Microsoft Defender: Schedule automatic scans

  • Set up scheduled quick scans and complement with real-time protection.
  • Choose from quick, full, or custom based on the scenario and impact.
  • Manage with GPO, Intune, PowerShell, WMI, and Defender Portal for greater control.
  • Optimizes performance and considers mail and network drive limitations.

Automatic scans in Microsoft Defender

Automate antivirus scans with Microsoft Defender It allows you to keep your computers protected without interrupting your daily work, running periodic scans when the system is idle or during periods you define. In this article, we explain in detail how these automatic scans work, what types exist, and how to choose the most appropriate one for each scenario.

We also analyzed some performance optimizations to avoid unnecessary scans, Important limitations such as the handling of email and mapped network drives, as well as threat intelligence improvements such as automatic file and URL detonation analysis integrated into the Defender XDR experience.

What do we mean by automatic scans in Microsoft Defender?

Automatic analyses are Scheduled scans that add to the real-time protection of Microsoft Defender Antivirus, which inspects files when they're opened or closed, and when you navigate through folders. The goal is to periodically and proactively scan your computer, ideally when you're not using it, to minimize the impact on productivity.

In addition to regular programming, you can force one-off reviews on demand and even trigger remote scans from the portal Microsoft Defender, giving you complete control to respond to signs of possible infection or to verify that a previous threat has been completely eradicated.

Antivirus

Scan types in Microsoft Defender: Quick, Full, and Custom

  • Quick exam (recommended)This type of scan checks critical locations where malware often establishes persistence. Combined with real-time protection, it provides robust coverage against threats that start with the system and against kernel-level malware, without excessive resource consumption.
  • Relevant novelty of the rapid examination- Since the December 2023 platform update (4.18.2311.xx), a preview version of 'Quick scan includes exclusions' is available to scan files and directories during the quick scan that are excluded from real-time protection using contextual exclusions.
  • complete exam. It starts with a quick scan and then scans all mounted fixed disks, as well as removable or network drives if you configure it. This can take hours or even days, depending on the volume and type of data.
  • Personalized exam. It focuses on the paths you choose: specific folders, a USB drive, a specific network location, etc. It's useful for validating portable media or system areas you want to scan specifically.
Windows Defender
Related article:
How to schedule Windows Defender to scan at a specific time

Schedule automatic scans: options and steps

The scheduled exams are additional to real-time protection and can be defined on a daily or weekly basisThere are two native scheduling modes: daily (quick scan only) and weekly (quick or full). Scheduled scans run based on the device's local time zone.

If you prefer to fine-tune your schedule from within Windows, you can use the Task SchedulerAs a general guide, these are the key steps:

  1. In the search bar, type 'Task Scheduler' and open the application.
  2. In the left panel, expand 'Task Scheduler Library' > 'Microsoft' > 'Windows' and navigate to the 'Windows Defender' folder.
  3. In the central panel, double-click 'Windows Defender Scheduled Scan'.
  4. In Scheduled Scan Properties, go to the 'Triggers' tab and choose 'New'.
  5. Specifies the frequency with which you want the exam to run and the start time you prefer.

Microsoft Defender automatic scans

Scheduled performance optimization for quick exams

To minimize the impact, Defender may skip a scheduled quick scan if a 'qualified' scan has already been run within the last 7 daysThis optimization only applies to scheduled quick scans; it does not affect manual, on-demand quick scans.

If the internal qualification conditions of the last rapid exam are not met, the optimization doesn't apply, and the system will launch a scheduled scan. Although the detailed criteria aren't listed in this excerpt, the intent is to avoid unnecessary repetition without compromising protection.

Key points and good practices to consider:

  • Real-time protection + quick scanThe combination of both provides strong coverage, as real-time protection inspects every file opened or closed and every folder accessed by the user, while quick protection checks persistence locations.
  • Protection in the cloudCloud-based protection and controlled access make it easy for accessed files to be evaluated using the latest cloud-based intelligence and machine learning models.
  • Escalation to full exam for certain detectionsIf real-time protection detects malware and initially can't determine the extension of the affected files, Defender can initiate a full scan as part of the remediation process.
  • Impact and durationFull exams consume more resources and can take a long time. Consider your schedule carefully and prioritize the quick exam as the default option, reserving the full exam for specific cases.

Configuration using Intune, Configuration Manager, and Group Policy

  • Microsoft IntuneYou can configure device scanning and restriction settings from Intune, including managing Defender Antivirus on Windows 10 and Windows 11. The Endpoint Security view allows you to centrally apply antivirus policies.
  • Microsoft Configuration Manager (current branch)If you use ConfigMgr, you can create and deploy anti-malware policies using the Scan Settings section, defining cadences and behaviors for managed clients.
  • Group Policy (GPO)From the Group Policy Management Console, edit the desired GPO and navigate to 'Computer Configuration' > 'Administrative Templates' > 'Windows Components' > 'Microsoft Defender Antivirus'. Select the appropriate location and adjust the policies as needed. Apply with 'OK' and repeat for other options.

Main GPO options and associated parameters

  • Email Examination (Scan > Enable Email Scanning). Default: Disabled. PowerShell: -DisableEmailScanningSee email limitations below.
  • Script Exam. Enabled by default. Allows you to enable or maintain script scanning. Reference: Defender/AllowScriptScanning.
  • Reanalysis Points Examination (Scan > Enable Reanalysis Point Scanning). Default: Disabled. Direct parameter not available; see the Reanalysis Point Guide.
  • Mapped network drives in full exam (Scan > Run full scan on mapped network drives). Default: Disabled. PowerShell: -DisableScanningMappedNetworkDrivesForFullScan.
  • Archive files (Scan > Archive File Scan). Default enabled. PowerShell: -DisableArchiveScanningThe extension exclusion list takes priority.
  • Network files (Scan > Network File Scan). Default disabled. PowerShell: -DisableScanningNetworkFilesSome templates also show 'Network File Scanning Configuration' as enabled by default; please note possible differences between ADMX versions.
  • Packaged executables (Scan > Packaged Executable File Scan). Enabled by default. This option has been removed from certain Windows 11 Administrative Templates (21H2, 22H2, and 23H2). There is no equivalent setting.
  • Removable drives (Scan > Scan removable drives only during full scans). Default: Disabled. PowerShell: -DisableRemovableDriveScanning.
  • Maximum depth of archive files (Scan > Specify Maximum Depth). Default 0. No parameter available.
  • Maximum CPU usage (Scan > Maximum CPU percentage during a scan). Default 50. PowerShell: -ScanAvgCPULoadFactorIt's a guideline average, not a hard limit; manual tests ignore it.
  • Maximum file size of archive (Scan > Specify maximum size in KB). Default is unlimited (value 0 means no limit). No parameter available.
  • Low CPU priority for scheduled exams. Default disabled. No direct parameter.
  • CPU Throttling Type. Disabled by default. PowerShell: -ThrottleForScheduledScanOnly.
  • Include excluded in rapid exam (Scan > Excluded files and directories scan during quick scan). Disabled by default. Related to the ability to preview exclusions.

Run exams on demand and remotely

Microsoft Defender Portal (security.microsoft.com)You can launch a remote scan on a device:

  1. Access the portal and log in.
  2. Open the device page objective.
  3. Select the ellipsis (…) and choose 'Run antivirus scan'.
  4. Choose the type of exam between quick or full, add a comment and confirm.

Check status in the Action Center. Go to 'Actions & Submissions' > 'Action Center' > 'History' tab. Under 'Filters,' select the 'Start Antivirus Scan' action type, apply it, and review the status. You'll see a 'Completed' status when it's finished.

Microsoft Intune. You have two common routes to take an exam:

  • Endpoint Security > Antivirus: From the list of actions, select Quick scan (recommended) or Full scan on Windows 10 or Windows 11.
  • Devices > All Devices: Go to the desired device, select '… More' and run Quick Scan or Full Scan.

Windows Security ApplicationOn the endpoint itself, you can initiate a scan from the native Windows Security app, ideal for spot checks.

PowerShell. To start an exam use Start-MpScan. If you want the quick scan to include the exclusions, set the preference with Set-MpPreference -QuickScanIncludeExclusions 1.

Command line (mpcmdrun.exe). Uses mpcmdrun.exe -scan -scantype 1 for a quick scan. The utility offers other parameters for complete or specific paths, useful in scripts or interfaceless environments.

WMI. Through class MSFT_MpScan and his method Start You can automate scans from management tools that orchestrate WMIv2 calls.

mdti

What's new: Automatic detonation analysis for files and URLs

Microsoft Defender Threat Intelligence (MDTI) incorporates an automatic file and URL detonation capability, integrated into the Defender XDR interface. When you search for a file or URL with no reputation results, an asynchronous background detonation process is triggered, primarily in the US region.

If there is no reputation or detonation initially, MDTI retries the query for that file or URL in the background. Although there is no fixed SLA for volume and availability, the operational goal is to deliver results within approximately two hours, depending on system load.

This automation expands the knowledge base on the global threat landscape, giving security teams deeper, more timely insight into unknown files and URLs to strengthen defenses.

Applies to platforms and versions

The capabilities described are targeted at Windows endpoints managed with Microsoft Defender Antivirus.. In particular, the optimization to skip scheduled quick scans applies to Windows 10 Anniversary Update (1607) and later, and Windows Server 2016 (1607) and later, excluding Core Server installations.

Strengthen your security posture by reviewing exam best practices documentation and Microsoft Defender Antivirus considerations, as well as Microsoft Security help and learning resources.


Add as preferred source in Google