Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Microsoft Defender sample sharing in Intune involves two separate controls: Sample Sharing in a Defender for Endpoint EDR policy and Submit Samples Consent in a Microsoft Defender Antivirus policy. The EDR control governs sharing suspicious files for analysis; the Antivirus control governs automatic submission of safe or all samples. Choose the policy that matches the behavior you intend to manage, and weigh the detection benefits against your organization’s data-handling requirements.

How do I configure sample sharing?

First identify which product setting you need. Microsoft’s Intune onboarding guidance describes EDR Sample Sharing as: “Configure whether devices share suspicious file samples with Microsoft for analysis.” Defender Antivirus Submit Samples Consent is a different setting in an Antivirus policy.

Control Intune policy area What it governs Documented choices
Sample Sharing Defender for Endpoint onboarding/EDR configuration Sharing suspicious file samples with Microsoft for analysis All (automatic sharing enabled) or None (disabled)
Submit Samples Consent Endpoint security > Antivirus, Windows, Microsoft Defender Antivirus profile Automatic submission of safe samples or all samples Send safe samples automatically or Send all samples automatically; related documentation also describes an always-prompt choice

Configure Defender for Endpoint EDR Sample Sharing

  1. In the Microsoft Intune admin center, open the Defender for Endpoint onboarding or EDR configuration policy for the intended Windows device group. Microsoft’s Intune onboarding guidance documents the setup context.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  2. Find Sample Sharing and choose All to enable automatic sharing, or None to disable it. The EDR settings reference says Sample Sharing sends a file to Microsoft for deep analysis.

    #1 Best Overall
    Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
    • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
    • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
    • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
    • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
    • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  3. Assign the policy to the device group whose sharing behavior you intend to control. Microsoft says organizations can disable sharing on specific devices considered too sensitive, so a scoped exception is an option rather than treating the decision as necessarily organization-wide.

  4. Check that the assigned policy and device targeting reflect your intended choice. Microsoft cautions that disabling EDR Sample Sharing can reduce detection capabilities; it does not publish a quantified detection-rate change for this setting.

Configure Defender Antivirus Submit Samples Consent

  1. In Intune, go to Endpoint security > Antivirus, create or edit a policy for Windows, and select the Microsoft Defender Antivirus profile. Microsoft documents this workflow in its Intune configuration guidance for Defender Antivirus.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  2. Set Allow cloud protection to Allowed.

  3. Set Submit Samples Consent to Send safe samples automatically or Send all samples automatically, according to your organization’s policy. Microsoft identifies safe-sample automatic submission as the default choice in this flow.

    Rank #3
    FEITIAN K40 USB Security Key - Two Factor Authenticator - USB-C with NFC, FIDO2 - Help Prevent Account Takeovers
    • FIDO2 + FIDO U2F certified and supported USB security key
    • Supports Computers, Laptops, Tablets, and Mobile Devices with a USB-C port and/or NFC
    • Works without downloading any drivers. Supported OS: Android, Chrome OS, Windows, MacOS, Linux
    • Durable design made to last for a long time with everyday use. Water-resistant (IP67)
    • Helps protect your accounts from phishing and other cyber-attacks. Prevents your devices from unauthorized use.
  4. Assign the policy to the intended Windows device group, then verify policy application using your normal Intune monitoring process.

For Defender Antivirus configuration or validation using PowerShell, Microsoft documents Set-MpPreference -MAPSReporting Advanced for cloud protection reporting and Set-MpPreference -SubmitSamplesConsent SendSafeSamples or Set-MpPreference -SubmitSamplesConsent SendAllSamples for automatic submission choices. Use Get-MpPreference to inspect MAPSReporting, SubmitSamplesConsent, and CloudBlockLevel. Microsoft documents MAPSReporting value 2 as Advanced and SubmitSamplesConsent values 1 and 3 as automatic safe and all submission, respectively. For managed endpoints, use the supported policy workflow where appropriate; PowerShell can help validate the resulting Defender Antivirus configuration. See Microsoft’s cloud protection configuration documentation.

Rank #4
Yubico - YubiKey Bio C (FIDO Edition) - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C, Biometric, FIDO Certified - Protect Your Online Accounts
  • FIDO-ONLY FUNCTIONALITY: Supports FIDO2 (passkeys) and FIDO U2F protocols for passwordless and second-factor authentication. Does not support OTP, TOTP, Smart Card (PIV), or other advanced features - upgrade to YubiKey 5 Series for extended functionality
  • SECURE AND CONVENIENT: Passwordless MFA login with the YubiKey Bio authenticator and biometric information using a fingerprint, with a PIN as a fallback. Simply plug in via USB and use your fingerprint to authenticate
  • DEVICE & OS COMPATIBILITY: Compatible with Windows, macOS, ChromeOS, and Linux. Works seamlessly with supported services like Google and Microsoft accounts, and major password managers. See the full compatibility list at "Works With YubiKey"
  • DURABLE & RELIABLE: Resistant to tampering, water, and crushing. No batteries or network connectivity required, offering dependable authentication without any downtime. Securely manufactured in USA & Sweden
  • Yubico Authenticator App - Fingerprint enrollment, passkey management and PIN configuration available via the app app - Upgrade to YubiKey 5 Series to generate one-time-passwords (OTP) via Yubico Authenticator and for advanced compatibility (OATH, PIV)

What the two choices mean for privacy

EDR Sample Sharing

With EDR Sample Sharing enabled, suspicious file samples can be sent to Microsoft for analysis. Microsoft explicitly allows disabling this control for devices considered too sensitive. An organization can therefore assess sensitive device groups separately, while recognizing Microsoft’s warning that disabling the setting can reduce detection capabilities.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Safe samples versus all samples

For Defender Antivirus, Microsoft describes safe samples as files that typically do not contain personally identifiable information and gives examples including .bat, .scr, .dll, and .exe. “Typically” is not a guarantee that a submitted file can never contain sensitive information. Choosing all samples broadens what may be submitted; align the choice with internal data-handling rules. Microsoft’s cloud protection guidance and Defender Antivirus policy documentation describe these settings.

Best Value
Cryptnox FIDO2 Security Key with MIFARE DESFire NFC Smart Card for 2FA MFA
  • HARDWARE 2FA AND MFA: FIDO Alliance Certified FIDO2 v2.1 with CTAP2 plus legacy U2F and CTAP1 for strong two-factor login and passwordless sign-in on services that support security keys
  • BUILDING ACCESS ON ONE CARD: MIFARE DESFire EV2 4K applet with AES encryption adds office door and physical access control alongside digital authentication
  • CERTIFIED SECURE ELEMENT: An NXP Common Criteria EAL6+ certified secure controller and Java Card platform protects your keys on a tamper-resistant chip
  • DUAL INTERFACE SMART CARD: Contactless NFC ISO 14443 plus ISO 7816 contact reader support in an ISO 7810 ID-1 format that is passive and needs no battery
  • SWISS ENGINEERED DESIGN: Built by Cryptnox as a single card for authentication and access control and backed by a 2 year warranty
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Keep cloud protection separate from sample consent

Cloud protection is a distinct Defender Antivirus setting, not another name for sample submission consent. Microsoft recommends keeping cloud protection enabled because some Defender features depend on it. Automatic sample submission relies on cloud protection, although it can also be configured as a standalone setting. Block at first sight uses the cloud protection backend to assess suspicious files; see Microsoft’s Block at first sight guidance.

Cloud protection level is also separate from both sample-sharing controls. Microsoft documents choices including Default, High, High plus, and Zero tolerance, and advises enabling cloud protection before setting its level. Higher levels can affect false-positive risk or performance, so do not treat a level change as a substitute for choosing a sample-consent option. For baseline context, consult Microsoft’s Intune Defender security baseline settings reference.

Choose and target the policy deliberately

  • Need to control EDR submission of suspicious files? Configure Sample Sharing in the Defender for Endpoint EDR policy.
  • Need to control automatic Defender Antivirus sample submission? Configure Submit Samples Consent in the Windows Microsoft Defender Antivirus policy, with cloud protection allowed.
  • Have devices with stricter data-handling requirements? Evaluate whether to scope a different EDR policy for those devices or select the narrower safe-samples option for Antivirus submission.
  • Unsure which setting currently applies? Confirm the product, policy area, platform, and device assignments before changing values. Policy context and defaults can differ; validate Defender Antivirus values with Get-MpPreference when appropriate.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.