Setting Up and Managing Windows Defender Antivirus
Security & antivirus
Windows Defender
antivirus
policy
endpoint
By Kerry · Updated 03/05/26 07:41 AM
Windows Defender (Microsoft Defender Antivirus) is built into Windows 10/11 and provides solid baseline protection at no additional cost. For unmanaged devices, verify it's enabled: Settings > Windows Security > Virus & threat protection. The status should show 'No action needed.'
Key settings to verify: Real-time protection (On), Cloud-delivered protection (On — enables faster signature updates), Automatic sample submission (On), and Tamper protection (On — prevents malware from disabling Defender). Keep Windows Update current, as Defender signature updates are delivered via Windows Update.
For managed environments, control Defender through Microsoft Intune (Endpoint security > Antivirus) or Group Policy. Configure scheduled scans (full scan weekly, quick scan daily), exclusions for known safe paths, and alerts for detected threats. Review the Windows Security event log and Defender operational log (Event Viewer > Applications and Services > Microsoft > Windows > Windows Defender > Operational) for detection history.