Create Intune Turn Off Real-Time Protection Policy

Here, this post will help you in the deployment of the Turn Off Real-Time Protection Policy. We’ll make use of Intune’s Settings Catalog to install this policy. We are using configuration Profiles of Intune to deploy the Turn Off Real-Time Protection Policy.

Turn Off Real-Time Protection Policy setting disables the real-time protection prompts related to the detection of known malware. Microsoft Defender Antivirus typically notifies users when malware or potentially unwanted software tries to install or run on the computer.

Enabling this policy means that Microsoft Defender Antivirus will refrain from prompting users to take action upon detecting malware. Conversely, disabling or leaving this policy unconfigured will result in Microsoft Defender Antivirus prompting users to take action when malware is detected.

When utilizing an antivirus solution like Microsoft Defender Antivirus, it is crucial to verify that it is set up to actively and heuristically monitor for both suspicious and well-known malicious activities in real time.

Patch My PC
Create Intune Turn Off Real-Time Protection Policy Fig.1
Create Intune Turn Off Real-Time Protection Policy Fig.1

Turn Off Real-Time Protection Policy

To create a Turn Off Real-Time Protection Policy, follow the steps stated below:

  • Sign in to the Intune Admin Center portal https://intune.microsoft.com/.
  • Select Devices > Windows > Configuration profiles > Create a profile.

In Create Profile, I select Windows 10 and later in Platform and select Profile Type as Settings catalog. Click on the Create button.

Create Intune Turn Off Real-Time Protection Policy Fig.2
Create Intune Turn Off Real-Time Protection Policy Fig.2

On the Basics tab pane, I provide a name for the policy “Turn Off Real-Time Protection Policy.”

  • Optionally, if you want, you can enter a policy description and proceed by selecting “Next“.
Create Intune Turn Off Real-Time Protection Policy Fig.3
Create Intune Turn Off Real-Time Protection Policy Fig.3

Now in Configuration Settings, Click Add Settings to browse or search the catalog for the settings I want to configure.

Create Intune Turn Off Real-Time Protection Policy Fig.4
Create Intune Turn Off Real-Time Protection Policy Fig.4

In the Settings Picker windows, I searched for the keyword Microsoft Defender. I found the category Administrative Templates\Windows Components\ Microsoft Defender Antivirus\ Real-time Protection and selected this.

  • When I select that option as stated above, I see the sub-category Turn off real-time protection. After selecting that, click the cross mark at the right-hand corner, as shown below.
Create Intune Turn Off Real-Time Protection Policy Fig.5
Create Intune Turn Off Real-Time Protection Policy Fig.5

Here in Administrative Templates, I have Disabled the Turn off real-time protection.

Create Intune Turn Off Real-Time Protection Policy Fig.6
Create Intune Turn Off Real-Time Protection Policy Fig.6

Using Scope tags, you can assign a tag to filter the profile to specific IT groups. One can add scope tags (if required). More details on Intune Scope Tags Implementation Guide.

  • Click Next to continue.

Now in Assignments, in Included Groups, you need to click on Add Groups and choose Select Groups to include one or more groups. Click Next to continue.

Create Intune Turn Off Real-Time Protection Policy Fig.7
Create Intune Turn Off Real-Time Protection Policy Fig.7

In the Review + Create tab, I review settings. After clicking on Create, changes are saved, and the profile is assigned.

Create Intune Turn Off Real-Time Protection Policy Fig.8
Create Intune Turn Off Real-Time Protection Policy Fig.8

After successfully creating the “Turn Off Real-Time Protection Policy,” a notification will appear in the top right-hand corner confirming the action. You can also verify the policy’s existence by navigating to the Configuration Profiles list, where it will be prominently displayed.

Your groups will receive your profile settings when the devices check in with the Intune service. The Policy applies to the device.

Intune Report for Turn Off Real-Time Protection Policy

From the Intune Portal, you can view the Intune settings catalog profile report, which provides an overview of device configuration policies and deployment status.

To track the assignment of the policy, you need to select the relevant policy from the Configuration Profiles list, which is the Turn Off Real-Time Protection Policy. Then, you can review the device and user check-in status to determine whether the policy has been successfully applied.

  • If you require more detailed information, you can click on “View Report” to access additional insights.
Create Intune Turn Off Real-Time Protection Policy Fig.9
Create Intune Turn Off Real-Time Protection Policy Fig.9

Windows CSP Details DisableRealtimeMonitoring

We will see Windows CSP Details for this Policy setting DisableRealtimeMonitoring. This configuring an antivirus solution to heuristically monitor in real-time is a proactive strategy to enhance the effectiveness of threat detection. It reflects a commitment to staying ahead of the evolving threat landscape and provides an essential layer of defence against emerging and sophisticated malware.

CSP URI – ./Device/Vendor/MSFT/Policy/Config/ADMX_MicrosoftDefenderAntivirus/DisableRealtimeMonitoring

Create Intune Turn Off Real-Time Protection Policy Fig.10
Create Intune Turn Off Real-Time Protection Policy Fig.10

Intune MDM Event Log – Turn Off Real-Time Protection

You can leverage event IDs 813 and 814 to verify the successful implementation of String or integer policies for the Turn Off Real-Time Protection Policy Policy on Windows 10 or 11 devices through Intune.

These event IDs provide valuable insights into the Turn Off Real-Time Protection Policy’s application status and the specific value assigned to the policy on those devices. In the case of this particular policy, the value is String and is linked to the event ID 814.

By analyzing these event IDs, you can clearly understand the policy’s application status and the corresponding value associated with it on the devices in question.

To confirm this, you can check the Event log path – Applications and Services Logs – Microsoft – Windows – Devicemanagement-Enterprise-Diagnostics-Provider – Admin.

MDM PolicyManager: Set policy string, Policy: (DisableRealtimeMonitoring), Area: (ADMX_MicrosoftDefenderAntivirus), EnrollmentID requesting merge: (5B88AEF1-09E8-43BB-B144-7254ACBBDF3E), Current User: (Device), String: (<disabled/>), Enrollment Type: (0x6), Scope: (0x0).

Create Intune Turn Off Real-Time Protection Policy Fig.11
Create Intune Turn Off Real-Time Protection Policy Fig.11

When I opened the above Event log, I found that the Turn Off Real-Time Protection Policy I applied to the device was successfully implemented.

  • By reviewing the log entry shown in the above image, the Event Viewer, I came across essential information, including the Area and Enrollment ID.

These details play a significant role in identifying the corresponding registry path. To locate the specific information, please consult the table provided below:

AreaPolicyStringScopedEvent ID
ADMX_MicrosoftDefenderAntivirusDisableRealtimeMonitoringDisabledDevice814
Table 1 – Create Intune Turn Off Real-Time Protection Policy

The details presented in the table above for the Create Intune Turn Off Real-Time Protection Policy can be employed to access the registry settings that hold the group policy configurations on a specific computer. T

To accomplish this, you can execute “REGEDIT.exe” on the target computer and navigate to the precise registry path where these settings are stored.

Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\providers\5B88AEF1-09E8-43BB-B144-7254ACBBDF3E\default\Device\ADMX_MicrosoftDefenderAntivirus

When you navigate the above path in the Registry Editor, you will find the registry key named DisableRealtimeMonitoring. Also, when I navigated to the above path, I saw that the Registry Key was created successfully.

Registry NameData
DisableRealtimeMonitoringDisabled
Table 2 – Create Intune Turn Off Real-Time Protection Policy
Create Intune Turn Off Real-Time Protection Policy Fig.12
Create Intune Turn Off Real-Time Protection Policy Fig.12

We are on WhatsApp. To get the latest step-by-step guides and news updates, Join our Channel. Click hereHTMD WhatsApp.

Author

Abhinav Rana is working as an SCCM and Intune Admin with several years of experience. He loves to help the community by sharing his knowledge. He is a B.Tech graduate in Information Technology.

1 thought on “Create Intune Turn Off Real-Time Protection Policy”

  1. Doubt, if we do not activate the turn off policy we are not really activating the real-time protectión?

    If you enable this policy setting, Microsoft Defender Antivirus will not prompt users to take actions on malware detections. If you disable or do not configure this policy setting, Microsoft Defender Antivirus will prompt users to take actions on malware detections.

    Reply

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.