If you have deployed Windows 10 Anniversary 1607 and are using Windows Defender you should be very interested in the new BLOCK ON FIRST SIGHT feature. When a user runs a program that Defender has never seen before, BLOCK ON FIRST SIGHT, sends a metadata about
This process typically takes just 1 to 4 seconds and only occurs the first time a user runs a new program so they are unlikely to notice the delay.
This is a great way to keep your company safe and if you are using System Center Endpoint Protection (= corporate version of Defender) you can easily enable this feature.
You need to have both CLOUD BASED PROTECTION and AUTOMATIC SAMPLE SUBMISSION turned on. This can be done in current versions of SCEP (i.e. build 1511 or newer) or through a GPO:
You can manually set it up on a single PC by:
For more details see:
https://technet.microsoft.com/en-us/itpro/windows/keep-secure/windows-defender-block-at-first-sight
NOTE: this article implies that SCCM is not supported but I have confirmed that it is . If you are a Microsoft Partner you can read my thread HERE.
This website uses cookies.