Enable or Disable Microsoft Defender Antivirus Block at First Sight  

Page 1 of 2 12 LastLast
    Enable or Disable Microsoft Defender Antivirus Block at First Sight

    Enable or Disable Microsoft Defender Antivirus Block at First Sight

    How to Enable or Disable Microsoft Defender Antivirus Block at First Sight in Windows 10
    Published by Category: Security System
    01 Nov 2022
    Designer Media Ltd

    How to Enable or Disable Microsoft Defender Antivirus Block at First Sight in Windows 10


    Microsoft Defender Antivirus helps protect your PC against malware (malicious software) like viruses, spyware, and other potentially unwanted software. Malware can infect your PC without your knowledge: it might install itself from an email message, when you connect to the Internet, or when you install certain apps using a USB flash drive, CD, DVD, or other removable media. Some malware can also be programmed to run at unexpected times, not only when it's installed.

    Block at First Sight is a feature of Microsoft Defender Antivirus cloud protection starting with Windows 10 Anniversary Update (version 1607) that provides a way to detect and block new malware within seconds. Block at First Sight requires a number of Group Policy settings to be configured correctly or it will not work.

    See also: Use next-gen technologies in Windows Defender Antivirus through cloud-delivered protection | Microsoft Docs

    How Block at First Sight works

    When a Microsoft Defender Antivirus client encounters a suspicious but undetected file, it queries our cloud protection backend. The cloud backend will apply heuristics, machine learning, and automated analysis of the file to determine the files as malicious or clean.

    If the cloud backend is unable to make a determination, the file will be locked by Microsoft Defender Antivirus while a copy is uploaded to the cloud. Only after the cloud has received the file will Microsoft Defender Antivirus release the lock and let the file run. The cloud will perform additional analysis to reach a determination, blocking all future encounters of that file.

    In many cases this process can reduce the response time to new malware from hours to seconds.

    Suspicious file downloads requiring additional backend processing to reach a determination will be locked by Microsoft Defender Antivirus on the first machine where the file is encountered, until it is finished uploading to the backend. Users will see a longer "Running security scan" message in the browser while the file is being uploaded. This might result in what appear to be slower download times for some files.

    This tutorial will show you how to enable or disable the Block at First Sight cloud protection feature in Microsoft Defender Antivirus for all users in Windows 10.

    You must be signed in as an administrator to be able to enable or disable Block at First Sight.



    Contents

    • Option One: To Turn On or Off Microsoft Defender Antivirus Block at First Sight in Settings
    • Option Two: To Enable Microsoft Defender Antivirus Block at First Sight in Group Policy
    • Option Three: To Disable Microsoft Defender Antivirus Block at First Sight in Group Policy
    • Option Four: To Enable or Disable Microsoft Defender Antivirus Block at First Sight using a REG file






    OPTION ONE

    To Turn On or Off Microsoft Defender Antivirus Block at First Sight in Settings


    You can confirm that Block at First Sight is enabled in Windows Settings. The feature is automatically enabled, as long as Cloud-based protection and Automatic sample submission are both turned on.

    If you enabled Block at First Site using Option Two or Option Four below, then the settings in this option will be grayed out.


    1 Open Windows Security, and click/tap on the Virus & threat protection icon. (see screenshot below)

    Enable or Disable Microsoft Defender Antivirus Block at First Sight-windows_dedender_block_at_first_sight-1.jpg

    2 Click/tap on the Manage settings link under Virus & threat protection settings. (see screenshot below)

    Enable or Disable Microsoft Defender Antivirus Block at First Sight-windows_dedender_block_at_first_sight-2.jpg

    3 Do step 4 (on) or step 5 (off) below for what you want to do.


     4. To Turn On Block at First Sight Cloud Protection in Microsoft Defender Antivirus

    This is the default setting.

    A) Turn on Real-time protection. (see screenshot below)

    B) Turn on Cloud-delivered protection.

    C) Turn on Automatic sample submission, and go to step 6 below.


     5. To Turn Off Block at First Sight Cloud Protection in Microsoft Defender Antivirus

    A) Turn off Cloud-delivered protection. (see screenshot below)

    B) Turn off Automatic sample submission, and go to step 6 below.


    6 When finished, you can close Windows Security if you like.

    Enable or Disable Microsoft Defender Antivirus Block at First Sight-windows_dedender_block_at_first_sight-3.jpg






    OPTION TWO

    To Enable Microsoft Defender Antivirus Block at First Sight in Group Policy


    This option will override Option One.

    Local Group Policy Editor is only available in the Windows 10 Pro, Enterprise, and Education editions.

    All editions can use Option Four below to enable Block at First Sight using a .reg file instead.


    1 Open the Local Group Policy Editor.

    2 Navigate to the location below in the left pane of Local Group Policy Editor. (see screenshot below)

    Computer Configuration/Administrative Templates/Windows Components/Microsoft Defender Antivirus/MAPS

    Enable or Disable Microsoft Defender Antivirus Block at First Sight-configure_block_at_first_site_gpedit-1.jpg

    3 In the right pane of MAPS in Local Group Policy Editor, double click/tap on the Configure the ‘Block at First Sight’ feature policy to edit it. (see screenshot above)

    A) Select (dot) Enabled, and click/tap on OK. (see screenshot below)

    Enable or Disable Microsoft Defender Antivirus Block at First Sight-configure_block_at_first_site_gpedit-2.jpg

    4 In the right pane of MAPS in Local Group Policy Editor, double click/tap on the Join Microsoft MAPS policy to edit it. (see screenshot below)

    Enable or Disable Microsoft Defender Antivirus Block at First Sight-join_microsoft_maps_gpedit-1.jpg

    A) Select (dot) Enabled. (see screenshot below)

    B) Select Advanced MAPS under Options, and click/tap on OK.

    Advanced MAPS membership, in addition to basic information, will send more information to Microsoft about malicious software, spyware, and potentially unwanted software, including the location of the software, file names, how the software operates, and how it has impacted your computer.

    Enable or Disable Microsoft Defender Antivirus Block at First Sight-join_microsoft_maps_gpedit-2.jpg

    5 In the right pane of MAPS in Local Group Policy Editor, double click/tap on the Send file samples when further analysis is required policy to edit it. (see screenshot below)

    Enable or Disable Microsoft Defender Antivirus Block at First Sight-send_file_samples_gpedit-1.jpg

    A) Select (dot) Enabled. (see screenshot below)

    B) Select Send safe samples or Send all samples under Options for what you want, and click/tap on OK.

    Enable or Disable Microsoft Defender Antivirus Block at First Sight-send_file_samples_gpedit-2.jpg

    6 Navigate to the location below in the left pane of Local Group Policy Editor. (see screenshot below)

    Computer Configuration/Administrative Templates/Windows Components/Microsoft Defender Antivirus/Real-time Protection

    Enable or Disable Microsoft Defender Antivirus Block at First Sight-real-time_protection_gpedit-1.png

    7 In the right pane of Real-time Protection in Local Group Policy Editor, double click/tap on the Turn off real-time protection policy to edit it. (see screenshot above)

    A) Select (dot) Disabled, and click/tap on OK. (see screenshot below)

    Enable or Disable Microsoft Defender Antivirus Block at First Sight-real-time_protection_gpedit-2.png

    8 In the right pane of Real-time Protection in Local Group Policy Editor, double click/tap on the Scan all downloaded files and attachments policy to edit it. (see screenshot below)

    Enable or Disable Microsoft Defender Antivirus Block at First Sight-scan_all_gpedit-1.jpg

    A) Select (dot) Enabled, and click/tap on OK. (see screenshot below)

    Enable or Disable Microsoft Defender Antivirus Block at First Sight-scan_all_gpedit-2.jpg

    9 When finished, you can close the Local Group Policy Editor if you like.





    OPTION THREE

    To Disable Microsoft Defender Antivirus Block at First Sight in Group Policy


    You may choose to disable the Block at First Sight feature if you want to retain the pre-requisite settings without using Block at First Sight protection. You might wish to do this if you are experiencing latency issues or you want to test the feature's impact on your network.

    Local Group Policy Editor is only available in the Windows 10 Pro, Enterprise, and Education editions.

    All editions can use Option Four below to disable Block at First Sight using a .reg file instead.


    1 Open the Local Group Policy Editor.

    2 Navigate to the location below in the left pane of Local Group Policy Editor. (see screenshot below)

    Computer Configuration/Administrative Templates/Windows Components/Microsoft Defender Antivirus/MAPS

    Enable or Disable Microsoft Defender Antivirus Block at First Sight-configure_block_at_first_site_gpedit-1.jpg

    3 In the right pane of MAPS in Local Group Policy Editor, double click/tap on the Configure the ‘Block at First Sight’ feature policy to edit it. (see screenshot above)

    4 Select (dot) Disabled, and click/tap on OK. (see screenshot below)

    Enable or Disable Microsoft Defender Antivirus Block at First Sight-configure_block_at_first_site_gpedit-2.jpg

    5 When finished, you can close the Local Group Policy Editor if you like.





    OPTION FOUR

    To Enable or Disable Microsoft Defender Antivirus Block at First Sight using a REG file


    The downloadable .reg files below will add and modify the DWORD values in the registry keys.

    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection

    DisableIOAVProtection DWORD

    (delete) = Default Not Configured
    0 = Enable

    DisableRealtimeMonitoring DWORD

    (delete) = Default Not Configured
    0 = Enable

    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet

    DisableBlockAtFirstSeen DWORD

    (delete) = Default Not Configured
    1 = Disable
    0 = Enable

    SpynetReporting DWORD

    (delete) = Default Not Configured
    2 = Advanced MAPS

    SubmitSamplesConsent DWORD

    (delete) = Default Not Configured
    1 = Send safe samples
    3 = Send all samples


    1 Do step 2 (enable with "Send safe samples"), step 3 (enable with "Send all sample"), step 4 (disable), or step 5 (default Not Configured) below for what you would like to do.


     2. To Enable Block at First Sight with "Send safe samples"

    A) Click/tap on the Download button below to download the file below, and go to step 6 below.

    EnableBlockAtFirstSight_AdvancedMAPS_SendSafeSamples.reg

    Download

     3. To Enable Block at First Sight with "Send all samples"

    A) Click/tap on the Download button below to download the file below, and go to step 6 below.

    EnableBlockAtFirstSight_AdvancedMAPS_SendAllSamples.reg

    Download

     4. To Disable Block at First Sight

    A) Click/tap on the Download button below to download the file below, and go to step 6 below.

    Disable_BlockAtFirstSight.reg

    Download

     5. To Set Block at First Sight to Default "Not Configured"


    This is the default setting to set all Block at First Sight group polices back to "Not Configured".

    This will have the settings in Option One above to no longer be grayed out.

    A) Click/tap on the Download button below to download the file below, and go to step 6 below.

    Default_NotConfigured_BlockAtFirstSight.reg

    Download


    6 Save the .reg file to your desktop.

    7 Double click/tap on the downloaded .reg file to merge it.

    8 When prompted, click/tap on Run, Yes (UAC), Yes, and OK to approve the merge.

    9 If you like, you can now delete the downloaded .reg file.


    That's it,
    Shawn Brink






  1. Posts : 27,181
    Win11 Pro, Win10 Pro N, Win10 Home, Windows 8.1 Pro, Ubuntu
       #1

    Until I saw your gray out screenshot, I hadn't realized mine was, nice thing about Defender--set & forget:):
    Enable or Disable Microsoft Defender Antivirus Block at First Sight-image.png

    Of course I had used the GPEdit version when I found out about it, as it makes it harder for anyone(and any, hopefully, malware) to change.
      My Computers


  2. Posts : 26
    Windows 10 1803 & Win10 Insider
       #2

    Just a heads-up but the new guide from Microsoft (the same page that you link to) now also says to set File Blocking Level to High (or High+), and to increase the time it waits for the cloud analysis to complete (detonation, etc.)

    So probably the registry items that GPedit.msc sets have also changed. Maybe update the .reg file ?

    - - - Updated - - -

    For reference, after following the guide, but setting the level to blocking level to High+ (user cannot allow a harmful operation).

    Code:
    Windows Registry Editor Version 5.00
    
    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender]
    
    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\MpEngine]
    "MpBafsExtendedTimeout"=dword:00000032
    "MpCloudBlockLevel"=dword:00000004
    
    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Policy Manager]
    
    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection]
    "DisableIOAVProtection"=dword:00000000
    "DisableRealtimeMonitoring"=dword:00000000
    
    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet]
    "SubmitSamplesConsent"=dword:00000003
    "SpynetReporting"=dword:00000002
    "DisableBlockAtFirstSeen"=dword:00000000
      My Computer


  3. Posts : 68,886
    64-bit Windows 11 Pro for Workstations
    Thread Starter
       #3

    Hello @Henk Poley,

    Thank you for the addition.

    Changing the Select cloud protection level policy below is optional. If you don't want to use the default Windows Defender Antivirus blocking level, then you could change this policy to increase the blocking level. However, increasing the blocking level will also increase the chance of false positives, and as you mentioned "High +" and "Zero tolerence" will not let users to allow a blocked item.

    Enable or Disable Microsoft Defender Antivirus Block at First Sight-select_cloud_protection_level-1.jpg

    Enable or Disable Microsoft Defender Antivirus Block at First Sight-select_cloud_protection_level-2.png
      My Computers


  4. Posts : 4
    w10
       #4

    Hi.. so one of my programs was blocked by capture on first sight. I was a program that I am writing.. Now I cannot run it. I turned off the cloud based and automatic sample options.. still won't run. Where is the option to enable my file again?

    Thanks.
      My Computer


  5. Posts : 68,886
    64-bit Windows 11 Pro for Workstations
    Thread Starter
       #5

    Hello @rgalka, and welcome to Ten Forums.

    You might see if adding the file as an exclusion for Windows Defender Antivirus may allow it to run.

    Add or Remove Windows Defender Exclusions in Windows 10
      My Computers


  6. Posts : 4
    w10
       #6

    Hi.. thanks for replying...

    So I added program to exception list... blocked form outgoing firewall, renamed the program.. installed in another location.. each thing one at a time.. program still won't run...

    I know It was blocked by capture on first sight because it took me to the block on first sight web page.. but only once.

    It seems to be something more than just the file name since renaming it got the same result.. nothing.. not running in task manager...
      My Computer


  7. Posts : 68,886
    64-bit Windows 11 Pro for Workstations
    Thread Starter
       #7

    You might also check your protection history to see if it may be listed there, and either clear filters or check blocked actions to hopefully remove it as blocked.

    View Protection History of Windows Defender Antivirus in Windows 10
      My Computers


  8. Posts : 4
    w10
       #8

    No nothing there for today. But thanks.
    I get the capture thing for the cloud based security, but seems we are missing a released option for a false capture.
      My Computer


  9. Posts : 68,886
    64-bit Windows 11 Pro for Workstations
    Thread Starter
       #9

    That's what I can't find either. Nothing for an easy unblock option.
      My Computers


 

Tutorial Categories

Enable or Disable Microsoft Defender Antivirus Block at First Sight Tutorial Index Network & Sharing Instalation and Upgrade Browsers and Email General Tips Gaming Customization Apps and Features Virtualization BSOD System Security User Accounts Hardware and Drivers Updates and Activation Backup and Restore Performance and Maintenance Mixed Reality Phone


  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 10:16.
Find Us




Windows 10 Forums