Microsoft Secure Tech Accelerator
Apr 03 2024, 07:00 AM - 11:00 AM (PDT)
Microsoft Tech Community

Scheduled Scans with Defender AV with ATP

Copper Contributor

Good afternoon.  I'm working on migrating our company over to Microsoft Defender AV with Defender ATP as ATP is included in our E5 license.  Is there any guidance regarding running scheduled AV scans with Defender Antivirus when making use of Defender ATP?

 

Is there any need to run scheduled scans with Defender Antivirus or does Defender ATP cover that aspect?

 

I have been looking online and reading through some other post but have not found anything definite regarding is scheduled quick or full scans with Defender Antivirus are recommend to supplement the protection provided by ATP so any assistance with this would be appreciated.  Thank you.

3 Replies
Scheduled scans are all but obsolete now that most good malware is polymorphic and obfuscates itself to evade traditional virus definitions. If real-time protection is enabled, then in theory a scheduled scan shouldn't be needed other than upon first installation to verify the prior disk contents (because real-time protection will scan all new added content).
So a weekly scan is probably fine but I wouldn't recommend daily - the risk/reward ratio just isn't there when you consider the CPU overhead costs of scans. This is just my opinion.
Here is where you can find those settings using GPO, PowerShell, Intune or MEM
https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/confi...
Joe, Thanks for your reply. I think we are going to go ahead and not have scheduled scans in place. I'm not sure if you know the answer to this question or not but I'm using this documentation when working on our Anti-Malware policy https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/use-g... What I'm trying to find the answer to is why the settings under the Reporting, Network Inspection, and Root section of the Windows Defender Antivirus are being marked as Not Used? Are these settings not supported anymore? An example would be "Configure Watson Events"
According to the MSFT Documentation team, (I opened a ticket in Github to confirm), it means the documentation article has not yet been created. Notice how all the other items have articles in that same column.