Microsoft Defender for Endpoint
Endpoint protection

Respond File Alerts

In brief

The page now uses repository-relative links for Defender Antivirus compatibility and cloud-delivered protection guidance, and points sample submissions to the Microsoft Security Intelligence submission portal.

What Defender admins need to know

No administrator action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

The Stop and Quarantine File action includes stopping running processes, quarantining the files, and deleting persistent data such as registry keys.

You can also submit a sample through the Microsoft Defender portalMicrosoft Security Intelligence submission portal if the file wasn't observed on a Windows 10 device (or Windows 11 or Windows Server 2012 R2+), and wait for Submit for deep analysis button to become available.