How to disable threat actions in Windows Defender managed by Defender for Endpoint?

Moises Orlando La Torre Dávila 0 Reputation points
2025-04-03T16:36:33.2866667+00:00

I have Defender for Endpoint set up on Windows 10 devices. The enrollment was done in Defender (without enrolling them directly in Microsoft Intune). However, MDE has been allowed to apply security settings in Intune.

A highlight of the policies is that tamper protection has been enabled for all devices.

Even with these settings, local users are allowed to perform the image actions (Restore or Remove Threats).

Also, I've seen that this restriction is available on Linux and MacOS under the key "disallowedThreatActions".

My intention is to disable these options.

DefenderActions

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
491 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Crystal-MSFT 53,821 Reputation points Microsoft External Staff
    2025-04-04T02:18:06.3166667+00:00

    @Moises Orlando La Torre Dávila, Thanks for posting in Q&A. Based on my checking, I find windows haven't provide the CSP to disable threat actions yet. Therefore, from Intune, we don't have this setting for windows either.

    https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-defender#defender-threatseveritydefaultaction

    But after researching more, I find when we set "User defined" for Actions for detected threats. The user needs to make the decision on which action to take. Therefore, the remove and restore will show. If we change to other action like Quarantine or Block. I think the remove and restore will not show. You can try this to see if it can work.

    User's image

    https://learn.microsoft.com/en-us/intune/intune-service/protect/antivirus-microsoft-defender-settings-windows

    https://learn.microsoft.com/en-us/defender-endpoint/configure-remediation-microsoft-defender-antivirus

    Please try the above suggestion and if there's any update, feel free to let us know.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.