Process ExclusionsID: oval:org.secpod.oval:def:28595 | Date: (C)2015-10-08 (M)2023-07-04 |
Class: COMPLIANCE | Family: windows |
This policy setting allows you to disable scheduled and real-time scanning for any file opened by any of the specified processes. The process itself will not be excluded. To exclude the process, use the Path exclusion. Processes should be added under the Options for this setting. Each entry must be listed as a name value pair, where the name should be a string representation of the path to the process image. Note that only executables can be excluded. For example, a process might be defined as: c:\windows\app.exe. The value is not used and it is recommended that this be set to 0.
If you enable this setting, scheduled and real-time scanning for any file opened by a specified process will be excluded.
If you disable or do not configure this setting, scheduled and real-time scanning for files will happen for all processes.
Fix:
(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Windows Defender\Exclusions!Process Exclusions
(2) REG: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows Defender\Exclusions!Exclusions_Processes
Platform: |
Microsoft Windows Server 2012 R2 |