Microsoft Defender Antivirus in the Windows Security app

Applies to:

  • Microsoft Defender for Endpoint Programme 1
  • Microsoft Defender for Endpoint Plan 2

In Windows 10, version 1703 and afterward, the Windows Defender app is office of the Windows Security.

Settings that were previously part of the Windows Defender client and main Windows Settings have been combined and moved to the new app, which is installed past default every bit part of Windows 10, version 1703.

Important

Disabling the Windows Security app service does non disable Microsoft Defender Antivirus or Windows Defender Firewall. These are disabled automatically when a tertiary-party antivirus or firewall product is installed and kept up to date.

If you lot do disable the Windows Security app service, or configure its associated Grouping Policy settings to prevent it from starting or running, the Windows Security app might display stale or inaccurate information virtually any antivirus or firewall products you accept installed on the device. Information technology might also prevent Microsoft Defender Antivirus from enabling itself if you take an quondam or outdated third-political party antivirus, or if you uninstall any third-party antivirus products you might have previously installed. This will significantly lower the protection of your device and could lead to malware infection.

See the Windows Security commodity for more information on other Windows security features that can exist monitored in the app.

The Windows Security app is a client interface on Windows x, version 1703 and later. It is not the Microsoft 365 Defender web portal that is used to review and manage Microsoft Defender for Endpoint.

Review virus and threat protection settings in the Windows Security app

Virus and threat protection settings in Windows Security app

  1. Open the Windows Security app past clicking the shield icon in the task bar or searching the start menu for Windows Security.

  2. Select the Virus & threat protection tile (or the shield icon on the left carte bar).

The post-obit sections describe how to perform some of the most common tasks when reviewing or interacting with the threat protection provided by Microsoft Defender Antivirus in the Windows Security app.

Notation

If these settings are configured and deployed using Group Policy, the settings described in this department will exist greyed-out and unavailable for use on individual endpoints. Changes made through a Grouping Policy Object must first be deployed to private endpoints earlier the setting will be updated in Windows Settings. The Configure end-user interaction with Microsoft Defender Antivirus topic describes how local policy override settings can be configured.

Run a scan with the Windows Security app

  1. Open the Windows Security app past searching the start menu for Security, and then selecting Windows Security.

  2. Select the Virus & threat protection tile (or the shield icon on the left card bar).

  3. Select Quick browse. Or, to run a total scan, select Scan options, and then select an option, such as Full browse.

Review the security intelligence update version and download the latest updates in the Windows Security app

Security intelligence version number

  1. Open the Windows Security app by searching the start carte du jour for Security, and then selecting Windows Security.

  2. Select the Virus & threat protection tile (or the shield icon on the left card bar).

  3. Select Virus & threat protection updates. The currently installed version is displayed along with some information almost when it was downloaded. You can check your current against the latest version available for manual download, or review the change log for that version. Encounter Security intelligence updates for Microsoft Defender Antivirus and other Microsoft antimalware.

  4. Select Check for updates to download new protection updates (if there are any).

Ensure Microsoft Defender Antivirus is enabled in the Windows Security app

  1. Open up the Windows Security app by searching the offset carte du jour for Security, and so selecting Windows Security.

  2. Select the Virus & threat protection tile (or the shield icon on the left menu bar).

  3. Select Virus & threat protection settings.

  4. Toggle the Existent-time protection switch to On.

    Annotation

    If you switch Real-fourth dimension protection off, information technology will automatically plough dorsum on after a short filibuster. This is to ensure yous are protected from malware and threats. If you install some other antivirus product, Microsoft Defender Antivirus automatically disables itself and is indicated as such in the Windows Security app. A setting will appear that will allow you to enable limited periodic scanning.

Add exclusions for Microsoft Defender Antivirus in the Windows Security app

  1. Open up the Windows Security app by searching the offset menu for Security, and then selecting Windows Security.

  2. Select the Virus & threat protection tile (or the shield icon on the left card bar).

  3. Under Virus & threat protection settings, select Manage settings.

  4. Nether Exclusions, select Add together or remove exclusions.

  5. Select the plus icon (+) to choose the type and set the options for each exclusion.

The post-obit tabular array summarizes exclusion types and what happens:



Exclusion type Defined past What happens
File Location
Example: c:\sample\sample.test
The specific file is skipped by Microsoft Defender Antivirus.
Folder Location
Example: c:\test\sample
All items in the specified folder are skipped past Microsoft Defender Antivirus.
File type File extension
Example: .test
All files with the .exam extension anywhere on your device are skipped by Microsoft Defender Antivirus.
Process Executable file path
Instance: c:\exam\process.exe
The specific process and whatsoever files that are opened by that process are skipped past Microsoft Defender Antivirus.

To acquire more, run across the following resources:

  • Configure and validate exclusions based on file extension and folder location
  • Configure exclusions for files opened by processes

Review threat detection history in the Windows Defender for Cloud app

  1. Open up the Windows Security app by searching the start carte for Security, and then selecting Windows Security.

  2. Select the Virus & threat protection tile (or the shield icon on the left menu bar).

  3. Select Protection history. Any recent items are listed.

Prepare ransomware protection and recovery options

  1. Open up the Windows Security app past searching the start card for Security, and then selecting Windows Security.

  2. Select the Virus & threat protection tile (or the shield icon on the left menu bar).

  3. Under Ransomware protection, select Manage ransomware protection.

  4. To change Controlled folder admission settings, see Protect important folders with Controlled binder access.

  5. To set up ransomware recovery options, select Set up under Ransomware data recovery and follow the instructions for linking or setting up your OneDrive business relationship so you can easily recover from a ransomware attack.

See besides

  • Microsoft Defender Antivirus