You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-endpoint/manage-outdated-endpoints-microsoft-defender-antivirus.md
+25-8Lines changed: 25 additions & 8 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,6 @@
1
1
---
2
2
title: Apply Microsoft Defender Antivirus protection updates to out of date endpoints
3
-
description: Define when and how updates should be applied for endpoints that haven't updated in a while.
3
+
description: Define when and how updates should be applied for out of date endpoints in Microsoft Defender Antivirus.
4
4
ms.service: defender-endpoint
5
5
ms.localizationpriority: medium
6
6
ms.topic: conceptual
@@ -14,7 +14,7 @@ ms.collection:
14
14
- m365-security
15
15
- tier3
16
16
search.appverid: met150
17
-
ms.date: 04/08/2021
17
+
ms.date: 02/18/2025
18
18
---
19
19
20
20
# Manage Microsoft Defender Antivirus updates and scans for endpoints that are out of date
@@ -45,7 +45,7 @@ You can use one of several methods to set up catch-up protection updates:
45
45
46
46
### Use Configuration Manager to configure catch-up protection updates
47
47
48
-
1. On your Microsoft Configuration Manager console, open the antimalware policy you want to change (select **Assets and Compliance** in the navigation pane on the left, then expand the tree to **Overview**\>**Endpoint Protection**\>**Antimalware Policies**)
48
+
1. On your Microsoft Configuration Manager console, open the anti-malware policy you want to change (select **Assets and Compliance** in the navigation pane on the left, then expand the tree to **Overview**\>**Endpoint Protection**\>**Antimalware Policies**)
49
49
50
50
2. Go to the **Security intelligence updates** section and configure the following settings:
51
51
@@ -58,7 +58,7 @@ You can use one of several methods to set up catch-up protection updates:
58
58
59
59
### Use Group Policy to enable and configure the catch-up update feature
60
60
61
-
1. On your Group Policy management computer, open the [Group Policy Management Console](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc731212(v=ws.11)), right-click the Group Policy Object you want to configure and then select **Edit**.
61
+
1. On your Group Policy management computer, open the [Group Policy Management Console](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc731212(v=ws.11)). Right-click the Group Policy Object you want to configure and then select **Edit**.
62
62
63
63
2. In the **Group Policy Management Editor** go to **Computer configuration**.
64
64
@@ -119,9 +119,9 @@ You can use Group Policy to specify the number of days after which endpoint prot
119
119
120
120
4. Select **OK**.
121
121
122
-
## Set up catch-up scans for endpoints that have not been scanned for a while
122
+
## Set up catch-up scans for endpoints that haven't been scanned for a while
123
123
124
-
You can set the number of consecutive scheduled scans that can be missed before Microsoft Defender Antivirus will force a scan.
124
+
You can set the number of consecutive scheduled scans that can be missed before Microsoft Defender Antivirus forces a scan.
125
125
126
126
The process for enabling this feature is:
127
127
@@ -145,7 +145,7 @@ You can use one of several methods to set up catch-up scans:
145
145
146
146
### Use Group Policy to enable and configure the catch-up scan feature
147
147
148
-
1. Ensure you have set up at least one scheduled scan.
148
+
1. Ensure you set up at least one scheduled scan.
149
149
150
150
2. On your Group Policy management machine, open the [Group Policy Management Console](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc731212(v=ws.11)), right-click the Group Policy Object you want to configure and select **Edit**.
151
151
@@ -193,14 +193,31 @@ See the following article for more information and allowed parameters:
193
193
194
194
### Use Configuration Manager to configure catch-up scans
195
195
196
-
1. On your Microsoft Configuration Manager console, open the antimalware policy you want to change (select **Assets and Compliance** in the navigation pane on the left, then expand the tree to **Overview**\>**Endpoint Protection**\>**Antimalware Policies**)
196
+
1. On your Microsoft Configuration Manager console, open the anti-malware policy you want to change (select **Assets and Compliance** in the navigation pane on the left, then expand the tree to **Overview**\>**Endpoint Protection**\>**Antimalware Policies**)
197
197
198
198
2. Go to the **Scheduled scans** section and **Force a scan of the selected scan type if client computer is offline...** to **Yes**.
199
199
200
200
3. Select **OK**.
201
201
202
202
4.[Deploy the updated policy as usual](/sccm/protect/deploy-use/endpoint-antimalware-policies#deploy-an-antimalware-policy-to-client-computers).
203
203
204
+
### Use Group Policy to configure security intelligence updates over a metered connection
205
+
206
+
1. On your Group Policy management machine, open the [Group Policy Management Console](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc731212(v=ws.11)), right-click the Group Policy Object you want to configure and select **Edit**.
207
+
208
+
1. In the **Group Policy Management Editor**, go to **Computer configuration**.
209
+
210
+
1. Select **Policies** and then select **Administrative templates**.
211
+
212
+
1. Expand the tree to **Windows components > Microsoft Defender Antivirus > Security Intelligence Update** and configure the following settings:
213
+
214
+
- If you have set up scheduled quick scans, double-click the Allow Microsoft Defender Antivirus to update and communicate over a metered connection setting and set the option to **Enabled**.
215
+
- Select **OK**.
216
+
217
+
|Settings| Description| Default |
218
+
| -------- | -------- | -------- |
219
+
|Allow Microsoft Defender Antivirus to update and communicate over a metered connection.|Enabling this policy will automatically download updates, even over metered data connections (charges may apply)| Disabled |
220
+
204
221
> [!TIP]
205
222
> If you're looking for Antivirus related information for other platforms, see:
206
223
> -[Set preferences for Microsoft Defender for Endpoint on macOS](mac-preferences.md)
0 commit comments