We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Intune and endpoint management
  2. Endpoint security antivirus
Intune antivirus policy, UAE

When two antivirus policies conflict and neither wins, no policy is delivered to the device at all.

Microsoft publishes the resolution order: most secure wins, then last modified, then nothing. That third outcome is the one worth knowing, because a device receiving no policy for a setting looks identical in the console to a device receiving the right one.

Book an antivirus policy reviewSee how policies interact
Intune endpoint security antivirus policy for UAE organisations
  • 3 platformsLinux, macOS and Windows, plus Windows Server
  • 3 settingsSupport policy merge into a superset
  • Most secureWins where merge is not supported
  • No policyThe outcome when a conflict cannot resolve
Read this before adding exclusions

Every exclusion lowers the protection. Microsoft says so plainly.

Exclusions are the most requested and least examined change in antivirus policy, and they are the one place where a routine ticket quietly reduces the security position.

  • The published warning is direct: defining exclusions lowers the protection offered by Microsoft Defender Antivirus, you should always evaluate the risks associated with implementing exclusions, and you should only exclude files you know are not malicious.
  • Exclusions also behave differently from most settings. Excluded Processes, Excluded Extensions and Excluded Paths support policy merge, so when several policies apply to the same device those settings are merged into a single superset rather than one winning.
  • That merge behaviour is useful and occasionally surprising. An exclusion added by one team for one application becomes part of the effective configuration for every device the policies overlap on, which is rarely what the requester had in mind.
  • The practical control is a record. An exclusion with a named requester, a named application, a reason and a review date is defensible. An exclusion list that has accumulated for three years with no provenance is not, and it is what an assessor will ask about.
What antivirus policy does

Eight things that determine what actually reaches your devices.

Antivirus settings can arrive from endpoint security policy, device configuration templates, the settings catalog, Group Policy and local changes. Understanding how those interact is more valuable than knowing any individual setting.

Antivirus settings, without the surrounding noise

Each profile contains only the settings relevant to Defender antivirus for macOS and Windows, or to the Windows Security app experience. The same settings exist in endpoint protection and device restriction templates, alongside other categories that complicate configuring the antivirus workload.

The macOS case where nothing else works

Microsoft states that settings in the macOS antivirus policy are not available through the other policy types, and that the macOS antivirus profile replaces the need to configure them using property list files. For Mac estates, this is the supported route rather than one option among several.

Policy merge, for three specific settings

Excluded processes, excluded extensions and excluded paths support policy merge, so multiple policies assigned to the same user or device combine into a single superset of exclusions. That is why exclusion lists sometimes contain entries nobody remembers adding to that policy.

Conflict resolution, and the third outcome

Where merge is not supported, the most secure policy applies. If two are equally secure, the last modified policy applies. If that cannot resolve it, no policy is delivered to the device for that setting, which is a silent gap rather than a visible error.

Tamper protection and its prerequisite

Managed through the Windows Security experience profile, and supported on macOS, Windows 10 and 11 including Enterprise multi-session, and Windows Server from 2012 R2 with the modern unified solution. Devices must be onboarded to Defender for Endpoint, and it enables on the first check-in after onboarding.

Controlled configuration, which goes further

In preview, it makes Intune the single authoritative source for Defender settings. Where tamper protection locks certain settings to secure defaults, controlled configuration locks all applicable settings to the values configured in Intune, with non-configured settings falling back to secure platform defaults.

Four Windows profiles, each with a purpose

Microsoft Defender Antivirus for the core settings, Microsoft Defender Antivirus exclusions for exclusion paths, extensions and processes, Windows Security experience for what users see and for tamper protection, and Defender Update controls for the engine, platform and security intelligence update channels.

Reports that only show the problems

The unhealthy endpoints view shows antivirus status from Defender running on the device, and only devices with detected issues appear. Devices identified as clean are not displayed, so an empty report is good news rather than a broken report.

The gap nobody sees

An unresolvable conflict means no policy is delivered for that setting.

Microsoft publishes the resolution order explicitly, and the final step is the one with real consequences.

  • Where a setting does not support policy merge, conflicts resolve in three steps. The most secure policy applies. If two policies are equally secure, the last modified policy applies. If the last modified policy cannot resolve the conflict, no policy is delivered to the device.
  • That last outcome is a silent gap. The device does not receive the setting from any policy, which means it keeps whatever it already had, and the console does not present that as an obvious failure. Devices then drift apart in ways nobody can attribute to a specific change.
  • Merge behaves differently and is worth understanding for the same reason. Excluded processes, extensions and paths merge into a single superset across every applicable policy. So a device may carry exclusions from three different policies, and no single policy shows the full list that device is actually using.
  • Both behaviours argue for a small number of antivirus policies with clear ownership. Estates that accumulated policies from several projects tend to have exclusion supersets nobody has audited, alongside settings that quietly resolve to nothing.
Ask us to audit your policy overlap
How we approach it

Four things that make antivirus policy predictable.

Almost every antivirus configuration problem we assess is a multiplicity problem. Too many sources configuring the same settings, and nobody able to say what a device ends up with.

We assemble the effective exclusion list

Excluded processes, extensions and paths merge across every applicable policy into a superset, so no single policy shows what a device is actually excluding. Assembling that list is consistently the most valuable hour of an antivirus review, and consistently the most uncomfortable.

We hunt for settings that resolve to nothing

Where merge is not supported and a conflict cannot be resolved by most secure or last modified, no policy is delivered to the device for that setting. That is a silent gap rather than an error, and consolidating policies is what removes the possibility rather than the symptom.

We treat exclusions as risk, because Microsoft does

The documentation states directly that defining exclusions lowers the protection offered by Defender Antivirus, and that you should only exclude files you know are not malicious. Every exclusion in the superset needs a reason and an owner, and the ones that have neither should go.

We scope controlled configuration honestly

It makes Intune the authoritative source for Defender settings and, during preview, covers only the antivirus and attack surface reduction templates. It does not cover endpoint detection and response, firewall settings, settings catalog policies or account protection, and that boundary matters.

How a review runs

Four phases across roughly four weeks.

Most of the value is in consolidation. Estates accumulate antivirus settings from several sources over years, and nobody has traced what a given device is actually running.
  1. 01
    Week 1

    Find every source of antivirus settings

    Endpoint security antivirus policies, endpoint protection and device restriction templates in device configuration, settings catalog policies, Group Policy where it still applies, and Configuration Manager where devices are co-managed. All of them can configure the same settings.

    • Every source of Defender settings inventoried
    • Overlapping policies identified per setting
    • Group Policy and ConfigMgr contributions mapped
    • Co-management workload slider position confirmed
  2. 02
    Week 2

    Audit the exclusion superset

    Because excluded processes, extensions and paths merge across policies into a superset, the effective exclusion list on a device is not visible in any single policy. Assembling it is usually uncomfortable, and Microsoft is explicit that exclusions lower the protection offered.

    • Effective exclusion superset assembled per device group
    • Each exclusion justified or removed
    • Exclusions with no owner identified
    • Exclusion policy consolidated where possible
  3. 03
    Week 3

    Consolidate policies and resolve conflicts

    A small number of clearly owned antivirus policies replacing the accumulated set, so that conflict resolution rarely has to run at all. Where conflicts remain, they are deliberate rather than accidental, and the outcome is known rather than discovered.

    • Policy set consolidated with clear ownership
    • Remaining conflicts identified and resolved deliberately
    • Old platform profiles migrated where still in use
    • macOS settings moved off property list files
  4. 04
    Week 4

    Lock it down and verify

    Tamper protection enabled where devices are onboarded to Defender for Endpoint, and a decision recorded on controlled configuration given its preview status and its documented scope. Then reporting verified, including that clean devices do not appear in unhealthy endpoints.

    • Tamper protection enabled with prerequisites met
    • Controlled configuration decision recorded with scope understood
    • Reports demonstrated including the empty-is-good behaviour
    • Ongoing exclusion review cadence agreed
Where this matters

Six situations where antivirus policy needs untangling.

The recurring theme is Defender behaving differently across devices that should be identical, with no obvious explanation in any single policy.

An organisation where Defender settings vary by device

Usually several sources configuring the same settings, with conflicts resolving differently depending on modification order, or resolving to nothing at all. Microsoft describes exactly this as indeterminate device states caused by multiple management channels overriding cloud-delivered settings.

A business with an exclusion list nobody can explain

Because exclusions merge into a superset across policies, the effective list on a device is not visible in one place and grows every time somebody adds one to solve a problem. Given that exclusions lower protection, that accumulation is a security position rather than housekeeping.

A Mac estate configured through property list files

The macOS antivirus profile replaces the need to configure those settings using property list files, and Microsoft notes those settings are not available through the other policy types. For organisations still shipping plists, this is the supported route rather than an alternative.

An operator with a mix of Windows Server versions

Antivirus policy reaches Windows Server through Defender for Endpoint security settings management, and tamper protection covers Server 2016 and later, Server version 1803 or later, and Server 2012 R2 through the modern unified solution. That covers estates the console does not natively show.

A regulated firm that needs settings to stay set

Tamper protection locks certain settings to secure defaults, and controlled configuration goes further by locking all applicable settings to the Intune values with non-configured settings falling back to secure platform defaults. For an auditable configuration, that difference is the point.

A company still using the retired platform profiles

The Windows 10 and later platform was replaced by the Windows platform in April 2022. New versions of the old profiles cannot be created, though existing instances remain usable and editable. Estates still relying on them are on a path with a limited future.

Three positions

How UAE organisations configure Defender antivirus.

The middle column is the most common, and its problem is not any individual setting. It is that no single place shows what a given device is actually running.
Effective configuration knowable
Consolidated endpoint security policyYes
Settings from several sourcesDifficult
Defaults plus local changesNo
Exclusion superset audited
Consolidated endpoint security policyYes
Settings from several sourcesRarely
Defaults plus local changesNot applicable
Conflicts deliberate
Consolidated endpoint security policyYes
Settings from several sourcesAccidental
Defaults plus local changesNot applicable
Silent no-policy gaps
Consolidated endpoint security policyNone
Settings from several sourcesPossible
Defaults plus local changesNot applicable
macOS managed without plist files
Consolidated endpoint security policyYes
Settings from several sourcesSometimes
Defaults plus local changesNo
Tamper protection enabled
Consolidated endpoint security policyYes
Settings from several sourcesPartly
Defaults plus local changesNo
Group Policy contributions removed
Consolidated endpoint security policyYes
Settings from several sourcesNo
Defaults plus local changesNot applicable
Unhealthy endpoints monitored
Consolidated endpoint security policyYes
Settings from several sourcesRarely
Defaults plus local changesNo
Update channels controlled
Consolidated endpoint security policyYes
Settings from several sourcesDefault
Defaults plus local changesDefault
Ownership per policy clear
Consolidated endpoint security policyYes
Settings from several sourcesNo
Defaults plus local changesNot applicable
Feature
Consolidated endpoint security policy
Settings from several sources
Defaults plus local changes
Effective configuration knowable
YesDifficultNo
Exclusion superset audited
YesRarelyNot applicable
Conflicts deliberate
YesAccidentalNot applicable
Silent no-policy gaps
NonePossibleNot applicable
macOS managed without plist files
YesSometimesNo
Tamper protection enabled
YesPartlyNo
Group Policy contributions removed
YesNoNot applicable
Unhealthy endpoints monitored
YesRarelyNo
Update channels controlled
YesDefaultDefault
Ownership per policy clear
YesNoNot applicable
Controlled configuration

What it covers, and what it deliberately does not.

This is the preview capability that resolves the multi-channel Defender configuration problem, and its scope is narrower than the name suggests.
AreaCovered by controlled configuration
Antivirus policy templateYes, during preview
Attack surface reduction templateYes, during preview
Endpoint detection and responseNo
Firewall settingsNo
Settings Catalog policiesNo, authored outside Endpoint Security
Account ProtectionNo, not a Defender component
Settings not explicitly configuredRevert to defaults, and local users can still modify them
Group Policy and Configuration Manager valuesOverridden where Intune configures the setting
Overlapping non-controlled policy settingsReport as Not applicable on that device
Scope of the switchPer device, reversible at the next policy check-in
How an engagement runs

Five steps, and consolidation does most of the work.

Adjusting individual settings rarely fixes an antivirus estate. Reducing the number of things configuring those settings usually does.
  1. 1

    Inventory every source of Defender settings

    Endpoint security antivirus policies, endpoint protection and device restriction templates, settings catalog policies, Group Policy, and Configuration Manager for co-managed devices. Microsoft names exactly this multiplicity as the cause of indeterminate and hard to troubleshoot device states.

  2. 2

    Assemble the effective exclusion superset

    Excluded processes, extensions and paths merge across all applicable policies, so the effective list has to be assembled rather than read. Each entry then justified or removed, because the documentation is explicit that exclusions lower the protection Defender offers.

  3. 3

    Consolidate to a small owned policy set

    Fewer policies means conflict resolution rarely has to run, which removes the possibility of a setting resolving to no policy at all. Where conflicts remain they become deliberate decisions with a known outcome rather than accidents discovered during an incident.

  4. 4

    Enable tamper protection and decide on controlled configuration

    Tamper protection needs devices onboarded to Defender for Endpoint and enables on the first check-in after onboarding. Controlled configuration is a further step, in preview, covering the antivirus and attack surface reduction templates but not endpoint detection and response, firewall or settings catalog policies.

  5. 5

    Verify through the reports and set a review cadence

    Unhealthy endpoints shows only devices with detected issues, so an empty view is a good result rather than a broken report. Then a recurring exclusion review, because exclusions accumulate and removing one is a decision nobody makes unless it is scheduled.

Straight answers

What organisations ask about Intune antivirus policy.

Where the setting supports policy merge, they combine into a superset. Where it does not, the most secure policy applies, then if two are equally secure the last modified policy applies, and if that cannot resolve it, no policy is delivered to the device for that setting.

Excluded processes, excluded extensions and excluded paths. Intune evaluates them across all applicable policies for the user or device and delivers a single combined superset. That is why a device may be excluding paths defined in a policy you are not looking at.

Possibly an unresolvable conflict. If the most secure policy and last modified policy rules both fail to resolve, no policy is delivered to the device for that setting, which leaves it at whatever it already had. It is a silent outcome rather than a reported error.

Antivirus policy contains only the settings relevant to Defender antivirus and the Windows Security app experience. The endpoint protection and device restriction templates in device configuration include the same settings alongside other unrelated categories, which complicates configuring the antivirus workload.

No. Microsoft states the macOS antivirus profile replaces the need to configure those settings using property list files, and that the settings in the macOS antivirus policy are not available through the other policy types. Defender for Endpoint must be installed on the device first.

Yes, and this is a specific advantage over device restriction profiles. Microsoft notes that unlike the antivirus settings in a device restriction profile, these settings can be used with co-managed devices, provided the co-management workload slider for Endpoint Protection is set to Intune.

Devices onboarded to Microsoft Defender for Endpoint, either Plan 1 or Plan 2. Microsoft notes that devices might see a delay enabling it if not previously onboarded, and that tamper protection enables on the first device check-in after onboarding to Defender for Endpoint.

A preview capability that extends tamper protection by making Intune the single authoritative source for Defender security settings. Tamper protection locks certain settings to secure defaults. Controlled configuration locks all applicable settings to the values configured in Intune, with non-configured settings falling back to secure platform defaults.

During preview it enforces settings from the antivirus and attack surface reduction templates. It does not apply to endpoint detection and response, firewall settings, policies authored outside the endpoint security experience such as settings catalog policies, or endpoint security policy types not used by Defender components such as account protection.

No, and this nuance matters. Settings not explicitly configured in controlled configuration revert to their default values, and local users can still modify those, because controlled configuration locks only the settings its policy defines. Coverage follows what you configured rather than being absolute.

Where a device is in the controlled configuration state, overlapping settings in non-controlled policies such as settings catalog policies report as not applicable on that device. The controlled configuration policy takes precedence regardless of the value configured in the other policy.

They are a documented risk. Microsoft states directly that defining exclusions lowers the protection offered by Defender Antivirus, that you should always evaluate the associated risks, and that you should only exclude files you know are not malicious. Every exclusion needs a reason and an owner.

Because nothing is unhealthy. Only devices with detected issues appear in that view, and it does not display details for devices identified as clean. An empty report is the desired state rather than a sign the report is not working.

Existing instances remain available to use and edit, and you can no longer create new versions of them, since the Windows 10 and later platform was replaced by the Windows platform in April 2022. The newer profiles use the settings catalog format and add Windows Server support.

We scope by the number of policy sources and platforms involved. The free first step: try to assemble the complete list of antivirus exclusions applying to one device group. If that takes more than an hour, the consolidation work will pay for itself in the audit alone.

Where merge is not supported the documented order is that the most secure policy applies, then if two policies are equally secure the last modified policy applies, and if that cannot resolve the conflict no policy is delivered to the device at all.

Yes, and that is a documented advantage over the antivirus settings in a Device Restriction profile. To use these settings the co-management workload slider for Endpoint Protection must be set to Intune.

It extends tamper protection by making Intune the single authoritative source for Defender security settings, locking all applicable settings to the values configured in Intune rather than only locking certain settings to secure defaults. It is currently in preview.
Policy review

Fifteen questions about your own antivirus configuration.

The second group is where most estates find something uncomfortable, because exclusions accumulate and almost nobody removes one.

Sources

  • How many antivirus policies do we have?
    And who owns each.
  • Do device restriction templates also set these?
    They contain the same settings.
  • Any settings catalog policies overlapping?
    Another source.
  • Does Group Policy still configure Defender?
    Common in hybrid estates.
  • Is the co-management slider set to Intune?
    Required for these settings.

Exclusions

  • What is the effective exclusion superset?
    It merges across policies.
  • Can we justify each exclusion?
    They lower protection.
  • Who added the oldest ones?
    Usually unknown.
  • Are any exclusions overly broad?
    Whole drive paths, for example.
  • Do we review exclusions periodically?
    Most estates never do.

Protection

  • Is tamper protection enabled?
    Needs Defender for Endpoint onboarding.
  • Are devices onboarded to Defender for Endpoint?
    P1 or P2.
  • Have we considered controlled configuration?
    Preview, and narrower than it sounds.
  • Are we still using old platform profiles?
    No new versions can be created.
  • Does anybody read unhealthy endpoints?
    Only problem devices appear.
Related reading

The pages around this one.

Intune security baselines

The wider hardening baseline these settings sit inside.

Learn more

Attack surface reduction rules

The other template controlled configuration covers.

Learn more

Defender for Endpoint

The product these policies configure.

Learn more
Next step

Try to assemble the complete antivirus exclusion list for one device group.

Exclusions merge into a superset across every applicable policy, so no single policy shows it. If assembling that list takes more than an hour, you have found the problem worth fixing.

Book an antivirus policy reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Intune Firewall Policy

Host firewall rules that actually apply

Learn more

Security Baselines

Why deploying one does not make you CIS compliant

Learn more

Attack Surface Reduction Rules

Eighteen rules, audit first, then warn, then block

Learn more

Defender for Endpoint

Business, Plan 1 or Plan 2, and what each actually gives you

Learn more

Intune Configuration Profiles

Settings catalog, templates and conflict management

Learn more

Endpoint Security

Defender for Endpoint and Intune managed

Learn more

Co-Management

ConfigMgr and Intune, deliberately together

Learn more

MDM Solutions Dubai

Device management across Windows, Apple and Android

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy