PayloadKit
Back to browser

Microsoft Defender for Endpoint

com.microsoft.wdav

Microsoft Defender for Endpoint settings

macOS

Configuration Keys (10)

KeyTypeTitle
antivirusEngine
dictAntivirus engine
cloudService
dictCloud delivered protection preferences
userInterface
dictUser interface preferences
edr
dictEDR preferences
tamperProtection
dictTamper protection
deviceControl
dictDevice Control
features
dictFeatures
networkProtection
dictNetwork protection
dlp
dictData Loss Prevention
scheduledScan
dictScheduled scan configuration
behaviorMonitoring
stringBehavior Monitoring
enforcementLevel
stringEnforcement level for antivirus engine
enableFileHashComputation
booleanEnable file hash computation
scanAfterDefinitionUpdate
booleanRun a scan after definitions are updated
scanArchives
booleanScanning inside archive files
maximumOnDemandScanThreads
integerDegree of parallelism for on-demand scans
exclusionsMergePolicy
stringExclusions merge
exclusions
arrayScan exclusions
allowedThreats
arrayAllowed threats
disallowedThreatActions
arrayDisallowed threat actions
threatTypeSettings
arrayThreat type settings
threatTypeSettingsMergePolicy
stringThreat type settings merge
scanResultsRetentionDays
stringAntivirus scan history retention
scanHistoryMaximumItems
stringMaximum number of items in the antivirus scan history
enableRealTimeProtection
booleanReal-time protection
passiveMode
booleanPassive mode
dictExclusions
$type
stringType
path
stringPath
isDirectory
booleanIs directory
extension
stringFile extension
name
stringProcess name
stringThreat
stringAction
dictSetting
key
stringThreat type
value
stringAction to take
enabled
booleanCloud delivered protection
diagnosticLevel
stringDiagnostic data collection
cloudBlockLevel
stringCloud Block Level
automaticSampleSubmission
booleanEnable / disable automatic sample submissions
automaticDefinitionUpdateEnabled
booleanAutomatic security intelligence updates
automaticSampleSubmissionConsent
stringAutomatic sample submission Consent
hideStatusMenuIcon
booleanHide status menu icon
userInitiatedFeedback
stringUser initiated feedback
consumerExperience
stringControl sign-in to consumer version
tags
arrayDevice tags
groupIds
stringGroup identifier
dictTag
key
stringType of tag
value
stringValue of tag
enforcementLevel
stringEnforcement level
exclusions
arrayProcess exclusions
dictProcess identity
path
stringProcess path
teamId
stringProcess's TeamIdentifier
signingId
stringProcess's Signing Identifier
args
arrayProcess's arguments
stringArgument
navigationTarget
stringCustomize URL target for notifications raised by device control
removableMediaPolicy
dictAllow or block removable devices
policy
stringDevice Control Policy
enforcementLevel
stringPolicy enforcement level
permission
arrayDefault permission level
vendors
dictVendors
stringPermissions
{{key}}
stringVendor ID
{{value}}
dictVendor Details
permission
arrayPermission level
products
dictProducts
stringPermissions
{{key}}
stringProduct ID
{{value}}
dictProduct Details
permission
arrayPermission level
serialNumbers
dictSerial Numbers
stringPermissions
{{key}}
stringSerial Number
{{value}}
arraySerial Number Details
stringPermissions
dataLossPrevention
stringUse Data Loss Prevention
scheduledScan
stringScheduled Scan
enforcementLevel
stringEnforcement level
exclusions
arrayExclusions
features
arrayFeatures
dictExclusion
signingId
stringSigning ID
dictFeature
name
stringFeature Name
state
stringState
ring
stringRelease Ring
checkForDefinitionsUpdate
booleanCheck for definitions update
dailyConfiguration
dictDaily and Hourly quick scan configuration
ignoreExclusions
booleanIgnore exclusions
lowPriorityScheduledScan
booleanLow priority scheduled scan
runScanWhenIdle
booleanRun scheduled scan when idle
weeklyConfiguration
dictWeekly scheduled scan configuration
scanType
stringScan type