GPO policy: "Configure Network Protection" under Computer Configuration > Administrative Templates
Windows Components > Microsoft Defender Antivirus > Microsoft Defender Exploit Guard > Network Protection. Controls whether Microsoft Defender Network Protection blocks access to malicious/ suspicious domains and IP addresses at the network level (SmartScreen-like enforcement for all processes, not just browsers). Registry: HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Windows Defender Exploit Guard\Network Protection:EnableNetworkProtection (REG_DWORD). CIS Benchmark (L1) recommends value 1 (Enabled). Requires Windows Defender real-time protection to be active. Reference: Policy CSP - Defender (EnableNetworkProtection)
Values
| Enum Value | Description |
|---|---|
|
|
Network Protection disabled (registry value 0). No network-level blocking of malicious URLs/IPs is performed. |
|
|
Network Protection enabled (registry value 1). Malicious or suspicious outbound network connections are blocked for all processes. CIS L1 recommended value. |
|
|
Audit mode (registry value 2). Malicious connections are detected and logged but not blocked. Use to evaluate impact before switching to enforcement mode. |
Used by
ComputerAdministrativeTemplatestype: Computer-specific Administrative Templates (ADMX) settings on an Endpoint.
Example
Example
"DISABLED"