Microsoft Defender Antivirus in Windows Overview - Microsoft Defender for Endpoint (2024)

  • Article

Applies to:

  • Microsoft Defender for Endpoint Plans 1 and 2
  • Microsoft Defender for Business
  • Microsoft Defender Antivirus

Platforms

  • Windows

Microsoft Defender Antivirus is available in Windows 10 and Windows 11, and in versions of Windows Server.

Microsoft Defender Antivirus is a major component of your next-generation protection in Microsoft Defender for Endpoint. This protection brings together machine learning, big-data analysis, in-depth threat resistance research, and the Microsoft cloud infrastructure to protect devices (or endpoints) in your organization. Microsoft Defender Antivirus is built into Windows, and it works with Microsoft Defender for Endpoint to provide protection on your device and in the cloud.

Tip

As a companion to this article, see our Security Analyzer setup guide to review best practices and learn to fortify defenses, improve compliance, and navigate the cybersecurity landscape with confidence. For a customized experience based on your environment, you can access the Security Analyzer automated setup guide in the Microsoft 365 admin center.

Microsoft Defender Antivirus capabilities

Microsoft Defender Antivirus provides anomaly detection, a layer of protection for malware that doesn't fit any predefined pattern. Anomaly detection monitors for process creation events or files that are downloaded from the internet. Through machine learning and cloud-delivered protection, Microsoft Defender Antivirus can stay one step ahead of attackers. Anomaly detection is on by default and can help block attacks such as 3CX Security Alert for Electron Windows App. Microsoft Defender Antivirus started blocking this malware four days before the attack was registered in VirusTotal.

Modern malware requires modern solutions. In 2015, Microsoft Defender Antivirus moved away from using a static signature-based engine to a model that uses predictive technologies such as, machine learning, applied science, and artificial intelligence as this is what's necessary to keep you and your organizations safe from the complexity of today's ever-evolving malware landscape.

Microsoft Defender Antivirus can block almost all malware at first sight, in milliseconds.

We've also designed our antivirus solution to work in both online and offline scenarios. For offline scenarios, the latest dynamic intelligence from the Intelligence Security Graph is provisioned to the endpoint regularly throughout the day. When connected to the cloud, it's fed real-time intelligence from the Intelligent Security Graph.

Microsoft Defender Antivirus can also stop threats based on their behaviors and process trees even when the threat has started execution. A common example of these kinds of attacks is fileless malware. Microsoft's Next-generation protection features work together to identify and block malware based on abnormal behavior. To learn more, see Behavioral blocking and containment.

Compatibility with other antivirus products

If you're using a non-Microsoft antivirus/antimalware product on your device, you might be able to run Microsoft Defender Antivirus in passive mode alongside the non-Microsoft antivirus solution. It depends on the operating system used and whether your device is onboarded to Defender for Endpoint. To learn more, see Microsoft Defender Antivirus compatibility.

Microsoft Defender Antivirus processes and services

The following table summarizes Microsoft Defender Antivirus processes and services. You can view them in Task Manager in Windows.

Process or serviceWhere to view its status
Microsoft Defender Antivirus Core service
(MdCoreSvc)
- Processes tab: Antimalware Core Service
- Details tab: MpDefenderCoreService.exe
- Services tab: Microsoft Defender Core Service
Microsoft Defender Antivirus service
(WinDefend)
- Processes tab: Antimalware Service Executable
- Details tab: MsMpEng.exe
- Services tab: Microsoft Defender Antivirus
Microsoft Defender Antivirus Network Realtime Inspection service
(WdNisSvc)
- Processes tab: Microsoft Network Realtime Inspection Service
- Details tab: NisSrv.exe
- Services tab: Microsoft Defender Antivirus Network Inspection Service
Microsoft Defender Antivirus command-line utility- Processes tab: N/A
- Details tab: MpCmdRun.exe
- Services tab: N/A
Microsoft Security Client Policy Configuration Tool- Processes tab: N/A
- Details tab: ConfigSecurityPolicy.exe
- Services tab: N/A

To learn more about the Microsoft Defender Core service, please visit Microsoft Defender Core service overview.

For Microsoft Endpoint Data Loss Prevention (Endpoint DLP), the following table summarizes processes and services. You can view them in Task Manager in Windows.

Process or serviceWhere to view its status
Microsoft Endpoint DLP service
(MDDlpSvc)
- Processes tab: MpDlpService.exe
- Details tab: MpDlpService.exe
- Services tab: Microsoft Data Loss Prevention Service
Microsoft Endpoint DLP command-line utility- Processes tab: N/A
- Details tab: MpDlpCmd.exe
- Services tab: N/A

Comparing active mode, passive mode, and disabled mode

The following table describes what to expect when Microsoft Defender Antivirus is in active mode, passive mode, or disabled.

ModeWhat happens
Active modeIn active mode, Microsoft Defender Antivirus is used as the primary antivirus app on the device. Files are scanned, threats are remediated, and detected threats are listed in your organization's security reports and in your Windows Security app.
Passive modeIn passive mode, Microsoft Defender Antivirus is not used as the primary antivirus app on the device. Files are scanned, and detected threats are reported, but threats are not remediated by Microsoft Defender Antivirus.

IMPORTANT: Microsoft Defender Antivirus can run in passive mode only on endpoints that are onboarded to Microsoft Defender for Endpoint. See Requirements for Microsoft Defender Antivirus to run in passive mode.

Disabled or uninstalledWhen disabled or uninstalled, Microsoft Defender Antivirus is not used. Files are not scanned, and threats are not remediated. In general, we do not recommend disabling or uninstalling Microsoft Defender Antivirus.

To learn more, see Microsoft Defender Antivirus compatibility.

Check the state of Microsoft Defender Antivirus on your device

You can use one of several methods, such as the Windows Security app or Windows PowerShell, to check the state of Microsoft Defender Antivirus on your device.

Important

Beginning with platform version 4.18.2208.0 and later: If a server has been onboarded to Microsoft Defender for Endpoint, the "Turn off Windows Defender" group policy setting will no longer completely disable Windows Defender Antivirus on Windows Server 2012 R2 and later. Instead, it will place it into passive mode. In addition, the tamper protection feature will allow a switch to active mode but not to passive mode.

  • If "Turn off Windows Defender" is already in place before onboarding to Microsoft Defender for Endpoint, there will be no change and Defender Antivirus will remain disabled.
  • To switch Defender Antivirus to passive mode, even if it was disabled before onboarding, you can apply the ForceDefenderPassiveMode configuration with a value of 1. To place it into active mode, switch this value to 0 instead.

Note the modified logic for ForceDefenderPassiveMode when tamper protection is enabled: Once Microsoft Defender Antivirus is toggled to active mode, tamper protection will prevent it from going back into passive mode even when ForceDefenderPassiveMode is set to 1.

Use the Windows Security app to check the status of Microsoft Defender Antivirus

  1. On your Windows device, select the Start menu, and begin typing Security. Then open the Windows Security app in the results.

  2. Select Virus & threat protection.

  3. Under Who's protecting me?, choose Manage Providers.

You'll see the name of your antivirus/antimalware solution on the security providers page.

Use PowerShell to check the status of Microsoft Defender Antivirus

  1. Select the Start menu, and begin typing PowerShell. Then open Windows PowerShell in the results.

  2. Type Get-MpComputerStatus.

  3. In the list of results, look at the AMRunningMode row.

    • Normal means Microsoft Defender Antivirus is running in active mode.

    • Passive mode means Microsoft Defender Antivirus running, but is not the primary antivirus/antimalware product on your device. Passive mode is only available for devices that are onboarded to Microsoft Defender for Endpoint and that meet certain requirements. To learn more, see Requirements for Microsoft Defender Antivirus to run in passive mode.

    • EDR Block Mode means Microsoft Defender Antivirus is running and Endpoint detection and response (EDR) in block mode, a capability in Microsoft Defender for Endpoint, is enabled. Check the ForceDefenderPassiveMode registry key. If its value is 0, it is running in normal mode; otherwise, it is running in passive mode.

    • SxS Passive Mode means Microsoft Defender Antivirus is running alongside another antivirus/antimalware product, and limited periodic scanning is used.

Tip

To learn more about the Get-MpComputerStatus PowerShell cmdlet, see the reference article Get-MpComputerStatus.

Tip

Performance tip Due to a variety of factors (examples listed below) Microsoft Defender Antivirus, like other antivirus software, can cause performance issues on endpoint devices. In some cases, you might need to tune the performance of Microsoft Defender Antivirus to alleviate those performance issues. Microsoft's Performance analyzer is a PowerShell command-line tool that helps determine which files, file paths, processes, and file extensions might be causing performance issues; some examples are:

  • Top paths that impact scan time
  • Top files that impact scan time
  • Top processes that impact scan time
  • Top file extensions that impact scan time
  • Combinations – for example:
    • top files per extension
    • top paths per extension
    • top processes per path
    • top scans per file
    • top scans per file per process

You can use the information gathered using Performance analyzer to better assess performance issues and apply remediation actions.See: Performance analyzer for Microsoft Defender Antivirus.

Get your antivirus/antimalware platform updates

It's important to keep Microsoft Defender Antivirus (or any antivirus/antimalware solution) up to date. Microsoft releases regular updates to help ensure that your devices have the latest technology to protect against new malware and attack techniques. To learn more, see Manage Microsoft Defender Antivirus updates and apply baselines.

Tip

If you're looking for Antivirus related information for other platforms, see:

  • Set preferences for Microsoft Defender for Endpoint on macOS
  • Microsoft Defender for Endpoint on Mac
  • macOS Antivirus policy settings for Microsoft Defender Antivirus for Intune
  • Set preferences for Microsoft Defender for Endpoint on Linux
  • Microsoft Defender for Endpoint on Linux
  • Configure Defender for Endpoint on Android features
  • Configure Microsoft Defender for Endpoint on iOS features

See also

  • Performance analyzer for Microsoft Defender Antivirus
  • Microsoft Defender Antivirus management and configuration
  • Evaluate Microsoft Defender Antivirus protection
  • Exclusions for Microsoft Defender for Endpoint and Microsoft Defender Antivirus

Tip

Do you want to learn more? Engage with the Microsoft Security community in our Tech Community: Microsoft Defender for Endpoint Tech Community.

Microsoft Defender Antivirus in Windows Overview - Microsoft Defender for Endpoint (2024)

FAQs

What is Microsoft Defender for Endpoint Overview? ›

Microsoft Defender for Endpoint is an enterprise endpoint security platform designed to help enterprise networks prevent, detect, investigate, and respond to advanced threats. Example endpoints may include laptops, phones, tablets, PCs, access points, routers, and firewalls.

What is the difference between Microsoft Defender Antivirus and Microsoft Defender for Endpoint? ›

Windows Defender is the desktop security client default for Microsoft Windows OS and other OSes. Microsoft Defender is a broader suite of security tools that includes Windows Defender for Endpoint (a variant of Windows Defender) that is used for enterprise security particularly for Microsoft 365 licensees.

Do I need antivirus or is Windows Defender enough? ›

Is Windows Defender good enough? Windows Defender is a good basic virus protection software, but you may not find everything you want if you are extremely security-focused. A third-party antivirus or anti-malware software will likely find threats that Windows Defender may miss.

Why is my Windows Defender antivirus turned off? ›

Malware can turn off Defender and keep it off despite your best efforts to re-enable it. If you aren't able to turn Defender back on you might be infected. Install and run another malware detector of your choice and see if you can find and remove the infection.

How do I disable Microsoft defender for endpoint? ›

How to disable Windows Defender ATP
  1. Go to the Microsoft Defender portal (https://security.microsoft.com) and sign in.
  2. In the navigation pane, choose Settings, and then choose Endpoints.
  3. Under Device management, choose Offboarding.
Nov 21, 2023

What is the benefit of Microsoft Defender for Endpoint? ›

Defender for Endpoint is a comprehensive, cloud-native endpoint security solution that delivers visibility and AI-powered cyberthreat protection to help stop cyberattacks across Windows, macOS, Linux, Android, iOS, and IoT devices.

What is the new name for Microsoft Defender for Endpoint? ›

Product Name Changes
Previous nameNew name
Microsoft Defender Advanced Threat ProtectionMicrosoft Defender for Endpoint
Microsoft Threat ProtectionMicrosoft 365 Defender
Office 365 Advanced Threat ProtectionMicrosoft Defender for Office 365
Microsoft 365 BusinessMicrosoft 365 Business Premium
56 more rows

How do I know if I have Microsoft Defender for Endpoint? ›

The easiest way to check if Microsoft Defender for Endpoint is running is to open the Windows Security app. If you see the Microsoft Defender icon in the app, it means that the service is running. You can also search for “Microsoft Defender” in the Start menu to open the Windows Security app.

Should I turn off Windows Defender if I have antivirus? ›

It is generally not recommended to disable Windows Defender if you have another antivirus program like McAfee installed. Multiple antivirus programs running simultaneously can cause conflicts and performance issues on your computer.

Is Windows Defender good enough to protect your PC by itself? ›

Microsoft Defender Antivirus does a fine job of securing Windows 10 and 11 PCs that have no other protection, but it doesn't beat the best free or paid third-party tools.

Can Windows Defender remove malware? ›

Microsoft Defender Antivirus is a powerful tool that finds and removes malware from your PC. Here's how to use it in Windows 10 or 11 to scan your PC. Important: Before you use Microsoft Defender Offline, make sure to save any open files and close apps and programs.

Is Microsoft Defender free? ›

Microsoft Defender Antivirus is free and is included in Windows, always on and always working to protect your PC against malware. Hackers and scammers sometimes use fake antimalware software to trick you into installing viruses or malware on your computer.

What is the default antivirus for Windows? ›

Microsoft Defender Antivirus is built into Windows, and it works with Microsoft Defender for Endpoint to provide protection on your device and in the cloud.

How to permanently disable Microsoft Defender Antivirus on Windows? ›

  1. Press Win + R to open the "Run" dialog, type services. ...
  2. In the "Services" window, find and double-click on "Security Center" (or "Windows Defender Security Center" in newer versions).
  3. In the "Properties" window, set the "Startup type" to "Disabled," then click "Apply" and "OK."
Mar 7, 2024

Is defender for endpoint any good? ›

Defender for Endpoint is great endpoint security solution, it's integration into the MS Windows OS, gives it an advantage over other solutions as it's built-in. There's no need for a third party software to protect your Windows systems against threats such as malware, ransomware and APTs.

What data is collected by Defender for Endpoint? ›

Microsoft Defender for Endpoint collects and uses data about endpoint diagnostic events, device information, and files to provide its security services. This may include data about hardware, OS, applications, logged-in users, system processes, and network communications.

How do I know if my Windows Defender is running for Endpoint? ›

The easiest way to check if Microsoft Defender for Endpoint is running is to open the Windows Security app. If you see the Microsoft Defender icon in the app, it means that the service is running.

What plans include Microsoft Defender for Endpoint? ›

Microsoft Defender for Endpoint is available in two plans, Endpoint Plan 1 and Endpoint Plan 2, which are available either as standalone services or a part of Microsoft 365.

Top Articles
How does whole life insurance work?
The importance of having enough Life Insurance
Www.1Tamilmv.cafe
Elleypoint
Enrique Espinosa Melendez Obituary
Repentance (2 Corinthians 7:10) – West Palm Beach church of Christ
Jonathon Kinchen Net Worth
Shs Games 1V1 Lol
Brgeneral Patient Portal
Free VIN Decoder Online | Decode any VIN
Poplar | Genus, Description, Major Species, & Facts
Decaying Brackenhide Blanket
Espn Expert Picks Week 2
LeBron James comes out on fire, scores first 16 points for Cavaliers in Game 2 vs. Pacers
Synq3 Reviews
10 Free Employee Handbook Templates in Word & ClickUp
7 Fly Traps For Effective Pest Control
Truth Of God Schedule 2023
Chastity Brainwash
Jinx Chapter 24: Release Date, Spoilers & Where To Read - OtakuKart
Las 12 mejores subastas de carros en Los Ángeles, California - Gossip Vehiculos
Bank Of America Financial Center Irvington Photos
Ms Rabbit 305
Recap: Noah Syndergaard earns his first L.A. win as Dodgers sweep Cardinals
Cvs El Salido
Lakewood Campground Golf Cart Rental
Gazette Obituary Colorado Springs
Boston Dynamics’ new humanoid moves like no robot you’ve ever seen
Sec Baseball Tournament Score
Meta Carevr
Craigslist Northern Minnesota
Annapolis Md Craigslist
lol Did he score on me ?
Frommer's Belgium, Holland and Luxembourg (Frommer's Complete Guides) - PDF Free Download
Sams La Habra Gas Price
Second Chance Apartments, 2nd Chance Apartments Locators for Bad Credit
Wayne State Academica Login
The Realreal Temporary Closure
Craigslist Malone New York
QVC hosts Carolyn Gracie, Dan Hughes among 400 laid off by network's parent company
Anthem Bcbs Otc Catalog 2022
Poe Self Chill
Toomics - Die unendliche Welt der Comics online
Arcanis Secret Santa
Craigslist Binghamton Cars And Trucks By Owner
Timothy Warren Cobb Obituary
Mother Cabrini, the First American Saint of the Catholic Church
Dlnet Deltanet
Mlb Hitting Streak Record Holder Crossword Clue
Join MileSplit to get access to the latest news, films, and events!
Aspen.sprout Forum
Texas 4A Baseball
Latest Posts
Article information

Author: Rueben Jacobs

Last Updated:

Views: 5983

Rating: 4.7 / 5 (77 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Rueben Jacobs

Birthday: 1999-03-14

Address: 951 Caterina Walk, Schambergerside, CA 67667-0896

Phone: +6881806848632

Job: Internal Education Planner

Hobby: Candle making, Cabaret, Poi, Gambling, Rock climbing, Wood carving, Computer programming

Introduction: My name is Rueben Jacobs, I am a cooperative, beautiful, kind, comfortable, glamorous, open, magnificent person who loves writing and wants to share my knowledge and understanding with you.