Additional Microsoft Defender tools and services that provide security across various platforms and environments
- WDSI submissions focus on malware/PUA classification (false positives/negatives for threats), not on CFA (Controlled Folder Access) behavior. Submitting to WDSI and getting “No threats detected” only confirms that the file is not classified as malware; it does not directly change CFA allow/block decisions. So CFA false positives are generally not resolved via standard WDSI malware submissions alone.
- The provided context only documents these official channels for false positives/negatives:
- Submitting files, hashes, or diagnostic data for malware analysis via the Microsoft Security Intelligence submission site and related Defender for Endpoint workflows.
- Reporting missed or wrongly detected items in Microsoft Defender XDR and Defender for Office 365.
- Submitting files when Windows Defender Antivirus incorrectly flags or misses malware.
- From the available documentation, the actionable options for a software vendor are:
- Continue submitting new versions as needed:
- Use the Microsoft Security Intelligence submission site to submit each new build when it is blocked, including hashes and supporting diagnostic data (such as
MpSupportFiles.cab) as described in the Defender for Endpoint false positive/negative guidance. - This ensures Microsoft security researchers can analyze each version and adjust protection logic where appropriate.
- Use the Microsoft Security Intelligence submission site to submit each new build when it is blocked, including hashes and supporting diagnostic data (such as
- Encourage customers (especially enterprise customers) to use Defender for Endpoint controls:
- In Defender for Endpoint environments, security admins can create custom indicators (for example, for the file or signer) with an Allow action so that the application is treated as safe on managed devices. This is the documented way to prevent recurring false positives for files, IPs, URLs, or domains that are known to be safe.
- Use feedback channels when Defender on Windows clients misclassifies files:
- When Windows Defender Antivirus or related protections (including unwanted software or suspicious behavior) incorrectly classify a file, users can submit that file for malware analysis via the documented “Submit a file for malware analysis” and “submit the files to Microsoft” flows.
- Continue submitting new versions as needed:
References:
- Address false positives/negatives in Microsoft Defender for Endpoint
- Address false positives or false negatives in Microsoft Defender XDR
- Troubleshoot problems with detecting and removing malware
- Protect your PC from unwanted software
- What to do when a malicious file is found in SharePoint Online, OneDrive, or Microsoft Teams