1.13.1 Ensure 'Check for the latest virus and spyware security intelligence before running a scheduled scan' is set to 'Enabled'

Information

This policy setting controls whether to check for new virus and spyware security intelligence before running a scan.

The recommended state for this setting is: Enabled.

Note: This setting applies to scheduled scans and has no effect on scans that are initiated manually from the user interface or to the ones that have been started from the command line using mpcmdrun -Scan.

A malware scan is only as effective as the threat definitions it uses. Running a scan with outdated intelligence significantly reduces detection accuracy and can create a false sense of security.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Antivirus\Scan\Check for the latest virus and spyware security intelligence before running a scheduled scan

Note: This Group Policy path is provided by the Group Policy template WindowsDefender.admx/adml that is included with the Microsoft Windows 11 Release 24H2 Administrative Templates (or newer).

Impact:

Checking for updated security intelligence can add a small amount of overhead before a scan begins.

See Also

https://workbench.cisecurity.org/benchmarks/25919

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, CSCv7|8.1

Plugin: Windows

Control ID: 5d2d640342144f1939f4b880b207a6c17b4696dd49df8f4aa735e067f01d1e26