When it comes to endpoint security, visibility matters but control matters even more. In many environments, exposing security areas that users are not meant to manage can lead to confusion, unnecessary questions, and even risk.
The Account Protection area in Windows Security is one of those sections. While it provides valuable information, it also exposes account-related security features that are typically centrally enforced through Intune and should not be modified by end users.
With Intune, administrators can precisely control whether the Account Protection area is visible in the Windows Security app. This allows IT teams to define the right balance between transparency and governance, ensuring users see only what they are expected to interact with.
By hiding the Account Protection section, organizations maintain a consistent and protected security experience across managed devices. Sensitive account settings remain enforced by policy, untouched by user actions, and aligned with corporate security standards.
At the same time, this approach improves the overall user experience. A cleaner Windows Security interface reduces confusion, sets clear boundaries around security responsibilities, and helps minimize unnecessary help desk tickets related to settings users are not authorized to change.
Why This Policy Matters
In managed and security-focused environments, consistency and control are critical. Allowing end users to view or interact with sensitive account-related security settings can introduce unnecessary risk, confusion, and support overhead.
This policy ensures that security decisions remain centralized with IT, not delegated to end users. By controlling the visibility of the Account Protection area, organizations reduce the likelihood of users questioning, attempting to override, or misinterpreting security configurations that are already enforced through Intune.
From an operational perspective, this leads to:
A consistent security posture across all managed devices
Reduced risk of accidental changes or misconfiguration
Fewer help desk tickets related to restricted security settings
Clear ownership of security controls by IT and security teams
Ultimately, this policy helps organizations move closer to a standardized, predictable, and governed endpoint security model.
Why Hiding the Account Protection UI Improves Security Governance
Hiding the Account Protection UI is not about limiting transparency it’s about enforcing governance.
In modern endpoint management, users are not expected to manage or modify security controls such as credential protection, account hardening, or identity-related safeguards. These settings should be defined, enforced, and monitored centrally using tools like Intune and Microsoft Defender.
By removing the Account Protection section from Windows Security:
Users can no longer view or attempt to interact with protected account settings
There is no ambiguity about who controls security decisions
The risk of users searching for workarounds or exceptions is significantly reduced
At the same time, this approach improves the end-user experience. A simplified Windows Security interface removes options that users are not authorized to change, reducing confusion and increasing trust in the organization’s security model.
This aligns directly with Zero Trust principles, where security is enforced by design, continuously validated, and never dependent on user behavior.
Windows CSP Details
This policy is applied at the device level, not the user level, meaning it affects the entire device regardless of which user signs in. This ensures consistent enforcement across all managed endpoints.
It supports the following Windows editions:
Windows 10 Pro
Enterprise
Education
IoT Enterprise / IoT Enterprise LTSC
The policy is supported on Windows 10 version 1803 (build 10.0.17134) and later, which guarantees broad compatibility across modern Windows 10 and Windows 11 devices managed with Intune.

By leveraging this CSP, administrators can centrally control whether the Account Protection area is visible in the Windows Security app, preventing users from accessing or interacting with account-related security settings that are already enforced by Intune.
Policy Properties
The configuration framework for this policy defines the following properties:
Format: Integer (int)
Access Type: Add, Delete, Get, Replace
Default Value: 0
This structure ensures the policy can be consistently deployed, updated, or replaced across managed devices using Intune configuration profiles.

Allowed Values
The policy supports two possible values:
0 (Default – Disabled): Users can see the Account Protection area in the Windows Security app.
1 (Enabled): The Account Protection area is hidden from users in Windows Security.
When the value is set to 1, the UI is removed entirely, preventing users from viewing or attempting to change sensitive account-related security settings.

Group Policy Mapping (Reference)
For environments that still rely on Group Policy or hybrid management models, this Intune CSP maps directly to the following Group Policy settings:
Policy Name: AccountProtection_UILockdown
Friendly Name: Hide the Account protection area
Location: Computer Configuration

Enforce Consistent Security: Control the Account Protection UI in Windows Security via Intune
How to Configure Account Protection Area Visibility using Intune
You can centrally control the visibility of the Account Protection area in Windows Security using Intune, ensuring this setting is managed consistently across all devices and not left to user interaction.
To begin configuring this policy, sign in to the Microsoft Intune admin center and follow the steps below, as illustrated in the screenshot.
Step-by-Step Configuration (Intune)
In the Microsoft Intune admin center, navigate to Endpoint security.
Under Endpoint security, select Antivirus.
Click + Create Policy to start creating a new security profile.
In the Create a profile pane, set the Platform to Windows.
For Profile, select Windows Security Experience.
Click Create to proceed to the configuration settings.
At this point, you’ve created the foundation of a Windows Security Experience policy. In the next steps, you’ll configure the specific setting that controls the visibility of the Account Protection area and define how it is enforced across managed devices.

Define Basic Profile Details
After clicking Create, the next step is to define the basic details of your Windows Security Experience policy. This includes providing a clear Name and a meaningful Description, which are critical for long-term management and operational clarity.
A well-defined name and description make it easier to identify the purpose of the policy later especially in environments with multiple security profiles or mature Intune implementations.
As shown in the screenshot, configure the fields as follows:
Suggested Name and Description
Name: Hide Account Protection UI in Windows Security
Description: This policy controls the visibility of the Account Protection area in the Windows Security app. When enabled, it hides the Account Protection section from end users, preventing them from viewing or attempting to modify account-related security settings that are centrally enforced through Intune.
This configuration helps maintain a consistent security posture across managed devices, reduces user confusion, minimizes help desk tickets, and ensures that organizational security policies remain intact.

No changes are required for the Platform, as it is already pre-selected. Once the name and description are defined, click Next to continue to the configuration settings.
Configure the Disable Account Protection UI Policy (Default Behavior)
By default, the Disable Account Protection UI setting is configured as Not configured, as shown in the screenshot.
When this policy is Not configured or explicitly set to Disabled, the Account Protection area is visible by default in the Windows Security app. This means end users can see the Account Protection section in Windows Defender Security Center, even though the underlying security settings may already be enforced through Intune.
At this stage:
The Account Protection UI remains visible to users
No changes are made to security enforcement
Users can still view account-related security information
This default behavior is useful for environments that want full transparency, but it may not be ideal for organizations aiming for strict security governance and centralized control.
Enable the Policy to Hide the Account Protection UI
To hide the Account Protection area from end users, the policy must be explicitly enabled.
As illustrated in the screenshot, configure the setting Disable Account Protection UI and select:
Enable – The users cannot see the display of the Account protection area in Windows Defender Security Center
When this option is enabled:
Users can no longer see the Account Protection section in Windows Security
Account-related security settings remain active and enforced
All controls stay centrally managed by administrators through Intune
This configuration removes the Account Protection UI from view while ensuring that security protections continue to operate in the background without user interaction.
Enabling this setting is recommended for organizations that want to:
Enforce centralized security governance
Reduce user confusion
Prevent unnecessary interaction with restricted security areas
Maintain a clean and consistent Windows Security experience
Once the setting is selected, click Next to continue with the policy assignment.

Configure Scope Tags (Optional)
Scope tags are used to control who can view and manage this policy within the Microsoft Intune admin center. They are especially useful in larger or delegated environments where administrative responsibilities are separated across different IT teams or regions.
As shown in the screenshot, the Default scope tag is selected. This is the standard behavior and is sufficient for most environments, as it allows the policy to be visible to all administrators who have access to Intune.
You can optionally assign custom scope tags if you need to:
Limit policy visibility to specific IT roles or teams
Enforce administrative separation
Support delegated or regional management models
If no additional scope tags are required, simply keep the Default selection and click Next to proceed.

Assignments – Account Protection Area Visibility Policy
After configuring the policy settings, the next step is to assign the Account Protection Area Visibility policy to the appropriate target group. Assignments determine which devices will receive and enforce this configuration, ensuring the policy is applied only where intended.
In the Assignments tab, use the Search by group name field to quickly locate the group you want to target. This makes it easy to apply the policy in controlled phases or to specific test or production groups.
As shown in the screenshot, select the desired group. In this example, the policy is assigned to:
GRP – MS365Education – Test Computers
Once the group is selected:
Ensure the Target type is set to Include
Confirm the correct group appears in the assignment list
After selecting the group, click Next to continue to the final review step.

Review + Create – Final Validation
In the Review + Create step, take a moment to validate all configured settings before deploying the policy.
By default, this section is displayed in a collapsed view, as shown in the first screenshot. To review the details, simply expand each section, as demonstrated in the second screenshot.
Carefully verify the following items:
Policy name and description
Configured settings (Disable Account Protection UI enabled)
Scope tags assigned
Assignments, including the correct target group
This final review ensures that the policy is correctly configured and aligned with your security and deployment strategy.
Once everything has been confirmed and validated, click Create (or Save) to finalize and deploy the policy to the assigned devices.


Monitor Policy Deployment Status
After creating and assigning the Hide Account Protection UI in Windows Security policy, the final step is to monitor its deployment and confirm that the configuration has been successfully applied to the targeted devices.
By default, Intune policy propagation can take up to several hours. If needed, you can speed up the process by triggering a manual sync from the device (via Company Portal) or by initiating a sync directly from the Intune admin center.
How to Verify Deployment Status
Follow these steps to validate the policy deployment:
In the Microsoft Intune admin center, navigate to: Endpoint security ➝ Antivirus
Locate the policy Hide Account Protection UI in Windows Security in the policy list
Click the policy name to open its overview page
Review the Device and user check-in status section

As shown in the screenshot, you can see the overall status summary, which confirms that the policy has been successfully applied:
Succeeded: 2
Error: 0
Conflict: 0
Not applicable: 0
In progress: 0
This confirms that there are no deployment issues and that the policy is being enforced correctly on all targeted devices.

Why This Matters
Monitoring policy status allows administrators to:
Quickly validate successful deployment
Identify and troubleshoot errors or conflicts
Ensure consistent security posture across managed devices
This visibility is essential for maintaining confidence in your Intune security configurations and for taking immediate action if any device falls out of compliance.
Client-Side Verification via Event Viewer
After the device syncs with Microsoft Intune either automatically or through a manual sync you can confirm that the DisableAccountProtectionUI policy has been successfully applied directly on the client device using Event Viewer.
This verification method is extremely useful for troubleshooting, auditing, and validating security configurations, especially in enterprise or regulated environments.
How to Verify Policy Application
Open Event Viewer on the target Windows device
Navigate to: Applications and Services Logs ➝ Microsoft ➝ Windows ➝ DeviceManagement-Enterprise-Diagnostics-Provider ➝ Admin
In the right-hand pane, select Filter Current Log
Look for Event ID 813 or 814, which typically indicates successful processing of Intune configuration policies
Open the event details and confirm the following information:
The Int value (0x1) confirms that the policy is enabled, meaning the Account Protection UI is hidden in the Windows Security app while the underlying security controls remain active and managed by Intune.
You may also see additional metadata such as Enrollment ID, User SID, and Scope, depending on how the device was enrolled and how the policy was assigned.
Pro Tip
Always verify that the event timestamp aligns with the most recent device sync. This client-side validation is one of the most reliable methods to confirm Intune policy enforcement especially when investigating delayed deployments or unexpected behavior.
More Information
For additional technical details, official documentation, and deeper insights into this policy and related Intune concepts, refer to the Microsoft Learn resources below:
Policy CSP – Windows Defender Security Center (DisableAccountProtectionUI) https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-windowsdefendersecuritycenter
Create a Windows Security Experience Policy in Intune https://learn.microsoft.com/en-us/mem/intune/protect/endpoint-security-antivirus-policy
Create a Settings Catalog Policy in Intune https://learn.microsoft.com/en-us/mem/intune/configuration/settings-catalog
Monitor Intune Policy Deployment and Troubleshoot Profiles https://learn.microsoft.com/en-us/mem/intune/configuration/device-profile-troubleshoot
Event Viewer Logs for MDM and Intune Diagnostics https://learn.microsoft.com/en-us/mem/intune/configuration/device-profile-troubleshoot#event-viewer-logs
Thank you!
🖥️ Ricardo Barbosa
🎖️ Microsoft MVP | 📘 Microsoft Certified Trainer (MCT)
☁️ Intune & Cloud Architect |💼 Technology Director at Altelix.com
