Skip to content

Commit 7e91bc3

Browse files
authored
Merge pull request #2784 from YongRhee-MSFT/docs-editor/schedule-antivirus-scans-group-1739567964
Update schedule-antivirus-scans-group-policy.md
2 parents 026f378 + 5dcab3c commit 7e91bc3

File tree

1 file changed

+12
-11
lines changed

1 file changed

+12
-11
lines changed

defender-endpoint/schedule-antivirus-scans-group-policy.md

Lines changed: 12 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ ms.localizationpriority: medium
66
author: emmwalshh
77
ms.author: ewalsh
88
ms.custom: nextgen
9-
ms.date: 09/07/2024
9+
ms.date: 02/18/2025
1010
ms.reviewer: pauhijbr, ksarens
1111
manager: deniseb
1212
ms.subservice: ngp
@@ -37,27 +37,28 @@ This article describes how to configure scheduled scans using Group Policy. To l
3737

3838
2. Right-click the Group Policy Object you want to configure, and then select **Edit**.
3939

40-
3. Specify settings for the Group Policy Object, and then select **OK**.
40+
3. Specify the settings for the Group Policy Object, and then select **OK**.
4141

4242
4. Repeat steps 1-4 for each setting you want to configure.
4343

4444
5. Deploy your Group Policy Object as you normally do. If you need help with Group Policy Objects, see [Create a Group Policy Object](/windows/security/threat-protection/windows-firewall/create-a-group-policy-object).
4545

4646
> [!NOTE]
47-
> When configuring scheduled scans, the setting **Start the scheduled scan only when computer is on but not in use**, which is enabled by default, can impact the expected scheduled time by requiring the machine to be idle first.
47+
> When configuring scheduled scans, the setting **Start the scheduled scan only when computer is on but not in use** (which is enabled by default) can affect the expected scheduled time by requiring the machine to be idle first.
4848
>
49-
> For weekly scans, default behavior on Windows Server is to scan outside of automatic maintenance when the machine is idle. The default on Windows 10 and later is to scan during automatic maintenance when the machine is idle. To change this behavior, modify the settings by disabling **ScanOnlyIfIdle**, and then define a schedule.
49+
> For weekly scans, the default behavior on Windows Server and Windows 10 and later, is to scan outside of the automatic maintenance when the machine is idle. To change this behavior, modify the settings by disabling **ScanOnlyIfIdle**, and then define a schedule.
5050
51-
For more information, see the [Manage when protection updates should be downloaded and applied](manage-protection-update-schedule-microsoft-defender-antivirus.md) and [Prevent or allow users to locally modify policy settings](configure-local-policy-overrides-microsoft-defender-antivirus.md) topics.
51+
For more information, see the [Manage when protection updates should be downloaded and applied](manage-protection-update-schedule-microsoft-defender-antivirus.md) and [Prevent or allow users to locally modify policy settings](configure-local-policy-overrides-microsoft-defender-antivirus.md) articles.
5252

5353
## Group Policy settings for scheduling scans
5454

5555
| Location | Setting | Description | Default setting (if not configured) |
5656
|:---|:---|:---|:---|
57-
| Scan | Specify the scan type to use for a scheduled scan | Quick scan |
57+
| Scan | Specify the scan type to use for a scheduled scan | Quick scan ||
5858
| Scan | Specify the day of the week to run a scheduled scan | Specify the day (or never) to run a scan. | Never |
59-
| Scan | Specify the time of day to run a scheduled scan | Specify the number of minutes after midnight (for example, enter **60** for 1 a.m.). | 2 a.m. |
60-
| Root | Randomize scheduled task times |In Microsoft Defender Antivirus, randomize the start time of the scan to any interval from 0 to 23 hours. By default, scheduled tasks begin at a random time within four hours of the time specified in Task Scheduler. | Enabled |
59+
| Scan | Specify the time of day to run a scheduled scan | Specify the number of minutes after midnight to run a scan (for example, enter **60** for 1 AM). | 2 AM. |
60+
| Root | Randomize scheduled task times |In Microsoft Defender Antivirus, randomize the start time of the scan to any interval from **0 to 23 hours**. By default, scheduled tasks begin at a random time within four hours of the time specified in Task Scheduler. | Enabled |
61+
| Root | Configure scheduled task times randomization window |- This setting lets you set the start time for scheduled task scans and security updates. <br> - When enabled, you can choose a randomization window between **1 and 23 hours**. <br> - The Randomize Scheduled Task Times uses the specified window. <br> - If disabled or not configured, it randomizes times between **0 and 4 hours**. | Not configured (Disabled)|
6162

6263
## Group Policy settings for scheduling scans for when an endpoint isn't in use
6364

@@ -66,21 +67,21 @@ For more information, see the [Manage when protection updates should be download
6667
| Scan | Start the scheduled scan only when computer is on but not in use | Scheduled scans won't run, unless the computer is on but not in use | Enabled |
6768

6869
> [!NOTE]
69-
> When you schedule scans for times when endpoints aren't in use, scans don't honor the CPU throttling configuration and will take full advantage of the resources available to complete the scan as fast as possible.
70+
> When you schedule scans for times when endpoints aren't in use, scans don't honor the CPU throttling configuration and takes full advantage of the resources available to complete the scan as fast as possible.
7071
7172
## Group Policy settings for scheduling remediation-required scans
7273

7374
| Location | Setting | Description | Default setting (if not configured) |
7475
|---|---|---|---|
7576
| Remediation | Specify the day of the week to run a scheduled full scan to complete remediation | Specify the day (or never) to run a scan. | Never |
76-
| Remediation | Specify the time of day to run a scheduled full scan to complete remediation | Specify the number of minutes after midnight (for example, enter **60** for 1 a.m.) | 2 a.m. |
77+
| Remediation | Specify the time of day to run a scheduled full scan to complete remediation | Specify the number of minutes after midnight (for example, enter **60** for 1 AM.) | 2 AM. |
7778

7879
## Group Policy settings for scheduling daily scans
7980

8081
| Location | Setting | Description | Default setting (if not configured) |
8182
|:---|:---|:---|:---|
8283
| Scan | Specify the interval to run quick scans per day | Specify how many hours should elapse before the next quick scan. For example, to run every two hours, enter **2**, for once a day, enter **24**. Enter **0** to never run a daily quick scan. | Never |
83-
| Scan | Specify the time for a daily quick scan | Specify the number of minutes after midnight (for example, enter **60** for 1 a.m.) Note that if this setting is set to 0, daily quick scans do not run.| 2 a.m. |
84+
| Scan | Specify the time for a daily quick scan | Specify the number of minutes after midnight (for example, enter **60** for 1 AM.) Note that if this setting is set to 0, daily quick scans don't run.| 2 AM. |
8485

8586
## Group Policy settings for scheduling scans after protection updates
8687

0 commit comments

Comments
 (0)