Policy
Specify threat alert levels at which default action should not be taken when detected
Windows 11 25H2
Policy overview
Key metadata and intent for this policy.
Supported OS tags: Windows10, Windows10RT, Windows11, Windows8, Windows81, WindowsRT, WindowsRT81, WindowsServer2012, WindowsServer2012R2, WindowsServer2016
This policy setting allows you to customize which automatic remediation action will be taken for each threat alert level.Threat alert levels should be added under the Options for this setting. Each entry must be listed as a name value pair. The name defines a threat alert level. The value contains the action ID for the remediation action that should be taken. Valid threat alert levels are: 1 = Low 2 = Medium 4 = High 5 = Severe Valid remediation action values are: 2 = Quarantine 3 = Remove 6 = Ignore
Registry values
How enabled and disabled states update the registry.
No explicit registry values are set for enabled or disabled states.
Policy elements
Inputs and configuration options exposed by this policy.
| Element | Type | Registry mapping | Constraints & behavior |
|---|---|---|---|
Specify threat alert levels at which default action should not be taken when detected ID Threats_ThreatSeverityDefaultActionList | list | HKLM\Software\Policies\Microsoft\Windows Defender\Threats\ThreatSeverityDefaultAction\Threats_ThreatSeverityDefaultAction Type REG_MULTI_SZ | List: additive, explicit value |
Other policies in this category
Explore related policies at the same level.