Policy overview

Key metadata and intent for this policy.

ClassComputer
CategoryWindows Components > Microsoft Defender Antivirus > Device Control
Supported onAt least Windows Server 2016, Windows 10 Version 1607

Supported OS tags: Windows10, Windows10RT, Windows11, WindowsServer2016

This policy setting determines how long device control retains files for evidence in its local cache on the device. Device control keeps a file in its local cache only if it is unable to upload the file to a designated network share or Azure storage. By default, device control retains files in its local cache for 60 days.

Internal name
DeviceControl_DataDuplicationLocalRetentionPeriod
Policy ID
28baaa338936
Elements
1

Registry values

How enabled and disabled states update the registry.

No explicit registry values are set for enabled or disabled states.

Policy elements

Inputs and configuration options exposed by this policy.

ElementTypeRegistry mappingConstraints & behavior
Set the retention period for files in the local device control cache
ID DeviceControl_DataDuplicationLocalRetentionPeriod
decimal
HKLM\Software\Policies\Microsoft\Windows Defender\Device Control\DataDuplicationLocalRetentionPeriod
Type REG_DWORD
Range: 0 to 10000

Other policies in this category

Explore related policies at the same level.