Microsoft Defender for Endpoint
Endpoint protection

Schedule Microsoft Defender Antivirus protection updates

In brief

The article now provides detailed steps for configuring security intelligence update day, interval, and time settings through Group Policy, including current and legacy policy paths and local Group Policy guidance.

What Defender admins need to know

Administrators can use the revised instructions to configure scheduled protection updates consistently across managed endpoints.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Manage the schedule for when protection updates should be downloaded and applied

  • Set Check for Endpoint Protection security intelligence updates at a specific interval... to 0.
  • Set Check for Endpoint Protection security intelligence updates daily at... to the time when updates should be checked.
  1. To check and download updates on a continual interval, Set Check for Endpoint Protection security intelligence updates at a specific interval... to the number of hours that should occur between updates.

  2. Deploy the updated policy as usual.

Use Group Policy to schedule protection updates

To schedule protection updates by using Group Policy, perform the following steps:

  1. In Centralized Group Policy, open the Group Policy Management Console (GPMC), right-click the on your Group Policy Objectmanagement computer.

  2. In the GPMC console tree, expand Group Policy Objects in the forest and domain containing the GPO you want to configureedit.

  3. Right-click the GPO, and clickthen select Edit.

  4. In the Group Policy Management Editor, go to Computer configuration.

  5. Click Policies then > Administrative templates.

  6. Expand the tree to > Windows components > Microsoft Defender Antivirus > Security Intelligence Updates and configure the following settings:

    1. Double-click the Specify the day of the week to check for security intelligence updates setting and set the option to Enabled. Enter the day of the week to check for updates. Click OK.

    2. Double-click the Specify the interval to check for security intelligence updates setting and set the option to Enabled. Enter the number of hours between updates. Click OK.

    3. Double-click the Specify the time to check for security intelligence updates setting and set the option to Enabled. Enter the time when updates should be checked. The time is based on the local time of the endpoint. Click OK.

    1. In the details pane of Security Intelligence Updates, the available settings are:

      To open and configure a security intelligence update schedule setting, use any of the following methods:

      • Double-click the setting.
      • Right-click the setting, and then select Edit.
      • Select the setting, and then select Action > Edit.

    Use PowerShell cmdlets to schedule protection updates

    • Manage event-based forced updates

      Enable and configure the security intelligence update day

      1. In the details pane of Security Intelligence Updates, open the Specify the day of the week to check for security intelligence updates setting.

      2. In the setting window that opens, configure the following options:

        1. Select Enabled.
        2. Specify the day of the week to check for security intelligence updates in the Options section: Select the day of the week to check for updates.

        When you're finished, select OK.

      Enable and configure the security intelligence update interval

      1. In the details pane of Security Intelligence Updates, open the Specify the interval to check for security intelligence updates setting.

      2. In the setting window that opens, configure the following options:

        1. Select Enabled.
        2. Specify the interval to check for security intelligence updates in the Options section: Enter a value from 1 to 24 for the number of hours between updates.

        When you're finished, select OK.

      Enable and configure the security intelligence update time

      1. In the details pane of Security Intelligence Updates, open the Specify the time to check for security intelligence updates setting.

      2. In the setting window that opens, configure the following options:

        1. Select Enabled.
        2. Specify the time to check for security intelligence updates in the Options section: Enter the number of minutes after midnight when updates should be checked. For example, enter 120 for 2:00 AM. The schedule is based on the local time of the endpoint.

        When you're finished, select OK.

      Use PowerShell cmdlets to schedule protection updates