SCCM Client installed, Microsoft Defender showing as at risk

James Dixon 26 Reputation points
2022-11-07T16:57:31.577+00:00

We have recently installed and configured SCCM and Microsoft Defender on our servers. 16 of them have installed the SCCM client, applied the Microsoft Defender policies and are reporting back to the SCCM console. One of our servers has installed the client, applied the Microsoft Defender policies but has not reported back to SCCM and is showing at risk.

I have uninstalled the client, restarted the server, deleted the leftover SCCM folder in C:\Windows and reinstalled the client. This has reinstalled but I am still seeing the same issue where the server shows as at risk.

The Endpoint Protection Remediation Information information for this server in SCCM all shows as blank, which I suspect is why it shows as at risk. Any tips or suggestions as to where I should start looking here? Many thanks in advance.

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,767 questions
Microsoft Configuration Manager
0 comments No comments
{count} votes

5 additional answers

Sort by: Most helpful
  1. James Dixon 26 Reputation points
    2022-11-10T12:07:13.237+00:00

    Hi @CherryZhang-MSFT , thanks for your replies.

    I can see some error 2001, cannot find the file specified when trying to update from the File Share source. The server does have definition updates installed so must be updating from another source. I've checked and the other Windows Server 2019 servers are also reporting the same error but are updating.

    As far as I can tell (other than this file share update source which I'll have a look into) Windows Defender is working correctly on the server. I still feel like the issue is with the SCCM client not reporting rather than Windows Defender.