Knowledge Base
Engineer Login
Back to Knowledge Base

Setting Up and Managing Windows Defender Antivirus

Security & antivirus Windows Defender antivirus policy endpoint By Kerry · Updated 03/05/26 07:41 AM
Windows Defender (Microsoft Defender Antivirus) is built into Windows 10/11 and provides solid baseline protection at no additional cost. For unmanaged devices, verify it's enabled: Settings > Windows Security > Virus & threat protection. The status should show 'No action needed.' Key settings to verify: Real-time protection (On), Cloud-delivered protection (On — enables faster signature updates), Automatic sample submission (On), and Tamper protection (On — prevents malware from disabling Defender). Keep Windows Update current, as Defender signature updates are delivered via Windows Update. For managed environments, control Defender through Microsoft Intune (Endpoint security > Antivirus) or Group Policy. Configure scheduled scans (full scan weekly, quick scan daily), exclusions for known safe paths, and alerts for detected threats. Review the Windows Security event log and Defender operational log (Event Viewer > Applications and Services > Microsoft > Windows > Windows Defender > Operational) for detection history.