SCAN starting not on settings?

Duchemin, Dominique 2,011 Reputation points
2023-04-06T03:45:59.1533333+00:00

Hello, I have the following settings given by the policy:

2023-04-05_15-18-12 ISS - Servers - SCEP - Parata.png

but why does the scan starts at 11:54:09 AM in the middle of the day!!! Log Name:      Microsoft-Windows-Windows Defender/Operational Source:        Microsoft-Windows-Windows Defender Date:          4/5/2023 11:54:09 AM Event ID:      1000 Task Category: None Level:         Information Keywords:      User:          SYSTEM Computer:      VIPPARATA1.ad Description: Microsoft Defender Antivirus scan has started.               Scan ID: {CDB87FA3-D296-4EB8-8F6F-8BBE363463F9}               Scan Type: Antimalware               Scan Parameters: Full Scan               Scan Resources:               User: NT AUTHORITY\SYSTEM I noticed this is happening time to time... not sure why?

VIPPARA1 Event Logc.png Thanks, Dom

Microsoft Security | Intune | Configuration Manager | Other
{count} votes

2 answers

Sort by: Most helpful
  1. CherryZhang-MSFT 6,506 Reputation points
    2023-04-07T05:55:00.6766667+00:00

    Hi @Duchemin, Dominique 1, According to the screenshot your provided, the option Start a scheduled scan only when the computer is idle is set to Yes, this will impact the expected scheduled time by requiring the machine to be idle first.  1

    2, Besides, please help check if the policy is set on your client. for example: 2

    Looking forward to your feedback. Best regards Cherry


      If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  2. Duchemin, Dominique 2,011 Reputation points
    2023-04-07T20:20:41.87+00:00

    Hello,

    Point 1: Does this mean that the machine is waiting an idled time ANYTIME after 2:00 AM before running? so it could start anytime without notice!!! this could be the culprit but how to manage the date & time the Full Scan starts? should I change all policies to No for this particular setting?

    Point 2: Two different machines with two different settings: 2023-04-07_9-35-28 SCEP Client Policy.png 2023-04-07_9-42-29 SCEP Client Policy.png 2023-04-07_9-49-50 SCEP Client Policy Parata.png 2023-04-07_9-56-56 Client Policy CZOHVCTSIWSP01.png

    If I believe the Operational Logs there is never a Full Scan running on most of the machines... no event 1000 & 1001 for a lot of machines Thank you Dom


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.