Defender Antivirus STIG Checklist
21 items · Security · Medium difficulty · 3 hours
Practical checklist to implement the Windows Defender Antivirus STIG.
-
Gather STIG resources
Collect SCAP, XCCDF, GPO, Intune and SCC artifacts before configuring
-
Download SCAP 1.3 content
Obtain the SCAP benchmark package for automated validation
-
Download GPOs and SCC resources
Get the latest Group Policy Objects and SCC content files
-
Download Intune policies and automated content
Fetch Intune policy bundles if managing endpoints via Intune
-
Review STIG summary and change history
Confirm applicability, authority (DoDI 8500.01), and recent updates
-
Enable real-time protection
Turn on Defender real-time scanning on all endpoints
-
Enable cloud-delivered protection
Activate cloud protection to improve detection speed
-
Enable automatic sample submission
Allow safe automatic sample uploads to Microsoft for analysis
-
Enable Tamper Protection
Prevent unauthorized changes to Defender settings
-
Configure signature and platform update sources
Set update cadence and sources (Microsoft Update or WSUS/SCCM)
-
Import and apply GPOs to domain
Import STIG-provided GPOs and link to appropriate OUs
-
Import and apply Intune policies
Deploy Intune policy bundles to enrolled devices
-
Run SCC/SCCM validation tools
Use provided SCC or SCAP tools to validate STIG settings
-
Schedule regular quick and full scans
Create scan schedules to balance coverage and performance
-
Configure minimal exclusions and document exceptions
Allow exclusions only when justified; record rationale
-
Enable network protection and exploit mitigation
Activate network protection and latest exploit defenses
-
Configure logging and central event collection
Send Defender operational logs to SIEM or central log store
-
Backup GPOs and record configuration baseline
Export policy backups and save a configuration snapshot
-
Test detections and update response playbooks
Run detection tests and validate incident response steps
-
Monitor update status and remediate failures weekly
Check definitions and platform patching; fix failures
-
Review and document compliance with DoDI 8500.01
Confirm STIG alignment with DoD security requirements
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.