Microsoft Defender for Endpoint
Endpoint protection

Schedule antivirus scans using Microsoft Intune

In brief

The article now documents daily quick-scan states, valid times from 0 to 1380 minutes, the 120-minute default, and a noon example. It also updates weekly scan guidance, supported OS wording, and configuration links.

What Defender admins need to know

Administrators have clearer information for creating and reviewing scan policies. No administrator action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Schedule antivirus scans using Microsoft Intune

YouSecurity administrators can use Microsoft Intune to schedule Microsoft Defender Antivirus scans on managed Windows devices. This article shows youexplains how to create a scanan antivirus policy, set upschedule daily and weekly quick scans, and change settings likeconfigure CPU throttlingusage and catchup scans. These steps are for IT admins who use Intune to keepcatch-up scan coverage consistent across their devices. To learn more aboutsettings. For guidance on choosing a scan types,type, see About scheduled quick or full Microsoft Defender Antivirus scans.

Prerequisites

Before you configure scheduled antivirus scans in Intune, make sureverify that your devices meet the following requirements.use a supported operating system.

Supported operating systems

ScheduledIntune supports scheduled antivirus scans through Intune are supported on the following operating systems:

  • Windows
  • Windows Server

Configure antivirus scans using Intune

To configureCreate an antivirus scanspolicy by using Intune, seefollowing Create an endpoint security policy (opens in a new tab in the Intune documentation). When creatingUse the policy, use thesefollowing settings:

For more information about Intune antivirus endpoint security policies,information, see Antivirus policy for endpoint security in Intune.

Use Intune for schedulingSchedule daily quick scans using Intune

Use the following Intune setting to schedule a daily quick scan in Intune:on Windows devices:

  • Setting: Schedule Quick Scan Time
  • Values:
    • :::image type="icon" source="media/toggle-off.png" border="false"::: Not Configured
    • :::image type="icon" source="media/toggle-on.png" border="false"::: Configured
      • Enter a time of day from 0 (12:00 AM) through 1380 (11:00 PM). The default value is 120 (2:00 AM).

For example, a value of 720 schedules the daily quick scan for 12:00 PM.

Schedule weekly quick or full scans using Intune

Use the following Intune settings to schedule a weekly quick or full scan on Windows devices:

  • Setting: Scan parameter

  • Values:

    • Not configured
    • Quick scan (Default)
    • Full scan
  • Setting: Schedule Scan Day

  • Values:

    • Not configured
    • Every day (Default)
    • Sunday to Saturday
    • No scheduled scan
  • Setting: Schedule Scan Time

  • Values:

    • :::image type="icon" source="media/toggle-off.png" border="false"::: Not Configured
    • :::image type="icon" source="media/toggle-on.png" border="false"::: Configured
      • Enter a time of day from 0 (12:00 AM) through 1380 (11:00 PM). The default value is 120 (2:00 AM).

The following example schedules a quick scan on Windows devices every Wednesday at 5:00 PM (1020):

DescriptionSetting SettingValue
Scan parameterQuick scan (Default)
Schedule QuickScan DayWednesday
Schedule Scan Time 720:::image type="icon" source="media/toggle-on.png" border="false"::: Configured
1020

Use Intune for scheduling Weekly Scan (Quick or Full)

The following example settings schedule a weekly quick or full scan in Intune:

Description Setting
Scan Parameter Quick scan (Default)
Schedule Scan Day Windows Clients: Wednesday
Schedule Scan Time Windows Clients: 1020