U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.


Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Microsoft Windows Defender Antivirus STIG Ver 2, Rel 4 Checklist Details (Checklist Revisions)

SCAP 1.2 Content:

Supporting Resources:


Target CPE Name
Microsoft Windows Defender cpe:/a:microsoft:windows_defender (View CVEs)

Checklist Highlights

Checklist Name:
Microsoft Windows Defender Antivirus STIG
Checklist ID:
Ver 2, Rel 4
Review Status:
Governmental Authority: Defense Information Systems Agency
Original Publication Date:

Checklist Summary:

The Microsoft Windows Defender Antivirus Security Technical Implementation Guide (STIG) provides the technical security policies, requirements, and implementation details for applying security concepts to the Defender Antivirus application. This document is meant to improve the security of Department of Defense (DoD) information systems.

Checklist Role:

  • Antivirus Software

Known Issues:

Not provided.

Target Audience:

Not provided.

Target Operational Environment:

  • Managed
  • Specialized Security-Limited Functionality (SSLF)

Testing Information:

Not provided.

Regulatory Compliance:

This document is provided under the authority of DoDI 8500.01.


Not provided.


Not provided.

Product Support:

Parties within the DoD and Federal Government's computing environments can obtain the applicable STIG from the Information Assurance Support Environment (IASE) website. This site contains the latest copies of any STIGs, SRGs, and other related security information. The address for the IASE site is http://iase.disa.mil/.

Point of Contact:

All technical NIST SP 800-53 requirements were considered while developing these STIGs. Requirements that are applicable and configurable will be included in the final STIG. A report marked For Official Use Only (FOUO) will be available for those items that did not meet requirements. This report will be available to component Authorizing Official (AO) personnel for risk assessment purposes by request via email to: disa.stig_spt@mail.mil.


Not provided.


Not provided.

Change History:

Updated to FINAL - 8/18/2017
Updated to v1, r2 - 11/20/2017
Updated to FINAL - 12/20/2017
updated to v1,r3 - 02/16/2018
Updated to FINAL - 3/18/2018
updated to v1,r4 - 4/25/18
Updated to FINAL - 5/27/18
Added GPOs - 8/6/18
Updated to FINAL - 9/6/2018
Updated GPO Resource - 11/29/2018
Corrected SHA for GPO file - 12/19/2018
updated to v1, r5 - 4/30/19
Updated GPO resource - 5/2/19
Updated to FINAL  - 6/4/19
Updated URLs - 6/12/19
Updated URLs - 8/12/2019
Updated GPO file - 10/31/19
updated URLs - 11/1/19
updated to V1, R7 - removed reference link per DISA - 1/17/2020
Updated GPO file per DISA - 1/29/2020
Updated GPO file per DISA - 2/3/2020
updated GPO file - 3/6/2020
updated resource title per DISA - 3/12/2020
Updated URLs per DISA - 4/24/2020
updated URLs per DISA - 6/8/2020
Updated GPO file per DISA - 7/7/2020
Updated GPO file per DISA - 8/5/2020
updated GPO file - 10/29/2020
updated URLs and GPO file - 12/3/2020
Updated GPO per DISA - 1/28/21
Updated GPO per DISA - 3/1/21
added SCC links per DISA guidance - 4/20/2021
Updated resource per DISA - 5/5/21
Updated GPO per DISA - 5/12/21
Updated resources per DISA - 5/25/21
Updated GPO - 8/9/21
Updated GPO per DISA - 8/24/21
updated SCC tool per DISA - 9/16/2021
updated GPO files - 11/22/2021
Updated resources per DISA - 11/24/21
Updated GPO per DISA - 2/17/22
Updated GPO per DISA - 5/3/22
Updated resource per DISA - 5/26/22
Updated resources per DISA - 5/29/22
Updated SCC per DISA - 6/14/22
Updated GPO per DISA - 8/1/22


URL Description


Reference URL Description

NIST checklist record last modified on 08/06/2022