Back to blog
SecurityPublished on July 14, 20268 min read

Deploying Defender Antivirus with Intune

Turn on real-time, cloud-delivered and PUA protection in Microsoft Defender Antivirus across your Windows PCs through Intune, with no install required.

Microsoft Defender Antivirus already ships with every Windows 10 and 11 PC: there is nothing to install and no third-party antivirus licence to renew. Yet an antivirus that is merely "present" is not the same as one that is "effective". The real value comes from central configuration and from turning on the advanced protection mechanisms that are too often left at their default or switched off by a hurried user acting on bad advice found on a forum.

This article is aimed at IT administrators and MSSPs managing a fleet of Windows PCs with Microsoft Intune. The goal: ensure every device applies the same protection level with no exception, actually verify it, and be able to prove it during an ISO 27001 audit or a NIS2 review. We will cover which settings truly matter, how to create the endpoint security antivirus policy, how to confirm it applies and is not stuck in passive mode, and how to tie all of this back to compliance.

The settings that actually matter

Beyond "antivirus on", a few options decide real-world effectiveness against recent threats. They rely on behavioral analysis and Microsoft's cloud telemetry, which spot attacks that classic signatures do not yet recognize. These are exactly the options to lock down on the administrator side, because a user with local rights can otherwise disable them in a moment of frustration.

The essential baseline

  • Real-time protection: continuous scanning of files and processes on every open, write or execution. This is the core of the system and must never be disabled.
  • Cloud-delivered protection: queries Microsoft's Advanced Protection Service to block emerging threats within seconds, before signatures are even distributed.
  • Automatic sample submission: sends suspicious files to Microsoft for analysis; set it to "safe samples" or "all samples" depending on your privacy tolerance.
  • Potentially Unwanted Application (PUA) protection: blocks adware, toolbars and bundled software, often overlooked yet very common.
  • Regular scheduled scans and automatic security intelligence (signature) updates.

The fine-tuning you should not skip

Two settings often make the difference between cosmetic and genuine protection. The cloud protection level, which you can push to "high" for more aggressive detection, and the cloud block timeout, which lets Defender hold a suspicious file a few extra seconds while the cloud verdict comes back. Also enable tamper protection, which prevents malware — or a user — from turning the antivirus off.

Real-time, cloud-delivered and tamper protection enabled: the genuinely effective antivirus baseline.

Create the policy in Intune

In the Intune admin center, the Endpoint security section offers antivirus policies dedicated to Microsoft Defender. The pattern is the same as for any policy: define the configuration, assign it to a group, watch the state report. This way you no longer depend on each user's goodwill, and a new PC inherits the same protection the moment it enrolls.

  1. 1In Intune, open Endpoint security, then Antivirus, and create a policy for the Windows platform using the Microsoft Defender Antivirus profile.
  2. 2Enable real-time protection and cloud-delivered protection, and set the cloud block level to "high".
  3. 3Configure automatic sample submission, set PUA protection to "Enable", and schedule a daily quick scan or a weekly full scan.
  4. 4Assign the policy to a pilot group of a few PCs first, observe behavior for 48 hours, then widen to the whole fleet.
  5. 5Track compliance state and detections in the Antivirus dashboard and in the endpoint security reports.

Take a concrete example: a 60-seat SMB deploys this policy on a Friday evening to its pilot group of five machines. On Monday, the dashboard confirms all five are healthy and active. The policy is then extended to the "All Windows devices" group, and new machines enrolled through Autopilot apply it with no manual step.

Tracking detections and antivirus state across the whole fleet from Intune.

Confirm the protection actually applies

An assigned policy is only useful if it is actually applied. The classic pitfall: a third-party antivirus left installed (or an incomplete uninstall) pushes Defender into passive mode. In that mode Defender no longer performs real-time scanning — it only runs periodic scans as a supplement. A few checks on a reference machine remove the doubt.

  • On a reference machine, open PowerShell and run Get-MpComputerStatus: verify that RealTimeProtectionEnabled and AntivirusEnabled are True, and that AMRunningMode reads "Normal" rather than "Passive Mode".
  • Make sure no third-party antivirus remains in the installed programs list or in Windows Security.
  • Confirm that security intelligence is up to date (a recent AntivirusSignatureLastUpdated value).
  • Check the state report in Intune a few hours after assignment: the policy should show as "Succeeded", not "Pending" or "Error".
An antivirus in passive mode looks reassuring on paper but does not protect in real time: it is the most common mistake after migrating away from a third-party solution.

Tie Defender to compliance

Once the antivirus is solidly configured and verified, the next step is to tie these machines to an Intune compliance policy. A device whose antivirus is inactive is then flagged as non-compliant, and Conditional Access can restrict its access to company resources such as email or SharePoint. Defender protection thus stops being a mere checkbox and becomes an access criterion that is actually enforced.

This chain — antivirus enabled, state verified, compliance required — maps directly to framework expectations. ISO 27001 calls for protection against malware (control A.8.7) and evidence that it is applied; NIS2 mandates technical risk-management and continuity measures. Intune reports provide exactly this timestamped evidence, exportable for the auditor.

How AuPoint speeds up the rollout

Tuning these settings to the right level, without breaking usage or missing a key option, means knowing Defender's CSPs (Configuration Service Providers). AuPoint deploys a proven antivirus policy in a few clicks, in plain language and with no PowerShell. You get an impact preview before applying, a break-glass safety mechanism, and reversible policies: if a setting causes friction, you roll it back in one click. Connect your Microsoft tenant in a few clicks and start for free.

From active antivirus to compliant device: an audit-ready chain of evidence.

FAQ

Should I uninstall a third-party antivirus before deploying Defender?

Yes, this is strongly recommended. As long as a third-party antivirus stays registered as the protection provider, Windows automatically switches Defender into passive mode and real-time scanning is suspended. Uninstall the third-party solution, restart the PC, then verify with Get-MpComputerStatus that AMRunningMode has returned to "Normal".

Can PUA protection block legitimate applications?

Rarely. PUA protection targets adware, cryptominers and bundled software, not standard business applications. If an internal tool triggers a false positive, you can add a targeted exclusion. You may start in audit mode to observe what would be blocked before switching to block mode.

How long before the policy applies on the PCs?

Usually a few minutes to a few hours. Intune synchronizes devices periodically; a connected PC picks up the policy at the next sync cycle, often within eight hours. You can force a sync from Intune or from the device to speed up testing on your pilot group.

Ready to give Microsoft Defender Antivirus the level of configuration it deserves? Connect your Microsoft tenant to AuPoint in a few clicks, preview the impact, and deploy compliant antivirus protection across your whole fleet. It is free to start at aupoint.io.

Secure your tenant in 15 minutes

Free trial