The option to upload unknown files to MetaDefender is the Cloud scan unknown files option in your portal settings (for Windows endpoints: Endpoint Privilege Management > Settings > Windows Settings > Malware > DETECT):
A similar setting is available for Mac endpoints.
If you turn off “Cloud scan unknown files” but leave “Real-time detection” on, only checksum lookup for the known 75% is performed and the rest must be handled by your local endpoint anti-virus product.
It is not recommended to ever disable the “Real-time detection” option, simply because there is no drawback to having it on. The extra wait time for the end user is a tenth of a second.
The file scanning flow looks like this:
Refer to OPSWAT MetaDefender for more information.