Skip to content

Commit 026f378

Browse files
authored
Merge pull request #2788 from YongRhee-MSFT/docs-editor/manage-outdated-endpoints-micr-1739570500
Update manage-outdated-endpoints-microsoft-defender-antivirus.md
2 parents 43cf508 + 4e329e7 commit 026f378

File tree

1 file changed

+25
-8
lines changed

1 file changed

+25
-8
lines changed

defender-endpoint/manage-outdated-endpoints-microsoft-defender-antivirus.md

Lines changed: 25 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
22
title: Apply Microsoft Defender Antivirus protection updates to out of date endpoints
3-
description: Define when and how updates should be applied for endpoints that haven't updated in a while.
3+
description: Define when and how updates should be applied for out of date endpoints in Microsoft Defender Antivirus.
44
ms.service: defender-endpoint
55
ms.localizationpriority: medium
66
ms.topic: conceptual
@@ -14,7 +14,7 @@ ms.collection:
1414
- m365-security
1515
- tier3
1616
search.appverid: met150
17-
ms.date: 04/08/2021
17+
ms.date: 02/18/2025
1818
---
1919

2020
# Manage Microsoft Defender Antivirus updates and scans for endpoints that are out of date
@@ -45,7 +45,7 @@ You can use one of several methods to set up catch-up protection updates:
4545

4646
### Use Configuration Manager to configure catch-up protection updates
4747

48-
1. On your Microsoft Configuration Manager console, open the antimalware policy you want to change (select **Assets and Compliance** in the navigation pane on the left, then expand the tree to **Overview** \> **Endpoint Protection** \> **Antimalware Policies**)
48+
1. On your Microsoft Configuration Manager console, open the anti-malware policy you want to change (select **Assets and Compliance** in the navigation pane on the left, then expand the tree to **Overview** \> **Endpoint Protection** \> **Antimalware Policies**)
4949

5050
2. Go to the **Security intelligence updates** section and configure the following settings:
5151

@@ -58,7 +58,7 @@ You can use one of several methods to set up catch-up protection updates:
5858

5959
### Use Group Policy to enable and configure the catch-up update feature
6060

61-
1. On your Group Policy management computer, open the [Group Policy Management Console](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc731212(v=ws.11)), right-click the Group Policy Object you want to configure and then select **Edit**.
61+
1. On your Group Policy management computer, open the [Group Policy Management Console](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc731212(v=ws.11)). Right-click the Group Policy Object you want to configure and then select **Edit**.
6262

6363
2. In the **Group Policy Management Editor** go to **Computer configuration**.
6464

@@ -119,9 +119,9 @@ You can use Group Policy to specify the number of days after which endpoint prot
119119

120120
4. Select **OK**.
121121

122-
## Set up catch-up scans for endpoints that have not been scanned for a while
122+
## Set up catch-up scans for endpoints that haven't been scanned for a while
123123

124-
You can set the number of consecutive scheduled scans that can be missed before Microsoft Defender Antivirus will force a scan.
124+
You can set the number of consecutive scheduled scans that can be missed before Microsoft Defender Antivirus forces a scan.
125125

126126
The process for enabling this feature is:
127127

@@ -145,7 +145,7 @@ You can use one of several methods to set up catch-up scans:
145145

146146
### Use Group Policy to enable and configure the catch-up scan feature
147147

148-
1. Ensure you have set up at least one scheduled scan.
148+
1. Ensure you set up at least one scheduled scan.
149149

150150
2. On your Group Policy management machine, open the [Group Policy Management Console](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc731212(v=ws.11)), right-click the Group Policy Object you want to configure and select **Edit**.
151151

@@ -193,14 +193,31 @@ See the following article for more information and allowed parameters:
193193

194194
### Use Configuration Manager to configure catch-up scans
195195

196-
1. On your Microsoft Configuration Manager console, open the antimalware policy you want to change (select **Assets and Compliance** in the navigation pane on the left, then expand the tree to **Overview** \> **Endpoint Protection** \> **Antimalware Policies**)
196+
1. On your Microsoft Configuration Manager console, open the anti-malware policy you want to change (select **Assets and Compliance** in the navigation pane on the left, then expand the tree to **Overview** \> **Endpoint Protection** \> **Antimalware Policies**)
197197

198198
2. Go to the **Scheduled scans** section and **Force a scan of the selected scan type if client computer is offline...** to **Yes**.
199199

200200
3. Select **OK**.
201201

202202
4. [Deploy the updated policy as usual](/sccm/protect/deploy-use/endpoint-antimalware-policies#deploy-an-antimalware-policy-to-client-computers).
203203

204+
### Use Group Policy to configure security intelligence updates over a metered connection
205+
206+
1. On your Group Policy management machine, open the [Group Policy Management Console](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc731212(v=ws.11)), right-click the Group Policy Object you want to configure and select **Edit**.
207+
208+
1. In the **Group Policy Management Editor**, go to **Computer configuration**.
209+
210+
1. Select **Policies** and then select **Administrative templates**.
211+
212+
1. Expand the tree to **Windows components > Microsoft Defender Antivirus > Security Intelligence Update** and configure the following settings:
213+
214+
- If you have set up scheduled quick scans, double-click the Allow Microsoft Defender Antivirus to update and communicate over a metered connection setting and set the option to **Enabled**.
215+
- Select **OK**.
216+
217+
|Settings| Description| Default |
218+
| -------- | -------- | -------- |
219+
|Allow Microsoft Defender Antivirus to update and communicate over a metered connection.|Enabling this policy will automatically download updates, even over metered data connections (charges may apply)| Disabled |
220+
204221
> [!TIP]
205222
> If you're looking for Antivirus related information for other platforms, see:
206223
> - [Set preferences for Microsoft Defender for Endpoint on macOS](mac-preferences.md)

0 commit comments

Comments
 (0)