Microsoft Defender for Cloud
Cloud and workloads

Understand malware scanning results

In brief

The article’s date and authoring metadata were updated, failure wording was clarified, and a named anchor plus revised “Next steps” heading were added.

What Defender admins need to know

No administrator action is indicated; the updated wording and anchor improve documentation references.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Error states

Malware scanning might fail to scan a blob. When this happens,malware scanning fails to scan a blob, the scan result indicates what the error was.

Error Message Cause of Error Guidance Charge incurred
SAM259220: Not scanned - immutability policy conflicted with another storage policy preventing blob access. The scan could not be completed because the container has an immutability policy enabled and the storage account has Last Access Time (LAT) tracking enabled. These settings conflict and block read access to the blob. Review your storage account configuration. To allow malware scanning, consider disabling LAT tracking or modifying the immutability policy to permit necessary access during scans. No
SAM259221: Not scanned - the storage account is busy or not responsive. Blob could not be scanned because the storage account was busy or did not respond. This can happen when the storage account experiences high load and read requests are throttled, or when network access to the blob is blocked. The workload owner should consider reducing the load on the account or distribute the load across multiple account or upgrading it to a higher performance tier. Defender cannot effectively protect accounts that experience throttling issues as it cannot access the blobs in it. No

Next stepsteps

[!div class="nextstepaction"] Set up advanced configurations for malware scanning