Skip to content

Commit 8ff893e

Browse files
authored
Merge branch 'main' into dhagarwal_working
2 parents 811b1d1 + 2b8f244 commit 8ff893e

17 files changed

+575
-994
lines changed

defender-endpoint/TOC.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -511,8 +511,8 @@
511511
href: troubleshoot-collect-support-log.md
512512
- name: Troubleshoot Microsoft Defender Antivirus settings
513513
href: troubleshoot-settings.md
514-
- name: Troubleshoot Microsoft Defender Antivirus service startup problems
515-
href: troubleshoot-service-startup-problems.md
514+
- name: Troubleshoot Microsoft Defender Antivirus Security intelligence not getting updated
515+
href: troubleshoot-security-intelligence-not-updated.md
516516
- name: Troubleshooting Security Intelligence Updates from Microsoft Update source
517517
href: security-intelligence-update-tshoot.md
518518
displayName: Troubleshooting Security Intelligence Updates from Microsoft Update source
42.2 KB
Loading
114 KB
Loading

defender-endpoint/microsoft-defender-antivirus-compatibility.md

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: Learn about Microsoft Defender Antivirus with other security produc
44
ms.service: defender-endpoint
55
ms.subservice: ngp
66
ms.localizationpriority: medium
7-
ms.date: 10/17/2024
7+
ms.date: 01/10/2025
88
ms.topic: conceptual
99
author: emmwalshh
1010
ms.author: ewalsh
@@ -132,6 +132,12 @@ In order for Microsoft Defender Antivirus to run in passive mode, endpoints must
132132

133133
- Endpoints must be onboarded to Defender for Endpoint.
134134

135+
- Windows Security Center Service must be enabled.
136+
137+
> [!WARNING]
138+
> If the **Windows Security Center Service** is *disabled* on Windows Clients then Microsoft Defender Antivirus can't detect third-party antivirus installations and will stay **Active**.
139+
> This could lead to conflicts between the Microsoft Defender Antivirus and the third-party Antivirus, as both will attempt to provide active protection. This will impact performance and is not supported.
140+
135141
> [!IMPORTANT]
136142
> - Microsoft Defender Antivirus is only available on devices running Windows 10 and 11, Windows Server 2022, Windows Server 2016, Windows Server 2019, Windows Server, version 1803 or newer, Windows Server 2016, and Windows Server 2012 R2.
137143
> - Passive mode is only supported on Windows Server 2012 R2 & 2016 when the device is onboarded using the [modern, unified solution](configure-server-endpoints.md).

defender-endpoint/run-analyzer-macos-linux.md

Lines changed: 18 additions & 431 deletions
Large diffs are not rendered by default.
Lines changed: 75 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,75 @@
1+
---
2+
title: Troubleshoot Microsoft Defender Antivirus Security intelligence not getting updated
3+
description: Learn how to troubleshoot Microsoft Defender Antivirus Security intelligence not getting updated.
4+
author: emmwalshh
5+
ms.author: ewalsh
6+
manager: ewalsh
7+
ms.date: 01/10/2025
8+
ms.topic: troubleshooting
9+
ms.service: defender-endpoint
10+
ms.subservice: ngp
11+
ms.localizationpriority: medium
12+
ms.collection: # Useful for querying on a set of strategic or high-priority content.
13+
ms.custom:
14+
- partner-contribution
15+
ms.reviewer: ewalsh
16+
search.appverid: MET150
17+
f1.keywords: NOCSH
18+
audience: ITPro
19+
---
20+
21+
# Troubleshoot Microsoft Defender Antivirus Security intelligence not getting updated
22+
23+
**Applies to:**
24+
25+
- [Microsoft Defender XDR](/defender-xdr)
26+
- [Microsoft Defender for Endpoint Plan 1 and 2](microsoft-defender-endpoint.md)
27+
- [Microsoft Defender for Business](https://www.microsoft.com/security/business/endpoint-security/microsoft-defender-business)
28+
- [Microsoft Defender for Individuals](https://www.microsoft.com/microsoft-365/microsoft-defender-for-individuals)
29+
- Microsoft Defender Antivirus
30+
31+
## Symptom
32+
33+
When you update Microsoft Defender Antivirus security intelligence, you might see the error **Protection definition update failed**.
34+
35+
:::image type="content" source="media/protection-definition-update-failed.png" alt-text="Screenshot of Protection definition update failed.":::
36+
37+
These error codes might also appear:
38+
39+
- 0x8024402c
40+
- 0x80240022
41+
- 0X80004002
42+
- 0x80070422
43+
- 0x80072efd
44+
- 0x80070005
45+
- 0x80072f78
46+
- 0x80072ee2
47+
- 0x8007001B
48+
49+
The following screenshot shows the error **Signature Update failed**.
50+
51+
:::image type="content" source="media/signature-update-failed.png" alt-text="Screenshot showing signature update failed." lightbox="media/signature-update-failed.png":::
52+
53+
## Solution
54+
55+
1. Check the URLs required for the Security intelligence updates. You can get them via the firewall and/or proxy. See [Configure your network environment to ensure connectivity with Defender for Endpoint service](configure-environment.md).
56+
57+
1. Ensure that Microsoft Defender Antivirus (MDAV) is your primary antivirus. If you have a third-party antivirus that uses the Windows Security Center (WSC) API, it will disable MDAV. When MDAV is disabled, updates can't occur.
58+
59+
1. Given that MDAV is the primary antivirus and the services are running:
60+
61+
1. Check if updating Security Intelligence works when you manually download from [Latest security intelligence updates for Microsoft Defender Antivirus and other Microsoft antimalware?](https://www.microsoft.com/wdsi/defenderupdates)
62+
63+
1. If so, try updating through the Microsoft Malware Protection Center (MMPC).
64+
65+
Run the following PowerShell command as an administrator.
66+
67+
```powershell
68+
& "${env:ProgramFiles}\Windows Defender\MpCmdRun.exe" -SignatureUpdate -MMPC
69+
```
70+
71+
1. If this command works, the issue might be that the Security intelligence [Fallback order](manage-protection-updates-microsoft-defender-antivirus.md#fallback-order) is set to a WSUS server without **Security intelligence** approved updates. Alternatively, the UNC share might be stale, or the Windows Update service might have issues.
72+
73+
1. To check the WSUS server that the machine goes to, review `HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\WUServer (REG_SZ)`. Once you find the WUServer, check if that WSUS server has the MDAV security intelligence [(KB2267602 for MDAV and KB2461484 for SCEP)](microsoft-defender-antivirus-updates.md#security-intelligence-updates) approved.
74+
1. To check the UNC share, review [Manage how and where Microsoft Defender Antivirus receives updates](manage-protection-updates-microsoft-defender-antivirus.md#create-a-unc-share-for-security-intelligence-and-platform-updates).
75+
1. To check the status of the Windows Update service, review [Guidance for troubleshooting Windows Update issues](/troubleshoot/windows-client/installing-updates-features-roles/troubleshoot-windows-update-issues) and [Troubleshoot problems updating Windows](https://support.microsoft.com/windows/troubleshoot-problems-updating-windows-188c2b0f-10a7-d72f-65b8-32d177eb136c).

0 commit comments

Comments
 (0)