Skip to main content
Version: 2.1.1-preview

MT.1154 - Full Scan Removable Drives should be enabled

Overview​

Verify that full scan of removable drives is enabled to mitigate USB risks.

Disabled removable drive scanning allows USB-based malware infections.

Remediation action:​

  1. Open Microsoft Endpoint Manager > Endpoint Security > Antivirus
  2. Edit the relevant Microsoft Defender Antivirus policy
  3. Enable Allow Full Scan on Removable Drives

Test Metadata​

FieldValue
Test IDMT.1154
SeverityHigh
SuiteMaester
CategoryDefender
PowerShell testTest-MtMdeRemovableDriveScanning
TagsDefender, Maester, MT.1154

Source​

  • Pester test: tests/Maester/Defender/Test-MtMdeAntivirusPolicy.Tests.ps1
  • PowerShell source: powershell/public/maester/defender/Test-MtMdeRemovableDriveScanning.ps1