Microsoft antivirus exclusion guidelines for domain controllers

Rakri Aizat 40 Reputation points
2026-07-20T07:12:31.63+00:00

AV real‑time scanning now touches ntds.dit database

It also scans SYSVOL replication folders unexpectedly

This behavior is causing domain controller performance issues

We need the official Microsoft exclusion list

i want to ask what is the Microsoft‑recommended antivirus exclusion list for domain controller roles to prevent these performance problems ?

Windows for business | Windows 365 Business
0 comments No comments

Answer accepted by question author
VPHAN 43,740 Reputation points Independent Advisor
2026-07-20T08:13:05.55+00:00

Hi Rakri Aizat

The primary vector encompasses the Active Directory database (ntds.dit) and associated patch streams within the directory designated by the DSA Database File registry entry. The secondary vector isolates the volatile transactional logging subsystem, specifically EDB*.log, Res*.log, Edb*.jrs, and TEMP.edb structures defined by the `Database Log Files Path registry entry, preserving low-latency write cycles. The tertiary vector encompasses the distributed policy environment, mandating the exclusion of the entire SYSVOL folder hierarchy, its structural policy artifacts like registry.pol and gpt.ini, and the execution path of the replication engine binary (dfsr.exe) to maintain absolute synchronization integrity across the enterprise topology.

Hope this answer has brought you some useful information. If it did, please hit “accept answer”. Should you have any questions, feel free to leave a comment.

VPHAN

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

0 additional answers

Sort by: Newest

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.