Windows Defender management pack false alerts

Tommy Zhou 1 Reputation point
2023-01-04T09:04:23.24+00:00

Hello all,

I'm using the Windows Defender MP
https://systemcenter.wiki/?Get-ManagementPack=Microsoft.WindowsDefender&Version=7.1.10128.1

We often get these alerts about Defender that RTP is turned off.
275929-image.png

However when I check it out, seems like RTP is on. The monitor doesn't work actually...
Anyone else have this problem or know how to fix?

Thank you,

Sam

System Center Operations Manager
System Center Operations Manager
A family of System Center products that provide infrastructure monitoring, help ensure the predictable performance and availability of vital applications, and offer comprehensive monitoring for datacenters and cloud, both private and public.
1,633 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. SChalakov 10,576 Reputation points
    2023-01-04T13:30:43.643+00:00

    Hi Sam (TommyZhou-9058),

    this is soemthing that comes up from time to time and I think the reply from CyrAz here will give you more details:

    Management Pack for Windows Defender generates false alerts
    https://social.technet.microsoft.com/Forums/lync/en-US/671424d8-a8e7-4564-b7fc-02db13dc7acf/management-pack-for-windows-defender-generates-false-alerts?forum=operationsmanagermgmtpacks

    Can you please check if the mntioned conditions (events and WMI data, gathered through PowerShell) are also met in your case and post a short update here?

    Thanks in advance!

    ----------

    (If the reply was helpful please don't forget to upvote and/or accept as answer, thank you)
    Regards
    Stoyan Chalakov

    0 comments No comments

  2. Tommy Zhou 1 Reputation point
    2023-01-05T14:21:30.27+00:00

    I think it has to do with the PowerShell script. I have to take a look at it later, when I see a false positive again.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.