Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

To exclude a specific file or folder from Microsoft Defender Antivirus scans on managed Windows devices, create an Intune Endpoint security → Antivirus policy for Windows using the Microsoft Defender Antivirus exclusions profile. Add the path under Defender files and folders to exclude, assign the policy to a test device group, then verify the effective exclusion on an endpoint. An exclusion narrows antivirus scanning for that location; it does not turn Defender off, but it does reduce protection there.

Before adding an exclusion

First confirm that Microsoft Defender Antivirus is responsible for the detection or performance problem. An alert might instead come from an Attack Surface Reduction (ASR) rule, another Defender component, or a different antivirus product. Identify the exact runtime path involved and, where possible, resolve the issue by updating or reconfiguring the application.

If an exclusion is necessary, record the business or technical reason, application owner, affected devices, and a review date. Choose the narrowest path that addresses the issue. Avoid broad locations such as C: or C:Users: a folder exclusion also covers its files and subfolders, including content that may be writable or untrusted.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Create an Intune antivirus exclusions policy

  1. Open the Microsoft Intune admin center.
  2. Go to Endpoint security → Antivirus, then select Create Policy.
  3. Set Platform to Windows and Profile to Microsoft Defender Antivirus exclusions.
  4. Continue to Configuration settings and find Defender files and folders to exclude.
  5. Add the required file or folder path, then create and assign the policy.

This is the dedicated current endpoint security profile for exclusions. Some tenants or older policies may show different labels; older Intune profiles can use legacy terminology or layouts. If you do not see the profile or setting, check the policy type, tenant interface, and Windows build rather than assuming every policy experience is identical. Microsoft documents the configuration in its Defender Antivirus exclusions guidance and Intune Antivirus policy reference.

#1 Best Overall
Sale
Microsoft Surface Laptop (2026), 13.8-inch Premium Performance Laptop, Snapdragon X2 Elite Processor, Touchscreen Display, 16GB RAM, 512GB SSD Storage, Windows 11 Copilot+ PC Built for AI, Platinum
  • Brilliant Display – Stunning 13.8" PixelSense touchscreen[1], with brilliant LCD display[2], unleashes luminous whites, deeper blacks and colors so richly saturated bringing vivid life into every frame – perfect for work, school, streaming and creative tasks.
  • Power that lasts all day – With 20 hours of battery life[3], the new Surface Laptop powers through your entire day, so you can create, work and stream from morning to night without reaching for a charger.​
  • Work at the speed of your ideas – Built with the latest Qualcomm Snapdragon X2 Elite (12 Core) processors, Surface Laptop delivers fast, AI‑accelerated performance—making it the most powerful Surface laptop for everything from multitasking to demanding workloads.
  • The ports you need – Charge on-the-go, transfer data fast, or create the ultimate desktop set up with two USB-C / USB4[4] ports.
  • Built-in AI Companion – Work smarter, create freely, and communicate with confidence—Copilot[5] on Windows 11 is always there to help.​

Choose and enter the path

Use a fully qualified path that matches the device’s actual location. For example:

  • Folder: C:Program FilesContosoAppcache
  • Individual file: C:ProgramDataContosoAppdata.db

Prefer the individual file when only that file causes the problem. Use a folder only when the application genuinely needs a changing set of files in that controlled directory. A folder exclusion includes descendants, so do not use a general-purpose or user-writable folder unless the risk has been explicitly accepted.

Intune’s graphical editor accepts separate entries for exclusions. The underlying Defender Policy CSP represents multiple paths as a vertical-bar-delimited list, for example C:Program FilesContosoAppcache|C:ProgramDataContosoAppdata.db. Avoid assuming that arbitrary wildcard syntax works in every interface. Microsoft examples include environment-variable paths in some policy contexts, but path interpretation can vary by management method and Windows version; validate any non-literal path on a pilot device.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Microsoft Surface Laptop 5 13.5" Touchscreen Notebook - 2256 x 1504 - Intel Core i7 12th Gen i7-1265U - Intel Evo Platform - 16 GB Total RAM - 512 GB SSD (Platinum) (Renewed)
  • With 16 GB of memory, runs as many programs as you want without losing the execution
  • The 13.5" 2256 x 1504 screen provides a great movie watching experience
  • 512 GB SSD is enough to store your essential documents and files, favorite songs, movies and pictures
  • 8 Hours battery run time helps you stay unwired and work longer non-stop

Understand what kind of exclusion you need

Control What it affects Why scope matters
File or folder path The specified location; folder exclusions cover descendants. Microsoft describes these exclusions as applying to real-time protection and scheduled scans. Malware placed in the excluded location may not receive normal antivirus scanning.
Extension Files with that extension, regardless of location. Usually much broader than excluding one known path.
Process Files opened by the specified process; it does not exclude the process executable itself. A process that can access untrusted files may create a wide blind spot.
ASR exclusion Evaluation by specified Attack Surface Reduction rules. It is not necessarily an antivirus path exclusion and may not resolve an antivirus detection.

Use a path exclusion for a known file or directory issue. Consider an extension or process exclusion only when its broader behavior is specifically required and understood. If the event is an ASR block, investigate the relevant ASR rule and its separate policy instead of assuming an antivirus exclusion will fix it. See Microsoft’s guidance on file, folder, and contextual exclusions, the Defender Policy CSP, and Intune ASR policies.

Assign narrowly and test first

Assign the policy to a pilot device group before production. After validating the result, target only the devices that need the exception; use separate groups or filters if different device populations have different paths. Avoid tenant-wide assignment for an application-specific exception.

Review the Defender local admin merge setting as a governance decision. When local-admin merge is allowed, locally configured preference exclusions can merge with management-defined exclusions; when configured to prevent that merge, only management-defined items are used. This can change the effective list beyond the new entry, so do not change it casually on an established fleet. The setting is documented in Microsoft’s Windows Defender Antivirus settings reference.

Rank #3
Sale
Microsoft Surface Laptop (2026), 13.8-inch Premium Performance Laptop, Snapdragon X2 Elite Processor, Touchscreen Display, 16GB RAM, 512GB SSD Storage, Windows 11 Copilot+ PC Built for AI, Black
  • A PREMIUM PERFORMANCE LAPTOP — Ready for work, school, and creativity. Built for busy days, big projects, and nonstop multitasking. Run video calls, school and work apps, 20+ browser tabs, and AI tools at the same time without slowing down.
  • WITH AI BUILT IN — With a dedicated AI chip (Qualcomm Snapdragon X2 Elite), this Copilot+ PC[5] on Windows 11 helps you work smarter and faster. Prompt, create, and automate with ease - ready for even your most demanding tasks.
  • A 13.8" TOUCHSCREEN YOU'LL ACTUALLY USE — Sharp colors, real detail, smooth 120Hz scrolling on the PixelSense touchscreen[1] with LCD display[2]. Tap, scroll, or pinch to zoom - whichever feels right for streaming, editing photos, or daily work.
  • 20 HOURS OF BATTERY (LEAVE THE CHARGER) — Up to 20 hours of video playback[3] on a single charge. Work from a coffee shop, take it to class/work, or binge an entire season on a long flight — it'll keep up.
  • THE PORTS YOU NEED — Two USB-C / USB4[4] ports for fast charging, big file transfers, or hooking up to three 4K monitors when you want a full desktop. Wi-Fi 7 keeps you online and fast wherever you are.

Sync Intune and verify on Windows

  1. Trigger an Intune sync on a pilot device and allow time for policy processing.
  2. Check the policy’s device status in Intune and confirm it reports success.
  3. On the endpoint, run PowerShell as an administrator and inspect the effective path exclusions:
Get-MpPreference | Select-Object -ExpandProperty ExclusionPath

For a broader view of exclusion categories, run:

Get-MpPreference | Format-List ExclusionPath, ExclusionExtension, ExclusionProcess

This output shows the locally effective configuration, which can include entries from more than one management source. It does not, by itself, identify which Intune policy supplied each path. Confirm the application behavior with a safe, documented test; do not use real malware to test an exclusion.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If the exclusion is missing or the application still triggers an alert

  • Check assignment and sync: Verify the intended device is in scope, has synced, and reports policy processing success.
  • Check the exact path: The application may use a different runtime, data, temporary, redirected, or installation path than expected.
  • Check Defender’s role: If another antivirus product is primary, the policy may not behave as expected. Identify the Defender component and rule that generated the alert.
  • Check Windows support: Availability depends on policy type, build, servicing level, and edition. The relevant ADMX-backed path-exclusion documentation lists Windows 10 version 2004 with the specified servicing update and later, and Windows 11 version 21H2 and later; do not treat that as a universal minimum for every Intune policy experience. See the ADMX-backed policy reference.
  • Check other management sources: Group Policy, Configuration Manager, scripts, local configuration, other Intune profiles, or Defender for Endpoint security settings management may affect the effective list.
  • Distinguish antivirus from ASR: An antivirus path exclusion does not automatically exempt a path from ASR evaluation, and an ASR-only exclusion does not necessarily stop antivirus scanning.
  • Consider path behavior: Mapped drives, network paths, symbolic links, and redirected locations can behave differently from a straightforward local path. Test the actual path on the target build.

Tamper protection is an important safeguard, but do not assume that enabling it blocks every possible exclusion-management route. Microsoft notes that exclusion protection has conditions; follow the applicable CSP guidance and validate your management design.

Multiple policies and removing an exclusion

Intune supports policy merge for Defender path exclusions: applicable antivirus policies can combine different paths into a superset. Consequently, removing an entry from one policy may not remove it from the device if another applicable policy or management source still supplies it.

Rank #4
Sale
Microsoft Surface Laptop (2026), 15-inch Premium Performance Laptop, Snapdragon X2 Elite Processor, Touchscreen Display, 16GB RAM, 1TB SSD Storage, Windows 11 Copilot+ PC Built for AI, Black
  • A PREMIUM PERFORMANCE LAPTOP — Ready for work, school, and creativity. Built for busy days, big projects, and nonstop multitasking. Run video calls, school and work apps, 20+ browser tabs, and AI tools at the same time without slowing down.
  • WITH AI BUILT IN — With a dedicated AI chip (Qualcomm Snapdragon X2 Elite), this Copilot+ PC[5] on Windows 11 helps you work smarter and faster. Prompt, create, and automate with ease - ready for even your most demanding tasks.
  • A 15" TOUCHSCREEN YOU'LL ACTUALLY USE — Sharp colors, real detail, smooth 120Hz scrolling on the PixelSense touchscreen[1] with LCD display[2]. Tap, scroll, or pinch to zoom - whichever feels right for streaming, editing photos, or daily work.
  • 19 HOURS OF BATTERY (LEAVE THE CHARGER) — Up to 19 hours of video playback[3] on a single charge. Work from a coffee shop, take it to class/work, or binge an entire season on a long flight — it'll keep up.
  • Two USB-C / USB4[4] ports and a microSD card reader for fast charging, big file transfers, or hooking up to three 4K monitors when you want a full desktop. Wi-Fi 7 keeps you online and fast wherever you are.

To retire an exception, remove it from every relevant Intune policy, then check custom OMA-URI profiles, Settings Catalog profiles, Group Policy, Configuration Manager, scripts, and local or Defender for Endpoint management. Sync the device, rerun Get-MpPreference, and confirm the exclusion is gone before closing the change. Retest the application and record why the exception was removed.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Advanced option: custom OMA-URI

Use a custom OMA-URI only if the native endpoint security policy does not expose the required setting or your organization already uses a deliberate custom-CSP design. The Defender path is device-scoped:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
./Device/Vendor/MSFT/Policy/Config/Defender/ExcludedPaths

Its value is a pipe-delimited list, for example:

C:ProgramDataContosoAppdata|C:Program FilesContosoAppcache

The native Antivirus policy is generally easier to audit, report on, and maintain. Intune is not the only possible management method: a compatible MDM can configure the Defender Policy CSP as well.

Best Value
Sale
Microsoft Surface Laptop (2026), 13.8-inch Premium Performance Laptop, Snapdragon X2 Elite Processor, Touchscreen Display, 16GB RAM, 512GB SSD Storage, Windows 11 Copilot+ PC Built for AI, Dune
  • Brilliant Display – Stunning 13.8" PixelSense touchscreen[1], with brilliant LCD display[2], unleashes luminous whites, deeper blacks and colors so richly saturated bringing vivid life into every frame – perfect for work, school, streaming and creative tasks.
  • Power that lasts all day – With 20 hours of battery life[3], the new Surface Laptop powers through your entire day, so you can create, work and stream from morning to night without reaching for a charger.​
  • Work at the speed of your ideas – Built with the latest Qualcomm Snapdragon X2 Elite (12 Core) processors, Surface Laptop delivers fast, AI‑accelerated performance—making it the most powerful Surface laptop for everything from multitasking to demanding workloads.
  • The ports you need – Charge on-the-go, transfer data fast, or create the ultimate desktop set up with two USB-C / USB4[4] ports.
  • Built-in AI Companion – Work smarter, create freely, and communicate with confidence—Copilot[5] on Windows 11 is always there to help.​

Security checklist

  • Confirm the issue is caused by Defender Antivirus and capture the exact path.
  • Document the reason, owner, target devices, and a review date.
  • Choose a file exclusion over a folder where it will solve the issue.
  • Keep excluded directories access-restricted and avoid user-writable content.
  • Pilot, sync, and verify the effective device configuration.
  • Check for duplicate policies and other sources before adding or removing entries.
  • Revisit the exception after application updates or remediation and remove it when no longer needed.

Windows 10 and licensing qualifications

Windows support matters: Microsoft ended Windows 10 support on October 14, 2025. Intune may still allow Windows 10 devices, but Microsoft warns that functionality is not guaranteed in the same way as on supported Windows releases. Test on the organization’s actual build and plan migration where applicable.

The exclusion feature itself does not require buying Intune Suite or an additional Defender product. The organization needs a suitable management entitlement to deploy Intune policies, and existing Microsoft 365 subscriptions may already include Intune Plan 1. Check the organization’s license terms and region before purchasing; a basic path exclusion alone is not a reason to buy a higher-tier bundle.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.