en-US windows computer

Select the Microsoft Defender safe deployment channel

Verified with Windows 11 25H2 — updated on September 24, 2026 Supported on: At least Windows Server 2008 R2 or Windows 7

Windows 11 25H2

KB5124010

Added by Windows update KB5124010 (build 26200.9550); not in the official ADMX package (Administrative Templates (.admx) for Windows 11 Oct 2025 Update).

Path in the GPO console

Computer Configuration\Administrative Templates\Windows Components\Microsoft Defender Antivirus

Registry

HKLM Software\Policies\Microsoft\Windows Defender

Options

Select the Microsoft Defender safe deployment channel:
DeploymentChannel enum
  • 10 Validation Channel default
  • 20 Release Channel - Early
  • 30 Release Channel - Fast
  • 40 Release Channel - Broad
  • 50 Delayed Channel

Description

Enable this policy to specify when devices receive Microsoft Defender binary updates.​ Validation Channel: Devices set to this channel are the first to receive new monthly binary (platform and engine) updates. The likelihood of new issues occurring is higher, so add only devices with the highest risk tolerance to this channel (recommended for 1% or less of devices in your environment). Release Channel - Early: The release channel is appropriate for most of your production environment. Devices set to this channel are offered updates earliest in the release channel. Distribute devices across early, fast and broad depending on their risk tolerance. Add devices in the earlier channels to surface issues sooner and avoid impacting the rest of your environment. Release Channel - Fast: The release channel is appropriate for most of your production environment. Devices are offered updates later during the gradual release cycle. Distribute devices across early, fast and broad depending on their risk tolerance. Use devices in the earlier channels to surface issues sooner and avoid impacting the rest of your environment. Release Channel - Broad: The release channel is appropriate for most of your production environment. Devices in this channel receive updates at the end of the gradual release cycle. Distribute devices across early, fast and broad depending on their risk tolerance. Use devices in the earlier channels to surface issues sooner and avoid impacting the rest of your environment. Delayed Channel: Devices in this channel are offered updates approximately 48 hours after the devices in the release channel (broad). Use this channel for critical infrastructure and high value assets (~1% or less of devices). If you don't configure this policy, devices are added to the release channel. Microsoft determines whether devices receive updates earlier or later within the release channel.

Export Builder

BETA

Configure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.

These exports write the registry — this is not a managed GPO. ⓘ

.reg file

Windows Registry Editor Version 5.00

; Exported from gporais.com
; Policy: Select the Microsoft Defender safe deployment channel
; State: Enabled
; Supported on: At least Windows Server 2008 R2 or Windows 7

[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows Defender]
"DeploymentChannel"=dword:0000000a
More formats (PowerShell, Intune, SCCM)

PowerShell

# Exported from gporais.com
# Policy: Select the Microsoft Defender safe deployment channel
# State: Enabled
# Supported on: At least Windows Server 2008 R2 or Windows 7

$path = 'HKLM:\Software\Policies\Microsoft\Windows Defender'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'DeploymentChannel' -Value 10 -Type DWord

Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.

Open the Builder

Embed this policy on your site

What to embed
Theme

Adds one script line: the theme follows your site’s appearance and the height fits the content. If your site blocks scripts, the embed follows the visitor’s system theme.

Preview