Configure Microsoft Defender Antivirus notifications - Microsoft Defender for Endpoint (2024)

  • Article

Applies to:

  • Microsoft Defender for Endpoint Plan 1
  • Microsoft Defender for Endpoint Plan 2
  • Microsoft Defender Antivirus

Platforms

  • Windows

In Windows 10 and Windows 11, application notifications about malware detection and remediation are more robust, consistent, and concise. Microsoft Defender Antivirus notifications appear on endpoints when scans are completed and threats are detected. Notifications follow both scheduled and manually triggered scans. These notifications also appear in the Notification Center, and a summary of scans and threat detections appear at regular time intervals.

If you're part of your organization's security team, you can configure how notifications appear on endpoints, such as notifications that prompt for a system reboot or that indicate a threat has been detected and remediated.

Configure antivirus notifications using Group Policy or the Windows Security app

You can configure the display of additional notifications, such as recent threat detection summaries, in the Windows Security app and with Group Policy.

Note

In Windows 10, version 1607 the feature was called Enhanced notifications and was configured under Windows Settings > Update & security > Windows Defender. In Group Policy settings for all versions of Windows 10 and Windows 11, the notification feature is called Enhanced notifications.

Use Group Policy to disable additional notifications

  1. On your Group Policy management computer, open the Group Policy Management Console.

  2. Right-click the Group Policy Object you want to configure, and then select Edit.

  3. In the Group Policy Management Editor go to Computer configuration.

  4. Select Administrative templates.

  5. Expand the tree to Windows components > Microsoft Defender Antivirus > Reporting.

  6. Double-click Turn off enhanced notifications, and set the option to Enabled. Then select OK. This will prevent additional notifications from appearing.

Important

Disabling additional notifications will not disable critical notifications, such as threat detection and remediation alerts.

Use the Windows Security app to disable additional notifications

  1. Open the Windows Security app by clicking the shield icon in the task bar or searching the start menu for Security.

  2. Select Virus & threat protection tile (or the shield icon on the left menu bar) and, then select Virus & threat protection settings

  3. Scroll to the Notifications section and select Change notification settings.

  4. Slide the switch to Off or On to disable or enable additional notifications.

Important

Disabling additional notifications will not disable critical notifications, such as threat detection and remediation alerts.

Configure standard notifications on endpoints using Group Policy

You can use Group Policy to:

  • Display additional, customized text on endpoints when the user needs to perform an action
  • Hide all notifications on endpoints
  • Hide reboot notifications on endpoints

Hiding notifications can be useful in situations where you can't hide the entire Microsoft Defender Antivirus interface. See Prevent users from seeing or interacting with the Microsoft Defender Antivirus user interface for more information. Hiding notifications will only occur on endpoints to which the policy has been deployed. Notifications related to actions that must be taken (such as a reboot) will still appear on the Microsoft Configuration Manager Endpoint Protection monitoring dashboard and reports.

To add custom contact information to endpoint notifications, see Customize the Windows Security app for your organization.

Use Group Policy to hide notifications

  1. On your Group Policy management computer, open the Group Policy Management Console.

  2. Right-click the Group Policy Object you want to configure, and then select Edit.

  3. In the Group Policy Management Editor go to Computer configuration and then select Administrative templates.

  4. Expand the tree to Windows components > Microsoft Defender Antivirus > Client interface.

  5. Double-click Suppress all notifications and set the option to Enabled.

  6. Select OK. This will prevent additional notifications from appearing.

Use Group Policy to hide reboot notifications

  1. On your Group Policy management computer, open the Group Policy Management Console.

  2. Right-click the Group Policy Object you want to configure and then select Edit.

  3. In the Group Policy Management Editor go to Computer configuration.

  4. Click Administrative templates.

  5. Expand the tree to Windows components > Microsoft Defender Antivirus > Client interface.

  6. Double-click Suppresses reboot notifications and set the option to Enabled.

  7. Select OK. This will prevent additional notifications from appearing.

Tip

If you're looking for Antivirus related information for other platforms, see:

  • Set preferences for Microsoft Defender for Endpoint on macOS
  • Microsoft Defender for Endpoint on Mac
  • macOS Antivirus policy settings for Microsoft Defender Antivirus for Intune
  • Set preferences for Microsoft Defender for Endpoint on Linux
  • Microsoft Defender for Endpoint on Linux
  • Configure Defender for Endpoint on Android features
  • Configure Microsoft Defender for Endpoint on iOS features

Tip

Do you want to learn more? Engage with the Microsoft Security community in our Tech Community: Microsoft Defender for Endpoint Tech Community.

Configure Microsoft Defender Antivirus notifications - Microsoft Defender for Endpoint (2024)

FAQs

How to configure Microsoft Defender alerts? ›

Open the Windows Security app by clicking the shield icon in the task bar or searching the start menu for Security. Scroll to the Notifications section and select Change notification settings. Slide the switch to Off or On to disable or enable additional notifications.

How do I configure Microsoft Defender endpoint? ›

Sign in to the Microsoft Defender portal using at least a Security Administrator role. Select Endpoints > Configuration management > Endpoint security policies and then select Create new Policy. Select a platform from the dropdown list. Select a template, then select Create policy.

How to configure Microsoft Defender Antivirus exclusions on Windows 10? ›

Go to Start > Settings > Update & Security > Windows Security > Virus & threat protection. Under Virus & threat protection settings, select Manage settings, and then under Exclusions, select Add or remove exclusions. Select Add an exclusion, and then select from files, folders, file types, or process.

How to configure the workflow automation to respond automatically to Microsoft Defender for Cloud Alerts? ›

From Defender for Cloud's sidebar, select Workflow automation. From this page, create new automation rules, enable, disable, or delete existing ones. A scope refers to the subscription where the workflow automation is deployed. To define a new workflow, select Add workflow automation.

How do you configure alert recipients? ›

Configure Alert Recipients
  1. In the Management Console, click the. Settings. tab., click.
  2. Click. Alert Recipients. .
  3. From the. Actions. menu in the contents panel, select. New. .
  4. Enter the values for the Alert Recipients configuration. The following table describes the alert recipient properties: Property. Description. ...
  5. Click. Save. .

How do I check Windows Defender alerts? ›

Follow these steps:
  1. Sign in to the Azure portal.
  2. Navigate to Microsoft Defender for Cloud > Security alerts.
  3. (Optional) Filter the alerts list with any of the relevant filters. You can add extra filters with the Add filter option. The list updates according to the filters selected.
Aug 7, 2024

What is the difference between Microsoft Defender and Microsoft Defender for Endpoint? ›

Microsoft Defender for Office 365 is a cloud-based product offering protection against email threats and safeguarding files stored in the cloud. Microsoft Defender for Endpoint provides cybersecurity against malware, spyware and other malicious software.

How do I know if Microsoft Defender for Endpoint is enabled? ›

Use PowerShell to check the status of Microsoft Defender Antivirus
  1. Select the Start menu, and begin typing PowerShell . Then open Windows PowerShell in the results.
  2. Type Get-MpComputerStatus .
  3. In the list of results, look at the AMRunningMode row. Normal means Microsoft Defender Antivirus is running in active mode.
May 2, 2024

Where is Microsoft Defender for Endpoint? ›

Data location

Defender for Endpoint operates in the Microsoft Azure data centers in the European Union, the United Kingdom, the United States, Australia, Switzerland, or India.

How do I enable Microsoft Defender Antivirus in Windows 10? ›

Open the Windows Security app by searching the start menu for Security, and then selecting Windows Security. Select the Virus & threat protection tile (or the shield icon on the left menu bar). Select Virus & threat protection settings. Toggle the Real-time protection switch to On.

How to manage Microsoft Defender Antivirus with PowerShell on Windows 10? ›

To complete a full scan using commands on Windows 10, use these steps:
  1. Open Start.
  2. Search for PowerShell, right-click the top result, and select the Run as administrator option.
  3. Type the following command to start a full virus scan and press Enter: Start-MpScan -ScanType FullScan.
Aug 29, 2024

How do I ensure that Microsoft Defender Antivirus is turned on? ›

Select Start > Settings > Update & Security > Windows Security and then Virus & threat protection > Manage settings. (In early versions of Windows 10, select Virus & threat protection > Virus & threat protection settings.)

How do I set up alerts in Microsoft Defender? ›

Go to Microsoft Defender XDR and sign in using an account with the Security administrator or Global administrator role assigned. In the navigation pane, select Settings > Endpoints > General > Email notifications.

How to configure detection for potentially unwanted applications in defender? ›

Expand the tree to Windows Components > Microsoft Defender Antivirus. Double-click Configure detection for potentially unwanted applications, and set it to Enabled. In Options, select Block to block potentially unwanted applications, or select Audit Mode to test how the setting works in your environment. Select OK.

Can Windows Defender send email notifications? ›

Go to the Microsoft Defender portal (https://security.microsoft.com) and sign in. In the navigation pane, select Settings, and then select Endpoints. Then, under General, select Email notifications. Review the information on the Alerts and Vulnerabilities tabs.

What is the difference between Microsoft Defender incident and alert? ›

A security incident is a collection of related alerts. Incidents provide you with a single view of an attack and its related alerts, so that you can quickly understand the actions an attacker took, and the affected resources.

How do I change Windows Security alerts? ›

The Notifications page of Windows Security settings lets you configure what kind of notifications you want to receive. You can find it by going to Settings in the lower left corner of the Windows Security app and selecting Manage notifications.

How do I change the alert severity in defender? ›

In Defender for IoT in the Azure portal, select the Alerts page on the left, and then select an alert in the grid. Either on the details pane on the right, or in an alert details page itself, select the new status and/or severity.

How to suppress alerts in Microsoft Defender? ›

From Defender for Cloud's security alerts page, select the alert you want to suppress. From the details pane, select Take action. In the Suppress similar alerts section of the Take action tab, select Create suppression rule.

Top Articles
OdysseyDAO - How to contribute to DAOs?
OneDrive stuck on Processing changes
Fernald Gun And Knife Show
Hometown Pizza Sheridan Menu
Jail Inquiry | Polk County Sheriff's Office
Tyler Sis 360 Louisiana Mo
Fredatmcd.read.inkling.com
Phone Number For Walmart Automotive Department
Crossed Eyes (Strabismus): Symptoms, Causes, and Diagnosis
Chalupp's Pizza Taos Menu
Ati Capstone Orientation Video Quiz
Unraveling The Mystery: Does Breckie Hill Have A Boyfriend?
Nestle Paystub
Obituary Times Herald Record
Phillies Espn Schedule
Beau John Maloney Houston Tx
Evil Dead Rise Showtimes Near Regal Columbiana Grande
Summer Rae Boyfriend Love Island – Just Speak News
60 X 60 Christmas Tablecloths
Everything We Know About Gladiator 2
Red Devil 9664D Snowblower Manual
The Grand Canyon main water line has broken dozens of times. Why is it getting a major fix only now?
Zalog Forum
Band Of Loyalty 5E
TBM 910 | Turboprop Aircraft - DAHER TBM 960, TBM 910
Kamzz Llc
Cvs El Salido
Greensboro sit-in (1960) | History, Summary, Impact, & Facts
Dove Cremation Services Topeka Ks
Santa Barbara Craigs List
Guinness World Record For Longest Imessage
Log in or sign up to view
Tripcheck Oregon Map
Earthy Fuel Crossword
Walter King Tut Johnson Sentenced
2015 Chevrolet Silverado 1500 for sale - Houston, TX - craigslist
Mgm Virtual Roster Login
The Best Carry-On Suitcases 2024, Tested and Reviewed by Travel Editors | SmarterTravel
Domino's Delivery Pizza
Dr. John Mathews Jr., MD – Fairfax, VA | Internal Medicine on Doximity
Woodman's Carpentersville Gas Price
Levothyroxine Ati Template
Wait List Texas Roadhouse
F9 2385
Samantha Lyne Wikipedia
Lcwc 911 Live Incident List Live Status
Craigslist Com Panama City Fl
Tunica Inmate Roster Release
Sallisaw Bin Store
8776725837
877-552-2666
Mit diesen geheimen Codes verständigen sich Crew-Mitglieder
Latest Posts
Article information

Author: Rob Wisoky

Last Updated:

Views: 6359

Rating: 4.8 / 5 (68 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Rob Wisoky

Birthday: 1994-09-30

Address: 5789 Michel Vista, West Domenic, OR 80464-9452

Phone: +97313824072371

Job: Education Orchestrator

Hobby: Lockpicking, Crocheting, Baton twirling, Video gaming, Jogging, Whittling, Model building

Introduction: My name is Rob Wisoky, I am a smiling, helpful, encouraging, zealous, energetic, faithful, fantastic person who loves writing and wants to share my knowledge and understanding with you.