Potentially Unwanted Application Detected [CHK-3032]
This ticket is opened when Microsoft Defender detects a Potentially Unwanted Application (PUA) on a device in your environment. PUA covers software that is not malware but is unwanted on a managed workstation: adware, browser toolbars and hijackers, bundled installers, aggressive "system optimiser" utilities, torrent clients and cryptocurrency miners. The application, the device and the actions Attic has already taken are written into the ticket.
Rationale
A PUA detection is usually a signal about behaviour rather than about an attack. Something was installed on a managed device that should not have been, and the most useful question is how it got there. Most PUA arrives bundled with free software downloaded from an unofficial source, which tells you that a user searched for a tool, clicked a download that was not the vendor's, and had the rights to install it.
That route is worth attention because it is the same route commodity malware takes. The user who installs a bundled toolbar from a search advertisement is doing exactly what a malvertising campaign relies on. The PUA itself may be harmless; the pattern that delivered it is not.
Some categories carry more direct impact. Cryptocurrency miners consume resources you are paying for and often arrive through a compromise rather than a download. Browser hijackers can intercept traffic and inject content into pages the user believes are legitimate. Adware frequently phones home with browsing data.
This is the lowest-urgency category of MDR ticket, and it is genuinely often benign. It is worth clearing rather than ignoring, mostly for what it tells you about the device and the user.
Follow-up
Follow these steps to adequately address this detection:
- Identify the application and how it arrived. The ticket names what Defender detected. Check the user's downloads and browser history around the installation time to establish the source.
- Establish whether the software is wanted.
- If no (unwanted): Remove it and address the route:
- Uninstall the application, and where a browser was affected, reset the browser's settings and review its extensions.
- Check for anything that came with it. Bundled installers rarely deliver one thing; review what else was installed at the same time.
- If a cryptocurrency miner was found, treat it more seriously: establish whether it was installed by the user or by something else, and investigate the device accordingly.
- Review the user's install rights. Standard users should not normally be able to install software on a managed workstation.
- If yes (wanted): Some detections are legitimate business tools that Defender classifies as PUA:
- Confirm the software has a business purpose and was obtained from the vendor directly.
- Add an exclusion in Microsoft Defender if it will remain in use, so the detection does not recur.
- Record the decision on the ticket.
- If no (unwanted): Remove it and address the route:
- Look for a pattern. Repeated PUA detections on the same device or from the same user are worth addressing at the source: through application control, removing local administrator rights, or a conversation about download habits. A single detection is noise; a recurring one is a gap.