Windows Defender updates deployment using SCCM

NM 1 Reputation point
2020-08-29T15:17:00.877+00:00

Hello Experts,

I have a SCCM site where i am working on deployment of windows defender definition updates, it's just a primary site managing around 700 clients but the problem i am facing is we have 2 sources selected for defender updates first is config manager and second is Microsoft server but still we are not getting a good compliance rate. The rate is as low as 2%(around 14-15 clients out of 700).

I have a ADR created for deployment of defender updates and then in the policy i have set to go to second source if the definition updates are 12 hours old but it didn't improved the compliance.

My understanding is - The sources are from where the updates will be downloaded, all the client machine will look to config manager first for downloading the definition updates and if they don't get it from there then they will reach out to Microsoft update servers to download the updates after 12 hours....Is this correct ? or i am missing something. What can i do to improve the compliance.

Please, suggest.

Not Monitored
Not Monitored
Tag not monitored by Microsoft.
36,287 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Bonus12 1,116 Reputation points
    2020-08-29T22:39:35.473+00:00

    Try to make sure you don't have a Group Policy with different settings that contradict with what you have mentioned .

    Also , Try to set Microsoft source as the first source and see if that will improve the compliance

    • Make sure you deployed this policy to your machines
    0 comments No comments

  2. Amandayou-MSFT 11,046 Reputation points
    2020-08-31T09:51:19.11+00:00

    We could pick one client at random to check if the Windows Defender is installed successfully by the following picture. If so, but the report to SCCM is not compliant, it seems that the Windows Defender is installed from Microsoft. If not, maybe we could check the ADR from CM is deployed to the client.

    The sources are from where the updates will be downloaded, all the client machine will look to config manager first for downloading the definition updates and if they don't get it from there then they will reach out to Microsoft update servers to download the updates after 12 hours....Is this correct?

    If you enable this setting, definition update sources will be contacted in the order specified. Once definition updates have been successfully downloaded from one specified source, the remaining sources in the list will not be contacted. If not, it will be downloaded from other specified source. For limitation of time, Microsoft has not explained it.


    If the response is helpful, please click "Accept Answer" and upvote it.