When two antivirus policies conflict and neither wins, no policy is delivered to the device at all.
Microsoft publishes the resolution order: most secure wins, then last modified, then nothing. That third outcome is the one worth knowing, because a device receiving no policy for a setting looks identical in the console to a device receiving the right one.

- 3 platformsLinux, macOS and Windows, plus Windows Server
- 3 settingsSupport policy merge into a superset
- Most secureWins where merge is not supported
- No policyThe outcome when a conflict cannot resolve
Every exclusion lowers the protection. Microsoft says so plainly.
Exclusions are the most requested and least examined change in antivirus policy, and they are the one place where a routine ticket quietly reduces the security position.
- The published warning is direct: defining exclusions lowers the protection offered by Microsoft Defender Antivirus, you should always evaluate the risks associated with implementing exclusions, and you should only exclude files you know are not malicious.
- Exclusions also behave differently from most settings. Excluded Processes, Excluded Extensions and Excluded Paths support policy merge, so when several policies apply to the same device those settings are merged into a single superset rather than one winning.
- That merge behaviour is useful and occasionally surprising. An exclusion added by one team for one application becomes part of the effective configuration for every device the policies overlap on, which is rarely what the requester had in mind.
- The practical control is a record. An exclusion with a named requester, a named application, a reason and a review date is defensible. An exclusion list that has accumulated for three years with no provenance is not, and it is what an assessor will ask about.
Eight things that determine what actually reaches your devices.
Antivirus settings, without the surrounding noise
Each profile contains only the settings relevant to Defender antivirus for macOS and Windows, or to the Windows Security app experience. The same settings exist in endpoint protection and device restriction templates, alongside other categories that complicate configuring the antivirus workload.
The macOS case where nothing else works
Microsoft states that settings in the macOS antivirus policy are not available through the other policy types, and that the macOS antivirus profile replaces the need to configure them using property list files. For Mac estates, this is the supported route rather than one option among several.
Policy merge, for three specific settings
Excluded processes, excluded extensions and excluded paths support policy merge, so multiple policies assigned to the same user or device combine into a single superset of exclusions. That is why exclusion lists sometimes contain entries nobody remembers adding to that policy.
Conflict resolution, and the third outcome
Where merge is not supported, the most secure policy applies. If two are equally secure, the last modified policy applies. If that cannot resolve it, no policy is delivered to the device for that setting, which is a silent gap rather than a visible error.
Tamper protection and its prerequisite
Managed through the Windows Security experience profile, and supported on macOS, Windows 10 and 11 including Enterprise multi-session, and Windows Server from 2012 R2 with the modern unified solution. Devices must be onboarded to Defender for Endpoint, and it enables on the first check-in after onboarding.
Controlled configuration, which goes further
In preview, it makes Intune the single authoritative source for Defender settings. Where tamper protection locks certain settings to secure defaults, controlled configuration locks all applicable settings to the values configured in Intune, with non-configured settings falling back to secure platform defaults.
Four Windows profiles, each with a purpose
Microsoft Defender Antivirus for the core settings, Microsoft Defender Antivirus exclusions for exclusion paths, extensions and processes, Windows Security experience for what users see and for tamper protection, and Defender Update controls for the engine, platform and security intelligence update channels.
Reports that only show the problems
The unhealthy endpoints view shows antivirus status from Defender running on the device, and only devices with detected issues appear. Devices identified as clean are not displayed, so an empty report is good news rather than a broken report.
An unresolvable conflict means no policy is delivered for that setting.
Microsoft publishes the resolution order explicitly, and the final step is the one with real consequences.
- Where a setting does not support policy merge, conflicts resolve in three steps. The most secure policy applies. If two policies are equally secure, the last modified policy applies. If the last modified policy cannot resolve the conflict, no policy is delivered to the device.
- That last outcome is a silent gap. The device does not receive the setting from any policy, which means it keeps whatever it already had, and the console does not present that as an obvious failure. Devices then drift apart in ways nobody can attribute to a specific change.
- Merge behaves differently and is worth understanding for the same reason. Excluded processes, extensions and paths merge into a single superset across every applicable policy. So a device may carry exclusions from three different policies, and no single policy shows the full list that device is actually using.
- Both behaviours argue for a small number of antivirus policies with clear ownership. Estates that accumulated policies from several projects tend to have exclusion supersets nobody has audited, alongside settings that quietly resolve to nothing.
Four things that make antivirus policy predictable.
We assemble the effective exclusion list
Excluded processes, extensions and paths merge across every applicable policy into a superset, so no single policy shows what a device is actually excluding. Assembling that list is consistently the most valuable hour of an antivirus review, and consistently the most uncomfortable.
We hunt for settings that resolve to nothing
Where merge is not supported and a conflict cannot be resolved by most secure or last modified, no policy is delivered to the device for that setting. That is a silent gap rather than an error, and consolidating policies is what removes the possibility rather than the symptom.
We treat exclusions as risk, because Microsoft does
The documentation states directly that defining exclusions lowers the protection offered by Defender Antivirus, and that you should only exclude files you know are not malicious. Every exclusion in the superset needs a reason and an owner, and the ones that have neither should go.
We scope controlled configuration honestly
It makes Intune the authoritative source for Defender settings and, during preview, covers only the antivirus and attack surface reduction templates. It does not cover endpoint detection and response, firewall settings, settings catalog policies or account protection, and that boundary matters.
Four phases across roughly four weeks.
- 01Week 1
Find every source of antivirus settings
Endpoint security antivirus policies, endpoint protection and device restriction templates in device configuration, settings catalog policies, Group Policy where it still applies, and Configuration Manager where devices are co-managed. All of them can configure the same settings.
- Every source of Defender settings inventoried
- Overlapping policies identified per setting
- Group Policy and ConfigMgr contributions mapped
- Co-management workload slider position confirmed
- 02Week 2
Audit the exclusion superset
Because excluded processes, extensions and paths merge across policies into a superset, the effective exclusion list on a device is not visible in any single policy. Assembling it is usually uncomfortable, and Microsoft is explicit that exclusions lower the protection offered.
- Effective exclusion superset assembled per device group
- Each exclusion justified or removed
- Exclusions with no owner identified
- Exclusion policy consolidated where possible
- 03Week 3
Consolidate policies and resolve conflicts
A small number of clearly owned antivirus policies replacing the accumulated set, so that conflict resolution rarely has to run at all. Where conflicts remain, they are deliberate rather than accidental, and the outcome is known rather than discovered.
- Policy set consolidated with clear ownership
- Remaining conflicts identified and resolved deliberately
- Old platform profiles migrated where still in use
- macOS settings moved off property list files
- 04Week 4
Lock it down and verify
Tamper protection enabled where devices are onboarded to Defender for Endpoint, and a decision recorded on controlled configuration given its preview status and its documented scope. Then reporting verified, including that clean devices do not appear in unhealthy endpoints.
- Tamper protection enabled with prerequisites met
- Controlled configuration decision recorded with scope understood
- Reports demonstrated including the empty-is-good behaviour
- Ongoing exclusion review cadence agreed
Six situations where antivirus policy needs untangling.
An organisation where Defender settings vary by device
Usually several sources configuring the same settings, with conflicts resolving differently depending on modification order, or resolving to nothing at all. Microsoft describes exactly this as indeterminate device states caused by multiple management channels overriding cloud-delivered settings.
A business with an exclusion list nobody can explain
Because exclusions merge into a superset across policies, the effective list on a device is not visible in one place and grows every time somebody adds one to solve a problem. Given that exclusions lower protection, that accumulation is a security position rather than housekeeping.
A Mac estate configured through property list files
The macOS antivirus profile replaces the need to configure those settings using property list files, and Microsoft notes those settings are not available through the other policy types. For organisations still shipping plists, this is the supported route rather than an alternative.
An operator with a mix of Windows Server versions
Antivirus policy reaches Windows Server through Defender for Endpoint security settings management, and tamper protection covers Server 2016 and later, Server version 1803 or later, and Server 2012 R2 through the modern unified solution. That covers estates the console does not natively show.
A regulated firm that needs settings to stay set
Tamper protection locks certain settings to secure defaults, and controlled configuration goes further by locking all applicable settings to the Intune values with non-configured settings falling back to secure platform defaults. For an auditable configuration, that difference is the point.
A company still using the retired platform profiles
The Windows 10 and later platform was replaced by the Windows platform in April 2022. New versions of the old profiles cannot be created, though existing instances remain usable and editable. Estates still relying on them are on a path with a limited future.
How UAE organisations configure Defender antivirus.
| Feature | Consolidated endpoint security policy | Settings from several sources | Defaults plus local changes |
|---|---|---|---|
Effective configuration knowable | Yes | Difficult | No |
Exclusion superset audited | Yes | Rarely | Not applicable |
Conflicts deliberate | Yes | Accidental | Not applicable |
Silent no-policy gaps | None | Possible | Not applicable |
macOS managed without plist files | Yes | Sometimes | No |
Tamper protection enabled | Yes | Partly | No |
Group Policy contributions removed | Yes | No | Not applicable |
Unhealthy endpoints monitored | Yes | Rarely | No |
Update channels controlled | Yes | Default | Default |
Ownership per policy clear | Yes | No | Not applicable |
What it covers, and what it deliberately does not.
| Area | Covered by controlled configuration | |
|---|---|---|
| Antivirus policy template | Yes, during preview | |
| Attack surface reduction template | Yes, during preview | |
| Endpoint detection and response | No | |
| Firewall settings | No | |
| Settings Catalog policies | No, authored outside Endpoint Security | |
| Account Protection | No, not a Defender component | |
| Settings not explicitly configured | Revert to defaults, and local users can still modify them | |
| Group Policy and Configuration Manager values | Overridden where Intune configures the setting | |
| Overlapping non-controlled policy settings | Report as Not applicable on that device | |
| Scope of the switch | Per device, reversible at the next policy check-in |
Five steps, and consolidation does most of the work.
- 1
Inventory every source of Defender settings
Endpoint security antivirus policies, endpoint protection and device restriction templates, settings catalog policies, Group Policy, and Configuration Manager for co-managed devices. Microsoft names exactly this multiplicity as the cause of indeterminate and hard to troubleshoot device states.
- 2
Assemble the effective exclusion superset
Excluded processes, extensions and paths merge across all applicable policies, so the effective list has to be assembled rather than read. Each entry then justified or removed, because the documentation is explicit that exclusions lower the protection Defender offers.
- 3
Consolidate to a small owned policy set
Fewer policies means conflict resolution rarely has to run, which removes the possibility of a setting resolving to no policy at all. Where conflicts remain they become deliberate decisions with a known outcome rather than accidents discovered during an incident.
- 4
Enable tamper protection and decide on controlled configuration
Tamper protection needs devices onboarded to Defender for Endpoint and enables on the first check-in after onboarding. Controlled configuration is a further step, in preview, covering the antivirus and attack surface reduction templates but not endpoint detection and response, firewall or settings catalog policies.
- 5
Verify through the reports and set a review cadence
Unhealthy endpoints shows only devices with detected issues, so an empty view is a good result rather than a broken report. Then a recurring exclusion review, because exclusions accumulate and removing one is a decision nobody makes unless it is scheduled.
What organisations ask about Intune antivirus policy.
Fifteen questions about your own antivirus configuration.
Sources
- How many antivirus policies do we have?And who owns each.
- Do device restriction templates also set these?They contain the same settings.
- Any settings catalog policies overlapping?Another source.
- Does Group Policy still configure Defender?Common in hybrid estates.
- Is the co-management slider set to Intune?Required for these settings.
Exclusions
- What is the effective exclusion superset?It merges across policies.
- Can we justify each exclusion?They lower protection.
- Who added the oldest ones?Usually unknown.
- Are any exclusions overly broad?Whole drive paths, for example.
- Do we review exclusions periodically?Most estates never do.
Protection
- Is tamper protection enabled?Needs Defender for Endpoint onboarding.
- Are devices onboarded to Defender for Endpoint?P1 or P2.
- Have we considered controlled configuration?Preview, and narrower than it sounds.
- Are we still using old platform profiles?No new versions can be created.
- Does anybody read unhealthy endpoints?Only problem devices appear.
Try to assemble the complete antivirus exclusion list for one device group.
Exclusions merge into a superset across every applicable policy, so no single policy shows it. If assembling that list takes more than an hour, you have found the problem worth fixing.
Related Services
Explore more solutions that work great with this service
Intune Firewall Policy
Host firewall rules that actually apply
Security Baselines
Why deploying one does not make you CIS compliant
Attack Surface Reduction Rules
Eighteen rules, audit first, then warn, then block
Defender for Endpoint
Business, Plan 1 or Plan 2, and what each actually gives you
Intune Configuration Profiles
Settings catalog, templates and conflict management
Endpoint Security
Defender for Endpoint and Intune managed
Co-Management
ConfigMgr and Intune, deliberately together
MDM Solutions Dubai
Device management across Windows, Apple and Android