Review detected threats on devices and take action - Microsoft 365 Business Premium (2024)

  • Article

As soon as Microsoft Defender detects a malicious file or software, Microsoft Defender blocks it and prevents it from running. And with cloud-delivered protection turned on, newly detected threats are added to the antivirus and antimalware engine so that your other devices and users are protected, as well.

Microsoft Defender Antivirus detects and protects against the following kinds of threats:

  • Viruses, malware, and web-based threats on devices
  • Phishing attempts
  • Data theft attempts

As an IT professional/admin, you can view information about threat detections across Windows devices enrolled in Intune in the Microsoft 365 admin center. Summary information includes:

  • How many devices need antivirus protection
  • How many devices aren't in compliance with security policies
  • How many threats are currently active, mitigated, or resolved

Actions you can take

When you view details about specific threats or devices, you see recommendations and one or more actions you can take. The following table describes actions that you might see.

ActionDescription
Configure protectionYour threat protection policies need to be configured. Select the link to go to your policy configuration page.

Need help? See Manage device security with endpoint security policies in Microsoft Intune.

Update policyYour antivirus and real-time protection policies need to be updated or configured. Select the link to go to the policy configuration page.

Need help? See Manage device security with endpoint security policies in Microsoft Intune.

Run quick scanStarts a quick antivirus scan on the device, focusing on common locations where malware might be registered, such as registry keys and known Windows startup folders.
Run full scanStarts a full antivirus scan on the device, focusing on common locations where malware might be registered, and including every file and folder on the device. Results are sent to Microsoft Intune.
Update antivirusRequires the device to get security intelligence updates for antivirus and antimalware protection.
Restart deviceForces a Windows device to restart within five minutes.

IMPORTANT: The device owner or user isn't automatically notified of the restart and could lose unsaved work.

View and manage threat detections in the Microsoft Defender portal

  1. Go to the (Microsoft Defender portal) and sign in.

  2. In the navigation pane, choose Threat Analytics to see all the current threats. Threads are categorized by threat severity and type.

  3. Select a threat to see more details about the threat.

  4. In the table, you can filter the alerts according to many criteria.

Manage threat detections in Microsoft Intune

You can use Microsoft Intune to manage threat detections as well. First, all devices whether Windows, iOS or Android, must be enrolled in Intune.

  1. Go to the Microsoft Intune admin center at https://endpoint.microsoft.com and sign in.

  2. In the navigation pane, select Endpoint security.

  3. Under Manage, select Antivirus. You see tabs for Summary, Unhealthy endpoints, and Active malware.

  4. Review the information on the available tabs, and then take any needed action.

For example, suppose that devices are listed on the Active malware tab. When you select a device, certain actions are available, such as Restart, Quick Scan, Full Scan, Sync, or Update signatures. Select an action for that device.

The following table describes the actions you might see in Microsoft Intune.

ActionDescription
RestartForces a Windows device to restart within five minutes.

IMPORTANT: The device owner or user isn't automatically notified of the restart and could lose unsaved work.

Quick ScanStarts a quick antivirus scan on the device, focusing on common locations where malware might be registered, such as registry keys and known Windows startup folders. Results are sent to Microsoft Intune.
Full ScanStarts a full antivirus scan on the device, focusing on common locations where malware might be registered, and including every file and folder on the device. Results are sent to Microsoft Intune.
SyncRequires a device to check in with Intune. When the device checks in, the device receives any pending actions or policies assigned to the device.
Update signaturesRequires the device to get security intelligence updates for antivirus and antimalware protection.

Tip

For more information, see Remote actions for devices.

How to submit a file for malware analysis

If you have a file that you think was missed or wrongly classified as malware, you can submit that file to Microsoft for malware analysis. Users and IT admins can submit a file for analysis. Visit https://www.microsoft.com/wdsi/filesubmission.

See also

Best practices for securing Microsoft 365 for business plans

Overview of Microsoft Defender for Business (Defender for Business is rolling out to Microsoft 365 Business Premium customers, beginning March 1, 2022)

Review detected threats on devices and take action - Microsoft 365 Business Premium (2024)

FAQs

Does Office 365 Business Premium include advanced threat protection? ›

Microsoft 365 Business Premium includes Defender for Business, which provides advanced protection for your organization's devices, including client computers, tablets, and mobile phones. Server protection is also available if you have Microsoft Defender for Business servers.

What does "threats detected" mean? ›

Threat detection and response is the practice of identifying any malicious activity that could compromise the network and then composing a proper response to mitigate or neutralize the threat before it can exploit any present vulnerabilities.

How do I fix Microsoft Defender antivirus found threats? ›

Click on Protection history. You can now see a list of blocked threats. You can use filters to find recommendations, quarantined, cleaned, blocked, or severity. You can also clear your filter history from the filters dropdown.

What if Defender finds malware on my device? ›

If Defender finds malware on your device it'll block it, notify you, and try to remove the malware if it can. In some instances Defender may need you to take some actions such as quarantining or removing the dangerous file or process.

What are the limits for Microsoft 365 Business Premium? ›

Microsoft 365 Business Premium was designed for small to medium-sized businesses with low to medium IT complexity requirements. Customers can purchase up to 300 Microsoft 365 Business Premium licenses for their organization. Customers can mix and match cloud subscriptions.

Does Office 365 Business Premium include antivirus? ›

Increased Threat Protection

The Defender portal includes anti-malware policies that you can set up or edit as needed. Microsoft Defender Antivirus - With Microsoft 365 Business Premium you can see detected and monitored threats in the Microsoft 365 Admin Center.

How do I turn off threat detection? ›

Windows Security
  1. Click Start.
  2. Scroll down and select Settings.
  3. Go to Update & Security.
  4. Select Windows Security.
  5. Open Virus & Threat Protection.
  6. Click Manage Settings.
  7. Switch Real-Time Protection to off.

How do I get rid of active threats? ›

Deleting files from the "Active threats" folder
  1. In the console tree, in the Repositories folder select the Active threats subfolder.
  2. In the workspace of the Active threats folder, select the files that you have to delete by using the Shift and Ctrl keys.
  3. Delete the files in one of the following ways:

What actions can an antivirus take if a threat is detected? ›

An antivirus is a program that can remove viruses or other malicious softwares. If it detects any unwanted, unusual activity or any virus, malware it automatically removes that thing or we can say it automatically fix the problem.

What does Windows Defender do when it finds a threat? ›

As soon as Microsoft Defender detects a malicious file or software, Microsoft Defender blocks it and prevents it from running.

What do you do when a threat found action is needed? ›

Threat found - action needed

Selecting the Actions dropdown at the bottom right corner will let you Quarantine the threat, rendering it harmless, or if you're confident that this item has been falsely identified as a threat you can choose to Allow on device.

Why is Windows Defender not removing threats? ›

Scan couldn't complete

Microsoft Defender Antivirus requires disk space to remove and quarantine malware files. It might be prevented from completely removing a threat if there isn't enough available space on your PC, particularly on your system drive (usually drive C).

Is this Microsoft warning real? ›

They may also put your browser in full screen mode and display pop-up messages that won't go away, apparently locking your browser. These fake error messages aim to scare you into calling their "technical support hotline". Important: Microsoft error and warning messages never include phone numbers.

Is the Windows Defender alert real or fake? ›

The Windows Defender warning you see on the browser is a scam identified and exposed by security professionals. Illegitimate actors use this scam to gain valuable information about the victims, such as bank and personal details.

How do I get rid of fake Microsoft security warnings? ›

What do I do if I get a Windows Defender security warning? If you get the Windows Defender security warning, close your web browser, reopen it, and check if the warning still appears. If it does, reinstall the browser, look for suspicious apps on your computer, or run an antivirus scan.

How do I get Office 365 Advanced Threat protection? ›

In order to set up O365 ATP, these are the steps you will need to take:
  1. Configure DKIM, DMARC, and SPF.
  2. Set Exchange Online Protection Live.
  3. Deploy Office Message Encryption.
  4. Enable O365 ATP (Also known as Defender)
  5. Set Up Office 365 MFA with the Authenticator App.
Sep 12, 2022

Does Microsoft business premium include MFA? ›

Microsoft 365 Business Premium includes the option to use security defaults or Conditional Access policies to turn on MFA for your admins and user accounts. For most organizations, security defaults offer a good level of sign-in security.

Which Defender plan is included in business premium? ›

Microsoft's site says this about Defender Plan 1: “Microsoft Defender for Office 365 Plan 1 is included in Microsoft 365 Business Premium.”

Does Microsoft 365 Business Premium include Azure Information protection? ›

Your Microsoft 365 Business Premium subscription includes information protection capabilities for compliance and privacy.

Top Articles
Crypto Market Pool - Build a website with an Unstoppable Domain
What Are “Unstoppable Domains” and Should You Use Them? - Digital.com
English Bulldog Puppies For Sale Under 1000 In Florida
Katie Pavlich Bikini Photos
Gamevault Agent
Pieology Nutrition Calculator Mobile
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Compare the Samsung Galaxy S24 - 256GB - Cobalt Violet vs Apple iPhone 16 Pro - 128GB - Desert Titanium | AT&T
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Craigslist Dog Kennels For Sale
Things To Do In Atlanta Tomorrow Night
Non Sequitur
Crossword Nexus Solver
How To Cut Eelgrass Grounded
Pac Man Deviantart
Alexander Funeral Home Gallatin Obituaries
Shasta County Most Wanted 2022
Energy Healing Conference Utah
Geometry Review Quiz 5 Answer Key
Hobby Stores Near Me Now
Icivics The Electoral Process Answer Key
Allybearloves
Bible Gateway passage: Revelation 3 - New Living Translation
Yisd Home Access Center
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
Marquette Gas Prices
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Vera Bradley Factory Outlet Sunbury Products
Pixel Combat Unblocked
Movies - EPIC Theatres
Cvs Sport Physicals
Mercedes W204 Belt Diagram
Mia Malkova Bio, Net Worth, Age & More - Magzica
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Teenbeautyfitness
Where Can I Cash A Huntington National Bank Check
Topos De Bolos Engraçados
Sand Castle Parents Guide
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Holzer Athena Portal
Hello – Cornerstone Chapel
Stoughton Commuter Rail Schedule
Selly Medaline
Latest Posts
Article information

Author: Mr. See Jast

Last Updated:

Views: 6076

Rating: 4.4 / 5 (75 voted)

Reviews: 82% of readers found this page helpful

Author information

Name: Mr. See Jast

Birthday: 1999-07-30

Address: 8409 Megan Mountain, New Mathew, MT 44997-8193

Phone: +5023589614038

Job: Chief Executive

Hobby: Leather crafting, Flag Football, Candle making, Flying, Poi, Gunsmithing, Swimming

Introduction: My name is Mr. See Jast, I am a open, jolly, gorgeous, courageous, inexpensive, friendly, homely person who loves writing and wants to share my knowledge and understanding with you.