Network File Scanning
complete
R
Richard Scheuer
There is no dropdown to enable or disable network file scanning. can you add this as an option
Russ Bashaw - Huntress
updated the status to
complete
Hi all, I apologize for the lapse in communications on this topic but we did want to let you know these settings are now live in the portal and can be configured at the account and organizational levels.
Want to call out that enabling network file scanning can impact performance so monitor endpoints accordingly.
Russ Bashaw - Huntress
updated the status to
complete
Hi all, I apologize for the lapse in communications on this topic but we did want to let you know these settings are now live in the portal and can be configured at the account and organizational levels.
Want to call out that enabling network file scanning can impact performance so monitor endpoints accordingly.
Matthiew Morin (Huntress)
Merged in a post:
Defender: Additional Scanning Options (Scan Network Files)
M
Mark Cordingley
Just like "Removable Drive Scanning", add the ability to set "Scan Network Files".
Photo Viewer
View photos in a modal
Russ Bashaw - Huntress
updated the status to
future planned
Thanks everyone. Adam and I spent some time together over email and I realized I was mixing up "Network scanning" and "removable file scanning". Brought this to the product team and we agree on the problem. Looking to get this on the future roadmap for all the missing scan settings.
A
Adam Kemp
Russ Bashaw - Huntress has there been any update on this please? It's annoying that so many of my endpoints show as "Non Compliant" purely because my Intune policies enable Network File Scanning, Huntress default policy sets this to Disabled, and there is no option to change the Huntress default value like we can for Removable Drive Scanning.
Russ Bashaw - Huntress
Hi Richard and Adam, we had an engineer look into this and this was their response.
"Looked into this and I think there are no changes needed here. Reasoning:
The MSFT documentation for this setting has the name DisableScanningNetworkFiles, which implies you set it to true to disable scanning.
It also has the description If you enable or don't configure this setting, network files will be scanned., which implies the opposite of the above. This contradiction causes the ambiguity.
On a fresh Windows install checking this setting in powershell shows a default of false, which tells us that in the description enable actually means set to false. It follows that the description is misleading, and the setting name is likely accurate.
portal UI currently already inverts this logic
Putting it all together, I believe the current behavior is correct:
Huntress is "Disabled" == MSFT Scan_DisableScanningNetworkFiles is true == Do not scan
Huntress is "Enabled" == MSFT Scan_DisableScanningNetworkFiles is false == Yes please scan"
Let me know if this tracks as your understanding of the functionality as well. Apologies on all the confusion.
A
Adam Kemp
Russ Bashaw - Huntress Hi Russ, the summary is correct, "Disabled" in Huntress does disable Network scanning. The issue is that Huntress does not let us change this setting (it is missing when configuring Huntress policy), and I believe the default should be to have network scanning enabled, so the Huntress value should be "Enabled" by default. If you could let us change the setting ourselves it would resolve the core issue.
Russ Bashaw - Huntress
updated the status to
in progress
Sorry for the delay on this gents. We're looking into it.
T
Tim Sword
Functionality to STOP or PAUSE scans while they're in progress.
A
Adam Kemp
As Artur has suggested, I think perhaps there has been a misunderstanding of the Microsoft documentation (https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#scan_disablescanningnetworkfiles). The policy name is "Scan_DisableScanningNetworkFiles" and the default is "Enabled" which suggests the default is to disable the scanning, but Microsoft clearly state "The default is enabled. Recommended to remain enabled in most cases. If you enable or don't configure this setting, network files WILL BE SCANNED". It seems the policy was previously named "EnableScanningNetworkFiles" and when they renamed it, the description was not updated resulting in a double negative which causes confusion.
Can we either be given the option to enable this setting in Huntress, or can the default be changed to enable scanning as per Microsoft recommendations?
Autopilot
Merged in a post:
Network File Scanning - Recommended setting
A
Artur Gawrych
The setting description in MAV states: "This is currently not recommended per Defender guidelines and set to "Disabled" by Huntress Managed Antivirus"
However, the Microsoft CSP policy suggests: "It is recommended to enable this setting." Here's the link to the policy document: https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-defender#allowscanningnetworkfiles
Is this the same rule, or am I missing something?
C
Corey DeBot
Please also note that there are TWO different network scan functions; one is for full network scan, which would be bad in most cases. The other is scanning network files upon access, which should never be disabled, and Microsoft enables it by default, yet Huntress has it disabled.
B
Brian Cook
If added I would feel sorry for any decent size network where this is turned on, imagine 50 computers all scanning the server shares at the same time, it would drop the network access speeds to a crawl. If you do add this please default to off.
Load More
→