Forum Discussion

Cloud0009's avatar
Cloud0009
Copper Contributor
Sep 01, 2022
Solved

Defender for endpoint incorrect malware reporting on security portal

We have few machines which had malware at the time of defender AV scan and the same was remediated by defender AV and an alert was generated on security portal. However it's been many days since malware was detected and remediated but the alert for this device still appears on security portal.

When checking the alert details it shows old alert only. 

Is this something related to incorrect defender for Endpoint reporting or do we need to check something else.

  • Cloud0009 We have a similar case opened with MS support where the portal is reporting old malware still active as alerts but nothing related on the actual device events or alerts. MS support mentioned that this was a bug and is expected to get fixed by this week

2 Replies

  • ambarishrh's avatar
    ambarishrh
    Iron Contributor

    Cloud0009 We have a similar case opened with MS support where the portal is reporting old malware still active as alerts but nothing related on the actual device events or alerts. MS support mentioned that this was a bug and is expected to get fixed by this week

Resources