Use Microsoft Intune to configure and manage Microsoft Defender Antivirus

Applies to:


  • Windows

You can use the Microsoft Intune family of products to configure Microsoft Defender Antivirus scans, like Microsoft Intune and Configuration Manager.

Configure Microsoft Defender Antivirus scans in Intune

  1. Go to the Microsoft Intune admin center (, and sign in.

  2. Navigate to Endpoint Security.

  3. Under Manage, choose Antivirus.

  4. Select your Microsoft Defender Antivirus policy.

  5. Under Manage, choose Properties.

  6. Next to Configuration settings, choose Edit.


    AllowIntrusionPreventionSystem antivirus settings is officially being deprecated and as such cannot be configured.

  7. Expand the Scan section, and review or edit your scanning settings.

  8. Choose Review + save.


Performance tip Due to a variety of factors (examples listed below) Microsoft Defender Antivirus, like other antivirus software, can cause performance issues on endpoint devices. In some cases, you might need to tune the performance of Microsoft Defender Antivirus to alleviate those performance issues. Microsoft's Performance analyzer is a PowerShell command-line tool that helps determine which files, file paths, processes, and file extensions might be causing performance issues; some examples are:

  • Top paths that impact scan time
  • Top files that impact scan time
  • Top processes that impact scan time
  • Top file extensions that impact scan time
  • Combinations – for example:
    • top files per extension
    • top paths per extension
    • top processes per path
    • top scans per file
    • top scans per file per process

You can use the information gathered using Performance analyzer to better assess performance issues and apply remediation actions. See: Performance analyzer for Microsoft Defender Antivirus.


Do you want to learn more? Engage with the Microsoft Security community in our Tech Community: Microsoft Defender for Endpoint Tech Community.