An integrated threat protection solution designed to detect, investigate, and respond to cyber threats across Microsoft 365 services.
Hi there, Moo-kyung! This is Marc and thank you for posting.
According to Microsoft, Defender for Endpoint continuously analyzes endpoint data, and "vulnerability assessments are refreshed continuously and automatically using Microsoft threat intelligence" this means updates can occur without waiting for a full device scan, although local scans do contribute additional context.
TVM evaluations typically update when:
> New threat intelligence becomes available from Microsoft.
> A device reports changes (e.g., software updates, new apps, or misconfigurations).
> A vulnerability is detected during a scan.
The frequency depends on factors like network connectivity, sensor reporting, and scan schedules.
For deeper insights, you might find this Microsoft Learn page helpful:
https://learn.microsoft.com/en-us/microsoft-365...
If you're managing policy configurations, you might also find this documentation helpful for understanding scan behavior and data refresh timing:
https://learn.microsoft.com/en-us/microsoft-365...
Let me know if you find this information helpful. and I will be happy to assist further if needed.
Best regards,