You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-endpoint/manage-protection-updates-microsoft-defender-antivirus.md
+25-25Lines changed: 25 additions & 25 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -14,7 +14,7 @@ ms.collection:
14
14
- m365-security
15
15
- tier2
16
16
search.appverid: met150
17
-
ms.date: 09/09/2024
17
+
ms.date: 09/27/2024
18
18
---
19
19
20
20
# Manage the sources for Microsoft Defender Antivirus protection updates
@@ -63,15 +63,14 @@ There are five locations where you can specify where an endpoint should obtain u
63
63
-[Security intelligence updates for Microsoft Defender Antivirus and other Microsoft anti-malware](manage-protection-update-schedule-microsoft-defender-antivirus.md) (See note 2 below)
64
64
65
65
> [!NOTE]
66
-
> 1. Intune Internal Definition Update Server. If you use SCCM/SUP to get definition updates for Microsoft Defender Antivirus, and you must access Windows Update on blocked client devices, you can transition to co-management and offload the endpoint protection workload to Intune. In the antimalware policy configured in Intune there is an "internal definition update server" option that you can set to use on-premises WSUS as the update source. This configuration helps you control which updates from the official WU server are approved for the enterprise, and also helps proxy and save network traffic to the official Windows Updates network.
66
+
> - Intune Internal Definition Update Server. If you use SCCM/SUP to get definition updates for Microsoft Defender Antivirus, and you must access Windows Update on blocked client devices, you can transition to co-management and offload the endpoint protection workload to Intune. In the antimalware policy configured in Intune there is an "internal definition update server" option that you can set to use on-premises WSUS as the update source. This configuration helps you control which updates from the official WU server are approved for the enterprise, and also helps proxy and save network traffic to the official Windows Updates network.
67
67
>
68
-
> 2. Your policy and registry might have this listed as Microsoft Malware Protection Center (MMPC) security intelligence, its former name.
68
+
> - Your policy and registry might have this listed as Microsoft Malware Protection Center (MMPC) security intelligence, its former name.
69
69
70
70
To ensure the best level of protection, Microsoft Update allows for rapid releases, which means smaller downloads on a frequent basis. The Windows Server Update Service, Microsoft Endpoint Configuration Manager, Microsoft security intelligence updates, and platform updates sources deliver less frequent updates. Thus, the delta might be larger, resulting in larger downloads.
71
71
72
72
Platform updates and engine updates are released on a monthly cadence. Security intelligence updates are delivered multiple times a day, but this delta package doesn't contain an engine update. See [Microsoft Defender Antivirus security intelligence and product updates](microsoft-defender-antivirus-updates.md).
73
73
74
-
75
74
> [!IMPORTANT]
76
75
> If you have set [Microsoft Security intelligence page](https://www.microsoft.com/security/portal/definitions/adl.aspx) updates as a fallback source after Windows Server Update Service or Microsoft Update, updates are only downloaded from security intelligence updates and platform updates when the current update is considered out-of-date. (By default, this is seven consecutive days of not being able to apply updates from the Windows Server Update Service or Microsoft Update services).
77
76
> You can, however, [set the number of days before protection is reported as out-of-date](manage-outdated-endpoints-microsoft-defender-antivirus.md).<p>
@@ -100,27 +99,30 @@ The procedures in this article first describe how to set the order, and then how
100
99
101
100
1. In the **Group Policy Management Editor**, go to **Computer configuration**.
102
101
103
-
1. Select **Policies** then **Administrative templates**.
102
+
2. Select **Policies** then **Administrative templates**.
103
+
104
+
3. Expand the tree to **Windows components** > **Windows Defender** > **Signature updates**.
104
105
105
-
1. Expand the tree to **Windows components** > **Windows Defender** > **Signature updates** and then configure the following settings:
106
+
> [!NOTE]
107
+
> - For Windows 10, versions 1703 up to and including 1809, the policy path is **Windows Components > Microsoft Defender Antivirus > Signature Updates**
108
+
> - For Windows 10, version 1903, the policy path is **Windows Components > Microsoft Defender Antivirus > Security Intelligence Updates**
106
109
107
-
1. Edit the **Define the order of sources for downloading security intelligence updates** setting. Set the option to **Enabled**.
110
+
4. Edit the **Define the order of sources for downloading security intelligence updates** setting. Set the option to **Enabled**.
108
111
109
-
2. Specify the order of sources, separated by a single pipe, for example: `InternalDefinitionUpdateServer|MicrosoftUpdateServer|MMPC`, as shown in the following screenshot.
112
+
5. Specify the order of sources, separated by a single pipe, for example: `InternalDefinitionUpdateServer|MicrosoftUpdateServer|MMPC`, as shown in the following screenshot.
110
113
111
-
:::image type="content" source="/defender/media/wdav-order-update-sources.png" alt-text="Group policy setting listing the order of sources" lightbox="/defender/media/wdav-order-update-sources.png":::
114
+
:::image type="content" source="/defender/media/wdav-order-update-sources.png" alt-text="Group policy setting listing the order of sources" lightbox="/defender/media/wdav-order-update-sources.png":::
112
115
113
-
1. Select **OK**. This action sets the order of protection update sources.
114
-
115
-
1. Edit the **Define file shares for downloading security intelligence updates** setting and then set the option to **Enabled**.
116
-
117
-
1. Specify the file share source. If you have multiple sources, specify each source in the order they should be used, separated by a single pipe. Use [standard UNC notation](/openspecs/windows_protocols/ms-dtyp/62e862f4-2a51-452e-8eeb-dc4ff5ee33cc) for denoting the path, for example: `\\host-name1\share-name\object-name|\\host-name2\share-name\object-name`. If you don't enter any paths, then this source is skipped when the VM downloads updates.
116
+
6. Select **OK**. This action sets the order of protection update sources.
117
+
118
+
7. Edit the **Define file shares for downloading security intelligence updates** setting and then set the option to **Enabled**.
119
+
120
+
8. On a Windows Server, specify the file share source. If you have multiple sources, specify each source in the order they should be used, separated by a single pipe. Use [standard UNC notation](/openspecs/windows_protocols/ms-dtyp/62e862f4-2a51-452e-8eeb-dc4ff5ee33cc) for denoting the path. For example: `\\host-name1\share-name\object-name|\\host-name2\share-name\object-name`.
121
+
122
+
If you don't enter any paths, then this source is skipped when the VM downloads updates.
118
123
119
-
6. Select **OK**. This action sets the order of file shares when that source is referenced in the **Define the order of sources...** group policy setting.
124
+
9. Select **OK**. This action sets the order of file shares when that source is referenced in the **Define the order of sources...** group policy setting.
120
125
121
-
> [!NOTE]
122
-
> For Windows 10, versions 1703 up to and including 1809, the policy path is **Windows Components > Microsoft Defender Antivirus > Signature Updates**
123
-
> For Windows 10, version 1903, the policy path is **Windows Components > Microsoft Defender Antivirus > Security Intelligence Updates**
124
126
125
127
## Use Configuration Manager to manage the update location
126
128
@@ -172,18 +174,18 @@ For example, suppose that Contoso has hired Fabrikam to manage their security so
172
174
173
175
## Create a UNC share for security intelligence and platform updates
174
176
175
-
Set up a network file share (UNC/mapped drive) to download security intelligence and platform updates from the MMPC site by using a scheduled task.
177
+
On a Windows Server set up a network file share (UNC/mapped drive) to download security intelligence and platform updates from the MMPC site by using a scheduled task.
176
178
177
179
1. On the system for which you want to provision the share and download the updates, create a folder for the script.
178
180
179
-
```console
181
+
```cmd
180
182
Start, CMD (Run as admin)
181
183
MD C:\Tool\PS-Scripts\
182
184
```
183
185
184
186
2. Create a folder for signature updates.
185
187
186
-
```console
188
+
```cmd
187
189
MD C:\Temp\TempSigs\x64
188
190
MD C:\Temp\TempSigs\x86
189
191
```
@@ -253,7 +255,7 @@ Set up a network file share (UNC/mapped drive) to download security intelligence
253
255
254
256
If the scheduled task fails, run the following commands:
0 commit comments