Edit

Schedule antivirus scans using Microsoft Intune

You can use Microsoft Intune to schedule Microsoft Defender Antivirus scans on managed Windows devices. This article shows you how to create a scan policy, set up daily and weekly quick scans, and change settings like CPU throttling and catchup scans. These steps are for IT admins who use Intune to keep scan coverage consistent across their devices. To learn more about scan types, see About scheduled quick or full Microsoft Defender Antivirus scans.

Prerequisites

Before you configure scheduled antivirus scans in Intune, make sure your devices meet the following requirements.

Supported operating systems

Scheduled antivirus scans through Intune are supported on the following operating systems:

  • Windows
  • Windows Server

Configure antivirus scans using Intune

To configure antivirus scans by using Intune, see Create an endpoint security policy (opens in a new tab in the Intune documentation). When creating the policy, use these settings:

  • Policy type: Antivirus
  • Platform: Windows
  • Profile: Microsoft Defender Antivirus
  • Basics: Enter a name and description for the policy.
  • Configuration settings: Expand each group of settings, and configure the settings you want to manage with this policy. For more information about these settings, see Policy CSP - Defender.
  • Scope tags: If your organization is using scope tags, select the tags you want to use.
  • Assignments: Select the users or groups to receive this policy. For more information, see Assign policies in Microsoft Intune.

For more information about Intune antivirus endpoint security policies, see Antivirus policy for endpoint security in Intune.

Use Intune for scheduling daily quick scans

Use the following setting to schedule a daily quick scan in Intune:

Description Setting
Schedule Quick Scan Time 720

Note

In the daily quick scan example, a quick scan runs on the Windows clients at 12:00 PM (720). The scan is scheduled at lunch time because many devices are turned off after hours (for example, laptops).

Use Intune for scheduling Weekly Scan (Quick or Full)

The following example settings schedule a weekly quick or full scan in Intune:

Description Setting
Scan Parameter Quick scan (Default)
Schedule Scan Day Windows Clients: Wednesday
Schedule Scan Time Windows Clients: 1020

Note

In this example, a quick scan runs for Windows clients on Wednesdays at 5:00 PM. (1020).

Tip

Our recommendation for scheduled scans is to configure quick scan together with always-on real-time protection and cloud protection, as this combination provides strong coverage against malware that starts with the system and kernel-level malware. Quick scan with always-on real-time protection and cloud protection is the default configuration. In general, there's no need to schedule a full scan, and most users never need to manually run full scans (see Comparing quick scan, full scan, and custom scan).

Configure general settings for scheduled scans

Review the following general scheduled-scan settings when configuring your policy:

Description Setting
Check For Signatures Before Running Scan Disabled (Default)
Randomize Schedule Task Times Not configured
Scheduler Randomization Time Scheduled tasks aren't randomized
Avg CPU Load Factor Not Configured (Default, 50)
Enable Low CPU Priority Disabled (Default)
Disable Catchup Full Scan Enabled (Default)
Disable Catchup Quick Scan Disabled (Default)

Note

When you schedule scans for times when endpoints aren't in use, scans don't honor the CPU throttling configuration and takes full advantage of the resources available to complete the scan as fast as possible.

See also