Microsoft Defender for Endpoint
Endpoint protection

Address false positives/negatives in Microsoft Defender for Endpoint

In brief

The article now provides workflows for identifying detection sources, classifying and suppressing alerts, reviewing remediation, configuring exclusions, submitting files, and investigating suspected false negatives. Definitions, response guidance, links, and metadata were also updated.

What Defender admins need to know

Administrators have clearer source-specific steps for investigating and resolving detection issues.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Address false positives/negatives in Microsoft Defender for Endpoint

In endpoint protection solutions, a false positive is an entity, such as a filefile, process, or a process that was detected andother entity incorrectly identified as malicious even though the entity isn't actuallymalicious. A false negative is a threat. A false negative is anmalicious entity that wasnthe solution doesn't detected as a threat, even though it actually is malicious.detect. False positives/positives and false negatives can occur with any threat protection solution, including Microsoft Defender for Endpoint.

Use the workflows in this article to identify the detection source, classify and suppress alerts, review remediation actions, configure exclusions, submit files for analysis, and investigate suspected false negatives. Complete the portal procedures in the Microsoft Defender portal. If you haveuse Microsoft Defender XDR, reviewfirst identify the "Alerts sources"alert source as described in Investigate alerts in Microsoft Defender XDR. IfContinue with this article if the alert source is Defender for Endpoint, continue to read this article. Endpoint.

Prerequisites

Supported operating systems

  • WindowsWindows.

Identify the detection source

When you haveFor a false positive, a good first step is to try to determine itsidentify the detection source. The following table lists detection sources and potential solutions.Use the source to choose the appropriate response.

Detection source InformationRecommended response
Endpoint Detectiondetection and Responseresponse (EDR) The alert is related to EDR in Defender for Endpoint
- Solution:
Submit the false positive to the Microsoft Security Intelligence submission portal
- Work-around: Add
. You can also add an EDR exclusion or tune the alertsalert.
Microsoft Defender Antivirus The alert relates toIf Microsoft Defender Antivirus is in active mode (primary) where it blocks.
- Solution: Submit
mode, submit the false positive to the Microsoft Security Intelligence submission portal
- Work-around: Add
. As a temporary mitigation, create a file allow indicator or an antivirus exclusion

. If Microsoft Defender Antivirus is in passive mode, EDR in block mode might just detect.detect the threat.
Custom TIthreat intelligence Custom indicators:
-
Review custom indicators for file hashes
-
, IP addresses or URLs
-
, and certificates. To update them, see Manage indicators.

Solution: Manage indicators.

Or, if you see
A CustomEnterpriseBlock, your detection source could be one of the following capabilities in Defender for Endpoint: can also originate from:

1. Automated investigation and remediation
-- Solution:
. Submit the false positive to the Microsoft Security Intelligence submission portal
-- Work-around:
, or configure automation folder exclusions.

2. Custom detection rules deriving frombased on advanced hunting
-- Solution:
. Manage the custom detection rule.

3. EDR in block mode
-- Solution:
, live response, or potentially unwanted application protection. Submit the false positive to the Microsoft Security Intelligence submission portal
-- Work-around:
. As a temporary mitigation, create a file allow indicator or an antivirus exclusion

4. Live response
-- Solution: Submit the false positive to https://aka.ms/wdsi
-- Work-around: Indicators – File hash – allow or Antivirus exclusions

5. PUA protection
-- Solution: Submit the false positive to https://aka.ms/wdsi
-- Work-around: Indicators – File hash – allow or Antivirus exclusions
.
SmartscreenMicrosoft Defender SmartScreen Smartscreen: You can Report an unsafe siteReport an unsafe site or submit a network protection detection. For more information, see Microsoft Defender SmartScreen.

False positives and how to address them

:::image type="content" source="media/false-positives-overview.png" alt-text="Screenshot displaying theof definitions offor false positives and false negatives in the Microsoft Defender portal." lightbox="media/false-positives-overview.png":::

Fortunately, steps can be takenUse the following five-part workflow to address false positives and reduce these kinds of issues. future occurrences.

:::image type="content" source="media/false-positives-step-diagram.png" alt-text="The steps to addressDiagram that shows the five-part workflow for addressing false positives and negativesfalse negatives." lightbox="media/false-positives-step-diagram.png":::

Part 1: Review and classify alerts

If you see an alert that arose because something's detectedincorrectly identifies an entity as malicious or suspicioussuspicious, classify the alert and it shouldn't be, you can suppress the alertconsider suppressing similar alerts for that entity. You can also suppress accurate alerts for events that aren't necessarily false positives, but are unimportant. We recommend that you also classify alerts.important to your organization.

Managing yourClassifying alerts and classifying true/false positives helps to train yourimprove threat protection solution and can reduce the number of false positives orand false negatives over time. Taking these steps also helpsSuppression rules reduce queue noise in your queue so that your security team can focus on higher higher-priority work items.work.

Determine whether an alert is accurate

Before you classify or suppress an alert, determine whether the alert is accurate, a false positive, or benign.

  1. InOn the Microsoft Defender portal,Alerts page in the navigation pane, choose Incidents & alerts and thenDefender portal at https://security.microsoft.com/alerts, select Alerts.an alert.

  2. Select anReview the alert to viewdetails. For more details about it. (To get help with this task,information, see Review alerts in Defender for Endpoint.)

  3. Depending on the alert status, take the steps described in the following table:

    Alert statusassessment What to do
    The alert is accurate Assign the alert, and then investigate it further.
    The alert is a false positive 1. Classify the alert as a false positive.

    2. Suppress the alert.

    3. Create an indicator for Microsoft Defender for Endpoint.

    4. Submit a file to Microsoft for analysis.

Classify an alert

Alerts can be classifiedClassify alerts as false positives or true positives in the Microsoft Defender portal. Classifying alertsClassification helps trainimprove Defender for Endpoint so that over time, you'll see more trueaccurate alerts and fewer false alerts.over time.

  1. InOn the Microsoft Defender portal,Alerts page in the navigation pane, choose Incidents & alertsDefender portal at https://security.microsoft.com/alerts, select Alerts and then select an alert.

  2. For the selected alert, select Manage alert. A flyout pane opens.

  3. In the Manage alert section, in theUnder Classification field, classify the alert (True positive, , select True positive, Informational, expected activity,activity, or False positive)positive.

Suppress an alert

If you have alerts that are eitherSuppress false positives or that are true positives butand accurate alerts for unimportant events, you can suppress those alerts in the Defender portal. Suppressing alerts helpsevents to reduce noise in your alert queue.

  1. InOn the Microsoft Defender portal,Alerts page in the navigation pane, choose Incidents & alerts and thenDefender portal at https://security.microsoft.com/alerts, select Alerts.

  2. Select anthe alert that you want to suppress to open its Details pane.suppress.

  3. In the Details pane, chooseselect the ellipsis (...), and then select Create suppression rule.

  4. Specify allConfigure the settings for your suppression rule, and then chooseselect Save.

Part 2: Review remediation actions

Remediation actions, such as sendingquarantining a file to quarantine or stopping a process, are taken onapply to entities (such as files) that are detected as threats. Several types of remediation actions occur automatically through automatedAutomated investigation and Microsoft Defender Antivirus:Antivirus can take the following actions automatically:

  • Quarantine a filefile.
  • Remove a registry key
  • Kill a processkey.
  • Stop a serviceprocess.
  • Stop a service.
  • Disable a driverdriver.
  • Remove a scheduled tasktask.

Other actions, such as starting an antivirus scan or collecting an investigation package, occur manually or through live response. ActionsYou can't undo actions taken through Live Response can't be undone.live response.

After you've reviewed your review alerts, your next step is to review remediation actions. If any actions were taken as a result of false positives, youYou can undo most kinds of remediation actions. Specifically, you can:actions caused by false positives:

WhenAfter you're done reviewing review and undoingundo actions that were taken as a result ofcaused by false positives, proceed to review or define exclusions.

Review completed actions

Review the Action center history to see completed remediation actions:

  1. InOn the Microsoft Defender portal, select Actions & submissions and then select Action center.

  2. Select page in the Defender portal at https://security.microsoft.com/action-center, select the History tab to view a list of actions that were taken.tab.

  3. Select an item to view more details about the completed remediation action that was taken.action.

Restore a quarantined file from the Action Centercenter

Undo a quarantine action for a single file from Action center:

  1. InOn the Microsoft Defender portal, select Actions & submissions and then select Action center.

  2. On page in the Defender portal at https://security.microsoft.com/action-center, select the History tab, and then select anthe action that you want to undo.

  3. In the flyout pane, select Undo. If the action can't be undone with this method, you don't see anundone, the Undo button. (To learn more,button isn't available. For more information, see Undo completed actions.)

Undo multiple actions at one time

  1. In the Microsoft Defender portal, select Actions & submissions and then select Undo several completed actions together from Action center.center:

    1. On the Action center page in the Defender portal at https://security.microsoft.com/action-center, select the History tab, and then select the actions that you want to undo.

    2. In the flyout pane on the right side of the screen,pane, select Undo.

    Remove a file from quarantine acrosson multiple devices

    Apply an undo action to other instances of the same quarantined file:

    [!div class="mx-imgBorder"] :::image type="content" source="media/autoir-quarantine-file-1.png" alt-text="The QuarantineScreenshot of a quarantined file action in the Defender portal Action center." lightbox="media/autoir-quarantine-file-1.png":::

    1. InOn the Microsoft Defender portal, select Actions & submissions and then select Action center.

    2. On page in the Defender portal at https://security.microsoft.com/action-center, select the History tab, and then select a file that haswith the Action type value Quarantine file.

    3. In the pane on the right side of the screen,flyout pane, select Apply to X more instances of this file, and then select Undo.

    Review quarantined messages

    Review quarantined email messages in Exchange message trace:

    1. InOn the Microsoft Defender portal, in the navigation pane, under Email & collaboration, select Exchange message trace. page in the Defender portal at https://security.microsoft.com/messagetrace, select a message.

    2. Select aReview the message to view details.

    Restore a file from quarantine

    You can roll back and removeIf an investigation determines that a quarantined file from quarantine if you determineis safe, restore it's clean after an investigation. Do the following steps on each device whereaffected device.

    The following commands open the file was quarantined:

    In an elevatedlatest Microsoft Defender Antivirus platform folder and restore all files with the specified threat name. Run them in a Command Prompt (a Command Prompt window that you opened by selecting Run as administrator), run the following commands::

    Part 3: Review or define exclusions

    An exclusion is an entity, such as a file or URL, that you specify as an exception toexempt from remediation actions. The excluded entityDefender for Endpoint can still get detected,detect the entity, but no remediation actions are taken on that entity. That is, the detected file or process isnit doesn't stopped, sent tostop, quarantine, removed,remove, or otherwise changed by Microsoft Defender for Endpoint.change it.

    To define exclusions across Microsoftfor Defender for Endpoint, docomplete the following tasks:

    The procedures in this section describe how to define indicators and exclusions.

    Indicators for Defender for Endpoint

    Indicators (specifically,, specifically indicators of compromise, or IoCs) enablecompromise (IoCs), let your security operations team to definecontrol the detection, prevention, and exclusion of entities. For example, you can specify certainexempt specific files to be omitted from scans and remediation actions in Microsoft Defender for Endpoint. Or, indicators can be used toor generate alerts for certain files, IP addresses, or URLs.

    To specifyexempt entities as exclusions forin Defender for Endpoint, create "allow" indicators for those entities. Such "allow" indicators. Allow indicators apply to next-generation protection and automated investigation and remediation.

    "Allow"You can create allow indicators can be created for:

    :::image type="content" source="media/false-positives-indicators.png" alt-text="The IndicatorScreenshot of the indicator types available in the Microsoft Defender portal." lightbox="media/false-positives-indicators.png":::

    Indicators for files

    When you create an allow indicator for a file, such as an executable, it helpsyou help prevent Defender for Endpoint from blocking trusted files thatin your organization is using from being blocked. Files canorganization. Supported files include portable executable (PE) files, such as .exe and .dll files.

    Before you create indicators for files, make sure the following requirements are met:

    • Microsoft Defender Antivirus is configured withhas cloud-based protection enabled (see Manage cloud-based protection)enabled. For more information, see Manage cloud-based protection.
    • AntimalwareThe antimalware client version is 4.18.1901.x or laterlater.
    • Client devices must be runningrun Windows 11 or Windows 10, version 1703 or laterlater.
    • Server devices must be runningrun Windows Server 2016 and lateror later.
    • Windows Server 2012 R2 withdevices use the modern unified solution.
    • The block or allow feature is turned on.
    • Devices run Azure Stack HCI OS, version 23H2 andor later.

    Indicators for IP addresses, URLs, or domains

    When you create an allow indicator for an IP address, URL, or domain, it helpsyou help prevent the sites or IP addresses your organization usesDefender for Endpoint from being blocked.blocking trusted network destinations.

    Before you create indicators for IP addresses, URLs, or domains, make sure the following requirements are met:

    • Network protection in Defender for Endpoint is enabled in block mode (seemode. For more information, see Enable network protection).
    • AntimalwareThe antimalware client version is 4.18.1906.x or laterlater.
    • Devices are runningrun Windows 10, version 1709,1709 or later, or Windows 1111.

    Custom network indicators are turned on in the Microsoft Defender XDR. To learn more,For more information, see Advanced features.

    Indicators for application certificates

    When you create an allow indicator for an application certificate, it helpsyou help prevent Defender for Endpoint from blocking trusted applications, such as internally developed applications, that your organization uses from being blocked.applications. The supported file extensions are .CER orand .PEM file extensions are supported..

    Before you create indicators for application certificates, make sure the following requirements are met:

    • Microsoft Defender Antivirus is configured withhas cloud-based protection enabled. For more information, see:see Manage cloud-based protection.
    • AntimalwareThe antimalware client version is 4.18.1901.x or laterlater.
    • Devices are running either:run one of the following operating systems:
      • Windows 10, version 1703 or laterlater, or Windows 1111.
      • Windows Server 2012 R2 andor later with the modern unified solution.
      • Azure Stack HCI OS, version 23H2 and lateror later.
    • Virus and threat protection definitions are up to datedate.

    Exclusions for Microsoft Defender Antivirus

    In general, you shouldn't need to define exclusions for Microsoft Defender Antivirus. Make sure that you defineAntivirus exclusions. Define exclusions sparingly,sparingly and that you only include thefor files, folders, processes, and process-opened files that are resulting incause false positives. In addition, make sure to review your definedReview exclusions regularly. We recommend using Microsoft Intune to define or edit yourconfigure antivirus exclusions; however, youexclusions. You can also use other methods, such as Group Policy (see Manage Microsoft Defender for Endpoint).

    Use Intune to manage antivirus exclusions (for existing policies)

    To manage antivirus exclusions with Microsoft Intune, see Modify existing policies (opens in a new tab in the Intune documentation). Choose the following options:

    • Policy: Antivirus, then select your Microsoft Defender Antivirus policy
    • Microsoft Defender Antivirus Exclusions: Specify your exclusions.
      • Excluded Extensions are exclusions that you define by file type extension. These extensions apply to any file name that has the defined extension without the file path or folder. Separate each file type in the list must be separated with a | character. For example, lib|obj. For more information, see ExcludedExtensionsManage Microsoft Defender for Endpoint.
      • Excluded Paths are exclusions that you define by their location (path). These types of exclusions are also known as file

        For supported configuration methods and folder exclusions. Separate each path in the list with a | character. For example, C:\Example|C:\Example1. For more information,detailed procedures, see ExcludedPathsConfigure and validate exclusions for Microsoft Defender Antivirus.

      • Excluded Processes are exclusions for files that are opened by certain processes. Separate each file type in the list with a | character. For example, C:\Example. exe|C:\Example1.exe. These exclusions aren't for the actual processes. To exclude processes, you can use file and folder exclusions. For more information, see ExcludedProcesses.

    Use Intune to create a new antivirus policy with exclusions

    To create a new antivirus policy with exclusions in Microsoft Intune, see Create an endpoint security policy (opens in a new tab in the Intune documentation). When creating the policy, use these settings:

    • Policy type: Antivirus
    • Platform: Windows 10, Windows 11, and Windows Server
    • Profile: Microsoft Defender Antivirus exclusions
    • Configuration settings: Specify your antivirus exclusions.
      • Excluded Extensions are exclusions that you define by file type extension. These extensions apply to any file name that has the defined extension without the file path or folder. Separate each file type in the list with a | character. For example, lib|obj. For more information, see ExcludedExtensions.
      • Excluded Paths are exclusions that you define by their location (path). These types of exclusions are also known as file and folder exclusions. Separate each path in the list with a | character. For example, C:\Example|C:\Example1. For more information, see ExcludedPaths.
      • Excluded Processes are exclusions for files that are opened by certain processes. Separate each file type in the list with a | character. For example, C:\Example. exe|C:\Example1.exe. These exclusions aren't for the actual processes. To exclude processes, you can use file and folder exclusions. For more information, see ExcludedProcesses.
    • Scope tags: If you're using scope tags in your organization, specify scope tags for the policy you're creating. (See Scope tags.)
    • Assignments: specify the users and groups to whom your policy should be applied, and then choose Next. (If you need help with assignments, see Assign user and device profiles in Microsoft Intune.)

    Part 4: Submit a file for analysis

    You can submit entities, such as filesfiles, fileless detections, and fileless detections,other entities to Microsoft for analysis. Microsoft security researchers analyze all submissions, and their results help informsubmissions to improve Defender for Endpoint threat protection capabilities. When you signprotection. Sign in atto the submission site, you cansite to track your submissions.

    Submit hashes for analysis

    To investigate hashes, useUse the Microsoft Security Intelligence submission portal web portal. A maximum ofto submit up to 100 hashes can be submitted. Thefor analysis. Include the source of the Indicatoreach indicator of Compromise (IOC)compromise (IoC), must be provided. This can besuch as a blog post,post or security article, or any other relevant source.article.

    Submit a file for analysis

    If you haveDefender for Endpoint incorrectly detects or misses a file that was either wrongly detected as malicious or was missed, follow these steps tofile, submit the file for analysis.analysis:

    1. Review the guidelines here: file submission guidelines.

    2. Submit files in Defender for Endpoint, or visitsubmit them through the Microsoft Security Intelligence submission site and submit your files..

    Submit a fileless detection for analysis

    If something was detected asDefender for Endpoint detects malware based on behavior,behavior and you don't have a file, you canfile to submit, submit yourthe MpSupportFiles.cab diagnostic file for analysis. You can get the .cab file by usinginstead. Use the MpCmdRun command-line tool on Windows 10 or Windows 11.11 to generate the .cab file.

    1. Generate the file C:\ProgramData\Microsoft\Windows Defender\Support\MpSupportFiles.cab as described in Collect Microsoft Defender Antivirus diagnostic data.

    2. Review the guidelines here: file submission guidelines.

    3. VisitSubmit the .cab file through the Microsoft Security Intelligence submission site, and submit your .cab files..

    What happens after a file is submitted?

    YourMicrosoft systems scan your submission is immediately scanned by our systems to give youand provide the latest available determination even before an analyst starts handling yourreviews the case. It's possible that a fileIf an analyst already processed the file, you might have already been submitted and processed by an analyst. In those cases,receive a determination is made quickly.

    ForMicrosoft prioritizes unprocessed submissions that weren't already processed, they're prioritized for analysis as follows:

    • Prevalent files with the potential toFiles that are prevalent and might affect a large number of computers are given amany devices receive higher priority.
    • AuthenticatedSubmissions from authenticated customers, especially enterprise customers with valid Software Assurance IDs (SAIDs)Software Assurance IDs (SAIDs), are given areceive higher priority.
    • Submissions flaggedmarked as high priority by SAID holders are givenreceive immediate attention.

    To check for updates regardingthe status of your submission, sign in atto the Microsoft Security Intelligence submission site.

    Part 5: Review and adjust your threat protection settings

    Defender for Endpoint offers a wide variety of options, including the ability to fine-tune settings for various features and capabilities. If you're getting numerous receive many false positives, make sure to review your organization'sthe following threat protection settings. You might need to make some adjustments to:settings:

    Cloud-delivered protection

    Check yourthe cloud-delivered protection level for Microsoft Defender Antivirus. By default, cloud-delivered protectionThe default policy setting is set to Not configured; however,, but we recommend turning it on. To learn more about configuring youron cloud-delivered protection,protection. For configuration instructions, see Turn on cloud protection in Microsoft Defender Antivirus.

    If your organization has Microsoft Intune, you can use it to configure cloud-delivered protection. Intune is a separate product and isn't included in all subscriptions. For licensing information, see Microsoft Intune licensing. You can also use Intune or other methods,methods described in the configuration article, such as Group Policy, to edit or set your cloud-delivered protection settings.

    See Turn on cloud protection in Microsoft Defender Antivirus.

    Remediation for potentially unwanted applications

    Potentially unwanted applications (PUA) are a category of software that can cause devices to run slowly, display unexpected ads, or install other software that might be unexpected or unwanted.software. Examples of PUA include advertising software, bundling software,advertising, bundling, and evasion software that behaves differently withwhen security products.products are present. Although PUA isn't considered malware, security products classify some kinds of software areas PUA based on theirits behavior and reputation.

    To learn more about PUA, see Detect and block potentially unwanted applicationsDetect and block potentially unwanted applications.

    Depending on theYour PUA protection settings might cause false positives for apps that your organization is using, you might be getting false positives as a result of your PUA protection settings.uses. If necessary, consider runningneeded, run PUA protection in audit mode for a while,temporarily or apply PUA protectionit to a subset of devices in your organization.devices. You can configure PUA protection can be configured for the Microsoft Edge browser and for Microsoft Defender Antivirus.

    WeIf your organization has Microsoft Intune, we recommend using Intuneit to edit or setconfigure PUA protection settings; however,protection. Intune is a separate product and isn't included in all subscriptions. For licensing information, see Microsoft Intune licensing. If you candon't have Intune, use other methods,another method in Configure PUA protection in Microsoft Defender Antivirus, such as Group Policy.

    See Configure PUA protection in Microsoft Defender Antivirus.

    Automated investigation and remediation

    Automated investigation and remediation (AIR) capabilities are designed to examineexamines alerts and can take immediate action to resolve breaches. As alerts are triggered, andDuring an automated investigation runs, a verdict is generated forinvestigation, AIR assigns each piece of evidence investigated. Verdicts can bea verdict: Malicious, Suspicious, or No threats found.

    Depending on the level of automation set for your organization's automation level and other security settings, remediation actions are taken onAIR can remediate artifacts that are considered to bewith Malicious or Suspicious. In some cases, remediation actions occur automatically; in other cases, remediation actions are taken manually verdicts automatically, manually, or only uponafter approval by your security operations team.

    False negatives and how to address them

    A false negative occurs when a malicious entity (such as a file, process, or network connection) isn't detected by Defender for Endpoint. False negatives can result from outdated security intelligence, misconfigured features, or threats that evade existing signatures.

    Verify a suspected false negative

    Before you report a false negative, confirm that the suspicious activity occurred without a corresponding detection. Compare endpoint behavior in the device timeline with advanced hunting results in the Defender portal.

    1. On the Device inventory page of the Defender portal at https://security.microsoft.com/machines, select the affected device.

    2. On the device entity page that opens, select the Timeline tab and look for events that correspond to the suspicious activity (for example, file creation, process execution, or network connections during the expected time frame).

    3. On the Advanced hunting page in the Defender portal at https://security.microsoft.com/v2/advanced-hunting, query the relevant tables for activity throughout your environment. For example, the following query finds file-creation events for a specific file hash:

      DeviceFileEvents
      | where SHA1 == "<hash>"
      | where ActionType == "FileCreated"
      

      The following query finds network activity for a suspicious domain:

      DeviceNetworkEvents
      | where RemoteUrl has "<suspicious-domain>"
      
    4. If the logs contain the activity but Defender for Endpoint didn't generate an alert, collect evidence for escalation.

    Collect evidence for false negative escalation

    Before you submit a false negative to Microsoft, gather the following forensic artifacts:

    • Endpoint support files: Generate the diagnostic package C:\ProgramData\Microsoft\Windows Defender\Support\MpSupportFiles.cab by running MpCmdRun.exe -GetFiles in an elevated Command Prompt. For instructions, see Collect Microsoft Defender Antivirus diagnostic data.

    • Process execution details: Document the process tree, command-line parameters, and parent processes associated with the suspicious activity. Find these details in the device timeline or query the DeviceProcessEvents table in advanced hunting.

    • Network flow data: If the threat involves network connections, capture relevant connection details (remote IPs, domains, ports) from the DeviceNetworkEvents table.

    • Memory dumps or sandbox traces: If possible, capture memory dumps or sandbox execution traces from the affected device to help Microsoft analyze the threat behavior. You can also collect an investigation package from the device in the Defender portal.

    • Raw event data: Export relevant events from advanced hunting in the Microsoft Defender portal for inclusion in your submission.

    Submit false negatives for analysis

    After you gather the evidence, submit the false negative to Microsoft by using one of the following methods:

    Mitigate threats while awaiting analysis

    After you submit a false negative, the threat might remain active in your environment. Use custom indicators in Defender for Endpoint to block known malicious entities until Microsoft updates its detections:

    Custom indicators apply throughout your organization and provide immediate protection while Microsoft analyzes the submission.

    Check endpoint health and configuration

    Outdated security intelligence or disabled protection features can cause false negatives. Check endpoint health on the affected device:

    1. Run the following command in an elevated PowerShell window to check the engine and security intelligence versions:

      Get-MpComputerStatus | Select-Object AMServiceVersion, AMProductVersion, AMEngineVersion, AntispywareSignatureVersion, AntivirusSignatureVersion
      
    2. Confirm that security intelligence updates are current. If the versions are outdated, run the following command to update them:

      Update-MpSignature
      
    1. Verify that key protection features are enabled. False negatives can occur if the following features are disabled or misconfigured:

    2. Check that the device platform and operating system are up to date. Older builds might not include detection capabilities available in newer versions.

    Still need help?

    If you've worked through all the stepsissue remains after you complete the workflows in this article and still need help,article, contact technicalMicrosoft support.

    1. In the Microsoft Defender portal, inupper-right corner of the upper right corner,Defender portal at https://security.microsoft.com, select the question mark (?), and then select Microsoft support.

    2. In the Support Assistant window, describe your issue, and then send your message. From there, you can open a service request.