![]() |
MS-DEFCON 2:
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it.
|
-
Automatic virus definition updates for Defender
Home › Forums › AskWoody support › Windows › Windows 10 › Questions: Win10 › Automatic virus definition updates for Defender
- This topic has 8 replies, 3 voices, and was last updated 1 month ago.
Viewing 4 reply threads-
AuthorPosts
-
-
March 7, 2021 at 5:50 am #2348456
TonyC
AskWoody LoungerYou can use GP to edit the behavior of Windows Defender in terms of automatically updating itself, so that it automatically updates itself after each time the computer starts and the Windows Defender service starts.
However, I haven’t seen an entry that would dictate that Windows Defender should check for updates, say, every 2 or 4 hours. If that type of setting exists, I’d be very interested in seeing it and just maybe tweaking it a bit.
If you’re confident in looking into the group policy editor, I can tell you just where the entry lies that will allow your copy of Windows Defender to automatically update itself every time the computer and its service restart.
@Bob99 – I have no problem in using the group policy editor, so I would appreciate knowing where to find the setting that directs Defender to update it virus definitions automatically every time the computer starts.
However, if Defender already receives virus definition updates automatically and regularly even when GP=2 (Configure Automatic Updates in the group policy editor set to “Enabled” with a value of “2” (Notify)), what is the point of this additional setting?
-
March 7, 2021 at 7:04 am #2348477
PKCano
ManagerHowever, if Defender already receives virus definition updates automatically and regularly even when GP=2 (Configure Automatic Updates in the group policy editor set to “Enabled” with a value of “2” (Notify)), what is the point of this additional setting?
The Group Policy setting to notify download/install (“2”) controls the action of Windows Update where it pertains to Cumulative Updates, Servicing Stacks, .Net Cumulative Updates (not necessarily Previews), updates for other MS products, etc. It prevents the automatic download of the updates from the Windows Update queue until the “Download” button (NOT “check for updates”) is clicked. The updates remain in the queue, giving the User a control of updating that the on-off function of “Pause” does not give.
If you use this function, you should NOT also use Pause. If you use Pause in addition to “2,” when you “Resume updates,” it will ignore the “2” (notify) and immediately begin the download/install of updates. This is explained in AKB2000016.In my experience, the Defender updates will go ahead and install regardless of the “2” setting.
1 user thanked author for this post.
-
March 7, 2021 at 8:21 am #2348490
-
March 7, 2021 at 11:15 am #2348521
anonymous
GuestHi @TonyC !
You’re going to want to go to the following location to enable Windows Defender to automatically check for updates every time the computer starts and the Windows Defender service starts:
Local Computer Policy>Administrative Templates>Windows Components>Microsoft Defender Antivirus>Security Intelligence Updates
All of those are folder names within Group Policy. Once you’re in the Security Intelligence Updates folder, you’ll see a list of policies/preferences. Go down the list to the very last one. It should be labeled “Check for the latest virus and spyware security intelligence on startup”. This is the only one you need to change. Double click on that policy name to bring up its properties box, and click the “Enabled” setting and then click “OK”. Then close the policy editor.
A word of caution, though. There is a similarly-named setting a ways above the one I just mentioned, and it’s called “Initiate security intelligence update on startup”. This one should be left set to “Not configured”, as that will make things work just fine. Per the explanation that accompanies it, “If you enable or do not configure this setting, security intelligence updates will be initiated on startup when there is no antimalware engine present.”
R/
Bob99
-
March 8, 2021 at 9:26 am #2348750
TonyC
AskWoody LoungerThank you. When I connect to the Internet for the first time, I just going to have to wait and see what happens. But, before I connect for the first time, I will ensure Defender’s virus definitions are up to date by running the latest mpam-fe.exe file. Then, every time I logon subsequently, I will check to see whether Defender’s virus definitions are being updated automatically.
If it transpires that they are not being updated automatically, I will try your suggestion. If that doesn’t work, then I will have to revert to my original plan of writing a batch script to do the job and scheduling it to run on a regular basis.
I have also glanced at the “Initiate security intelligence update on startup” setting in gpedit, but I don’t really understand its description.
-
This reply was modified 1 month ago by
TonyC.
-
This reply was modified 1 month ago by
-
-
March 7, 2021 at 5:03 pm #2348585
Rick Corbett
AskWoody_MVPPersonally I would just use the PowerShell Update-MpSignature cmdlet. That’s what it’s there for.
Hope this helps…
-
March 8, 2021 at 3:20 am #2348658
TonyC
AskWoody LoungerI was originally under the impression that, if GP=2 (Configure Automatic Updates in the group policy editor set to “Enabled” with the value “2” (Notify)), Defender would not receive virus definition updates automatically. I was therefore preparing to configure a scheduled task to run a batch script containing the sequence of commands documented in https://www.microsoft.com/en-us/wdsi/defenderupdates. This sequence uses the MpCmdRun.exe command, not the PowerShell cmdlet that you mentioned.
Two queries:
- If, as others have indicated, Defender still receives virus definition updates automatically despite the setting GP=2, what is the point of doing anything else?
- I’m not familiar with PowerShell cmdlets. Does the use of the cmdlet that you mentioned have any distinct advantage over the MpCmdRun.exe command?
-
March 8, 2021 at 8:27 am #2348724
Rick Corbett
AskWoody_MVPI’m not familiar with PowerShell cmdlets. Does the use of the cmdlet that you mentioned have any distinct advantage over the MpCmdRun.exe command?
No advantage at all. Just different methods of calling the exact same functionality. If you’re more comfortable with MpCmdRun.exe and a batch script then IMO they are easier to schedule than PowerShell cmdlets.
1 user thanked author for this post.
-
March 8, 2021 at 8:54 am #2348731
-
-
-
-
AuthorPosts
Viewing 4 reply threads -
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments. Click here for details and to sign up.
Search Newsletters
Search Forums
Recent Replies
Hamsa Vicerra on How can I locate Bitlocker key in OEM refurb HP laptop?
4 minutes agorebop2020 on MS-DEFCON 2 – Deferring the April Updates
1 hour, 16 minutes agobradster on How to customize and manage your Microsoft Account
1 hour, 43 minutes agoanonymous on Upgrade Firefox…recommendations please.
1 hour, 43 minutes agoCWBillow on Mapping a drive
2 hours, 23 minutes agoCWBillow on Mapping a drive
2 hours, 57 minutes agokrism on Question about allowing/stopping laptop from turning off USB device
3 hours, 9 minutes agocastiel on The ides of March
3 hours, 24 minutes agoOscarCP on New age olympics – hacking contest
3 hours, 46 minutes agoanonymous on Why KB2999226 installed today?
3 hours, 49 minutes agoOscarCP on Good animated movies and shows for ages ten to one hundred and ten.
3 hours, 54 minutes agoCWBillow on Mapping a drive
3 hours, 56 minutes agocastiel on The ides of March
4 hours, 3 minutes agoMicrofix on Upgrade Firefox…recommendations please.
4 hours, 4 minutes agoanonymous on Why KB2999226 installed today?
4 hours, 5 minutes agob on Upgrade Firefox…recommendations please.
4 hours, 17 minutes agoMicrofix on The ides of March
4 hours, 22 minutes agoanonymous on New smartphone? Great! Now don’t charge it past 80%
4 hours, 24 minutes agoanonymous on How to customize and manage your Microsoft Account
4 hours, 25 minutes agocastiel on The ides of March
4 hours, 27 minutes agoTechTango on New smartphone? Great! Now don’t charge it past 80%
4 hours, 30 minutes agoSave_Us_from_MS on New smartphone? Great! Now don’t charge it past 80%
4 hours, 41 minutes agob on The ides of March
4 hours, 43 minutes agocastiel on The ides of March
4 hours, 48 minutes agoSusan Bradley on The ides of March
4 hours, 59 minutes agoanonymous on Am I FLoCed? A New Site to Test Google’s Invasive Experiment
5 hours, 9 minutes agoSusan Bradley on Why KB2999226 installed today?
5 hours, 21 minutes agoRetiredGeek on 1809 and SMBv1 – Still not fully fixed in 20H2
5 hours, 21 minutes agoanonymous on Why KB2999226 installed today?
5 hours, 23 minutes agoanonymous on Known Issue Rollback
5 hours, 24 minutes ago
Recent Topics
-
USB 3.0 slows down by a factor of 10x when not used
1 hour, 59 minutes ago
-
Upgrade Firefox…recommendations please.
1 hour, 44 minutes ago
-
Two links the get to Outlook online?
6 hours, 22 minutes ago
-
Am I FLoCed? A New Site to Test Google’s Invasive Experiment
5 hours, 9 minutes ago
-
20H2 and NVMe SSDs
7 hours, 58 minutes ago
-
Why KB2999226 installed today?
3 hours, 50 minutes ago
-
Error 4605 Command is not available
8 hours, 56 minutes ago
-
legitimate interest
15 hours, 43 minutes ago
-
How to customize and manage your Microsoft Account
1 hour, 44 minutes ago
-
New smartphone? Great! Now don’t charge it past 80%
4 hours, 25 minutes ago
-
Check or change Win10’s file-sharing encryption level
19 hours ago
-
Freeware Spotlight — Killer
19 hours, 2 minutes ago
-
Known Issue Rollback
5 hours, 24 minutes ago
-
Dism RestoreHealth shows two “Versions” and Q re 20H2 “Experience”
1 day, 4 hours ago
-
Firefox SSD capacity usage ?
6 hours, 54 minutes ago
-
Android : New Wormable Malware Spreads by Creating WhatsApp Auto-Replies
1 day, 10 hours ago
-
KB4092436 – can neither install it or hide it
1 day, 8 hours ago
-
MS-DEFCON 2 – Deferring the April Updates
1 hour, 16 minutes ago
-
Tasks for the weekend – April 10, 2021 – change your Office
16 hours, 21 minutes ago
-
Grandma, what big updates you have!
1 day, 19 hours ago
-
Mapping a drive
2 hours, 23 minutes ago
-
vssvc?
16 hours, 26 minutes ago
-
Inside tech support scams
1 day, 4 hours ago
-
Hackers hacked Swarmshop stolen credit cards database
2 days, 16 hours ago
-
DuckDuckGo updates its plugin to block Google’s creepy FLoC
1 day, 14 hours ago
-
Initial Apple M1 SoC Support Aims For Linux 5.13 Kernel
2 days, 16 hours ago
-
How much RAM does your computer have?
18 hours, 2 minutes ago
-
odd optional update
2 days, 23 hours ago
-
Editing a PDF in Mint
1 day, 6 hours ago
-
20H2 and and OOB optional March 18 printer problem update
1 day, 5 hours ago
Search for Topics
Recent blog posts
- How to customize and manage your Microsoft Account
- New smartphone? Great! Now don’t charge it past 80%
- Check or change Win10’s file-sharing encryption level
- Freeware Spotlight — Killer
- Known Issue Rollback
- MS-DEFCON 2 – Deferring the April Updates
- Tasks for the weekend – April 10, 2021 – change your Office
- Inside tech support scams
Key Links
Copyright © 2004 – 2021 AskWoody Tech LLC. All rights reserved.