Jump to content

Windows Defender with Windows 10 1809 - updated definition

Recommended Posts

Hi All,

Following an update to 1809, we have had issues with definitions for any Windows 10 machine with Intune (or just the vanilla Windows Defender).

Turns out the 'RemediationEXE' referenced by the LT default definition no longer exists.

I create the below definition which seems to work fine - thought I'd share with you all! 😀

Name: Windows Defender 10
AV Process: msmpeng*
Program Location: {%_if|{%_ne|{%-HKLM\SOFTWARE\Microsoft\Windows Defender:DisableAntiVirus-%}|1_%}|{%-HKLM\SOFTWARE\Microsoft\Windows Defender:InstallLocation-%}MsMpEng.exe_%}
Definition Location: {%-HKLM\SOFTWARE\Microsoft\Windows Defender\Signature Updates:SignatureLocation-%}\mpavdlta.vdm
Date Mask: (.*)
Update Command: "{%-HKLM\SOFTWARE\Microsoft\Windows Defender:InstallLocation-%}\mpcmdrun.exe" -SignatureUpdate -Trace -Grouping 15 -GetFiles


  • Like 1

Share this post

Link to post
Share on other sites

IT works on detecting its installed and also the virus definitions are correct. however, it always shows not running.

im not sure why because the AV process its looking for is msmpeng* which is correct exe it looks like. does anyone have any ideas why it shows not running?

Share this post

Link to post
Share on other sites

:)Brilliant thank you for the definition and it worked straight away and show's object under the location with Virus scanner and this definition

However I cannot get the "Antivirus Tile" on  the computer object to update,

Tried update config, resend full inventory, restart services, reload main control centre cache

And I know its this definition as soon as I chance the name, the name changes for the Virus Scanner on the agent showing under the location.

Thank you in advance for any ideas


Share this post

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now