Skip to content

Antivirus Configuration

Antivirus engine

SettingValue
Disallowed threat actionsallow, restore
Enforcement levelreal_time
Exclusions mergeadmin_only
Run a scan after definitions are updatedEnabled
Scanning inside archive filesTrue
Threat type (1)potentially_unwanted_application
Action to take (1)block
Threat type (2)archive_bomb
Action to take (2)block
Threat type settings mergeadmin_only

Cloud delivered protection preferences

SettingValue
Automatic security intelligence updatesEnabled
Cloud Block Levelnormal
Diagnostic collection leveloptional
Enable / disable automatic sample submissionsEnabled
Enable / disable cloud delivered protectionEnabled

Endpoint Detection and Response (EDR) preferences

SettingValue
Enable / disable early previewDisabled

Features

SettingValue
Use System Extensionsenabled

Network protection

SettingValue
Enforcement levelblock

Tamper protection

SettingValue
Enforcement levelblock
Process’s TeamIdentifierUBF8T346G9
Process path/Library/Intune/Microsoft Intune Agent.app/Contents/MacOS/IntuneMdmDaemon
Process’s Signing IdentifierIntuneMdmDaemon

User interface preferences

SettingValue
Control sign-in to consumer versiondisabled
Show / hide status menu iconDisabled