Back learn.microsoft.com Enable Cloud Protection Microsoft Defender Antivirus
Access to this page requires authorization. You can try signing in or changing directories .
Access to this page requires authorization. You can try changing directories .
Applies to: Microsoft Defender for Endpoint Plan 1, Microsoft Defender for Endpoint Plan 2, Microsoft Defender Antivirus
Cloud protection in Microsoft Defender Antivirus delivers accurate, real-time, and intelligent protection. Use this article to turn on cloud protection and configure how aggressively Microsoft Defender Antivirus blocks suspicious files. Cloud protection is enabled by default, and we recommend keeping it turned on.
Tamper protection helps prevent unauthorized changes to cloud protection and other security settings. When tamper protection is turned on, changes to tamper-protected settings are ignored. If tamper protection blocks a required change on a device, use troubleshooting mode to temporarily disable tamper protection. After troubleshooting mode ends, changes to tamper-protected settings revert to their configured state.
Supported operating systems
The following operating systems support cloud protection:
For information the network-connectivity requirements for the cloud protection service, see Configure and validate network connections .
Why cloud protection should be turned on
Microsoft Defender Antivirus cloud protection helps protect against malware on your endpoints and throughout your network. We recommend keeping cloud protection turned on because certain security features and capabilities in Microsoft Defender for Endpoint only work when cloud protection is enabled.
The following table summarizes the features and capabilities that depend on cloud protection:
In Windows 10 and Windows 11, there is no difference between the Basic and Advanced reporting options described in this article. The distinction between the Basic and Advanced reporting options is legacy, and choosing either setting results in the same level of cloud protection. There is no difference in the type or amount of information that is shared. For more information on what we collect, see the Microsoft Privacy Statement .
Specify the cloud protection level
Turning on cloud protection enables Microsoft Defender Antivirus to use the cloud protection service. The cloud protection level controls how aggressively Microsoft Defender Antivirus blocks and scans suspicious files. Turn on cloud protection before you configure the cloud protection level.
Use Microsoft Intune to turn on cloud protection
Microsoft Intune is the recommended tool for configuring and distributing Defender for Endpoint features to devices. However, Intune is a separate product that isn't part of Defender for Endpoint, and it isn't included in all subscriptions. To use Intune, you need a subscription that includes it, or you can buy it separately as a standalone subscription or add-on. If you don't have Intune, you can use any of the other methods in this article. For more information, see Microsoft Intune licensing .
To configure cloud protection in Microsoft Intune, use an endpoint security Antivirus policy. For detailed instructions, see Create endpoint security policies or Modify existing policies (links open new tabs in the Intune documentation).
When you create the policy, use these specific settings:
Policy type : On the Endpoint security | Overview page in the Microsoft Intune admin center at , under Manage , select Antivirus , and then select Create Policy .
Platform : Select Windows .
Profile : Select Microsoft Defender Antivirus .
When you create or modify the policy, configure the following settings on the Configuration settings tab:
Allow cloud protection : Select Allowed. Turns on Cloud Protection (Default) .
Submit samples consent : Select one of the following values: Send safe samples automatically. (Default) Send all samples automatically
Send safe samples automatically. (Default)
Send all samples automatically
Cloud block level : Select one of the following values: Not configured : Uses the default blocking level. High : Aggressively blocks unknown files while optimizing client performance. This option increases the chance of false positives. High plus : Aggressively blocks unknown files and applies more protection measures. This option might affect client performance. Zero tolerance : Blocks all unknown executable files.
Not configured : Uses the default blocking level.
High : Aggressively blocks unknown files while optimizing client performance. This option increases the chance of false positives.
High plus : Aggressively blocks unknown files and applies more protection measures. This option might affect client performance.
Zero tolerance : Blocks all unknown executable files.
For more information the available settings, see Windows Antivirus policy settings for Microsoft Defender Antivirus .
Use the Microsoft Defender portal to turn on cloud protection
If your organization manages endpoint security policies in the Microsoft Defender portal , use a Microsoft Defender Antivirus policy to configure cloud protection.
For detailed instructions, see Create an endpoint security policy or Edit an endpoint security policy (links open new tabs).
When you create the policy on the Windows policies tab of the Endpoint security policies page in the Defender portal at , use these specific settings:
Select platform : Select Windows .
Select template : Select Microsoft Defender Antivirus .
When you create or modify the policy, configure the following settings on the Configuration settings tab:
Allow cloud protection : Select Allowed. Turns on Cloud Protection (Default) .
Submit samples consent : Select one of the following values: Send safe samples automatically. (Default) Send all samples automatically
Send safe samples automatically. (Default)
Send all samples automatically
Cloud block level : Select one of the following values: Not configured : Uses the default blocking level. High : Aggressively blocks unknown files while optimizing client performance. This option increases the chance of false positives. High plus : Aggressively blocks unknown files and applies more protection measures. This option might affect client performance. Zero tolerance : Blocks all unknown executable files.
Not configured : Uses the default blocking level.
High : Aggressively blocks unknown files while optimizing client performance. This option increases the chance of false positives.
High plus : Aggressively blocks unknown files and applies more protection measures. This option might affect client performance.
Zero tolerance : Blocks all unknown executable files.
Use Microsoft Configuration Manager to turn on cloud protection
Use a Configuration Manager antimalware policy to configure cloud protection. For instructions to create and deploy an antimalware policy, see Endpoint Protection antimalware policies in Configuration Manager .
To turn on cloud protection, configure the following settings in the antimalware policy:
Advanced Settings : Enable auto sample file submission to help Microsoft determine whether certain detected items are Malicious : Select Yes .
Enable auto sample file submission to help Microsoft determine whether certain detected items are Malicious : Select Yes .
Cloud Protection Service : Cloud Protection Service membership : Select Advanced . Level for blocking suspicious files : Select one of the following values: Normal : Uses the default Microsoft Defender Antivirus blocking level. High : Aggressively blocks unknown files while optimizing client performance. This option increases the chance of false positives. High with extra protection : Aggressively blocks unknown files and applies more protection measures. This option might affect device performance. Block unknown programs : Blocks all unknown programs.
Cloud Protection Service membership : Select Advanced .
Level for blocking suspicious files : Select one of the following values: Normal : Uses the default Microsoft Defender Antivirus blocking level. High : Aggressively blocks unknown files while optimizing client performance. This option increases the chance of false positives. High with extra protection : Aggressively blocks unknown files and applies more protection measures. This option might affect device performance. Block unknown programs : Blocks all unknown programs.
Normal : Uses the default Microsoft Defender Antivirus blocking level.
High : Aggressively blocks unknown files while optimizing client performance. This option increases the chance of false positives.
High with extra protection : Aggressively blocks unknown files and applies more protection measures. This option might affect device performance.
Block unknown programs : Blocks all unknown programs.
Use Group Policy to turn on cloud protection
MAPS settings configure cloud-delivered protection.
To turn on cloud protection by using Group Policy:
Open the Group Policy Management Console (GPMC) on your Group Policy management device.
Open the Group Policy Management Console (GPMC) on your Group Policy management device.
In the GPMC console tree, expand Group Policy Objects in the forest and domain containing the GPO you want to edit.
In the GPMC console tree, expand Group Policy Objects in the forest and domain containing the GPO you want to edit.
Right-click the GPO, and then select Edit .
Right-click the GPO, and then select Edit .
In the Group Policy Management Editor , go to Computer configuration > Administrative templates > Windows components > Microsoft Defender Antivirus > MAPS . Note Group Policy paths before Windows 10, version 2004 (May 2020) might use Windows Defender Antivirus instead of Microsoft Defender Antivirus. Both names refer to the same policy location.
In the Group Policy Management Editor , go to Computer configuration > Administrative templates > Windows components > Microsoft Defender Antivirus > MAPS .
Group Policy paths before Windows 10, version 2004 (May 2020) might use Windows Defender Antivirus instead of Microsoft Defender Antivirus. Both names refer to the same policy location.
In the details pane of MAPS , the available settings are: Join Microsoft MAPS Send file samples when further analysis is required To open and configure a cloud protection setting, use any of the following methods: Double-click the setting. Right-click the setting, and then select Edit . Select the setting, and then select Action > Edit .
In the details pane of MAPS , the available settings are:
Send file samples when further analysis is required
To open and configure a cloud protection setting, use any of the following methods:
Double-click the setting.
Right-click the setting, and then select Edit .
Select the setting, and then select Action > Edit .
You can also configure Group Policy locally on individual devices by using the Local Group Policy Editor ( gpedit.msc ). Navigate to the same path: Computer configuration > Administrative templates > Windows components > Microsoft Defender Antivirus > MAPS .
Enable and configure Join Microsoft MAPS
In the details pane of MAPS , open the Join Microsoft MAPS setting.
In the details pane of MAPS , open the Join Microsoft MAPS setting.
In the setting window that opens, configure the following options: Select Enabled . Join Microsoft MAPS in the Options section: Select one of the following values: Basic MAPS : Basic membership sends basic information to Microsoft malware and potentially unwanted software that has been detected on your device. Information includes where the software came from (like URLs and partial paths), the actions taken to resolve the threat, and whether the actions were successful. Advanced MAPS : In addition to basic information, advanced membership sends detailed information malware and potentially unwanted software, including the full path to the software, and detailed information how the software has affected your device. When you're finished, select OK .
In the setting window that opens, configure the following options:
Join Microsoft MAPS in the Options section: Select one of the following values: Basic MAPS : Basic membership sends basic information to Microsoft malware and potentially unwanted software that has been detected on your device. Information includes where the software came from (like URLs and partial paths), the actions taken to resolve the threat, and whether the actions were successful. Advanced MAPS : In addition to basic information, advanced membership sends detailed information malware and potentially unwanted software, including the full path to the software, and detailed information how the software has affected your device.
Basic MAPS : Basic membership sends basic information to Microsoft malware and potentially unwanted software that has been detected on your device. Information includes where the software came from (like URLs and partial paths), the actions taken to resolve the threat, and whether the actions were successful.
Advanced MAPS : In addition to basic information, advanced membership sends detailed information malware and potentially unwanted software, including the full path to the software, and detailed information how the software has affected your device.
When you're finished, select OK .
Enable and configure Send file samples when further analysis is required
In the details pane of MAPS , open the Send file samples when further analysis is required setting.
In the details pane of MAPS , open the Send file samples when further analysis is required setting.
In the setting window that opens, configure the following options: Select Enabled . Send file samples when further analysis is required in the Options section: Select one of the following values: Send safe samples : Most samples are sent automatically. Files that are likely to contain personal information prompt the user for more confirmation. Send all samples When you're finished, select OK .
In the setting window that opens, configure the following options:
Send file samples when further analysis is required in the Options section: Select one of the following values: Send safe samples : Most samples are sent automatically. Files that are likely to contain personal information prompt the user for more confirmation. Send all samples
Send safe samples : Most samples are sent automatically. Files that are likely to contain personal information prompt the user for more confirmation.
When you're finished, select OK .
Always Prompt lowers the protection state of the device.
Never send lowers the protection state of the device and disables Block at First Sight .
Specify the cloud protection level with Group Policy
In the Group Policy Management Editor , go to Computer configuration > Administrative templates > Windows components > Microsoft Defender Antivirus > MpEngine .
In the Group Policy Management Editor , go to Computer configuration > Administrative templates > Windows components > Microsoft Defender Antivirus > MpEngine .
In the details pane of MpEngine , open the Select cloud protection level setting. To open the setting, use any of the following methods: Double-click the setting. Right-click the setting, and then select Edit . Select the setting, and then select Action > Edit .
In the details pane of MpEngine , open the Select cloud protection level setting. To open the setting, use any of the following methods:
Double-click the setting.
Right-click the setting, and then select Edit .
Select the setting, and then select Action > Edit .
In the setting window that opens, configure the following options: Select Enabled . Under Select cloud blocking level , select one of the following protection levels: Default blocking level : Provides strong detection without increasing the risk of detecting legitimate files. Caution If you're using Resultant Set of Policy with Group Policy (RSOP), selecting Default blocking level can produce misleading results because RSOP reads a setting with a 0 value as disabled. Instead, confirm that the registry key is present in Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\MpEngine , or use GPresult . Moderate blocking level : Provides moderate protection only for high-confidence detections. High blocking level : Aggressively blocks unknown files while optimizing client performance. This option increases the chance of false positives. High + blocking level : Applies more protection measures. This option might affect client performance and increase the chance of false positives. Zero tolerance blocking level : Blocks all unknown executable files. When you're finished, select OK .
In the setting window that opens, configure the following options:
Under Select cloud blocking level , select one of the following protection levels: Default blocking level : Provides strong detection without increasing the risk of detecting legitimate files. Caution If you're using Resultant Set of Policy with Group Policy (RSOP), selecting Default blocking level can produce misleading results because RSOP reads a setting with a 0 value as disabled. Instead, confirm that the registry key is present in Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\MpEngine , or use GPresult . Moderate blocking level : Provides moderate protection only for high-confidence detections. High blocking level : Aggressively blocks unknown files while optimizing client performance. This option increases the chance of false positives. High + blocking level : Applies more protection measures. This option might affect client performance and increase the chance of false positives. Zero tolerance blocking level : Blocks all unknown executable files.
Default blocking level : Provides strong detection without increasing the risk of detecting legitimate files. Caution If you're using Resultant Set of Policy with Group Policy (RSOP), selecting Default blocking level can produce misleading results because RSOP reads a setting with a 0 value as disabled. Instead, confirm that the registry key is present in Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\MpEngine , or use GPresult .
Default blocking level : Provides strong detection without increasing the risk of detecting legitimate files.
If you're using Resultant Set of Policy with Group Policy (RSOP), selecting Default blocking level can produce misleading results because RSOP reads a setting with a 0 value as disabled. Instead, confirm that the registry key is present in Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\MpEngine , or use GPresult .
Moderate blocking level : Provides moderate protection only for high-confidence detections.
Moderate blocking level : Provides moderate protection only for high-confidence detections.
High blocking level : Aggressively blocks unknown files while optimizing client performance. This option increases the chance of false positives.
High blocking level : Aggressively blocks unknown files while optimizing client performance. This option increases the chance of false positives.
High + blocking level : Applies more protection measures. This option might affect client performance and increase the chance of false positives.
High + blocking level : Applies more protection measures. This option might affect client performance and increase the chance of false positives.
Zero tolerance blocking level : Blocks all unknown executable files.
Zero tolerance blocking level : Blocks all unknown executable files.
When you're finished, select OK .
Are you using Group Policy Objects on premises? See how they translate in the cloud. Analyze your on-premises group policy objects using Group Policy analytics in Microsoft Intune .
Use PowerShell to turn on cloud protection
Run the commands in an elevated PowerShell session (a PowerShell window you opened by selecting Run as administrator ).
Turn on cloud protection with PowerShell
The following command turns on cloud protection:
Configure automatic sample submission with PowerShell
The following command configures automatic safe sample submission:
To submit all samples automatically instead of only safe samples, use SendAllSamples for the SubmitSamplesConsent value.
Specify the cloud protection level with PowerShell
The following command sets the cloud protection level to High:
CloudBlockLevel supports the following values:
Verify the configuration
The following command displays the current cloud protection, sample submission, and cloud block level settings:
To verify cloud protection is turned on, confirm that MAPSReporting is 2 (Advanced). If you configured automatic sample submission, SubmitSamplesConsent is 1 (Send safe samples automatically) or 3 (Send all samples automatically). CloudBlockLevel shows the configured cloud protection level.
Turn off cloud protection with PowerShell
The following command turns off cloud protection:
For detailed syntax and parameter information, see Set-MpPreference and Get-MpPreference .
Use the Windows Security app to turn on cloud protection
On an unmanaged device, you can turn on cloud protection in the Windows Security app .
If Group Policy manages these settings, they appear dimmed in the Windows Security app and can't be changed locally.
Group Policy changes must reach the device before the settings are updated in the Windows Security app.
In the Windows Security app on the device, go to Virus & threat protection .
In the Windows Security app on the device, go to Virus & threat protection .
In the Virus & threat protection pane, in the Virus & threat protection settings section, select Manage settings .
In the Virus & threat protection pane, in the Virus & threat protection settings section, select Manage settings .
Turn on Cloud-delivered protection and Automatic sample submission .
Turn on Cloud-delivered protection and Automatic sample submission .
The Windows Security app doesn't provide a setting to configure the cloud protection level.
Use Windows Management Instrumentation (WMI) to turn on cloud protection
Use the Set method of the MSFT_MpPreference class to configure the properties for cloud-delivered protection (MAPS reporting), sample submission behavior, and cloud blocking level:
For more information the API, see Windows Defender WMIv2 APIs .
Cloud protection and Microsoft Defender Antivirus
Configuration Manager: Microsoft Defender for Endpoint
Use PowerShell cmdlets to manage Microsoft Defender Antivirus
For Microsoft Defender Antivirus information for other platforms, see:
Set preferences for Microsoft Defender for Endpoint on macOS
Microsoft Defender for Endpoint on Mac
macOS Antivirus policy settings for Microsoft Defender Antivirus for Intune
Set preferences for Microsoft Defender for Endpoint on Linux
Microsoft Defender for Endpoint on Linux
Configure Defender for Endpoint on Android features
Configure Microsoft Defender for Endpoint on iOS features
Was this page helpful?
Need help with this topic?
Want to try using Ask Learn to clarify or guide you through this topic?
Last updated on 2026-09-11
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
