Bulk change of Managed Antivirus (Defender) policy settings for multiple agents
T
Tim Späth
Managed antivirus (Defender) policy settings can currently only be changed individually per agent in the GUI – this is not possible via the API. It is not possible to select multiple agents (or an entire group) and adjust Defender policy settings together.
Use Cases:
- Onboarding: newly set up servers require the correct Defender policy
- Environment-specific settings (e.g., exclusions on test VMs, restrictive in Prod)
- Audit/Remediation: Apply a policy change to hundreds of agents without clicking through them individually
Suggestion:
GUI:
- Select multiple agents (or filter by group/day) → Edit Managed Antivirus Policy
API:
- Endpoint to update Defender/AV policy settings for a list of agent IDs (or as a account-wide default policy)
Sub-Organization groups (feature idea): Allow sub-groups within existing organizations. New agents assigned to a sub-group automatically inherit the correct policy – no manual individual work is required for newly added agents.