Published Feb 6, 2026
Starting March 2026, Microsoft Defender Antivirus with MDE security settings will stop storing readable exclusions in the local registry. Organizations must use PowerShell cmdlets like Get-MpPreference to retrieve settings. Registry-based monitoring will no longer work; update scripts and notify teams accordingly.
Updated February 13, 2026: We have updated the content. Thank you for your patience.
Introduction
Microsoft Defender Antivirus on Windows is updating how antivirus configuration settings, such as exclusions, are stored when Microsoft Defender for Endpoint (MDE) security settings management is enabled. Starting with platform release 4.18.25110.6, devices using MDE security settings management will no longer store readable exclusion values in the local device registry. Organizations must retrieve configuration using supported Microsoft Defender PowerShell cmdlets, such as Get-MpPreference.
When this will happen:
General Availability (Worldwide): We will begin rolling out early March 2026 and expect to complete by late March 2026.
How this affects your organization:
Who is affected:
What will happen:
What you can do to prepare:
Get-MpPreferenceGet-MpComputerStatusLearn more: Troubleshoot Microsoft Defender Antivirus settings - Microsoft Defender for Endpoint | Microsoft Learn (will be updated to reflect this change)
Compliance considerations:
No compliance considerations identified, review as appropriate for your organization.