Endpoint configuration · GraphQL enum

PUAProtection enum

GPO policy: "Configure detection for potentially unwanted applications" under Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Antivirus. Controls whether Microsoft Defender blocks or reports Potentially Unwanted Applications (PUA) — software such as adware, coin miners, and bundled tools. Registry: HKLM\SOFTWARE\Policies\Microsoft\Windows Defender:PUAProtection (REG_DWORD). CIS Benchmark (L1) recommends value 1 (Enabled / block mode). Reference: Policy CSP - Defender (PUAProtection)

Values

Enum Value Description

DISABLED

PUA protection disabled (registry value 0). Potentially unwanted applications are not detected or blocked.

ENABLED

PUA protection enabled / block mode (registry value 1). Detected PUAs are blocked and quarantined. CIS L1 recommended value.

AUDIT

PUA protection in audit mode (registry value 2). Detected PUAs are logged as events but are not blocked. Use to assess detections before enabling block mode.

Used by

Example

Example

"DISABLED"