You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
|[Antivirus engine version card](#antivirus-engine-version-card) <br> [Antivirus security intelligence version card](#antivirus-security-intelligence-version-card) <br> [Antivirus platform version card](#antivirus-platform-version-card)|[Antivirus engine updates card](#antivirus-engine-updates-card) <br> [Security intelligence updates card](#security-intelligence-updates-card) <br> [Antivirus platform updates card](#antivirus-platform-updates-card)|
96
96
| The three version cards provide flyout reports that provide additional information, and enable further exploration. | The three up-to-date reporting cards provide links to resources to learn more. |
97
97
98
-
<sup>{[1](#fn1)}</sup> For the three _updates_ cards (also known as up-to-date reporting cards), "**No data available**" (or "Unknown" value) indicates devices that aren't reporting update status. Devices that aren't reporting update status can be due to various reasons, such as:
98
+
<sup>{[1](#fn1)}</sup> For the three `updates` cards (also known as up-to-date reporting cards), "**No data available**" (or "Unknown" value) indicates devices that aren't reporting update status. Devices that aren't reporting update status can be due to various reasons, such as:
99
99
100
100
- Computer is disconnected from the network.
101
101
- Computer is powered down or in a hibernation state.
@@ -176,15 +176,15 @@ For information on exporting using API, see the following articles:
176
176
177
177
### Microsoft Defender Antivirus version and update cards functionality
178
178
179
-
Following are descriptions for the six cards that report about the _version_ and _update_ information for Microsoft Defender Antivirus engine, security intelligence, and platform components:
179
+
Following are descriptions for the six cards that report about the `version` and `update` information for Microsoft Defender Antivirus engine, security intelligence, and platform components:
180
180
181
181
#### Full report
182
182
183
-
In any of the three _version_ cards, select **View full report** to display the nine most recent Microsoft Defender Antivirus _version_ reports for each of the three device types: Windows, Mac, and Linux; if fewer than nine exist, they're all shown. An **Other** category captures recent antivirus engine versions ranking tenth and below, if detected.
183
+
In any of the three `version` cards, select **View full report** to display the nine most recent Microsoft Defender Antivirus `version` reports for each of the three device types: Windows, Mac, and Linux; if fewer than nine exist, they're all shown. An **Other** category captures recent antivirus engine versions ranking tenth and below, if detected.
184
184
185
185
:::image type="content" source="media/device-health-defender-antivirus-health-view-full-report.png" alt-text="Shows the distribution of the top nine operating systems of each type" lightbox="media/device-health-defender-antivirus-health-view-full-report.png":::
186
186
187
-
A primary benefit of the three _version_ cards is that they provide quick indicators as to whether the most current versions of the antivirus engines, platforms, and security intelligence are being utilized. Coupled with the detailed information that is linked to the card, the versions cards become a powerful tool to check if versions are up to date and to gather information about individual computers, or groups of computers.
187
+
A primary benefit of the three `version` cards is that they provide quick indicators as to whether the most current versions of the antivirus engines, platforms, and security intelligence are being utilized. Coupled with the detailed information that is linked to the card, the versions cards become a powerful tool to check if versions are up to date and to gather information about individual computers, or groups of computers.
188
188
Ideally, when you run these reports, they'll indicate that the most current antivirus versions are installed, as opposed to older versions.
189
189
Use these reports to determine whether your organization is taking full advantage of the most current versions.
190
190
@@ -196,19 +196,19 @@ For more details on the current versions and how to update the different Microso
196
196
197
197
### Card descriptions
198
198
199
-
Following are brief summaries of the collected information reported in each of the _Antivirus version_ cards:
199
+
Following are brief summaries of the collected information reported in each of the `Antivirus version` cards:
200
200
201
201
#### Antivirus mode card
202
202
203
203
Reports on how many devices in your organization – on the date indicated on the card – are in any of the following Microsoft Defender Antivirus modes:
204
204
205
205
| value | mode |
206
206
|---|---|
207
-
|0| Active |
208
-
|1| Passive |
209
-
|2| Disabled (uninstalled, disabled, or SideBySidePassive {also known as Low Periodic Scan}) |
210
-
|3| Others (Not running, Unknown) |
211
-
|4| EDRBlocked |
207
+
|`0`|`Active`|
208
+
|`1`|`Passive`|
209
+
|`2`|`Disabled` (uninstalled, disabled, or SideBySidePassive {also known as Low Periodic Scan}) |
210
+
|`3`|`Others` (Not running, Unknown) |
211
+
|`4`|`EDRBlocked`|
212
212
213
213
:::image type="content" source="media/device-health-defender-antivirus-health-antivirus-mode.png" alt-text="Shows filtering Microsoft Defender Antivirus modes" lightbox="media/device-health-defender-antivirus-health-antivirus-mode.png":::
214
214
@@ -238,8 +238,8 @@ For more information on the current versions and how to update the different Mic
238
238
239
239
#### Antivirus security intelligence version card
240
240
241
-
Lists the most common _Microsoft Defender Antivirus security intelligence_ versions installed on devices on your network.
242
-
Microsoft continually updates Microsoft Defender security intelligence to address the latest threats, and to refine detection logic. These refinements to security intelligence enhance Microsoft Defender Antivirus' (and other Microsoft anti-malware solutions') ability to accurately identify potential threats. This security intelligence works directly with cloud-based protection to deliver AI-enhanced, next-generation protection that is fast and powerful.
241
+
Lists the most common Microsoft Defender Antivirus security intelligence versions installed on devices on your network.
242
+
Microsoft continually updates Microsoft Defender security intelligence to address the latest threats, and to refine detection logic. These refinements to security intelligence enhance the ability for Microsoft Defender Antivirus (and other Microsoft anti-malware solutions) to accurately identify potential threats. This security intelligence works directly with cloud-based protection to deliver AI-enhanced, next-generation protection that is fast and powerful.
243
243
244
244
##### Antivirus platform version card
245
245
@@ -248,13 +248,13 @@ For more information on the current versions and how to update the different Mic
248
248
249
249
#### Up-to-date cards
250
250
251
-
The up-to-date cards show the up-to-date status for **Antivirus engine**, **Antivirus platform**, and **Security intelligence** update versions. There are three possible states: _Up to date_ ('True'), _out of date_ ('False'), and _no data available_ ('Unknown').
251
+
The up-to-date cards show the up-to-date status for **Antivirus engine**, **Antivirus platform**, and **Security intelligence** update versions. There are three possible states: `Up to date` (`True`), `out of date` (`False`), and `no data available` (`Unknown`).
252
252
253
253
> [!IMPORTANT]
254
254
>
255
255
> The logic used to make up-to-date determinations has recently been enhanced and simplified. The new behavior is documented in this section.
256
256
257
-
Definitions for _Up to date_, _out of date_, and _no data available_ are provided for each card below.
257
+
Definitions for `Up to date`, `out of date`, and `no data available` are provided for each card below.
258
258
259
259
Microsoft Defender Antivirus uses the additional criteria of "Signature refresh time" (the last time device communicated with up to date reports) to make up-to-date reports and determinations for engine, platform, and security intelligence updates.
260
260
@@ -279,9 +279,9 @@ Following are up-to-date definitions for engine and platform:
279
279
280
280
| The engine/platform on the device is considered: | Situation |
281
281
|:---|:---|
282
-
|**up to date**| If the device communicated with the Defender report event ('Signature refresh time') within last seven days, and the Engine or Platform build version is greater than or equal to (`>=`) the most recent monthly release version. |
283
-
|**out-of-date**| If the device communicated with the Defender report event ('Signature refresh time') within last seven days, but Engine or Platform build version is less than (`<`) the most recent monthly release version. |
284
-
|**unknown (no data available)**| If the device hasn't communicated with the report event ('Signature refresh time') for more than seven days. |
282
+
|**up to date**| If the device communicated with the Defender report event (`Signature refresh time`) within last seven days, and the Engine or Platform build version is greater than or equal to (`>=`) the most recent monthly release version. |
283
+
|**out-of-date**| If the device communicated with the Defender report event (`Signature refresh time`) within last seven days, but Engine or Platform build version is less than (`<`) the most recent monthly release version. |
284
+
|**unknown (no data available)**| If the device hasn't communicated with the report event (`Signature refresh time`) for more than seven days. |
285
285
286
286
Following is the definitions for up-to-date security intelligence:
287
287
@@ -299,46 +299,46 @@ For more information, see:
299
299
300
300
This card identifies devices that have antivirus engine versions that are up to date versus out of date.
301
301
302
-
**The general definition of 'up to date'** - The engine version on the device is the most recent engine release. The engine is _typically_ released monthly, via Windows Update (WU)). There's a three-day grace period given from the day when Windows Update (WU) is released.
302
+
**The general definition of `up to date`** - The engine version on the device is the most recent engine release. The engine is typically released monthly, via Windows Update (WU). There's a three-day grace period given from the day when Windows Update (WU) is released.
303
303
304
-
The following table lays out the possible values for up to date reports for **Antivirus Engine**. Reported Status is based on the last time reporting event was received (_signature refresh time_). If the device hasn't communicated with reports for more than seven days (signature refresh time >7 days), then the status is automatically marked as 'Unknown' / 'No Data Available'.
304
+
The following table lays out the possible values for up to date reports for **Antivirus Engine**. Reported Status is based on the last time reporting event was received (signature refresh time). If the device hasn't communicated with reports for more than seven days (signature refresh time >7 days), then the status is automatically marked as `Unknown` / `No Data Available`.
305
305
306
-
| Event's Last Refresh Time (also known as "Signature Refresh Time" in reports) |_Reported Status_:|
306
+
| Event's Last Refresh Time (also known as "Signature Refresh Time" in reports) |Reported Status|
307
307
|:----|:----|
308
308
| < 7 days (new) | whatever client reports (_Up to date <br/> Out of date <br/> Unknown)_|
309
-
| > 7 days (old) |_Unknown_|
309
+
| > 7 days (old) |`Unknown`|
310
310
311
311
For information about Manage Microsoft Defender Antivirus update versions, see [Monthly platform and engine versions](microsoft-defender-antivirus-updates.md#monthly-platform-and-engine-versions).
312
312
313
313
#### Antivirus platform updates card
314
314
315
315
This card identifies devices that have Antivirus platform versions that are up to date versus out of date.
316
316
317
-
**The general definition of 'up to date'** is that the platform version on the device is the most recent platform release. Platform is _typically_ released monthly, via Windows Update (WU). There's a three-day grace period from the day when WU is released.
317
+
**The general definition of `up to date`** is that the platform version on the device is the most recent platform release. Platform is typically released monthly, via Windows Update (WU). There's a three-day grace period from the day when WU is released.
318
318
319
-
The following table lays out the possible up to date report values for **Antivirus Platform**. Reported values are based on the last time reporting event was received (signature refresh time). If the device hasn't communicated with reports for more than seven days (signature refresh time >7 days) then the status is automatically marked as 'Unknown'/ 'No Data Available'.
319
+
The following table lays out the possible up to date report values for **Antivirus Platform**. Reported values are based on the last time reporting event was received (signature refresh time). If the device hasn't communicated with reports for more than seven days (signature refresh time >7 days) then the status is automatically marked as `Unknown`/ `No Data Available`.
320
320
321
-
| Event's Last Refresh Time (also known as "Signature Refresh Time" in reports) |_Reported Status_|
321
+
| Event's Last Refresh Time (also known as "Signature Refresh Time" in reports) |Reported Status|
322
322
|:----|:----|
323
-
| < 7 days (new) | whatever client reports (_Up to date <br/> Out of date <br/> Unknown)_|
324
-
| > 7 days (old) |_Unknown_|
323
+
| < 7 days (new) | whatever client reports (`Up to date` <br/> `Out of date` <br/> `Unknown)`|
324
+
| > 7 days (old) |`Unknown`|
325
325
326
326
For information about Manage Microsoft Defender Antivirus update versions, see [Monthly platform and engine versions](microsoft-defender-antivirus-updates.md#monthly-platform-and-engine-versions).
327
327
328
328
##### Security intelligence updates card
329
329
330
330
This card identifies devices that have security intelligence versions that are up to date versus out of date.
331
331
332
-
**The general definition of 'up to date'** is that the security intelligence version on the device was written in the past 7 days.
332
+
**The general definition of `up to date`** is that the security intelligence version on the device was written in the past 7 days.
333
333
334
-
The following table lays out the possible up to date report values for **Security Intelligence** updates. Reported values are based on the last time reporting event was received, and the security intelligence publish time. If the device hasn't communicated with reports for more than seven days (signature refresh time >7 days), then the status is automatically marked as 'Unknown/ No Data Available'. Otherwise, the determination is made based on whether the security intelligence publish time is within seven days.
334
+
The following table lays out the possible up to date report values for **Security Intelligence** updates. Reported values are based on the last time reporting event was received, and the security intelligence publish time. If the device hasn't communicated with reports for more than seven days (signature refresh time >7 days), then the status is automatically marked as `Unknown/ No Data Available`. Otherwise, the determination is made based on whether the security intelligence publish time is within seven days.
335
335
336
336
| Event's Last Refresh Time <br/> (Also known as "Signature Refresh Time" in reports) | Security Intelligence Publish Time |_Reported Status_|
337
337
|:----|:----|:----|
338
-
| >7 days (old) | >7 days (old) |_Unknown_|
339
-
| <7 days (new) | >7 days (old) |_Out of date_|
340
-
| >7 days (old) | <7 days (new) |_Unknown_|
341
-
| <7 days (new) | <7 days (new) | Up to date |
338
+
| >7 days (old) | >7 days (old) |`Unknown`|
339
+
| <7 days (new) | >7 days (old) |`Out of date`|
340
+
| >7 days (old) | <7 days (new) |`Unknown`|
341
+
| <7 days (new) | <7 days (new) |`Up to date`|
342
342
343
343
## See also
344
344
@@ -373,4 +373,5 @@ The following table lays out the possible up to date report values for **Securit
373
373
> -[Microsoft Defender for Endpoint on Linux](microsoft-defender-endpoint-linux.md)
374
374
> -[Configure Defender for Endpoint on Android features](android-configure.md)
375
375
> -[Configure Microsoft Defender for Endpoint on iOS features](ios-configure-features.md)
376
+
376
377
[!INCLUDE [Microsoft Defender for Endpoint Tech Community](../includes/defender-mde-techcommunity.md)]
0 commit comments