Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form
Home » Windows » How to manage Microsoft Defender Antivirus using Group Policy and Command Line Utility
  • 33
    The wim file needs to be remounted: Fix error 0xc1510114 Windows Server
  • Always on and Veeam plugin setup
    Install SQL Server Always On & Configure Veeam Plug‑in for SQL Backup
  • WSUS Analysis and Initial Assessment
    Preliminary Guide for WSUS Analysis and Initial Assessment Windows Server
  • screenshot 2020 02 09 at 17.11.11
    How to uninstall a program via command prompt in Windows Windows
  • screenshot 2020 03 13 at 21.22.29
    How to determine Cygwin version Windows Server
  • drivelock 1280x720 1
    The server could not be reached or validated: Timeout expired. The Time out expired prior to obtaining a connection from the pool Security | Vulnerability Scans and Assessment
  • how to fix the sorry this file type is not permitted for security reasons error in wordpress 5e4a5632967c7
    Error 1707: Network address invalid when trying to connect remotely Windows
  • create a Lenovo USB Recovery key
    Windows 10 Yoga Recovery: Download the files needed to create a Lenovo USB Recovery key Windows

How to manage Microsoft Defender Antivirus using Group Policy and Command Line Utility

Posted on 18/05/202212/12/2023 Imoh Etuk By Imoh Etuk No Comments on How to manage Microsoft Defender Antivirus using Group Policy and Command Line Utility
Slide1-1

In this article, we shall discuss how to manage Microsoft Defender Antivirus using Group Policy and CMD (Commandline). Microsoft Defender Antivirus (previously Windows Defender Antivirus) is a component of the Windows Security experience, and it offers real-time protection against viruses, ransomware, spyware, rootkits, and a variety of other malware and hackers. Please see How to remove Microsoft Defender update on Windows 10 and Windows Server image.

It’s also one of the top antivirus software recommendations. Although the Windows Security app makes daily antivirus tasks simple, you can also operate the anti-malware solution via PowerShell commands, which can be useful in a variety of situations.

When you want to change a feature that isn’t available through the graphical user interface (GUI), such as scheduling a quick or full scan or a signature update, for example. To automate some Microsoft Defender Antivirus functions, you’ll need to write scripts.

Alternatively, utilizing commands rather than a GUI might speed up the configuration process, especially if you need to apply the same settings to many Windows PCs at the same time.

In this post, you will learn how to manage Microsoft Defender Antivirus in your business with Group Policy and Microsoft Malware Protection Command Line Utility (mpcmdrun.exe).

Here are some related guides: How to update Microsoft Defender Antivirus into the install image of Windows,  and how to schedule Windows Defender Antivirus to scan on-demand in Windows.

What is Group Policy?

Group Policy is a Windows feature that allows network administrators to regulate the working environment of users and computer accounts in Active Directory through a number of complex settings.

It essentially gives administrators a consolidated location to manage and modify operating systems, programs, and user preferences. Group Policy is essentially a security tool that enables applying security settings to users and computers.

Also, see Windows Defender Antivirus Management with Intune, and Install.wim: How to view Microsoft Defender Antivirus update details on Windows 10 image.

What is the MpCmdRun.exe command?

mpcmdrun.exe is an important part of Microsoft’s Windows Security system that helps protect your PC from online threats and malware. You can also use this utility if you’d like to automate Microsoft Security Antivirus. You must run the .exe from the Windows command prompt.

Learn more about Microsoft Defender and Windows 11 encryption features in these related posts how to remove Microsoft Defender update on Windows 10 and Windows Server image, how to view Microsoft Defender Antivirus update details on Windows 10 image (install.wim), and new Windows 11 encryption features and security enhancements will help protect hybrid work.

Managing Microsoft Defender Antivirus using Group Policy

You can configure and manage Microsoft Defender Antivirus on your endpoints using Group Policy. In practice, you can configure or alter Microsoft Defender Antivirus group policy settings by following the steps below:

From the Start Menu, search for and click on "Edit Group Policy". Alternatively, press the Windows key + R to open the Run dialog box and type "gpedit.msc" to open the Group Policy Management Console.

On local Windows 10 /11 that’s not a Windows Server, you find it as the “Local Group Policy Editor”. It is named Local Group Policy Editor because your Windows 10 or 11 PC is a Server.

Windows Defender Antivirus
Open the Run command

On the Group Policy Management Console or Local Group Policy, click on  Computer Configuration->Administrative Templates.

Windows Malware Protection
Editing the Local Group Policy

Expand the tree to Windows components > Microsoft Defender Antivirus.

Windows-Config-Microsoft-Defender-Antivirus
Open Windows Config->Microsoft Defender Antivirus

Select the area containing the setting you wish to alter, then double-click the setting to open it and make changes.

Windows Security Antivirus
Configure Settings

Enable an option under the “Client Interface”

Here, we are going to enable an option under the “Client Interface,” introducing the ability to display additional text to clients when they need to act. Additionally, the option allows you to suppress all notifications, suppress reboot notifications, and enable headless UI mode.”

Windows Malware Protection
Client Interface

The display of additional text to clients when they need to perform an action policy if enabled as stated in the flyout dialog box of the policy will allow you to configure whether or not to display additional text to clients when they need to act. The text displayed is a custom administrator-defined string.

For example, the phone number to call the company help desk. The client interface will only display a maximum of 1024 characters. Longer strings will be truncated before display.

To enable the display of additional text to clients when they need to perform an action policy, you can follow these steps:

Double-click on it to open, and click on "Enabled" type the text you will like to display to clients in the options column. Click Apply and Okay.

Display-text-to-clients
Text to display to clients

This policy supports at least Windows Server 2012, Windows 8 or Windows RT down to Windows 10 and 11.

After that, the status for display additional text to clients when they need to perform an action will become enabled.

State-is-Enabled
Status is Enabled

Managing Microsoft Defender Antivirus using Microsoft Malware Protection Command Line Utility (MpCmdRun.exe)

The Microsoft Malware Protection Command Line Utility is “MpCmdRun.exe.” It allows command-line, parameter-controlled execution of the computer’s native Microsoft antimalware program with administrator credentials (Windows Defender, Microsoft Security Client, or Microsoft Security Essentials)

You can use the specific command-line utility mpcmdrun.exe to perform numerous functions in Microsoft Defender Antivirus. When you wish to automate Microsoft Defender Antivirus tasks, this utility comes in handy. The program can be found in the folder %ProgramFiles%\Windows Defender\MpCmdRun.exe. Use a command prompt to run it.

To run the command, launch the command prompt as an administrator and then enter MpCmdRun.exe command and press enter. You can run directly from the C:\Program Files\Windows Defender directory.

Launch-the-cmd-from-the-location
Run the MpCmd command from the Location

If you’re running an updated Microsoft Defender Antivirus platform version, run MpCmdRun from the following location: C:\ProgramData\Microsoft\Windows Defender\Platform\<antimalware platform version>.

Run-from-platform
Run the MpCmdRun from the Platform

The MpCmdRun utility uses the following syntax:

MpCmdRun.exe [command] [-options]

For example, we use ScanType 1 to carry out a quick scan as shown below.

MpCmdRun.exe -Scan -ScanType 1
Scan-started
Starting ScanType 1
Scans for malicious software. Values for ScanType are:
 0 Default, according to your configuration. 1 Quick scan, 2 Full scan, 3 File and directory custom scan.

The scan is now completed

Scan-finished
Scan Completed

You will also be notified via the notification area of your PC window

Scan-completed-Notifications
Scan Completed Desktop Notifications

When clicked on the notifications, you will be directed to some recommended action to take to further strengthen the security of the PC.

Recommendations
Security Recommendations

As shown above, the SmartScreen for Microsoft Edge is turned off on my PC and I’m giving the action to take which is to turn it on.

I hope you found this blog post on how to manage Microsoft Defender Antivirus using Group Policy and CMD (Commandline) helpful. If you have any questions, please let me know in the comment section.

Rate this post

Thank you for reading this post. Kindly share it with others.

  • Click to share on X (Opens in new window) X
  • Click to share on Reddit (Opens in new window) Reddit
  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on Pinterest (Opens in new window) Pinterest
  • Click to share on Tumblr (Opens in new window) Tumblr
  • Click to share on Telegram (Opens in new window) Telegram
  • Click to share on WhatsApp (Opens in new window) WhatsApp
  • Click to share on Pocket (Opens in new window) Pocket
  • Click to share on Mastodon (Opens in new window) Mastodon
  • Click to share on Bluesky (Opens in new window) Bluesky
  • Click to share on Threads (Opens in new window) Threads
  • Click to share on Nextdoor (Opens in new window) Nextdoor
Anti-Virus Solution, Windows, Windows Server Tags:Microsoft Defender Antivirus, Microsoft Windows, Windows 11, Windows Server 2016

Post navigation

Previous Post: Fix the request to add or remove features on the specified server failed
Next Post: How to fix The Group Policy settings for BitLocker startup options are in conflict and cannot be applied

Related Posts

  • Install and configure wds 1
    Install Windows Deployment Services on Windows Server 2022 Windows Server
  • Featured Image
    Remote WMI Connection: How to enable or disable WMI Traffic Using Firewall UI Windows
  • How to Decrypt Files and Folders Encrypted with EFS in Windows 10
    How to decrypt Files and Folders Encrypted with an Encryption File System (EFS) in Windows Windows
  • windows 10 technical preview windows 10 logo microsoft 97543 1920x1080
    How to Remove the All Apps Option from Windows Start Menu via GPO /Registry Windows
  • Featured image new
    How to find out who restarted Windows Server Windows
  • Install Lets Encrypt Certificate on Windows with Certbot
    Install Lets Encrypt Certificate on Windows with Certbot Web Server

More Related Articles

Install and configure wds 1 Install Windows Deployment Services on Windows Server 2022 Windows Server
Featured Image Remote WMI Connection: How to enable or disable WMI Traffic Using Firewall UI Windows
How to Decrypt Files and Folders Encrypted with EFS in Windows 10 How to decrypt Files and Folders Encrypted with an Encryption File System (EFS) in Windows Windows
windows 10 technical preview windows 10 logo microsoft 97543 1920x1080 How to Remove the All Apps Option from Windows Start Menu via GPO /Registry Windows
Featured image new How to find out who restarted Windows Server Windows
Install Lets Encrypt Certificate on Windows with Certbot Install Lets Encrypt Certificate on Windows with Certbot Web Server

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

sysadmin top30a

  • 33
    The wim file needs to be remounted: Fix error 0xc1510114 Windows Server
  • Always on and Veeam plugin setup
    Install SQL Server Always On & Configure Veeam Plug‑in for SQL Backup
  • WSUS Analysis and Initial Assessment
    Preliminary Guide for WSUS Analysis and Initial Assessment Windows Server
  • screenshot 2020 02 09 at 17.11.11
    How to uninstall a program via command prompt in Windows Windows
  • screenshot 2020 03 13 at 21.22.29
    How to determine Cygwin version Windows Server
  • drivelock 1280x720 1
    The server could not be reached or validated: Timeout expired. The Time out expired prior to obtaining a connection from the pool Security | Vulnerability Scans and Assessment
  • how to fix the sorry this file type is not permitted for security reasons error in wordpress 5e4a5632967c7
    Error 1707: Network address invalid when trying to connect remotely Windows
  • create a Lenovo USB Recovery key
    Windows 10 Yoga Recovery: Download the files needed to create a Lenovo USB Recovery key Windows

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,839 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.