# Controlled configuration Configuration protection in Microsoft Defender for Endpoint - Microsoft Defender for Endpoint | Microsoft Learn
Controlled configuration Configuration protection is a configuration enforcement model that makes cloud-managed policy the single source of truth for Microsoft Defender Antivirus settings. When controlled configuration protection is enabled, Intune and Microsoft Defender for Endpoint policies take precedence. The device ignores settings from Group Policy, scripts, Microsoft Configuration Manager, and local admin changes.
Controlled configuration Configuration protection eliminates configuration drift and policy conflicts by extending tamper-protection-style enforcement to the entire Defender Antivirus configuration surface.
[Tamper protection] and controlled configuration protection are complementary but distinct capabilities:
| Feature | Tamper protection | Controlled configuration Configuration protection |
Controlled configuration Configuration protection is a superset of tamper protection that provides policy-driven control over the full Microsoft Defender Antivirus configuration.
Although tamper protection and controlled configuration protection can technically be turned on at the same time, we recommend that your organization selects one or the other.
Controlled configuration Configuration protection doesn't currently support:
## What controlled configuration protection covers
Currently, controlled configuration protection provides protection and enforcement for Microsoft Defender Antivirus settings, including:
Currently, controlled configuration protection doesn't cover:
## How controlled configuration protection enforcement works
Controlled configuration Configuration protection enforces cloud-managed policy through three mechanisms:
- **Single-source enforcement**: When controlled configuration protection is enabled, the following enforcement rules apply:
- **Secure defaults**: If a setting isn't explicitly configured in a policy, controlled configuration protection applies Microsoft-defined defaults. This behavior ensures that devices maintain a strong security posture even when administrators haven't configured every available setting.
- **Conflict resolution**: Controlled configuration Configuration protection uses a value-based precedence model rather than a last-write-wins model:
- **On** takes precedence over **Off**. If one policy sets controlled configuration protection to On and another sets it to Off, the feature stays enabled on the device.
**Not configured** doesn't mean **Off**. To disable the feature, explicitly deploy a policy that sets controlled configuration protection to **Off**.
## Enable controlled configuration protection
You can enable controlled configuration protection through either Microsoft Intune or [Microsoft Defender for Endpoint security settings management].
Controlled configuration Configuration protection is configured through the same policy surface as tamper protection. In the Windows Security Experience profile, Intune renames the tamper protection setting to **Controlled Configuration **Configuration protection (Device)** when controlled configuration protection is available. You can't enable controlled configuration protection through the Settings Catalog or the Device Control v1 (DCv1) template.
Because controlled configuration protection and tamper protection use the same policy setting, setting **Controlled Configuration **Configuration protection (On)** supersedes the tamper protection value on that device. You don't deploy separate tamper protection and controlled configuration protection policies for the same setting. To migrate existing tamper protection (DCv1) policies to controlled configuration, configuration protection, create a Windows Security Experience policy with **Controlled Configuration **Configuration protection (On)**, then remove the tamper protection setting from your DCv1 policies to avoid conflicts.
Locate the **Controlled Configuration **Configuration protection (Device)** setting (formerly **Tamper Protection**).
Set the value to **Controlled Configuration **Configuration protection (On)** to enable controlled configuration. configuration protection.
Before you assign **Controlled Configuration **Configuration protection (On)**, update devices to Microsoft Defender Antivirus platform version 4.18.26060.3004 or later, and validate the deployment with a pilot group.
… 19 more changes: see the page or its history