Microsoft Configuration Manager
Device security

Endpoint Antimalware Policies

In brief

The documentation now states that Microsoft Defender Antivirus contextual file and folder exclusions can be specified in the policy setting or with the Set-CMAntimalwarePolicy cmdlet starting in version 2609.

What Intune admins need to know

Administrators using version 2609 can configure contextual exclusions through either supported method.

This summary was assembled from the tracked documentation change. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Click Set to open the Configure File and Folder Exclusions dialog box and specify the names of the files and folders to exclude from Endpoint Protection scans.

Starting in version 2609, you can specify Microsoft Defender Antivirus contextual file and folder exclusions in this setting or by using the Set-CMAntimalwarePolicy cmdlet. For more information, see Contextual exclusions.

If you want to exclude files and folders that are located on a mapped network drive, specify the name of each folder in the network drive individually. For example, if a network drive is mapped as F:\MyFolder and it contains subfolders named Folder1, Folder2 and Folder 3, specify the following exclusions:

  • F:\MyFolder\Folder1
Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…