It is not necessary to exclude Microsoft defrag. For third party defrag, if they are signed, and if they touch executable files, they may turn into trusted installer. In trusted installer, every executable that it writes will be automatically trusted. Usually we may don't want this behavivour, so you may add them in the restricted application list (Settings->Application Whitelisting->Advanced Settings).