Enterprise also expects certain kind of user awareness, or if not then certain amount of admin-set restrictions on the machine. Not these kind of big daddy policing decisions.
Defender working this way by default is a ‘big daddy policing decision’. The default should be to not do this, and people that want it should have to enable it via Group Policy.
Are you saying that insecure by default is a good idea?
Defender enabled by default would save billions annually, and not just from businesses but also grandma who’s entire photo collection just got ransomware’d.
That big daddy policing move was the single best action taken by Microsoft.