Skip to content

Commit

Permalink
Update run-scan-microsoft-defender-antivirus.md
Browse files Browse the repository at this point in the history
Another internal ask, to specify the context of local and network scans
  • Loading branch information
martyav committed Sep 23, 2020
1 parent 3cb7bbe commit a206de2
Showing 1 changed file with 3 additions and 0 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -32,6 +32,9 @@ You can run an on-demand scan on individual endpoints. These scans will start im

Quick scan looks at all the locations where there could be malware registered to start with the system, such as registry keys and known Windows startup folders.

> [!IMPORTANT]
> Microsoft Defender Antivirus runs in the context of the [LocalSystem](https://docs.microsoft.com/en-us/windows/win32/services/localsystem-account) account when performing a local scan. For network scans, it uses the context of the device account. If the domain device account doesn't have appropriate permissions to access the share, the scan won't work. Ensure that the device has permissions to the access network share.
Combined with [always-on real-time protection capability](configure-real-time-protection-microsoft-defender-antivirus.md)--which reviews files when they are opened and closed, and whenever a user navigates to a folder--a quick scan helps provide strong coverage both for malware that starts with the system and kernel-level malware.

In most instances, this means a quick scan is adequate to find malware that wasn't picked up by real-time protection.
Expand Down

0 comments on commit a206de2

Please sign in to comment.