Template family: Intune — device configuration
Applies to: Microsoft Intune
Where to find it: Secure → Intune → Device Management → Configuration → Templates → Augmentt Default

What this template is for

Allow Archive Scanning. Allow Behavior Monitoring. Allow Cloud Protection. Allow Email Scanning. Allow Intrusion Prevention System. Allow scanning of all downloaded files and attachments. Allow Realtime Monitoring. Allow Scanning Network Files. Allow Script Scanning. Allow Full Scan Removable Drive Scanning. PUA (Potentially Unwanted Application) protection is enabled. PUAs are blocked and logged. CIS v8: 10.1, 10.4, 10.7.

What it actually does

SettingValue
platformswindows10
technologiesmdm,microsoftSense
templateReference.templateId804339ad-1553-4478-a742-138fb5807418_1
templateReference.templateFamilyendpointSecurityAntivirus
templateReference.templateDisplayNameMicrosoft Defender Antivirus
templateReference.templateDisplayVersionVersion 1

Anything not listed keeps the Microsoft default.


This is an Augmentt Default template, shipped with the product and shared across all customers. Deploying it creates a new policy in the customer tenant; edit the deployed policy rather than the template.