Defender Cloud Protection Level Registry Key

Windows Defender utilizes cloud-delivered protection to rapidly identify and block new, emerging threats before they can impact your system. This article identifies the specific Windows Registry key responsible for managing the cloud-delivered protection blocking levels and explains the exact values needed to configure this setting across your Windows devices.

The Master Registry Key

The master configuration for the cloud-delivered protection level is located in the following Registry path:

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\MpEngine

Within this key, the configuration is controlled by a 32-bit DWORD value named:

MpCloudBlockLevel

Protection Level Values

You can adjust the cloud blocking sensitivity by changing the MpCloudBlockLevel value data to one of the following integers (Base: Decimal or Hexadecimal):

How to Configure the Key in Regedit

  1. Press Win + R, type regedit, and press Enter to open the Registry Editor.
  2. Navigate to: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender
  3. If the MpEngine subkey does not exist, right-click the Windows Defender folder, select New > Key, and name it MpEngine.
  4. Select the MpEngine key, right-click in the right-hand pane, and select New > DWORD (32-bit) Value.
  5. Name the value MpCloudBlockLevel.
  6. Double-click MpCloudBlockLevel, set the value to your desired level (e.g., 2 for High), and click OK.
  7. Restart the computer or restart the Windows Defender service to apply the changes.

Required Prerequisite Setting

For cloud blocking levels to function, cloud-delivered protection must be enabled. This is managed via the Spynet key: