Feed / Defender
highDefenderMicrosoft Defender for Endpointupdatelink_discovery · Jul 16, 2026

[Docs] enableDisableLocalAdminMergeto prevent modification of antivirus exclusions via GPO

A change was made to prevent modification of antivirus exclusions via Group Policy Objects, enhancing security by restricting local admin access to endpoint protection settings. This update helps protect against destructive malware like GigaWiper that exploits such vulnerabilities.

Linked from "GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware": enableDisableLocalAdminMergeto prevent modification of antivirus exclusions via GPO
View original article →
Security
endpoint_securityvulnerability_management
Audience
security_engineeradmin
Environment
cloudhybridon_premises
Ontology Topics
AZ-500
Classification confidence: 95%
Loading correlations…
[Docs] enableDisableLocalAdminMergeto prevent modification of antivirus exclusions via GPO | 365Forge