Add File & Process Exclusions to Antivirus Management

Introduction

Our Antiviruses Management's File and process exclusions feature allow administrators to block Microsoft Defender from scanning specific files, folders, file types, or processes that are known to be safe or critical to your business operations. 


Adding these critical files and/or processes as an Antivirus Management "exclusion" helps reduce false positive detections and prevents security tools or business-critical applications from being disrupted by antivirus scanning.


Visit our Help Center chapter on the feature to learn more about Antivirus Management as a whole.


This article walks through the process of adding a file and/or path exclusion and covers the following topics: 

TOC 


Exclusion Types

There are 3 exclusion types available: 

  1. Path Exclusions: prevent Microsoft Defender from scanning files located within a folder and their subdirectories (specified by path).
    • Common path types include:
      • Application data directories
      • Backup repositories
      • Large database storage locations
      • Software that requires specific folders to be excluded from antivirus scanning
  2. Extension Exclusions: prevent Microsoft Defender from scanning files with specific file extensions. Examples include .vhd, .mdf, ,ldf.  
  3. Process Name Exclusions: prevent Microsoft Defender from triggering detections while specified processes are running.
    • Common use cases include:
      • Database services
      • Backup applications
      • Specialized line-of-business software


Exclusion Handling

Once exclusions are added, they can be handled in one of two ways: merge or strict. 


Merge

When Merge is selected:

  • Existing device exclusions are preserved.
  • Exclusions configured in the MDR Portal are added to the device.
  • Field Effect MDR audits devices to ensure the portal-defined exclusions are present.


This option is recommended when devices may require additional local exclusions that are managed outside of the MDR Portal.


Strict

When Strict is selected:

  • Devices must exactly match the exclusions configured in the MDR Portal.
  • Field Effect MDR can enforce compliance by replacing existing exclusions with the configured list.
  • Any exclusions not defined in the MDR Portal may be removed.


This option is recommended when organizations want centralized control and consistent exclusion policies across all managed devices.


Before you Begin

You must have appropriate administrative permissions in the MDR Portal to modify Antivirus Management settings.


Access Antivirus Management Exclusions

Partners: This is a client-level, so the organization selector must be set to a specific client view to access this page.
  1. Sign in to the MDR Portal.
  2. Navigate to Administration > Antivirus Management in the sidebar.
  3. Scroll to locate the File and Process Exclusions section.



Add or Update Exclusions

  1. Navigate to Administration > Antivirus Management.
  2. In the File and Process Exclusions section, click the Update button.
  3. Add, modify, or remove:
    1. Path exclusions
    2. Extension exclusions
    3. Process exclusions
  4. Select the desired Exclusion Handling mode.
  5. Save your changes.



Best Practices

When managing antivirus exclusions:

  • Use the smallest, most specific exclusion possible.
  • Exclude individual files or folders instead of broad directory structures whenever possible.
  • Review exclusions regularly to ensure they are still required.
  • Remove outdated or unused exclusions promptly.
  • Validate all exclusion requests with application vendors or internal security teams.
  • Avoid excluding entire drives or large directory trees unless absolutely necessary.


Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article