Vulnerability Update Frequency

Anonymous
2025-06-05T01:48:08+00:00

Good day,

Is there any documentation that outlines how frequently vulnerabilities are updated on endpoints in Defender for Endpoint?

If not, does anyone have any guidance on this?

is it on a live basis or when a scan is run?

Thank you.

Microsoft 365 and Office | Microsoft 365 Defender | Other | Other

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2025-06-05T03:27:16+00:00

Hi there, Moo-kyung! This is Marc and thank you for posting.

According to Microsoft, Defender for Endpoint continuously analyzes endpoint data, and "vulnerability assessments are refreshed continuously and automatically using Microsoft threat intelligence" this means updates can occur without waiting for a full device scan, although local scans do contribute additional context.

TVM evaluations typically update when:

> New threat intelligence becomes available from Microsoft.

> A device reports changes (e.g., software updates, new apps, or misconfigurations).

> A vulnerability is detected during a scan.

The frequency depends on factors like network connectivity, sensor reporting, and scan schedules.

For deeper insights, you might find this Microsoft Learn page helpful:

https://learn.microsoft.com/en-us/microsoft-365...

If you're managing policy configurations, you might also find this documentation helpful for understanding scan behavior and data refresh timing:

https://learn.microsoft.com/en-us/microsoft-365...

Let me know if you find this information helpful. and I will be happy to assist further if needed.

Best regards,

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

0 additional answers

Sort by: Most helpful