Microsoft releases Tamper Protection for Windows Defender

The new feature 'locks down' the antivirus, preventing malware from making changes to core settings

Microsoft's Tamper Protection feature for Windows Defender is now generally available for enterprise and consumers after a pre-release in May 2019's Windows 1903.

The feature aims to prevent malware from altering the settings in Windows Defender that could make a system more vulnerable to attacks, such as disabling behaviour monitoring.

Advertisement - Article continues below

It will also prevent malware from disabling virus and threat protection, cloud-delivered protection, real-time protection and prevent the removal of security intelligence updates.

Traditionally, these kinds of actions could be completed through methods such as registry editing, PowerShell commands, and through group policies.

Microsoft said that a lack of visibility when it comes to tampering attempts can make it difficult to spot and mitigate threats, so an automatic way of securing against harmful methods will further protect Microsoft Defender ATP customers.

Tamper Protection will be enabled by default for Windows Home users, and the rollout will be delivered in stages.

Enterprise system administrators must use Microsoft Intune to enable it across an organisation's computer suite. The company says this is done for security reasons - no other method of changing Defender such as group policy or registry key can be used.

"When an administrator enables the policy in Microsoft Intune, the tamper protection policy is digitally signed in the backend before it's sent to endpoints," said Microsoft. "The endpoint verifies the validity and intent, establishing that it is a signed package that only security operations personnel with Microsoft Intune admin rights can control.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

"With the right level of reporting, security operations teams are empowered to detect any irregularities."

When something malicious attempts to change the settings in Windows Defender, a threat alert will be sent to enterprise customers' Microsoft Defender ATP security centre for further analysis.

"Tamper protection is a critical feature for us as we need to defend Microsoft Defender ATP to ensure that malicious actions are not going around our security platforms," said Rich Lilly, partner/associate director at Netrixllc.

"While complex behind the scenes, Microsoft has made it extremely easy for us to configure and deploy through Microsoft Intune and allow our SecOps team visibility into any potential tampering events so we can further investigate and remediate."

Featured Resources

Successful digital transformations are future ready - now

Research findings identify key ingredients to complete your transformation journey

Download now

Cyber security for accountants

3 ways to protect yourself and your clients online

Download now

The future of database administrators in the era of the autonomous database

Autonomous databases are here. So who needs database administrators anymore?

Download now

The IT expert’s guide to AI and content management

Your guide to the biggest opportunities for IT teams when it comes to AI and content management

Download now
Advertisement

Recommended

Visit/security/cyber-security/355267/zoom-hires-ex-facebook-cso-to-boost-platform-security
cyber security

Zoom hires ex-Facebook CSO Alex Stamos to boost platform security

8 Apr 2020
Visit/security/vulnerability/355236/hp-support-assistant-flaws-leave-windows-devices-open-to-attack
vulnerability

HP Support Assistant flaws leave Windows devices open to attack

6 Apr 2020
Visit/security/cyber-security/355234/safari-bug-let-hackers-access-cameras-on-iphones-and-macs
cyber security

Safari bug let hackers access cameras on iPhones and Macs

6 Apr 2020
Visit/software/video-conferencing/355229/zoom-we-moved-too-fast
video conferencing

Zoom CEO admits company "moved too fast" as privacy issues mount

6 Apr 2020

Most Popular

Visit/mobile/mobile-phones/355239/microsofts-patent-design-reveals-a-mobile-device-with-a-third-screen
Mobile Phones

Microsoft patents a mobile device with a third screen

6 Apr 2020
Visit/server-storage/servers/355254/a-critical-flaw-in-350000-microsoft-exchange-remains-unpatched
servers

A critical flaw in 350,000 Microsoft Exchange remains unpatched

7 Apr 2020
Visit/software/video-conferencing/355257/taiwan-first-country-to-ban-zoom-amid-security-concerns
video conferencing

Taiwan becomes first country to ban Zoom amid security concerns

8 Apr 2020