Microsoft Defender Exclusions

Modified on Mon, 10 Aug at 3:47 PM

If you are running Microsoft Defender, the exclusions below will be automatically added at install via Group Policy Object (GPO) Defender Key. This manual list is only needed for hardened/third-party AV environments where the installer’s registry write is blocked (the code explicitly logs “registry potentially blocked by third party Anti-Virus”). 


Similarly, these exclusions are automatically removed if AZT is uninstalled.


File or Folder name
TypeExclusionComment
C:\Program Files\Aria\AZT\bin\TrustUtil.exeFile (Windows)Real-time and scheduledARIA AZT
C:\ProgramData\Aria\AZTFolder (Windows)Real-time and scheduledARIA AZT
C:\Windows\System32\drivers\AztAgent.sysFile or folder (Windows)Real-time and scheduledARIA AZT
C:\Windows\System32\drivers\NetworkPolicyEnforcer.sys
File or folder (Windows)
Real-time and scheduled
ARIA AZT
C:\Program Files\Aria\AZT\bin\TrustUtil.exeProcess/path entry (Windows)Real-time and scheduledARIA AZT


Note: These paths have recently changed to include \AZT in the path name. A fresh install of AZT will reflect these paths; upgrades keep the old exclusions and do not add exclusions for the new file locations.


Note: If you manually remove AZT exclusions, you may see alerts for the AZT Tamper countermeasure. Please note that this is NOT a critical alert and will have no impact on Microsoft Defender.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article