Policy overview

Key metadata and intent for this policy.

ClassComputer
CategoryWindows Components > Microsoft Defender Antivirus > Threats
Supported onAt least Windows Server 2012, Windows 8 or Windows RT

Supported OS tags: Windows10, Windows10RT, Windows11, Windows8, Windows81, WindowsRT, WindowsRT81, WindowsServer2012, WindowsServer2012R2, WindowsServer2016

This policy setting allows you to customize which automatic remediation action will be taken for each threat alert level.Threat alert levels should be added under the Options for this setting. Each entry must be listed as a name value pair. The name defines a threat alert level. The value contains the action ID for the remediation action that should be taken. Valid threat alert levels are: 1 = Low 2 = Medium 4 = High 5 = Severe Valid remediation action values are: 2 = Quarantine 3 = Remove 6 = Ignore

Internal name
Threats_ThreatSeverityDefaultAction
Policy ID
46677bae74d4
Elements
1

Registry values

How enabled and disabled states update the registry.

No explicit registry values are set for enabled or disabled states.

Policy elements

Inputs and configuration options exposed by this policy.

ElementTypeRegistry mappingConstraints & behavior
Specify threat alert levels at which default action should not be taken when detected
ID Threats_ThreatSeverityDefaultActionList
list
HKLM\Software\Policies\Microsoft\Windows Defender\Threats\ThreatSeverityDefaultAction\Threats_ThreatSeverityDefaultAction
Type REG_MULTI_SZ
List: additive, explicit value

Other policies in this category

Explore related policies at the same level.