Specify threat alert levels at which default action should not be taken when detected
Jump to overview

Policy overview

Key metadata and intent for this policy.

Computer
Category
Windows Components > Microsoft Defender Antivirus > Threats
Supported on
At least Windows Server 2012, Windows 8 or Windows RT

Supported OS tags: Windows10, Windows10RT, Windows11, Windows8, Windows81, WindowsRT, WindowsRT81, WindowsServer2012, WindowsServer2012R2, WindowsServer2016

This policy setting allows you to customize which automatic remediation action will be taken for each threat alert level.Threat alert levels should be added under the Options for this setting. Each entry must be listed as a name value pair. The name defines a threat alert level. The value contains the action ID for the remediation action that should be taken. Valid threat alert levels are: 1 = Low 2 = Medium 4 = High 5 = Severe Valid remediation action values are: 2 = Quarantine 3 = Remove 6 = Ignore

Internal name
Threats_ThreatSeverityDefaultAction
Policy ID
46677bae74d4
Elements
1

Registry values

How enabled and disabled states update the registry.

No explicit registry values are set for enabled or disabled states.

Policy elements

Inputs and configuration options exposed by this policy.

ScopeElementTypeRegistry mappingConstraints & behaviorCopy
Computer
Specify threat alert levels at which default action should not be taken when detected
ID Threats_ThreatSeverityDefaultActionList
list
Path
Software\Policies\Microsoft\Windows Defender\Threats\ThreatSeverityDefaultAction
Value name
Threats_ThreatSeverityDefaultAction
Type
REG_MULTI_SZ
List: additive, explicit value
Specify threat alert levels at which default action should not be taken when detected
Computer · Type list
Registry mapping
Path
Software\Policies\Microsoft\Windows Defender\Threats\ThreatSeverityDefaultAction
Value name
Threats_ThreatSeverityDefaultAction
Type
REG_MULTI_SZ
Details
List: additive, explicit value