Skip to content

Microsoft Defender

When defining scanner exclusions for Microsoft Defender, there are three folders you can exclude:

  • %ProgramFiles%\CapaInstaller
  • %ProgramFiles(X86)%\CapaInstaller
  • %ProgramData%\CiBaseAgent\Cache

Open your Group policy management Console.

Browse to Group Policy Objects. This is found under.

Forest:”Your Domain name” → Domains → “Your Domain name“ → Group Policy Objects

Right click to create a new Group policy :

Group Policy Objects context menu with New selected

Give it a name :

New GPO dialog with a name for the policy

Click OK. Now you have created an Empty policy. Now you should edit your newly created policy.

Edit selected in the context menu of the new policy

Now Browse to

Computer Configuration → Policies → Administrative Templates → Windows Components → Microsoft Defender Antivirus → Exclusions

In older administrative templates, the folder is named Windows Defender Antivirus.

Here you have the options for adding exclusions.

We are adding folders to exclude. This setting will disable all defender scanning in these folders.

Exclusions settings in the Group Policy Management Editor

Click Show to edit list of folders to exclude.

Path Exclusions list with the CapaInstaller folders added

Here we have added the basic Capainstaller folders.

Click OK and your policy are now ready for deployment.

Deploy policy by linking it to an Organization Unit (OU).

  1. Browse to the OU. (You should test First).
  2. Right click and choose “Link an Existing GPO”.
  3. Choose your newly created policy.
  4. Click OK

Now test your policy on the clients that should be affected by the new policy.