Windows Defender Offline via WinPE

~OSD~ 2,151 Reputation points
2020-11-28T14:01:09.34+00:00

Hi

Is it possible /supported to scan windows installation via WinPE?
I was testing the procedure outlined here for USB creation here:
https://support.microsoft.com/en-us/windows/help-protect-my-pc-with-microsoft-defender-offline-9306d528-64bf-4668-5b80-ff533f183d6c
After some adjustments was able to integrate to WinPE image ... however, it wasn't successful as Defender defination was outdated and I must have internet connection to perform a scan.
Can we configure /customize somehow to run scan without internet? Maybe not check for the latest defination update but rely on what is available in PE local assets?
Or any other optimized method?

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,840 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. AliceYang-MSFT 2,091 Reputation points
    2020-11-30T09:11:50.593+00:00

    Hi,

    It is supported to scan windows installation via WinPE.

    And we strongly recommend that you update latest full definition files. You can visit Launching a Windows Defender Offline Scan with Configuration Manager 2012 OSD and follow steps in Building the Windows Defender Offline WIM to perform scan via WinPE.

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.
    0 comments No comments

  2. ~OSD~ 2,151 Reputation points
    2020-11-30T13:32:52.05+00:00

    Hi,

    Was using the same link Config Mgr 2012 OSD but it always show error as definitions are not upto date.
    Where I should place the definitions files precisely?
    And limit to the local repository only thus without Internet connection?

    0 comments No comments