the device is onboarded to Defender for Endpoint, and is usually disabled if it isn't. Cloud protection, network protection, ASR rules and PUA protection don't work in passive mode.
  • Tamper protection. Protected settings stay at secure values, and attempts to change them can look successful while being blocked.

+1 more causes in the full article.

Checklist

  1. 1

    Confirm how the device is managed

    In the Microsoft Intune admin center, open Endpoint security › All devices and check the Managed by column:

    • MDM: enrolled in Intune; continue with step 2.
    • MDM/ConfigMgr Agent: co-managed. Move the Endpoint Protection workload slider to Intune or Pilot Intune.
    • MDE: security settings management. Assign policies to Microsoft Entra device groups and confirm Allow Microsoft Defender for Endpoint to enforce Endpoint Security Configurations is on under Endpoint security › Defender for Endpoint.
  2. 2

    Look for conflicts setting by setting

    Select the device, open Device configuration under Monitor, then open the antivirus policy to see each setting's state. Conflict means another policy sets the same thing: typically a security baseline, a Settings Catalog profile, an older endpoint protection or device restrictions profile, or a second antivirus policy.

  3. 3

    Prove the policy reached the device

    On the device, go to Settings › Accounts › Access work or school, select the work account, then Info › Create report and Export. The HTML report is saved in C:\Users\Public\Documents\MDMDiagnostics and lists the policies and values the device received.

  4. 4

    Read Defender's effective state

    powershell
    Get-MpComputerStatus |
        Select-Object AMRunningMode, RealTimeProtectionEnabled, IsTamperProtected
    
    Get-MpPreference |
        Select-Object DisableRealtimeMonitoring, MAPSReporting, PUAProtection, ExclusionPath

    AMRunningMode should be Normal. Passive or EDR Block Mode means another antivirus is primary, and settings for active-mode features won't do anything until that changes.

  5. 5

    Remove competing channels

    Run gpresult /h gpresult.html or look under HKLM\SOFTWARE\Policies\Microsoft\Windows Defender for Group Policy values. Because MDMWinsOverGP doesn't cover the Defender CSP, the dependable fix is to stop applying Defender GPOs to Intune-managed devices.

  6. 6

    Account for tamper protection

    With tamper protection on, settings such as real-time protection, behaviour monitoring, cloud protection and security intelligence updates stay locked, and a change from any tool can appear to work while being blocked. Look for event 5013 in Microsoft › Windows › Windows Defender › Operational; it names the setting that was refused.

  7. 7

    Check exclusion behaviour

    • Exclusions from every assigned policy merge into one list, so an unexpected exclusion usually comes from a policy you forgot.
    • With HideExclusionsFromLocalAdmins set, exclusions still apply but don't appear in Get-MpPreference or the registry.
    • With Disable local admin merge set in the Microsoft Defender Antivirus profile, exclusions added locally through PowerShell or Windows Security are ignored and only policy lists count.

Verify

  • Sync the device and re-run the PowerShell checks.
  • You should see the configured value in Get-MpPreference, an event 5007 (settings changed) in the Defender Operational log, and the setting reported as Succeeded in the device's policy view.
  • For the fleet, Reports › Antivirus › Antivirus agent status and Endpoint security › Antivirus › Unhealthy endpoints show which devices still need attention.

Key takeaways

  • Check AMRunningMode first; nothing else matters if Defender isn't active.
  • Give each Defender setting exactly one owner; only the three exclusion lists merge.
  • Keep Defender GPOs away from Intune-managed devices.
  • Use device groups for anything managed through security settings management.
  • Tamper protection and hidden exclusions can make a working policy look broken.

Microsoft Learn references