Forum Discussion
Inconsistent Microsoft Defender Behaviour
Hi everyone,
We have an issue whereby across several intune managed devices with identical defender AV policy, signature version, and platform version, we've found inconsistent detection/remediation behaviour.
Some devices block malicious files instantly on download (expected and correct). Others only detect on open rather than on write, or log a successful detection/remediation action without the file actually being removed from disk, it remains fully accessible indefinitely.
Since this occurs despite identical config, we're concerned this is a genuine gap in automatic remediation reliability that could affect real threats, not just our test files.
Troubleshooting completed, issue persists:
- Ruled out exclusions (path/extension/process)
- Confirmed PUA protection, real-time protection, tamper protection, and all granular protection flags enabled/healthy
- Removed orphaned third-party AV registrations from WSC (previously caused Defender to show as "snoozed")
- Confirmed filter driver (WdFilter) loaded correctly, no conflicts
- Cleared stuck "detected but not remediated" threat entries
- Ruled out file locks preventing remediation
- Cleared cached signature state, forced fresh signature pull
- Attempted full platform reset
- Confirmed cloud protection/MAPS enabled and reachable
- Increased CloudBlockLevel to test enforcement aggressiveness
Does anyone have any idea what could be happening here?
Thanks
2 Replies
- rahuljindalBronze Contributor
You mentioned that 3rd party AV was causing Defender to go in passive mode initially. Have you verified that after the removal MDE is in active mode? Is the status updated in mppreferences and on the Defender portal? Have you tried running the simulations to verify for the configuration? You can also run mde connect analyzer to ensure that all pre-reqs are met on the devices in question.
- OllieHay1Copper Contributor
Hi rahuljindal​, I can confirm after removing the 3rd party AV, it's no longer showing when checking the status. I haven't tried either of your following suggestions but will do