Forum Discussion
NY_Dina
Aug 25, 2022Copper Contributor
Microsoft Defender for Endpoint definition out of dated
Hi all, Some devices that connected to internet can't get update AV signature, I trying to forced security intelligence from GPO but can't latest definition update. Please advise solution to reso...
NY_Dina
Aug 30, 2022Copper Contributor
Jonhed Thank you Jonh for advise, Please kindly below path of GPO has configured
GPO: Computer Configuration\Policies\Windows Components\Microsoft Defender for Antivirus\Security Intelligence Updates
Please kindly see details as attached pictures. And also advise if missing policy not configure.
Thank you,
Jonhed
Aug 30, 2022Steel Contributor
Ok, so you are running the default sources.
Can't remember what those are, so could you run "Get-MpPreference" in powershell and check the value of "SignatureFallbackOrder" is?
Also, what happens if you try to run a manual update from the security center on one of the affected pcs? Do you get some sort of error code?
Can't remember what those are, so could you run "Get-MpPreference" in powershell and check the value of "SignatureFallbackOrder" is?
Also, what happens if you try to run a manual update from the security center on one of the affected pcs? Do you get some sort of error code?
- NY_DinaAug 30, 2022Copper ContributorIn powershell "Get-MpPreference" I got "SignatureFallbackOrder" is "MicrosoftUpdateServer | MMPC"
Manual update also got failed Microsoft defender antivirus definition update. And error code is (0x80244018).
Thank you- JonhedAug 30, 2022Steel ContributorCould be a network problem then.
Do you have a proxy in your environment
If you do are all the required URLs allowed, and have you setup defender to use said proxy?- NY_DinaAug 31, 2022Copper ContributorHi Jonhed, After we check with network team some of MDE update definition update url was blocked by firewall, now Microsoft security intelligence got update is working as normal. Just to verify about GPO that shared with you as attached picture there's correct or not?