Microsoft Defender for Endpoint
Endpoint protection

Manage Microsoft Defender Antivirus updates and scans for endpoints that are out of date

In brief

The article now provides updated GPMC navigation, uses “Security Intelligence Updates” terminology, notes older Windows naming, and adds detailed editing steps plus local Group Policy guidance.

What Defender admins need to know

Administrators can more easily locate and configure catch-up update and scan settings across supported Windows versions.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Manage Microsoft Defender Antivirus updates and scans for endpoints that are out of date

With Microsoft Defender Antivirus, your security team can define how long an endpoint can avoid an update or how many scans it can miss before it's required to receive the update and run a scan. This article shows how to configure catch-up protection updates, set the out-of-date reporting threshold, and enable catch-up scans for endpoints that have missed scheduled updates or scans. This capability is especially useful in environments where devices aren't often connected to a corporate or external network, or for devices that aren't used on a daily basis.

Prerequisites

Supported operating systems

The following operating systems support catch-up protection updates and catch-up scans:

To enable and configure the catch-up update feature in Group Policy, use the following steps:

  1. OnIn Centralized Group Policy, open the Group Policy Management Console (GPMC) on your Group Policy management computer, opencomputer.

  2. In the Group Policy Management Console. Right-click theGPMC console tree, expand Group Policy ObjectObjects in the forest and domain containing the GPO you want to configureedit.

  3. Right-click the GPO, and then select Edit.

  4. In the Group Policy Management Editor, go to Computer configuration.

  5. Select Policies then > Administrative templates.

  6. Expand the tree to > Windows components > Microsoft Defender Antivirus > SignatureSecurity Intelligence Updates.

  7. Double-click the Define the number of days after which a catch-up security intelligence update is required setting and set the option to Enabled. Enter the number of days after which you want Microsoft Defender Antivirus to check for and download the latest protection update.

  8. Select OK.

Use PowerShell cmdlets to configure catch-up protection updates

To specify when protection is considered out of date by using Group Policy, use the following steps:

  1. On

    1. In the details pane of Security Intelligence Updates, open the Define the number of days after which a catch-up security intelligence update is required setting. To open the setting, use any of the following methods:

      • Double-click the setting.
      • Right-click the setting, and then select Edit.
      • Select the setting, and then select Action > Edit.
    2. In the setting window that opens, configure the following options:

      1. Select Enabled.
      2. Enter the number of days after which you want Microsoft Defender Antivirus to check for and download the latest protection update.

      When you're finished, select OK.

    Use PowerShell cmdlets to configure catch-up protection updates

    To specify when protection is considered out of date by using Group Policy, use the following steps:

    1. In Centralized Group Policy, open the Group Policy Management Console (GPMC) on your Group Policy management machine, opencomputer.

    2. In the Group Policy Management Console, right-click theGPMC console tree, expand Group Policy ObjectObjects in the forest and domain containing the GPO you want to configureedit.

    3. Right-click the GPO, and then select Edit.

    4. In the Group Policy Management Editor, go to Computer configuration.

    5. Select Policies then > Administrative templates.

    6. Expand the tree to > Windows components > Microsoft Defender Antivirus > SignatureSecurity Intelligence Updates and configure the following settings:

      1. Double-click Define the number of days before spyware definitions are considered out of date and set the option to Enabled. Enter the number of days after which you want Microsoft Defender Antivirus to consider spyware Security intelligence to be out of date.

      2. Select OK.

      3. Double-click Define the number of days before virus definitions are considered out of date and set the option to Enabled. Enter the number of days after which you want Microsoft Defender Antivirus to consider virus Security intelligence to be out of date.

      4. Select OK.

      1. In the details pane of Security Intelligence Updates, the available settings are:

        To open and configure a security intelligence age setting, use any of the following methods:

        • Double-click the setting.
        • Right-click the setting, and then select Edit.
        • Select the setting, and then select Action > Edit.

      Set up catch-up scans for endpoints that haven't been scanned for a while

      1. Ensure you set up at least one scheduled scan.

      2. On

        Enable and configure the spyware security intelligence age setting

        1. In the details pane of Security Intelligence Updates, open the Define the number of days before spyware security intelligence is considered out of date setting.

        2. In the setting window that opens, configure the following options:

          1. Select Enabled.
          2. Define the number of days before spyware security intelligence is considered out of date in the Options section: Enter the number of days after which you want Microsoft Defender Antivirus to consider spyware security intelligence to be out of date.

          When you're finished, select OK.

        Enable and configure the virus security intelligence age setting

        1. In the details pane of Security Intelligence Updates, open the Define the number of days before virus security intelligence is considered out of date setting.

        2. In the setting window that opens, configure the following options:

          1. Select Enabled.
          2. Define the number of days before virus security intelligence is considered out of date in the Options section: Enter the number of days after which you want Microsoft Defender Antivirus to consider virus security intelligence to be out of date.

          When you're finished, select OK.

        Set up catch-up scans for endpoints that haven't been scanned for a while

        1. Ensure you set up at least one scheduled scan.

        2. In Centralized Group Policy, open the Group Policy Management Console (GPMC) on your Group Policy management machine, opencomputer.

        3. In the Group Policy Management Console, right-click theGPMC console tree, expand Group Policy ObjectObjects in the forest and domain containing the GPO you want to configureedit.

        4. Right-click the GPO, and then select Edit.

        5. In the Group Policy Management Editor, go to Computer configuration.

        6. Select Policies then > Administrative templates > Windows components > Microsoft Defender Antivirus > Scan.

        1. In the details pane of Scan, the available settings are:

          Expand the tree to Windows components > Microsoft Defender Antivirus > ScanTo open and configure the following settings:

          • If you have set up scheduled quick scans, double-click the Turn on catch-up quick scan setting and set the option to Enabled.
          • If you have set up scheduled full scans, double-click the Turn on catch-up full scan setting and set the option to Enabled. Select OK.
          • Double-click the Define the number of days after which a catch-up scan is forced settingsetting, use any of the following methods:
            • Double-click the setting.
            • Right-click the setting, and set the option tothen select EnabledEdit.
            • EnterSelect the number of scans that can be missed before a scan will be automatically run when the user next signs in on the endpoint. The type of scan that is run is determined by thesetting, and then select Specify the scan type to use for a scheduled scanAction (see About schedule scans)> Edit. Select

        Enable and configure catch-up quick scans

        1. In the details pane of Scan, open the Turn on catch-up quick scan setting.

        2. In the setting window that opens, select Enabled, and then select OK.

        Enable and configure catch-up full scans

        1. In the details pane of Scan, open the Turn on catch-up full scan setting.

        2. In the setting window that opens, select Enabled, and then select OK.

        Enable and configure forced catch-up scans

        1. In the details pane of Scan, open the Define the number of days after which a catch-up scan is forced setting.

        2. In the setting window that opens, configure the following options:

          1. Select Enabled.
          2. Enter the number of scans that can be missed before a scan automatically runs when the user next signs in on the endpoint.

          The type of scan that runs is determined by the Specify the scan type to use for a scheduled scan setting. For more information, see About scheduled scans.

          When you're finished, select OK.

        Use PowerShell cmdlets to configure catch-up scans

        Use the following cmdlets to enable or disable catch-up scans for full and quick scheduled scans. By default, catch-up full and quick scans are disabled. Set the corresponding value to $false to enable catch-up behavior and force a scan after missed scheduled scans:

        Set-MpPreference -DisableCatchupFullScan
        
        To configure security intelligence updates over a metered connection by using Group Policy, use the following steps:
        
        1. In Centralized Group Policy, open the [Group Policy Management Console (GPMC)](/windows-server/identity/ad-ds/manage/group-policy/group-policy-management-console) on your Group Policy management computer.
        
        1. In the GPMC console tree, expand Group Policy Objects in the forest and domain containing the GPO you want to edit.
        
        1. Right-click the GPO, and then select **Edit**.
        
        1. In the **Group Policy Management Editor**, go to **Computer configuration** \> **Administrative templates** \> **Windows components** \> **Microsoft Defender Antivirus** \> **Security Intelligence Updates**.
        
        1. In the details pane of **Security Intelligence Updates**, open the **Allows Microsoft Defender Antivirus to update and communicate over a metered connection.** setting. To open the setting, use any of the following methods:
           - Double-click the setting.
           - Right-click the setting, and then select **Edit**.
           - Select the setting, and then select **Action** \> **Edit**.
        
        1. In the setting window that opens, select Enabled, and then select OK.
        Settings Description Default
        Allows Microsoft Defender Antivirus to update and communicate over a metered connection. Enabling this policy automatically downloads updates, even over metered data connections (charges might apply). Disabled