Next-generation protection overview
Applies to
- Microsoft Defender Antivirus
- Microsoft Defender for Endpoint Plan 1
- Microsoft Defender for Endpoint Plan 2
- Microsoft Defender for Business
Platforms
- Windows
Microsoft Defender for Endpoint includes next-generation protection to reinforce the security perimeter of your network. Next-generation protection was designed to catch all types of emerging threats. In addition to Microsoft Defender Antivirus, your next-generation protection services include the following capabilities:
- Behavior-based, heuristic, and real-time antivirus protection, which includes always-on scanning using file and process behavior monitoring and other heuristics (also known as real-time protection). It also includes detecting and blocking apps that are deemed unsafe, but might not be detected as malware.
- Cloud-delivered protection, which includes near-instant detection and blocking of new and emerging threats.
- Dedicated protection and product updates, which includes updates related to keeping Microsoft Defender Antivirus up to date.
Tip
Next-generation protection is included in both Microsoft Defender for Endpoint Plan 1 and Plan 2. Learn more about Defender for Endpoint Plan 1 and Plan 2 Next-generation protection is also included in Microsoft Defender for Business and Microsoft 365 Business Premium. Compare security features in Microsoft 365 plans for small and medium-sized businesses.
Configure next-generation protection services
For information on how to configure next-generation protection services, see Configure Microsoft Defender Antivirus features.
Note
Configuration and management is largely the same in Windows Server as in Windows clients. However, there are some differences.
Tip
If you're looking for Antivirus related information for other platforms, see:
- Set preferences for Microsoft Defender for Endpoint on macOS
- Microsoft Defender for Endpoint on Mac
- macOS Antivirus policy settings for Microsoft Defender Antivirus for Intune
- Set preferences for Microsoft Defender for Endpoint on Linux
- Microsoft Defender for Endpoint on Linux
- Configure Defender for Endpoint on Android features
- Configure Microsoft Defender for Endpoint on iOS features
Tip
Performance tip Due to a variety of factors (examples listed below) Microsoft Defender Antivirus, like other antivirus software, can cause performance issues on endpoint devices. In some cases, you might need to tune the performance of Microsoft Defender Antivirus to alleviate those performance issues. Microsoft's Performance analyzer is a PowerShell command-line tool that helps determine which files, file paths, processes, and file extensions might be causing performance issues; some examples are:
- Top paths that impact scan time
- Top files that impact scan time
- Top processes that impact scan time
- Top file extensions that impact scan time
- Combinations – for example:
- top files per extension
- top paths per extension
- top processes per path
- top scans per file
- top scans per file per process
You can use the information gathered using Performance analyzer to better assess performance issues and apply remediation actions. See: Performance analyzer for Microsoft Defender Antivirus.
Feedback
Submit and view feedback for