Windows Defender Cloud Protection Registry Key

This article explains how to locate and configure the Windows Defender cloud-delivered protection setting using the Windows Registry Editor (Regedit). Cloud-delivered protection allows Microsoft Defender Antivirus to identify and block new and emerging threats in real time using cloud-based heuristics and telemetry. Below, you will find the exact registry path, the specific DWORD value used to control this feature, and the configuration options available.

Registry Location and Key Name

The configuration for Windows Defender cloud-delivered protection (historically known as Microsoft Active Protection Service or MAPS) is managed through the following registry path:

Configuration Values

The SpynetReporting value accepts numeric data to define the level of cloud reporting and protection:

How to Configure the Setting

  1. Press Windows Key + R, type regedit, and press Enter to open the Registry Editor.

  2. Navigate to:

    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender
  3. Check if the Spynet subkey exists under Windows Defender. If it does not, right-click Windows Defender, select New > Key, and name it Spynet.

  4. Select the Spynet key. In the right pane, right-click and choose New > DWORD (32-bit) Value.

  5. Name the new value SpynetReporting.

  6. Double-click SpynetReporting, set the Base to Hexadecimal or Decimal, and enter 0, 1, or 2 depending on your desired protection level.

  7. Click OK and restart your computer or restart the Windows Defender service to apply the changes.

Automatic Sample Submission Setting

Cloud protection is often paired with automatic sample submission, which is managed in the same registry key: