Select the Microsoft Defender safe deployment channel
Verified with Windows 11 25H2 — updated on September 24, 2026 Supported on: At least Windows Server 2008 R2 or Windows 7
Added by Windows update KB5124010 (build 26200.9550); not in the official ADMX package (Administrative Templates (.admx) for Windows 11 Oct 2025 Update).
Path in the GPO console
Computer Configuration\Administrative Templates\Windows Components\Microsoft Defender Antivirus Registry
Software\Policies\Microsoft\Windows Defender Description
Enable this policy to specify when devices receive Microsoft Defender binary updates. Validation Channel: Devices set to this channel are the first to receive new monthly binary (platform and engine) updates. The likelihood of new issues occurring is higher, so add only devices with the highest risk tolerance to this channel (recommended for 1% or less of devices in your environment). Release Channel - Early: The release channel is appropriate for most of your production environment. Devices set to this channel are offered updates earliest in the release channel. Distribute devices across early, fast and broad depending on their risk tolerance. Add devices in the earlier channels to surface issues sooner and avoid impacting the rest of your environment. Release Channel - Fast: The release channel is appropriate for most of your production environment. Devices are offered updates later during the gradual release cycle. Distribute devices across early, fast and broad depending on their risk tolerance. Use devices in the earlier channels to surface issues sooner and avoid impacting the rest of your environment. Release Channel - Broad: The release channel is appropriate for most of your production environment. Devices in this channel receive updates at the end of the gradual release cycle. Distribute devices across early, fast and broad depending on their risk tolerance. Use devices in the earlier channels to surface issues sooner and avoid impacting the rest of your environment. Delayed Channel: Devices in this channel are offered updates approximately 48 hours after the devices in the release channel (broad). Use this channel for critical infrastructure and high value assets (~1% or less of devices). If you don't configure this policy, devices are added to the release channel. Microsoft determines whether devices receive updates earlier or later within the release channel.
Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Select the Microsoft Defender safe deployment channel
; State: Enabled
; Supported on: At least Windows Server 2008 R2 or Windows 7
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows Defender]
"DeploymentChannel"=dword:0000000a More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Select the Microsoft Defender safe deployment channel
# State: Enabled
# Supported on: At least Windows Server 2008 R2 or Windows 7
$path = 'HKLM:\Software\Policies\Microsoft\Windows Defender'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'DeploymentChannel' -Value 10 -Type DWord Intune XML
No direct Policy CSP / OMA-URI mapping for this policy. Use the Intune Remediation tab, or ingest the ADMX in Intune. Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Select the Microsoft Defender safe deployment channel
# State: Enabled
# Supported on: At least Windows Server 2008 R2 or Windows 7
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows Defender' -Name 'DeploymentChannel' -Expected 10 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Select the Microsoft Defender safe deployment channel
# State: Enabled
# Supported on: At least Windows Server 2008 R2 or Windows 7
$path = 'HKLM:\Software\Policies\Microsoft\Windows Defender'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'DeploymentChannel' -Value 10 -Type DWord SCCM scripts
# Exported from gporais.com
# Policy: Select the Microsoft Defender safe deployment channel
# State: Enabled
# Supported on: At least Windows Server 2008 R2 or Windows 7
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Select the Microsoft Defender safe deployment channel
# State: Enabled
# Supported on: At least Windows Server 2008 R2 or Windows 7
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows Defender' -Name 'DeploymentChannel' -Expected 10 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Select the Microsoft Defender safe deployment channel
# State: Enabled
# Supported on: At least Windows Server 2008 R2 or Windows 7
$path = 'HKLM:\Software\Policies\Microsoft\Windows Defender'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'DeploymentChannel' -Value 10 -Type DWord Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.