|
| 1 | +--- |
| 2 | +title: Schedule antivirus scans using Microsoft Intune |
| 3 | +description: Schedule antivirus scans using Intune |
| 4 | +author: emmwalshh |
| 5 | +ms.author: ewalsh |
| 6 | +ms.reviewer: yongrhee |
| 7 | +ms.service: defender-endpoint |
| 8 | +ms.topic: how-to |
| 9 | +ms.custom: nextgen |
| 10 | +ms.collection: |
| 11 | +- m365-security |
| 12 | +- tier2 |
| 13 | +- mde-ngp |
| 14 | +search.appverid: met150 |
| 15 | +ms.date: 04/30/2025 |
| 16 | +ms.subservice: ngp |
| 17 | +ms.localizationpriority: medium |
| 18 | +--- |
| 19 | + |
| 20 | +# Schedule antivirus scans using Microsoft Intune |
| 21 | + |
| 22 | +**Applies to:** |
| 23 | + |
| 24 | +- [Microsoft Defender XDR](/defender-xdr) |
| 25 | + |
| 26 | +- [Microsoft Defender for Endpoint Plan 1 and Plan 2](microsoft-defender-endpoint.md) |
| 27 | + |
| 28 | +- Microsoft Defender for Business |
| 29 | +- Microsoft Defender Antivirus |
| 30 | + |
| 31 | +**Platforms** |
| 32 | + |
| 33 | +- Windows |
| 34 | +- Windows Server |
| 35 | + |
| 36 | +This article describes how to configure scheduled scans using Microsoft Intune. To learn more about scheduling scans and about scan types, see [Configure scheduled quick or full Microsoft Defender Antivirus scans](schedule-antivirus-scans.md). |
| 37 | + |
| 38 | +## Configure antivirus scans using Intune |
| 39 | + |
| 40 | +1. In the [Intune admin center](https://intune.microsoft.com/), go to **Endpoint security** > **Antivirus** > **Create Policy**. For **Platform**, select **Windows**, and for **Profile**, select **Microsoft Defender Antivirus**. Then select **Create**. |
| 41 | + |
| 42 | +2. On the **Basics** page, specify a name and description for the policy, and then choose **Next**. |
| 43 | + |
| 44 | +3. On the **Configuration settings** page, expand each group of settings, and configure the settings you want to manage with this policy. For more information about these settings, see [Policy CSP - Defender](/windows/client-management/mdm/policy-csp-defender). |
| 45 | + |
| 46 | + When you're done configuring settings, select **Next**. |
| 47 | + |
| 48 | +4. On the **Scope tags** page, you can either use the default setting, or search for scope tags to assign to the policy. For more information, see [Use role-based access control (RBAC) and scope tags for distributed IT](/intune/intune-service/fundamentals/scope-tags). |
| 49 | + |
| 50 | + When you're done specifying scope tags, select **Next**. |
| 51 | + |
| 52 | +5. On the **Assignments** page, select the users or groups to receive this policy. For more information, see [Assign policies in Microsoft Intune](/intune/intune-service/configuration/device-profile-assign). |
| 53 | + |
| 54 | + When you're done Then select **Next**. |
| 55 | + |
| 56 | +6. On the **Review + create**, review your settings. When you select **Save**, your changes are saved, and the policy is created and applied. |
| 57 | + |
| 58 | +For more information: [Antivirus policy for endpoint security in Intune ](/intune/intune-service/protect/endpoint-security-antivirus-policy) |
| 59 | + |
| 60 | +## Use Intune for scheduling daily quick scans |
| 61 | + |
| 62 | +| Description|Setting| |
| 63 | +| -------- | -------- | |
| 64 | +|Schedule Quick Scan Time|720| |
| 65 | + |
| 66 | +> [!NOTE] |
| 67 | +> In this example, a quick scan runs daily on the Windows clients at 12:00 PM. (720). In this example, we use lunch time, since many devices nowadays are turned off after-hours (e.g laptops). |
| 68 | +
|
| 69 | +## Use Intune for scheduling Weekly Scan (Quick or Full) |
| 70 | + |
| 71 | +| Description|Setting| |
| 72 | +| -------- | -------- | |
| 73 | +|Scan Parameter |Quick scan (Default) | |
| 74 | +|Schedule Scan Day|Windows Clients: Wednesday<br>| |
| 75 | +|Schedule Scan Time|Windows Clients: 1020 <br>| |
| 76 | + |
| 77 | +> [!NOTE] |
| 78 | +> In this example, a quick scan runs for Windows clients on Wednesdays at 5:00 PM. (1020). |
| 79 | +
|
| 80 | +> [!TIP] |
| 81 | +> Our recommendation for scheduled scans is to configure quick scan together with always-on real-time protection and [cloud protection](/defender-endpoint/cloud-protection-microsoft-defender-antivirus), as this combination provides strong coverage against malware that starts with the system and kernel-level malware. This configuration is the default configuration. In general, there's no need to schedule a full scan, and most users never need to manually run full scans (see [Comparing quick scan, full scan, and custom scan](/defender-endpoint/schedule-antivirus-scans)). |
| 82 | +
|
| 83 | +## General settings for Scheduled scan to consider: |
| 84 | + |
| 85 | +|Description| Setting| |
| 86 | +| -------- | -------- | |
| 87 | +|Check For Signatures Before Running Scan |Disabled (Default)| |
| 88 | +|Randomize Schedule Task Times|Not configured| |
| 89 | +|Scheduler Randomization Time|Scheduled tasks aren't randomized| |
| 90 | +|Avg CPU Load Factor|Not Configured (Default, 50)| |
| 91 | +|Enable Low CPU Priority|Disabled (Default)| |
| 92 | +|Disable Catchup Full Scan|Enabled (Default)| |
| 93 | +|Disable Catchup Quick Scan|Disabled (Default)| |
| 94 | + |
| 95 | +> [!NOTE] |
| 96 | +> When you schedule scans for times when endpoints aren't in use, scans don't honor the CPU throttling configuration and takes full advantage of the resources available to complete the scan as fast as possible. |
| 97 | +
|
| 98 | +### See also |
| 99 | + |
| 100 | +- [Troubleshoot Microsoft Defender Antivirus scan issues](/defender-endpoint/troubleshoot-mdav-scan-issues) |
| 101 | + |
| 102 | +- [Troubleshoot Microsoft Defender Antivirus settings](/defender-endpoint/troubleshoot-settings) |
| 103 | + |
| 104 | +- [Troubleshoot performance issues related to real-time protection](/defender-endpoint/troubleshoot-performance-issues) |
| 105 | + |
| 106 | +- [Run the client analyzer on Windows](/defender-endpoint/run-analyzer-windows) |
| 107 | + |
| 108 | +- [Performance analyzer for Microsoft Defender Antivirus](/defender-endpoint/tune-performance-defender-antivirus) |
| 109 | + |
| 110 | +- [Microsoft Defender Antivirus full scan considerations and best practices](/defender-endpoint/mdav-scan-best-practices) |
| 111 | + |
0 commit comments