Resources/Baseline/MicrosoftDefender.json

[
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows\\WTDS\\Components",
        "ValueName": "CaptureThreatWindow",
        "Type": 4,
        "Size": 4,
        "Data": "AQAAAA==",
        "RegValue": "1",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "CaptureThreatWindow-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-webthreatdefense#automaticdatacollection",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            99
        ],
        "ID": "019a8dfa-2539-771f-a167-a1af333c15e1"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows\\WTDS\\Components",
        "ValueName": "NotifyMalicious",
        "Type": 4,
        "Size": 4,
        "Data": "AQAAAA==",
        "RegValue": "1",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "NotifyMalicious-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-webthreatdefense#notifymalicious",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            99
        ],
        "ID": "019a8dfa-2539-70fc-ab4c-d7f6870fab4d"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows\\WTDS\\Components",
        "ValueName": "NotifyPasswordReuse",
        "Type": 4,
        "Size": 4,
        "Data": "AQAAAA==",
        "RegValue": "1",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "NotifyPasswordReuse-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-webthreatdefense#notifypasswordreuse",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            99
        ],
        "ID": "019a8dfa-2539-7ef2-a1e3-d568396edd31"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows\\WTDS\\Components",
        "ValueName": "NotifyUnsafeApp",
        "Type": 4,
        "Size": 4,
        "Data": "AQAAAA==",
        "RegValue": "1",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "NotifyUnsafeApp-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-webthreatdefense#notifyunsafeapp",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            99
        ],
        "ID": "019a8dfa-2539-7cef-b705-29a370bea48d"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows\\WTDS\\Components",
        "ValueName": "ServiceEnabled",
        "Type": 4,
        "Size": 4,
        "Data": "AQAAAA==",
        "RegValue": "1",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "PhishingProtectServiceEnabled-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-webthreatdefense#serviceenabled",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            99
        ],
        "ID": "019a8dfa-2539-71f9-879c-ebfe1703fa8f"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Features",
        "ValueName": "TDTFeatureEnabled",
        "Type": 4,
        "Size": 4,
        "Data": "AQAAAA==",
        "RegValue": "1",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "TDTFeatureEnabled-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/defender-csp#configurationinteltdtenabled",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            99
        ],
        "ID": "019a8dfa-2539-7914-a492-6739cf39221f"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\MpEngine",
        "ValueName": "MpCloudBlockLevel",
        "Type": 4,
        "Size": 4,
        "Data": "BgAAAA==",
        "RegValue": "6",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "MpCloudBlockLevel-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-defender#cloudblocklevel",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            2,
            3,
            4,
            5
        ],
        "ID": "019a8dfa-253a-783f-8a61-382f9561aabe"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\MpEngine",
        "ValueName": "MpBafsExtendedTimeout",
        "Type": 4,
        "Size": 4,
        "Data": "MgAAAA==",
        "RegValue": "50",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "MpBafsExtendedTimeout-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-defender#cloudextendedtimeout",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            2,
            3,
            4,
            5
        ],
        "ID": "019a8dfa-253a-73c8-b94a-0ddf909a3936"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\MpEngine",
        "ValueName": "EnableFileHashComputation",
        "Type": 4,
        "Size": 4,
        "Data": "AQAAAA==",
        "RegValue": "1",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "EnableFileHashComputation-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#mpengine_enablefilehashcomputation",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            2,
            3,
            4,
            5
        ],
        "ID": "019a8dfa-253a-72cb-90b1-3982f62cc84a"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Quarantine",
        "ValueName": "PurgeItemsAfterDelay",
        "Type": 4,
        "Size": 4,
        "Data": "AQAAAA==",
        "RegValue": "1",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "PurgeItemsAfterDelay-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#quarantine_purgeitemsafterdelay",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            2,
            3,
            4,
            5
        ],
        "ID": "019a8dfa-253a-7690-87ab-733e43c03d43"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection",
        "ValueName": "DisableAsyncScanOnOpen",
        "Type": 4,
        "Size": 4,
        "Data": "AQAAAA==",
        "RegValue": "1",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "DisableAsyncScanOnOpen-MSDefender",
        "URL": "https://learn.microsoft.com/defender-endpoint/microsoft-defender-endpoint-antivirus-performance-mode",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            99
        ],
        "ID": "019a8dfa-253a-7eb5-ad3c-e178b3c09b1b"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection",
        "ValueName": "OobeEnableRtpAndSigUpdate",
        "Type": 4,
        "Size": 4,
        "Data": "AQAAAA==",
        "RegValue": "1",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "OobeEnableRtpAndSigUpdate-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/defender-csp#configurationoobeenablertpandsigupdate",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            99
        ],
        "ID": "019a8dfa-253a-77fe-bb82-30b421c9f7b3"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection",
        "ValueName": "IOAVMaxSize",
        "Type": 4,
        "Size": 4,
        "Data": "gJaYAA==",
        "RegValue": "10000000",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "IOAVMaxSize-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#realtimeprotection_ioavmaxsize",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            99
        ],
        "ID": "019a8dfa-253a-78de-be06-9da3fcf5ca94"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Remediation\\Behavioral Network Blocks\\Brute Force Protection",
        "ValueName": "BruteForceProtectionConfiguredState",
        "Type": 4,
        "Size": 4,
        "Data": "AQAAAA==",
        "RegValue": "1",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "BruteForceProtectionConfiguredState-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/defender-csp#configurationbehavioralnetworkblocksbruteforceprotectionbruteforceprotectionconfiguredstate",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            99
        ],
        "ID": "019a8dfa-253b-782c-aa43-b81fdb9adfa4"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Remediation\\Behavioral Network Blocks\\Brute Force Protection",
        "ValueName": "BruteForceProtectionAggressiveness",
        "Type": 4,
        "Size": 4,
        "Data": "AQAAAA==",
        "RegValue": "1",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "BruteForceProtectionAggressiveness-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/defender-csp#configurationbehavioralnetworkblocksbruteforceprotectionbruteforceprotectionaggressiveness",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            2,
            3,
            4,
            5
        ],
        "ID": "019a8dfa-253b-7199-8fdc-5267c2813116"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Remediation\\Behavioral Network Blocks\\Remote Encryption Protection",
        "ValueName": "RemoteEncryptionProtectionConfiguredState",
        "Type": 4,
        "Size": 4,
        "Data": "AQAAAA==",
        "RegValue": "1",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "RemoteEncryptionProtectionConfiguredState-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/defender-csp#configurationbehavioralnetworkblocksremoteencryptionprotectionremoteencryptionprotectionconfiguredstate",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            99
        ],
        "ID": "019a8dfa-253b-7130-a348-7aceef12fd1d"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Remediation\\Behavioral Network Blocks\\Remote Encryption Protection",
        "ValueName": "RemoteEncryptionProtectionAggressiveness",
        "Type": 4,
        "Size": 4,
        "Data": "AgAAAA==",
        "RegValue": "2",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "RemoteEncryptionProtectionAggressiveness-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/defender-csp#configurationbehavioralnetworkblocksremoteencryptionprotectionremoteencryptionprotectionaggressiveness",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            2,
            3,
            4,
            5
        ],
        "ID": "019a8dfa-253b-7227-994d-195a4efe326c"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Scan",
        "ValueName": "ArchiveMaxDepth",
        "Type": 4,
        "Size": 4,
        "Data": "/////w==",
        "RegValue": "4294967295",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "ArchiveMaxDepth-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#scan_archivemaxdepth",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            2,
            3,
            4,
            5
        ],
        "ID": "019a8dfa-253b-7894-b96f-84ccbbf2f9f6"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Scan",
        "ValueName": "DisableRemovableDriveScanning",
        "Type": 4,
        "Size": 4,
        "Data": "AAAAAA==",
        "RegValue": "0",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "DisableRemovableDriveScanning-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-defender#allowfullscanremovabledrivescanning",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            99
        ],
        "ID": "019a8dfa-253b-7090-8527-b85cc001b1a2"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Scan",
        "ValueName": "DisableReparsePointScanning",
        "Type": 4,
        "Size": 4,
        "Data": "AAAAAA==",
        "RegValue": "0",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "DisableReparsePointScanning-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#scan_disablereparsepointscanning",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            99
        ],
        "ID": "019a8dfa-253b-7e41-a892-8c5659f5487b"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Scan",
        "ValueName": "DisableScanningMappedNetworkDrivesForFullScan",
        "Type": 4,
        "Size": 4,
        "Data": "AAAAAA==",
        "RegValue": "0",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "DisableScanningMappedNetworkDrivesForFullScan-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-defender#allowfullscanonmappednetworkdrives",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            2,
            3,
            4,
            5
        ],
        "ID": "019a8dfa-253c-7583-a297-6afc4131fa78"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Scan",
        "ValueName": "DisableScanningNetworkFiles",
        "Type": 4,
        "Size": 4,
        "Data": "AAAAAA==",
        "RegValue": "0",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "DisableScanningNetworkFiles-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-defender#allowscanningnetworkfiles",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            2,
            3,
            4,
            5
        ],
        "ID": "019a8dfa-253c-7e57-a51a-f2c7f9729cb9"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Scan",
        "ValueName": "DisableEmailScanning",
        "Type": 4,
        "Size": 4,
        "Data": "AAAAAA==",
        "RegValue": "0",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "DisableEmailScanning-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-defender#allowemailscanning",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            99
        ],
        "ID": "019a8dfa-253c-787b-be5f-a715bda3cef1"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Scan",
        "ValueName": "DisableCatchupQuickScan",
        "Type": 4,
        "Size": 4,
        "Data": "AAAAAA==",
        "RegValue": "0",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "DisableCatchupQuickScan-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-defender#disablecatchupquickscan",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            99
        ],
        "ID": "019a8dfa-253c-7630-844a-6807e10f86bb"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Scan",
        "ValueName": "CheckForSignaturesBeforeRunningScan",
        "Type": 4,
        "Size": 4,
        "Data": "AQAAAA==",
        "RegValue": "1",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "CheckForSignaturesBeforeRunningScan-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-defender#checkforsignaturesbeforerunningscan",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            99
        ],
        "ID": "019a8dfa-253c-7e41-b315-7aea71c6927c"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Signature Updates",
        "ValueName": "SignatureUpdateInterval",
        "Type": 4,
        "Size": 4,
        "Data": "AwAAAA==",
        "RegValue": "3",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "SignatureUpdateInterval-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-defender#signatureupdateinterval",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            2,
            3,
            4,
            5
        ],
        "ID": "019a8dfa-253c-736b-a77d-f4fbad6dc3a2"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Signature Updates",
        "ValueName": "UpdateOnStartUp",
        "Type": 4,
        "Size": 4,
        "Data": "AQAAAA==",
        "RegValue": "1",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "UpdateOnStartUp-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#signatureupdate_updateonstartup",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            99
        ],
        "ID": "019a8dfa-253c-7567-8281-52ce16ee958d"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Signature Updates",
        "ValueName": "MeteredConnectionUpdates",
        "Type": 4,
        "Size": 4,
        "Data": "AQAAAA==",
        "RegValue": "1",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "MeteredConnectionUpdates-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/defender-csp#configurationmeteredconnectionupdates",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            2,
            3,
            4,
            5
        ],
        "ID": "019a8dfa-253d-7f17-be4d-f58ed4423e79"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Signature Updates",
        "ValueName": "ASSignatureDue",
        "Type": 4,
        "Size": 4,
        "Data": "AgAAAA==",
        "RegValue": "2",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "ASSignatureDue-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#signatureupdate_assignaturedue",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            99
        ],
        "ID": "019a8dfa-253d-76ad-9fc2-41115fe19ce2"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Signature Updates",
        "ValueName": "AVSignatureDue",
        "Type": 4,
        "Size": 4,
        "Data": "AgAAAA==",
        "RegValue": "2",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "AVSignatureDue-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#signatureupdate_avsignaturedue",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            99
        ],
        "ID": "019a8dfa-253d-7bb0-bf13-89f4fdec59bc"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Spynet",
        "ValueName": "DisableBlockAtFirstSeen",
        "Type": 4,
        "Size": 4,
        "Data": "AAAAAA==",
        "RegValue": "0",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "DisableBlockAtFirstSeen-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#disableblockatfirstseen",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            2,
            3,
            4,
            5
        ],
        "ID": "019a8dfa-253d-7c14-9a37-13004e5bdede"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Spynet",
        "ValueName": "SpynetReporting",
        "Type": 4,
        "Size": 4,
        "Data": "AgAAAA==",
        "RegValue": "2",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "SpynetReporting-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-defender#allowcloudprotection",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            99
        ],
        "ID": "019a8dfa-253d-7a0e-940d-0722abdc4567"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Spynet",
        "ValueName": "SubmitSamplesConsent",
        "Type": 4,
        "Size": 4,
        "Data": "AwAAAA==",
        "RegValue": "3",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "SubmitSamplesConsent-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-defender#submitsamplesconsent",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            99
        ],
        "ID": "019a8dfa-253d-7f1d-ac07-2a2afd4e4185"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Threats",
        "ValueName": "Threats_ThreatSeverityDefaultAction",
        "Type": 4,
        "Size": 4,
        "Data": "AQAAAA==",
        "RegValue": "1",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "Threats_ThreatSeverityDefaultAction-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-defender#threatseveritydefaultaction",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            99
        ],
        "ID": "019a8dfa-253d-71f4-bc7f-8ccf25a44996"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Threats\\ThreatSeverityDefaultAction",
        "ValueName": "1",
        "Type": 1,
        "Size": 4,
        "Data": "MgAAAA==",
        "RegValue": "2",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "1-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-defender#threatseveritydefaultaction",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            99
        ],
        "ID": "019a8dfa-253d-724c-a066-8cbbdb979586"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Threats\\ThreatSeverityDefaultAction",
        "ValueName": "2",
        "Type": 1,
        "Size": 4,
        "Data": "MgAAAA==",
        "RegValue": "2",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "2-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-defender#threatseveritydefaultaction",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            99
        ],
        "ID": "019a8dfa-253d-7db4-81ae-08868c64b5d7"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Threats\\ThreatSeverityDefaultAction",
        "ValueName": "4",
        "Type": 1,
        "Size": 4,
        "Data": "MwAAAA==",
        "RegValue": "3",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "4-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-defender#threatseveritydefaultaction",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            99
        ],
        "ID": "019a8dfa-253e-7abb-a823-147f7b686081"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Threats\\ThreatSeverityDefaultAction",
        "ValueName": "5",
        "Type": 1,
        "Size": 4,
        "Data": "MwAAAA==",
        "RegValue": "3",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "5-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-defender#threatseveritydefaultaction",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            99
        ],
        "ID": "019a8dfa-253e-77b5-b7ef-922b599f3ae2"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Windows Defender Exploit Guard\\Controlled Folder Access",
        "ValueName": "EnableControlledFolderAccess",
        "Type": 4,
        "Size": 4,
        "Data": "AQAAAA==",
        "RegValue": "1",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "EnableControlledFolderAccess-MSDefender",
        "URL": "https://learn.microsoft.com/defender-endpoint/enable-controlled-folders",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            2,
            3,
            4,
            5
        ],
        "ID": "019a8dfa-253e-747b-b326-0c9523a6ae37"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Windows Defender Exploit Guard\\Network Protection",
        "ValueName": "EnableNetworkProtection",
        "Type": 4,
        "Size": 4,
        "Data": "AQAAAA==",
        "RegValue": "1",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "EnableNetworkProtection-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-defender#enablenetworkprotection",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            99
        ],
        "ID": "019a8dfa-253e-7f03-bd1e-cd16590f1a2b"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Windows Defender Exploit Guard\\Network Protection",
        "ValueName": "AllowNetworkProtectionOnWinServer",
        "Type": 4,
        "Size": 4,
        "Data": "AQAAAA==",
        "RegValue": "1",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "AllowNetworkProtectionOnWinServer-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/defender-csp#configurationallownetworkprotectiononwinserver",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            2,
            3,
            4,
            5
        ],
        "ID": "019a8dfa-253e-70cb-a6bd-32abb093a820"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows\\DataCollection",
        "ValueName": "AllowTelemetry",
        "Type": 4,
        "Size": 4,
        "Data": "AwAAAA==",
        "RegValue": "3",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "AllowTelemetry-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-system#allowtelemetry",
        "Category": 2,
        "SubCategory": 2,
        "DefaultRegValue": null,
        "DeviceIntents": [
            2,
            3,
            4,
            5
        ],
        "ID": "019a8dfa-253e-764f-acd5-d26c2c0e3d6c"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows\\DataCollection",
        "ValueName": "DisableTelemetryOptInSettingsUx",
        "Type": 4,
        "Size": 4,
        "Data": "AQAAAA==",
        "RegValue": "1",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "DisableTelemetryOptInSettingsUx-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-system#configuretelemetryoptinsettingsux",
        "Category": 2,
        "SubCategory": 2,
        "DefaultRegValue": null,
        "DeviceIntents": [
            2,
            3,
            4,
            5
        ],
        "ID": "019a8dfa-253e-7bef-95cc-a7277deae4cd"
    },
    {
        "Source": 1,
        "KeyName": "SYSTEM\\CurrentControlSet\\Control\\CI\\Policy",
        "ValueName": "VerifiedAndReputablePolicyState",
        "Type": 4,
        "Size": 0,
        "Data": "",
        "RegValue": "1",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "SAC-MSDefender",
        "URL": "https://learn.microsoft.com/windows/apps/develop/smart-app-control/overview",
        "Category": 2,
        "SubCategory": 0,
        "DefaultRegValue": null,
        "DeviceIntents": [
            3,
            4,
            5
        ],
        "ID": "019a8dfa-253e-767c-b531-de109f3929d8"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Remediation\\Behavioral Network Blocks\\Brute Force Protection",
        "ValueName": "BruteForceProtectionMaxBlockTime",
        "Type": 4,
        "Size": 4,
        "Data": "/////w==",
        "RegValue": "4294967295",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "Remediation_BNB_BFP_BruteForceProtection_MaxBlockTime-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/defender-csp#configurationbehavioralnetworkblocksbruteforceprotectionbruteforceprotectionmaxblocktime",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            3,
            4,
            5
        ],
        "ID": "019a8dfa-253f-7bab-a801-a65d8f334260"
    },
    {
        "Source": 0,
        "KeyName": "Software\\Policies\\Microsoft\\Windows Defender\\Remediation\\Behavioral Network Blocks\\Remote Encryption Protection",
        "ValueName": "RemoteEncryptionProtectionMaxBlockTime",
        "Type": 4,
        "Size": 4,
        "Data": "/////w==",
        "RegValue": "4294967295",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "Remediation_BNB_BFP_RemoteEncryptionProtection_MaxBlockTime-MSDefender",
        "URL": "https://learn.microsoft.com/en-us/windows/client-management/mdm/defender-csp#configurationbehavioralnetworkblocksremoteencryptionprotectionremoteencryptionprotectionmaxblocktime",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            3,
            4,
            5
        ],
        "ID": "019ab6f0-79fa-7f0c-891b-84d4db119bf6"
    },
    {
        "Source": 0,
        "KeyName": "software\\policies\\microsoft\\Windows Defender",
        "ValueName": "PUAProtection",
        "Type": 4,
        "Size": 4,
        "Data": "AQAAAA==",
        "RegValue": "1",
        "Hive": 0,
        "PolicyAction": 0,
        "FriendlyName": "Root_PUAProtection-MSDefender",
        "URL": "https://learn.microsoft.com/windows/client-management/mdm/policy-csp-defender#puaprotection",
        "Category": 2,
        "SubCategory": null,
        "DefaultRegValue": null,
        "DeviceIntents": [
            2,
            3,
            4,
            5
        ],
        "ID": "019ab74b-7b27-7594-a31b-66b2d5157929"
    }
]