🛡️ Microsoft is introducing Controlled Configuration for Microsoft Defender Antivirus (Preview)
Managing Microsoft Defender Antivirus across multiple management platforms has long been a challenge. Over time, organizations often accumulate policies from Intune, Group Policy, Configuration Manager, PowerShell scripts, and local administrator changes, making it difficult to know which configuration is actually in effect.
Controlled Configuration aims to solve that problem by making cloud-managed security policies the authoritative source of truth for Microsoft Defender Antivirus settings. Think of it as the next evolution of Tamper Protection—moving beyond protecting individual settings to enforcing a single, centrally managed configuration across your environment.
🚀 What changes?
When Controlled Configuration is enabled:
âś… Policies deployed through Microsoft Intune or Microsoft Defender for Endpoint Security Settings Management take precedence.
❌ Settings configured through:
- Group Policy (GPO)
- Microsoft Configuration Manager
- PowerShell scripts
- Local administrator changes
will no longer override your cloud-managed Defender Antivirus configuration.
đź”’ What can it enforce?
Controlled Configuration currently supports:
- Microsoft Defender Antivirus settings
- Scan configuration
- Antivirus exclusions
- Security intelligence and platform updates
- Attack Surface Reduction (ASR) rules
- Defender CSP and Policy CSP antivirus settings
- Local administrator merge behavior
⚠️ What's not included (yet)?
At this stage, Controlled Configuration does not manage:
- Microsoft Defender Device Control
- Endpoint Detection and Response (EDR) settings
- Windows Firewall
- Other Windows operating system security settings
đź’ˇ Why this matters
Many organizations have managed Microsoft Defender through multiple tools over the years. While policies may appear centrally managed, configuration drift can still occur—whether it's antivirus exclusions, scan schedules, or ASR rules modified by another management channel.
Controlled Configuration helps eliminate that drift by ensuring cloud-managed policies always win, giving security teams greater confidence that devices remain aligned with organizational security baselines.
⚠️ Before enabling it
Microsoft recommends:
Updating devices to Microsoft Defender Antivirus platform version 4.18.26060.3004 or later Validating the feature with a pilot group before broad deployment
On earlier platform versions, devices could unexpectedly have both Controlled Configuration and Tamper Protection disabled, so validating compatibility before rollout is essential.
đź’ˇ Bottom line: Controlled Configuration is a significant step toward modern, cloud-first endpoint security management. By establishing a single authoritative policy source for Microsoft Defender Antivirus, organizations can reduce configuration drift, simplify administration, and strengthen their overall security posture.
Read More: https://learn.microsoft.com/en-us/defender-endpoint/secure-controlled-configuration