Windows 11 includes Microsoft Defender Antivirus, which operates in the background and receives automatic updates. Its default settings focus on compatibility rather than maximum security, prompting the need for configuration to enhance protection.
Prerequisites for configuration include:
- Windows 11 version 24H2 or 25H2
- Fully patched build number (26100.9457 or newer)
- Local administrator account for certain steps
- Microsoft Defender Antivirus version 4.18.x
- Windows PowerShell 5.1 run as Administrator
- Stable internet connection
- No active third-party antivirus software
Steps to enhance Microsoft Defender include:
1. Confirming the current Windows 11 build.
2. Verifying that Defender is the active antivirus using PowerShell.
3. Enabling cloud-delivered protection and automatic sample submission via PowerShell commands.
4. Activating Tamper Protection through Windows Security.
5. Enabling Controlled Folder Access to protect against ransomware.
6. Deploying Attack Surface Reduction rules in audit mode.
7. Turning on Smart App Control.
8. Enabling Core Isolation and Memory Integrity.
9. Scheduling weekly full and offline scans.
10. Creating narrow exclusions for known safe applications.
11. Enhancing network protection and SmartScreen features.
12. Running a PowerShell verification script to audit settings.
These steps aim to optimize Microsoft Defender Antivirus for improved security comparable to premium solutions.