No. That's why I asked: What is Microsoft thinking? One one hand allow Windows Defender disabled, on the other hand allow AntiMalware Scan Interface and keep pushing "Malware Removal Tool" updates.
For the client version, it feels not very useful and there is no test. But for the server version, it should be useful.
I've removed amsi from Client, wait and see if Malware Removal Tool updates keep going. Bad news: No.It keeps pushing.
Server 2022 Windows Defender Information Code: Parent-package Microsoft-Windows-ServerCore-Server-Common-Package Child-package Windows-Defender-Server-Core-Package Microsoft-Windows-SenseClient-Package Parent-package Microsoft-Windows-ServerCore-SKU-Foundation-Package Child-package Microsoft-Antimalware-Scan-Interface-Core-Package Parent-package Microsoft-Windows-ServerCore-SKU-Foundation-WOW64-Package Child-package Microsoft-Antimalware-Scan-Interface-Core-WOW64-Package Parent-package Microsoft-Windows-GroupPolicy-ClientTools-Package Child-package Windows-Defender-Group-Policy-Package :: Windows Update Malware Removal Tool update :: Disable Malware Removal Tool update Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE1\Policies\Microsoft\MRT] "DontReportInfectionInformation"=dword:00000001 "DontOfferThroughWUAU"=dword:00000001
On Server, ServerManager.exe or OptionalFeatures.exe? ServerManager.exe: Server with Server Manager packages OptionalFeatures.exe: Client without Server Manager packages