Microsoft Defender exclusions for TAO
Add Microsoft Defender Antivirus path and process exclusions so TAO installs, heartbeats, and VisionX stay healthy.
Microsoft Defender exclusions for TAO
Use this when Windows endpoints run Microsoft Defender Antivirus (local or managed through Microsoft Defender for Endpoint / Intune). Apply exclusions from the TAO antivirus and EDR exclusions list before broad TAO rollout.
Exact menu names vary by Defender channel and tenant. Prefer central management (Intune, Configuration Manager, or Defender portal) over one-off local settings.
Paths to exclude
Add these as folder exclusions:
C:\Program Files\Trustity\TAOC:\ProgramData\Trustity\TAOC:\ProgramData\Trustity(covers portal CA and shared Trustity data)
Processes to exclude
Where process exclusions are available, add:
tao-agent.exetao-gui.exetao-tray.exetao-lock.exetao-zerodevice.exeTrustity-Agent-Setup.exe
Intune / Defender for Endpoint (typical)
- Open the Microsoft Defender or Endpoint security admin experience used by your tenant.
- Create or edit an Antivirus / Exclusions policy targeted at the TAO pilot device group.
- Add the path exclusions above.
- Add process exclusions if the policy template supports them.
- Assign the policy, wait for sync, then install TAO from Cloud Portal → Deployment.
For local pilot machines only (lab):
- Open Windows Security → Virus & threat protection → Manage settings.
- Under Exclusions, add the folders listed above.
- Reboot or wait for Defender to reload policy, then install TAO.
Validation
On a pilot PC:
sc query TrustityAgent
Expect RUNNING. Then confirm the host is Online under Managed devices with the expected agent version.
If Setup was quarantined before exclusions:
- Restore
Trustity-Agent-Setup.exeand anytao-*.exefiles from Defender protection history. - Confirm exclusions are active.
- Re-run Setup from a freshly downloaded Deployment package (verify SHA-256 when shown).
