Microsoft Defender Antivirus • Release: 7 Benchmark Date: 05 Jan 2026

CAT II V-278863 WNDF-AV-000073

Microsoft Defender AV must set cloud protection level to High.

Documentable No
Rule ID SV-278863r1144086_rule
CCI References
CCI-001170

Cloud protection in Microsoft Defender Antivirus delivers accurate, real-time, and intelligent protection. Cloud protection should be enabled by default.

Check Procedure

Verify the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> MpEngine >> Select cloud protection level is set to "Enabled". Verify the policy value for "Select cloud blocking level" is set to "High blocking level"; otherwise, this is a finding.

Procedure: Use the Windows Registry Editor to navigate to the following key: 
HKLM\Software\Policies\Microsoft\Windows Defender\MpEngine

Criteria: If the value "MpCloudBlockLevel" is REG_DWORD = 2, this is not a finding.

If the value is other than 2, this is a finding.

Fix Action

Set the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Defender Antivirus >> MpEngine >> Select cloud protection level to "Enabled".

Set policy value "Select cloud blocking level" to "High blocking level".

Click "OK".

Click "Apply".