Review detected threats on devices and take action - Microsoft 365 Business Premium (2024)

  • Article

As soon as Microsoft Defender detects a malicious file or software, Microsoft Defender blocks it and prevents it from running. And with cloud-delivered protection turned on, newly detected threats are added to the antivirus and antimalware engine so that your other devices and users are protected, as well.

Microsoft Defender Antivirus detects and protects against the following kinds of threats:

  • Viruses, malware, and web-based threats on devices
  • Phishing attempts
  • Data theft attempts

As an IT professional/admin, you can view information about threat detections across Windows devices enrolled in Intune in the Microsoft 365 admin center. Summary information includes:

  • How many devices need antivirus protection
  • How many devices aren't in compliance with security policies
  • How many threats are currently active, mitigated, or resolved

Actions you can take

When you view details about specific threats or devices, you see recommendations and one or more actions you can take. The following table describes actions that you might see.

ActionDescription
Configure protectionYour threat protection policies need to be configured. Select the link to go to your policy configuration page.

Need help? See Manage device security with endpoint security policies in Microsoft Intune.

Update policyYour antivirus and real-time protection policies need to be updated or configured. Select the link to go to the policy configuration page.

Need help? See Manage device security with endpoint security policies in Microsoft Intune.

Run quick scanStarts a quick antivirus scan on the device, focusing on common locations where malware might be registered, such as registry keys and known Windows startup folders.
Run full scanStarts a full antivirus scan on the device, focusing on common locations where malware might be registered, and including every file and folder on the device. Results are sent to Microsoft Intune.
Update antivirusRequires the device to get security intelligence updates for antivirus and antimalware protection.
Restart deviceForces a Windows device to restart within five minutes.

IMPORTANT: The device owner or user isn't automatically notified of the restart and could lose unsaved work.

View and manage threat detections in the Microsoft Defender portal

  1. Go to the (Microsoft Defender portal) and sign in.

  2. In the navigation pane, choose Threat Analytics to see all the current threats. Threads are categorized by threat severity and type.

  3. Select a threat to see more details about the threat.

  4. In the table, you can filter the alerts according to many criteria.

Manage threat detections in Microsoft Intune

You can use Microsoft Intune to manage threat detections as well. First, all devices whether Windows, iOS or Android, must be enrolled in Intune.

  1. Go to the Microsoft Intune admin center at https://endpoint.microsoft.com and sign in.

  2. In the navigation pane, select Endpoint security.

  3. Under Manage, select Antivirus. You see tabs for Summary, Unhealthy endpoints, and Active malware.

  4. Review the information on the available tabs, and then take any needed action.

For example, suppose that devices are listed on the Active malware tab. When you select a device, certain actions are available, such as Restart, Quick Scan, Full Scan, Sync, or Update signatures. Select an action for that device.

The following table describes the actions you might see in Microsoft Intune.

ActionDescription
RestartForces a Windows device to restart within five minutes.

IMPORTANT: The device owner or user isn't automatically notified of the restart and could lose unsaved work.

Quick ScanStarts a quick antivirus scan on the device, focusing on common locations where malware might be registered, such as registry keys and known Windows startup folders. Results are sent to Microsoft Intune.
Full ScanStarts a full antivirus scan on the device, focusing on common locations where malware might be registered, and including every file and folder on the device. Results are sent to Microsoft Intune.
SyncRequires a device to check in with Intune. When the device checks in, the device receives any pending actions or policies assigned to the device.
Update signaturesRequires the device to get security intelligence updates for antivirus and antimalware protection.

Tip

For more information, see Remote actions for devices.

How to submit a file for malware analysis

If you have a file that you think was missed or wrongly classified as malware, you can submit that file to Microsoft for malware analysis. Users and IT admins can submit a file for analysis. Visit https://www.microsoft.com/wdsi/filesubmission.

See also

Best practices for securing Microsoft 365 for business plans

Overview of Microsoft Defender for Business (Defender for Business is rolling out to Microsoft 365 Business Premium customers, beginning March 1, 2022)

Review detected threats on devices and take action - Microsoft 365 Business Premium (2024)
Top Articles
How do I set up or log into my Samsung Account?
What is a Long-Term Storage?
Obor Guide Osrs
Vaya Timeclock
Hk Jockey Club Result
Puretalkusa.com/Amac
Select The Best Reagents For The Reaction Below.
Self-guided tour (for students) – Teaching & Learning Support
Mylife Cvs Login
Roblox Character Added
Call Follower Osrs
Phillies Espn Schedule
ᐅ Bosch Aero Twin A 863 S Scheibenwischer
Lancasterfire Live Incidents
Georgia Vehicle Registration Fees Calculator
1v1.LOL - Play Free Online | Spatial
Nz Herald Obituary Notices
Woodmont Place At Palmer Resident Portal
Glover Park Community Garden
What Time Does Walmart Auto Center Open
27 Paul Rudd Memes to Get You Through the Week
Galaxy Fold 4 im Test: Kauftipp trotz Nachfolger?
Amelia Chase Bank Murder
Hdmovie2 Sbs
Smartfind Express Login Broward
Mobile crane from the Netherlands, used mobile crane for sale from the Netherlands
Revelry Room Seattle
91 Octane Gas Prices Near Me
Datingscout Wantmatures
Taktube Irani
Utexas Baseball Schedule 2023
Most popular Indian web series of 2022 (so far) as per IMDb: Rocket Boys, Panchayat, Mai in top 10
Solve 100000div3= | Microsoft Math Solver
Scioto Post News
Cvb Location Code Lookup
Dallas City Council Agenda
Daily Jail Count - Harrison County Sheriff's Office - Mississippi
Radical Red Doc
Emerge Ortho Kronos
The TBM 930 Is Another Daher Masterpiece
Insideaveritt/Myportal
Adam Bartley Net Worth
Craigslist Mexicali Cars And Trucks - By Owner
Lamp Repair Kansas City Mo
Powerboat P1 Unveils 2024 P1 Offshore And Class 1 Race Calendar
Swoop Amazon S3
Gabrielle Abbate Obituary
Gummy Bear Hoco Proposal
The Goshen News Obituary
Chitterlings (Chitlins)
683 Job Calls
Latest Posts
Article information

Author: Mr. See Jast

Last Updated:

Views: 6076

Rating: 4.4 / 5 (75 voted)

Reviews: 82% of readers found this page helpful

Author information

Name: Mr. See Jast

Birthday: 1999-07-30

Address: 8409 Megan Mountain, New Mathew, MT 44997-8193

Phone: +5023589614038

Job: Chief Executive

Hobby: Leather crafting, Flag Football, Candle making, Flying, Poi, Gunsmithing, Swimming

Introduction: My name is Mr. See Jast, I am a open, jolly, gorgeous, courageous, inexpensive, friendly, homely person who loves writing and wants to share my knowledge and understanding with you.