You can configure settings and run Adaptive Threat Protection in Observe mode to determine how often a file is seen in your environment. You can then adjust settings or reputations, as needed.
Configure Adaptive Threat Protection settings to determine what is blocked, allowed, or contained.
Run Adaptive Threat Protection in Observe mode to build file prevalence and see what Adaptive Threat Protection detects in your environment. Adaptive Threat Protection generates Would Block, Would Clean, and Would Contain events to show what actions it would take. File prevalence indicates how often a file is seen in your environment.
Caution
Because enabling this mode causes Adaptive Threat Protection to generate events but not enforce actions, your systems might be vulnerable to threats.
Monitor and adjust settings, or individual file or certificate reputations, to control what is allowed in your environment.