---
title: PUAProtection enum | Wartiva GraphQL API
description: GPO policy: "Configure detection for potentially unwanted applications". Wartiva GraphQL API reference with arguments, fields, and examples.
url: https://wartiva.com/api-docs/types/pua-protection.html
updated: 2026-10-07
---

Endpoint configuration · GraphQL enum

# `PUAProtection` enum

GPO policy: "Configure detection for potentially unwanted applications" under Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Antivirus. Controls whether Microsoft Defender blocks or reports Potentially Unwanted Applications (PUA) — software such as adware, coin miners, and bundled tools. Registry: HKLM\SOFTWARE\Policies\Microsoft\Windows Defender:PUAProtection (REG_DWORD). CIS Benchmark (L1) recommends value 1 (Enabled / block mode). Reference: [Policy CSP - Defender (PUAProtection)](https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-defender#puaprotection)

## Values

| Enum Value | Description |
|---|---|
| `DISABLED` | PUA protection disabled (registry value 0). Potentially unwanted applications are not detected or blocked. |
| `ENABLED` | PUA protection enabled / block mode (registry value 1). Detected PUAs are blocked and quarantined. CIS L1 recommended value. |
| `AUDIT` | PUA protection in audit mode (registry value 2). Detected PUAs are logged as events but are not blocked. Use to assess detections before enabling block mode. |

## Used by

- [`ComputerAdministrativeTemplates`](https://wartiva.com/api-docs/types/computer-administrative-templates.html) type: Computer-specific Administrative Templates (ADMX) settings on an Endpoint.

## Example

### Example

```json
"DISABLED"

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
