GPO policy: "Configure detection for potentially unwanted applications" under Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Antivirus. Controls whether Microsoft Defender blocks or reports Potentially Unwanted Applications (PUA) — software such as adware, coin miners, and bundled tools. Registry: HKLM\SOFTWARE\Policies\Microsoft\Windows Defender:PUAProtection (REG_DWORD). CIS Benchmark (L1) recommends value 1 (Enabled / block mode). Reference: Policy CSP - Defender (PUAProtection)
Values
| Enum Value | Description |
|---|---|
|
|
PUA protection disabled (registry value 0). Potentially unwanted applications are not detected or blocked. |
|
|
PUA protection enabled / block mode (registry value 1). Detected PUAs are blocked and quarantined. CIS L1 recommended value. |
|
|
PUA protection in audit mode (registry value 2). Detected PUAs are logged as events but are not blocked. Use to assess detections before enabling block mode. |
Used by
ComputerAdministrativeTemplatestype: Computer-specific Administrative Templates (ADMX) settings on an Endpoint.
Example
Example
"DISABLED"