Managed antivirus (Defender) policy settings can currently only be changed individually per agent in the GUI – this is not possible via the API. It is not possible to select multiple agents (or an entire group) and adjust Defender policy settings together.
Use Cases:
  • Onboarding: newly set up servers require the correct Defender policy
  • Environment-specific settings (e.g., exclusions on test VMs, restrictive in Prod)
  • Audit/Remediation: Apply a policy change to hundreds of agents without clicking through them individually
Suggestion:
GUI:
  • Select multiple agents (or filter by group/day) → Edit Managed Antivirus Policy
API:
  • Endpoint to update Defender/AV policy settings for a list of agent IDs (or as a account-wide default policy)
Sub-Organization groups (feature idea): Allow sub-groups within existing organizations. New agents assigned to a sub-group automatically inherit the correct policy – no manual individual work is required for newly added agents.