Prevent malware infection
In brief
The page now uses current Microsoft Support links for Windows Update, User Account Control, user accounts, Microsoft account security, and Microsoft Defender.
What Defender admins need to know
No administrator action is required.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
title: Prevent malware infection ms.reviewer: description: Learn steps you can take to help prevent a malware or potentially unwanted software from infecting your computer. keywords: security, malware, prevention, infection, tips, Microsoft, MMPC, Microsoft Malware Protection Center, virus, trojan, worm, stop, prevent, full scan, infection, avoid malware, avoid trojan, avoid virus, infection, how, detection, security software, antivirus, updates, how malware works, how virus works, firewall, turn on, user privileges, limit, prevention, WDSI, MMPC, Microsoft Malware Protection Center ms.service: defender-endpoint ms.subservice: reference ms.mktglfcycl: secure ms.localizationpriority: medium ms.collection:
- m365-security
- tier2 ms.topic: article
Keep software up to date
Exploits typically use vulnerabilities in software. It's important to keep your software, apps, and operating systems up to date.
To keep Microsoft software up to date, ensure that automatic Microsoft Updatesautomatic Microsoft Updates are enabled. Also, upgrade to the latest version of Windows to benefit from the latest built-in security enhancements.
Be wary of links and attachments
Email, SMS messages, Microsoft Teams chat, and other messaging tools are a few of the most common ways attackers can infect devices. Attachments or links in messages can open malware directly or can stealthily trigger a download.
Use an email service that provides protection against malicious attachments, links, and abusive senders. Microsoft Office 365 has built-in anti-malware, link protection, and spam filtering. Microsoft Outlook contains additional security configurations and settings you can enable. See
Advanced Outlook.com security for Microsoft 365 subscribersAdvanced Outlook.com security for Microsoft 365 subscribersSome attackers try to get you to share information about your login information, passwords, and more. Be aware of some of the common tactics attackers use to try to trick you. For more information, see phishing.
Users don't openly discuss visits to these sites, so any untoward experience are more likely to stay unreported.
To stay safe, download movies, music, and apps from official publisher websites or stores.
Don't attach unfamiliar removable drives
At the time they're launched, whether inadvertently by a user or automatically, most malware run under the same privileges as the active user. This means that by limiting account privileges, you can prevent malware from making consequential changes any devices.
By default, Windows uses User Account Control (UAC)User Account Control (UAC) to provide automatic, granular control of privileges—it temporarily restricts privileges and prompts the active user every time an application attempts to make potentially consequential changes to the system. Although UAC helps limit the privileges of admin users, users can override this restriction when prompted. As a result, it's quite easy for an admin user to inadvertently allow malware to run.
To help ensure that everyday activities don't result in malware infection and other potentially catastrophic changes, it's recommended that you use a non-administrator account for regular use. By using a non-administrator account, you can prevent installation of unauthorized apps and prevent inadvertent changes to system settings. Avoid browsing the web or checking email using an account with administrator privileges.
Whenever necessary, log in as an administrator to install apps or make configuration changes that require admin privileges.
Read about creating user accounts and giving administrator privilegesRead about creating user accounts and giving administrator privileges
Other safety tips
Be wary when connecting to public Wi-Fi hotspots, particularly those that don't require authentication.
Use
strong passwordsstrong passwords and enable multi-factor authentication.Don't use untrusted devices to log on to email, social media, and corporate accounts.
Microsoft provides comprehensive security capabilities that help protect against threats. We recommend:
Automatic Microsoft updatesAutomatic Microsoft updates keeps software up to date to get the latest protections.Microsoft Edge browser protects against threats such as ransomware by preventing exploit kits from running. By using Windows Defender SmartScreen, Microsoft Edge blocks access to malicious websites.
Microsoft Defender Antivirus is built into Windows and helps provide real-time protection against viruses, malware, and other attacks.
Microsoft Safety Scanner helps remove malicious software from computers. NOTE: This tool doesn't replace your antimalware product.
Microsoft DefenderMicrosoft Defender is the simple way to protect your digital life and all of your devices. It's included as part of your Microsoft 365 Family, or Personal, subscription at no extra cost.
Use Zero Trust
Businesses should move to a Zero Trust security strategy. Zero Trust isn't a product or a service, but an approach in designing and implementing the following set of security principles:
- Verify explicitly
- Use least privilege access
- Assume breach
Software solutions for business
Microsoft Defender for Business is a security solution designed especially for the small- and medium-sized business (up to 300 employees). With this endpoint security solution, your company's devices are better protected from ransomware, malware, phishing, and other threats.
The built-in security features for all cloud mailboxes offers enterprise-class reliability and protection against spam and malware, while maintaining access to email during and after emergencies.
Microsoft Defender for Office 365 includes machine learning capabilities that block dangerous emails, including millions of emails carrying ransomware downloaders.
Microsoft Defender for Endpoint provides comprehensive endpoint protection, detection, and response capabilities to help prevent ransomware. In the event of a breach, Microsoft Defender for Endpoint alerts security operations teams about suspicious activities and automatically attempts to resolve the problem.
Windows Hello for BusinessWindows Hello for Business replaces passwords with strong two-factor authentication on your devices. This authentication consists of a new type of user credential that is tied to a device and uses a biometric or PIN. It lets user authenticate to an Active Directory or Azure Active Directory account.
What to do with a malware infection
Microsoft Defender for Endpoint antivirus capabilities help reduce the chances of infection and automatically remove threats that it detects.
In case threat removal is unsuccessful, read about troubleshooting malware detection and removal problemstroubleshooting malware detection and removal problems.
@@ -1,13 +1,13 @@ --- title: Prevent malware infection-ms.reviewer: +ms.reviewer: description: Learn steps you can take to help prevent a malware or potentially unwanted software from infecting your computer. keywords: security, malware, prevention, infection, tips, Microsoft, MMPC, Microsoft Malware Protection Center, virus, trojan, worm, stop, prevent, full scan, infection, avoid malware, avoid trojan, avoid virus, infection, how, detection, security software, antivirus, updates, how malware works, how virus works, firewall, turn on, user privileges, limit, prevention, WDSI, MMPC, Microsoft Malware Protection Center ms.service: defender-endpoint ms.subservice: reference ms.mktglfcycl: secure ms.localizationpriority: medium-ms.collection: +ms.collection: - m365-security - tier2 ms.topic: article@@ -20,15 +20,15 @@ Attackers are always looking for new ways to infect computers. Follow the tips b ## Keep software up to date -[Exploits](exploits-malware.md) typically use vulnerabilities in software. It's important to keep your software, apps, and operating systems up to date. +[Exploits](exploits-malware.md) typically use vulnerabilities in software. It's important to keep your software, apps, and operating systems up to date. -To keep Microsoft software up to date, ensure that [automatic Microsoft Updates](https://support.microsoft.com/help/12373/windows-update-faq) are enabled. Also, upgrade to the latest version of Windows to benefit from the latest built-in security enhancements.+To keep Microsoft software up to date, ensure that [automatic Microsoft Updates](https://support.microsoft.com/Windows/Deployment/Updates-Lifecycle/windows-update-faq) are enabled. Also, upgrade to the latest version of Windows to benefit from the latest built-in security enhancements. ## Be wary of links and attachments -Email, SMS messages, Microsoft Teams chat, and other messaging tools are a few of the most common ways attackers can infect devices. Attachments or links in messages can open malware directly or can stealthily trigger a download. +Email, SMS messages, Microsoft Teams chat, and other messaging tools are a few of the most common ways attackers can infect devices. Attachments or links in messages can open malware directly or can stealthily trigger a download. -- Use an email service that provides protection against malicious attachments, links, and abusive senders. [Microsoft Office 365](/defender-office-365/mdo-about) has built-in anti-malware, link protection, and spam filtering. Microsoft Outlook contains additional security configurations and settings you can enable. See [Advanced Outlook.com security for Microsoft 365 subscribers](https://support.microsoft.com/office/advanced-outlook-com-security-for-microsoft-365-subscribers-882d2243-eab9-4545-a58a-b36fee4a46e2)+- Use an email service that provides protection against malicious attachments, links, and abusive senders. [Microsoft Office 365](/defender-office-365/mdo-about) has built-in anti-malware, link protection, and spam filtering. Microsoft Outlook contains additional security configurations and settings you can enable. See [Advanced Outlook.com security for Microsoft 365 subscribers](https://support.microsoft.com/Outlook/advanced-outlook-com-security-for-microsoft-365-subscribers) - Some attackers try to get you to share information about your login information, passwords, and more. Be aware of some of the common tactics attackers use to try to trick you. For more information, see [phishing](phishing.md). @@ -52,7 +52,7 @@ Using pirated content isn't only illegal, it can also expose your device to malw Users don't openly discuss visits to these sites, so any untoward experience are more likely to stay unreported. -To stay safe, download movies, music, and apps from official publisher websites or stores. +To stay safe, download movies, music, and apps from official publisher websites or stores. ## Don't attach unfamiliar removable drives @@ -64,13 +64,13 @@ Only use removable drives that you're familiar with or that come from a trusted At the time they're launched, whether inadvertently by a user or automatically, most malware run under the same privileges as the active user. This means that by limiting account privileges, you can prevent malware from making consequential changes any devices. -By default, Windows uses [User Account Control (UAC)](/windows/security/identity-protection/user-account-control/user-account-control-overview) to provide automatic, granular control of privileges—it temporarily restricts privileges and prompts the active user every time an application attempts to make potentially consequential changes to the system. Although UAC helps limit the privileges of admin users, users can override this restriction when prompted. As a result, it's quite easy for an admin user to inadvertently allow malware to run.+By default, Windows uses [User Account Control (UAC)](/windows/security/application-security/application-control/user-account-control) to provide automatic, granular control of privileges—it temporarily restricts privileges and prompts the active user every time an application attempts to make potentially consequential changes to the system. Although UAC helps limit the privileges of admin users, users can override this restriction when prompted. As a result, it's quite easy for an admin user to inadvertently allow malware to run. To help ensure that everyday activities don't result in malware infection and other potentially catastrophic changes, it's recommended that you use a non-administrator account for regular use. By using a non-administrator account, you can prevent installation of unauthorized apps and prevent inadvertent changes to system settings. Avoid browsing the web or checking email using an account with administrator privileges. Whenever necessary, log in as an administrator to install apps or make configuration changes that require admin privileges. -[Read about creating user accounts and giving administrator privileges](https://support.microsoft.com/help/4026923/windows-create-a-local-user-or-administrator-account-in-windows-10)+[Read about creating user accounts and giving administrator privileges](https://support.microsoft.com/Windows/Security/Identity-Signin/manage-user-accounts-in-windows) ## Other safety tips @@ -80,7 +80,7 @@ To further ensure that data is protected from malware and other threats: - Be wary when connecting to public Wi-Fi hotspots, particularly those that don't require authentication. -- Use [strong passwords](https://support.microsoft.com/help/12410/microsoft-account-help-protect-account) and enable multi-factor authentication.+- Use [strong passwords](https://support.microsoft.com/accounts-billing/manage/how-to-help-keep-your-microsoft-account-secure) and enable multi-factor authentication. - Don't use untrusted devices to log on to email, social media, and corporate accounts. @@ -90,27 +90,27 @@ To further ensure that data is protected from malware and other threats: Microsoft provides comprehensive security capabilities that help protect against threats. We recommend: -- [Automatic Microsoft updates](https://support.microsoft.com/help/12373/windows-update-faq) keeps software up to date to get the latest protections.+- [Automatic Microsoft updates](https://support.microsoft.com/Windows/Deployment/Updates-Lifecycle/windows-update-faq) keeps software up to date to get the latest protections. - [Microsoft Edge](/microsoft-edge/deploy/index) browser protects against threats such as ransomware by preventing exploit kits from running. By using [Windows Defender SmartScreen](/microsoft-edge/deploy/index), Microsoft Edge blocks access to malicious websites. - [Microsoft Defender Antivirus](../microsoft-defender-antivirus-windows.md) is built into Windows and helps provide real-time protection against viruses, malware, and other attacks. - [Microsoft Safety Scanner](../safety-scanner-download.md) helps remove malicious software from computers. NOTE: This tool doesn't replace your antimalware product.- -- [Microsoft Defender](https://support.microsoft.com/topic/getting-started-with-microsoft-defender-9df0cb0f-4866-4433-9cbc-f83e5cf77693) is the simple way to protect your digital life and all of your devices. It's included as part of your Microsoft 365 Family, or Personal, subscription at no extra cost. -### Use Zero Trust +- [Microsoft Defender](https://support.microsoft.com/defender/getting-started-with-microsoft-defender) is the simple way to protect your digital life and all of your devices. It's included as part of your Microsoft 365 Family, or Personal, subscription at no extra cost.++### Use Zero Trust Businesses should move to a [Zero Trust security strategy](/security/zero-trust/zero-trust-overview). Zero Trust isn't a product or a service, but an approach in designing and implementing the following set of security principles: - Verify explicitly - Use least privilege access-- Assume breach +- Assume breach ### Software solutions for business - [Microsoft Defender for Business](/defender-business/mdb-overview) is a security solution designed especially for the small- and medium-sized business (up to 300 employees). With this endpoint security solution, your company's devices are better protected from ransomware, malware, phishing, and other threats.- + - [The built-in security features for all cloud mailboxes](https://products.office.com/exchange/exchange-email-security-spam-protection) offers enterprise-class reliability and protection against spam and malware, while maintaining access to email during and after emergencies. - [Microsoft Defender for Office 365](/office365/servicedescriptions/office-365-advanced-threat-protection-service-description) includes machine learning capabilities that block dangerous emails, including millions of emails carrying ransomware downloaders.@@ -119,10 +119,10 @@ Businesses should move to a [Zero Trust security strategy](/security/zero-trust/ - [Microsoft Defender for Endpoint](../microsoft-defender-endpoint.md) provides comprehensive endpoint protection, detection, and response capabilities to help prevent ransomware. In the event of a breach, Microsoft Defender for Endpoint alerts security operations teams about suspicious activities and automatically attempts to resolve the problem. -- [Windows Hello for Business](/windows/security/identity-protection/hello-for-business/hello-identity-verification) replaces passwords with strong two-factor authentication on your devices. This authentication consists of a new type of user credential that is tied to a device and uses a biometric or PIN. It lets user authenticate to an Active Directory or Azure Active Directory account.+- [Windows Hello for Business](/windows/security/identity-protection/hello-for-business/deploy) replaces passwords with strong two-factor authentication on your devices. This authentication consists of a new type of user credential that is tied to a device and uses a biometric or PIN. It lets user authenticate to an Active Directory or Azure Active Directory account. ## What to do with a malware infection Microsoft Defender for Endpoint antivirus capabilities help reduce the chances of infection and automatically remove threats that it detects. -In case threat removal is unsuccessful, read about [troubleshooting malware detection and removal problems](https://support.microsoft.com/help/4466982/windows-10-troubleshoot-problems-with-detecting-and-removing-malware).+In case threat removal is unsuccessful, read about [troubleshooting malware detection and removal problems](https://support.microsoft.com/defender/troubleshoot-problems-with-detecting-and-removing-malware). 