Skip to content

Commit 140a699

Browse files
authored
Update enable-troubleshooting-mode.md
Update section for events that are being generated when changing settings in troubleshooting mode
1 parent 5eb5d22 commit 140a699

File tree

1 file changed

+3
-1
lines changed

1 file changed

+3
-1
lines changed

defender-endpoint/enable-troubleshooting-mode.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,9 @@ During troubleshooting mode, you can use the PowerShell command `Set-MPPreferenc
6262

6363
- Logs and snapshots are collected and are available for an admin to collect using the [Collect investigation package](respond-machine-alerts.md#collect-investigation-package-from-devices) feature on the device page. Microsoft doesn't remove this data from the device until an admin has collected it.
6464

65-
- Admins can also review the changes in settings that take place during Troubleshooting mode in **Event Viewer** on the device page.
65+
- Admins can also review the changes in settings that take place during Troubleshooting mode in **Event Viewer** on the device itself.
66+
- `Applications and Services Logs > Microsoft > Windows > Windows Defender > Operational`
67+
- Potential events may be event ID 5000, 5001, 5004, 5007 and others. See more details at [Review event logs and error codes to troubleshoot issues with Microsoft Defender Antivirus](https://learn.microsoft.com/en-us/defender-endpoint/troubleshoot-microsoft-defender-antivirus#event-id-5000).
6668

6769
- Troubleshooting mode automatically turns off after reaching the expiration time (it lasts for 4 hours). After expiration, all policy-managed configurations become read-only again and revert back to how the device was configured before enabling troubleshooting mode.
6870

0 commit comments

Comments
 (0)