Forum Discussion
MikeP751860
Sep 21, 2023Brass Contributor
Accessing a device scan results in Defender portal
Hi, I have been asked by our service desk if they start a scan using the Defender portal against an onboarded device can they see the final scan results. I believe all we can see is when the last...
LeonPavesic
Sep 21, 2023Silver Contributor
Hi MikeP751860,
Yes, you are correct, you won't get an ultra-detailed breakdown of the scan results right within the portal, but you can still use various reports and data related to scans and security threats on those devices. Here are the options:
1. Security Alerts: Start by checking out the "Security alerts" section within the Microsoft Defender portal. This is where you'll find info on any security incidents detected on your devices. You'll get insights into what threats were found, how severe they are, and what actions were taken. Security alerts and incidents - Microsoft Defender for Cloud | Microsoft Learn
2. Device Page: To get more device-specific details, head over to the "Devices" section in the portal. This includes recent scan results, threat history, and protection status. Device profile in Microsoft 365 security portal | Microsoft Learn
3. Reports: The portal lets you generate reports that cover scan results and threat detection in detail. These reports can provide a comprehensive view of what's been going on.
Reports in Microsoft Defender for Business | Microsoft Learn
4. Advanced Hunting: This feature allows you to craft custom queries to fetch specific scan results and threat data.
Overview - Advanced hunting | Microsoft Learn
Please click Mark as Best Response & Like if my post helped you to solve your issue.
This will help others to find the correct solution easily. It also closes the item.
If the post was useful in other ways, please consider giving it Like.
Kindest regards,
Leon Pavesic
- Didi00Oct 05, 2023Copper ContributorGet-MpThreatDetection can help to see detected potential threats(if any) but would require to run on the device. Not sure but maybe worth to run via live response on Defender portal?
in the end scan results may have a lot of entry we are not interested in, al we want to see if anything malicious is detected.