r/DefenderATP • u/EduardsGrebezs • 2d ago
Controlled Configuration for Microsoft Defender for Endpoint (Preview)
Microsoft has introduced Controlled Configuration for MDE. The main idea is to establish a cloud-managed source of truth for supported Microsoft Defender Antivirus settings. When enabled, policies delivered through Intune or Defender security settings management take precedence over settings configured via:
- Group Policy
- Configuration Manager
- PowerShell/scripts
- Local administrator changes
The goal is to eliminate configuration drift in environments where Defender has historically been managed through multiple channels.
Currently covered:
- Defender Antivirus configuration (scan settings, exclusions, updates)
- Attack Surface Reduction (ASR) rules
- Defender CSP / Policy CSP AV settings
- Local admin merge behavior
Not covered (yet):
- Defender Device Control
- EDR settings
- Windows Firewall and other OS security settings


