question

VikramDoss-0672 avatar image
0 Votes"
VikramDoss-0672 asked saldana-msft edited

Microsoft Defender Antivirus Update SCCM

Dear Team,

We need to update Defender but its currently disabled via GPO and we have SCCM for patch update management.

As per the security we are advices to do the update.

Please help, do i need to enable defender first in order to update.

and also how to update defender via SCCM.

Thank you
Vikram

windows-10-securitywindows-group-policy
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Reza-Ameri avatar image
1 Vote"
Reza-Ameri answered
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

VikramDoss-0672 avatar image
0 Votes"
VikramDoss-0672 answered RitaHu-MSFT converted comment to answer

Hi Reza,

Thank you for the details,

Actually, in our environment Microsoft defender is disabled via GPO, can I still push version and signature updates via SCCM to clients even if its disabled.

Regards,
Vikram Doss

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

LimitlessTechnology-2700 avatar image
1 Vote"
LimitlessTechnology-2700 answered

Hi there,

It is not necessary that you need to update the defender in order to update it.

Also to update defender via SCCM you can use any of several available methods to keep antimalware definitions up to date on client computers in your hierarchy.

To update antimalware definitions, you can use one or more of the following methods:

-Updates distributed from Configuration Manager
-Updates distributed from Windows Server Update Services (WSUS)
-Updates distributed from Microsoft Update
-Updates distributed from Microsoft Malware Protection Center
-Updates from UNC file shares

Configure definition updates for Endpoint Protection https://docs.microsoft.com/en-us/mem/configmgr/protect/deploy-use/endpoint-definition-updates

Use WSUS to deploy definition updates to computers that are running Windows Defender https://docs.microsoft.com/en-us/troubleshoot/mem/configmgr/deploy-definition-updates-using-wsus



--If the reply is helpful, please Upvote and Accept it as an answer–

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

RitaHu-MSFT avatar image
1 Vote"
RitaHu-MSFT answered

Hello Vikram Doss,

Thanks for your effort and time to feedback on this forum. In order to help us research further, please help to describe in detail what the following means.

Actually, in our environment Microsoft defender is disabled via GPO

As far as I know, we did could apply the devices and get the Microsoft Defender Antivirus Updates through group policies.
https://docs.microsoft.com/en-us/mem/configmgr/protect/deploy-use/endpoint-definitions-network

Also we could deploy the Microsoft Defender Antivirus Updates through MECM.
https://docs.microsoft.com/en-us/mem/configmgr/protect/deploy-use/endpoint-definitions-configmgr

Please refer to the below screenshot to modify the default antimalware policy on the MECM console if you want to.
192983-17.png

Best regards,
Rita

If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


17.png (125.3 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.