Skip to content
Endpoint Detection and Response (EDR) in block mode

Endpoint Detection and Response (EDR) in block mode

learn.microsoft.com • September 29, 2026

Access to this page requires authorization. You can try signing in or changing directories .

Access to this page requires authorization. You can try changing directories .

Applies to: Microsoft Defender for Endpoint Plan 2, Microsoft Defender Antivirus

This article describes EDR in block mode, which helps protect devices that are running a non-Microsoft antivirus solution (with Microsoft Defender Antivirus in passive mode).

Supported operating systems

What is EDR in block mode?

Endpoint detection and response (EDR) in block mode provides added protection from malicious artifacts when Microsoft Defender Antivirus is not the primary antivirus product and is running in passive mode. EDR in block mode is available in Defender for Endpoint Plan 2.

EDR in block mode cannot provide all available protection when Microsoft Defender Antivirus real-time protection is in passive mode. Some capabilities that depend on Microsoft Defender Antivirus to be the active antivirus solution will not work, such as the following examples:

Features like network protection and attack surface reduction (ASR) rules and indicators (file hash, ip address, URL, and certificates) are only available when Microsoft Defender Antivirus is running in Active mode. It is expected that your non-Microsoft antivirus solution includes these capabilities.

EDR in block mode works behind the scenes to remediate malicious artifacts that were detected by EDR capabilities. Such artifacts might have been missed by the primary, non-Microsoft antivirus product. EDR in block mode allows Microsoft Defender Antivirus to take actions on post-breach, behavioral EDR detections.

EDR in block mode is integrated with threat & vulnerability management capabilities. Your organization's security team gets a security recommendation to turn EDR in block mode on if it isn't already enabled.

To get the best protection, make sure to deploy Microsoft Defender for Endpoint baselines .

Watch this video to learn why and how to turn on endpoint detection and response (EDR) in block mode, enable behavioral blocking, and containment at every stage from pre-breach to post-breach.

What happens when something is detected?

When EDR in block mode is turned on, and a malicious artifact is detected, Defender for Endpoint remediates that artifact. Your security operations team sees the detection status as Blocked or Prevented in the Action center , listed as completed actions. The following image shows an instance of unwanted software that was detected and remediated through EDR in block mode:

Enable EDR in block mode

Make sure the requirements are met before turning on EDR in block mode.

Defender for Endpoint Plan 2 licenses are required.

Beginning with platform version 4.18.2202.X , you can set EDR in block mode to target specific device groups using Intune CSPs. You can continue to set EDR in block mode tenant-wide in the Microsoft Defender portal .

EDR in block mode is primarily recommended for devices that are running Microsoft Defender Antivirus in passive mode (a non-Microsoft antivirus solution is installed and active on the device).

Microsoft Defender portal

Go to the Microsoft Defender portal ( ) and sign in.

Go to the Microsoft Defender portal ( ) and sign in.

Choose Settings > Endpoints > General > Advanced features .

Choose Settings > Endpoints > General > Advanced features .

Scroll down, and then turn on Enable EDR in block mode .

Scroll down, and then turn on Enable EDR in block mode .

Microsoft Intune is the recommended tool for configuring and distributing Defender for Endpoint features to devices. However, Intune is a separate product that isn't part of Defender for Endpoint, and it isn't included in all subscriptions. To use Intune, you need a subscription that includes it, or you can buy it separately as a standalone subscription or add-on. If you don't have Intune, you can use any of the other methods in this article. For more information, see Microsoft Intune licensing .

To create a custom policy in Intune, see Deploy OMA-URIs to target a CSP through Intune, and a comparison to on-premises .

For more information on the Defender CSP used for EDR in block mode, see "Configuration/PassiveRemediation" under Defender CSP .

You can use Group Policy to enable EDR in block mode.

In Centralized Group Policy, open the Group Policy Management Console (GPMC) on your Group Policy management computer.

In Centralized Group Policy, open the Group Policy Management Console (GPMC) on your Group Policy management computer.

In the GPMC console tree, expand Group Policy Objects in the forest and domain containing the GPO you want to edit.

In the GPMC console tree, expand Group Policy Objects in the forest and domain containing the GPO you want to edit.

Right-click the GPO, and then select Edit .

Right-click the GPO, and then select Edit .

In the Group Policy Management Editor , go to Computer configuration > Administrative templates > Windows components > Microsoft Defender Antivirus > Features .

In the Group Policy Management Editor , go to Computer configuration > Administrative templates > Windows components > Microsoft Defender Antivirus > Features .

In the details pane of Features , open the Enable EDR in block mode setting. To open the setting, use any of the following methods: Double-click the setting. Right-click the setting, and then select Edit . Select the setting, and then select Action > Edit .

In the details pane of Features , open the Enable EDR in block mode setting. To open the setting, use any of the following methods:

Double-click the setting.

Right-click the setting, and then select Edit .

Select the setting, and then select Action > Edit .

In the setting window that opens, select Enabled , and then select OK .

In the setting window that opens, select Enabled , and then select OK .

You can also configure Group Policy locally on individual devices by using the Local Group Policy Editor ( gpedit.msc ). Navigate to the same path: Computer configuration > Administrative templates > Windows components > Microsoft Defender Antivirus > Features .

Requirements for EDR in block mode

The following table lists requirements for EDR in block mode:

To get the best protection value, make sure your antivirus solution is configured to receive regular updates and essential features, and that your exclusions are configured . EDR in block mode respects exclusions that are defined for Microsoft Defender Antivirus, but not indicators that are defined for Microsoft Defender for Endpoint.

Microsoft recommends that you use roles with the fewest permissions. This helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.

Endpoint detection and response (EDR) in block mode frequently asked questions (FAQ)

Was this page helpful?

Need help with this topic?

Want to try using Ask Learn to clarify or guide you through this topic?

Last updated on 2026-09-15