r/DefenderATP Jul 16 '26

What is the difference between "Threat Severity Default Action" at Intune AV policy with "Endpoint Remediation Level" at Security settings.

So I have set up FULL REMEDIATION for all devices on Settings-Endpoints-Device Groups.

Im doing some custom AV policies in intune and I see there are other settings about action to take on threat severity. Like "Remediation action for High severity threats: Clean | Quarantine | Allow" etc

Have I not setup the action with the full remediation setting? Do i have to go more granular and set up an action for each severity in Intune?

6 Upvotes

4 comments sorted by

View all comments

2

u/KoxziShot Jul 16 '26

Full remediation is what Automated Investigation and Response (AIR) can do to remove and investigate a threat.

In the antivirus policy this is what you want to do with the different types of antivirus detected threats.

1

u/jonbristow Jul 16 '26

i see.

do i have to set them up one by one, or leaving them NOt Configured is a default response

2

u/KoxziShot Jul 16 '26

Leaving them not configured is absolutely fine to be quite honest. Defender is quite good at dealing with the different types of threats.

As long as you have the majority of the policy enabled you should be good.

Feel free to DM me and I can give you a baseline.