The best way to do this is to deactivate Microsoft Defender globally via the Local Group Policy Editor or Group Policy Management (Active Directory) when using ServerProtect. Follow these steps:
- Manage Group Policies on a local computer.
- Open Local Group Policy Editor. You may search or run gpedit.msc (Press the Windows button + 'R') to open the Group Policy Management folder.
- Navigate to Computer Configuration > Administrative Templates > Windows Components.
- Select “Microsoft Defender Antivirus” and in the right panel and double click the setting Turn off Microsoft Defender Antivirus. Set "Turn off Microsoft Defender Antivirus" to "Enabled". The path may be different for different operating systems, like “Windows Defender”, “Windows Defender Antivirus” and “Microsoft Defender Antivirus”.
- Update them immediately by running the command gpupdate /force (using the Windows button + 'R') or just reboot server.
- Manage Group Policies in an Active Directory domain.
- Open Group Policy Management. You may search or run gpmc.msc (Press the Windows button + 'R') to open the Group Policy Management folder.
- Navigate to Group Policy Management > Forest > Domains > (your Domain) > Group Policy Objects then go to the Policy that needs to be adjusted.
- Right-click the target policy, then click Edit. The Group Policy Management Editor window will appear.
For illustration purposes, the image shown above changes to the Default Domain Policy. You may create an additional policy instead of modifying the Default Domain Policy.
- Navigate to Computer Configuration > Policies >Administrative Templates Policy definitions > Windows Components > Windows Defender. Note that the path may be different for different operating systems, like “Windows Defender”, “Windows Defender Antivirus” and “Microsoft Defender Antivirus”. The Windows Defender page will appear.
- Under Settings, click Turn off Windows Defender. When the "Turn off Windows Defender" window appears, tick the Enabled radio button, click Apply then click OK.
- The Domain member machines will pick up the settings after the next reboot, or you can update them immediately by running ‘gpupdate /force’.