Information
This policy setting ensures that a recognized antivirus solution is active and registered with the Windows Security Center (WSC) on Windows devices. When set to require, Intune verifies that antivirus software is present, running, and reporting a current status to WSC. This check recognizes both Microsoft Defender Antivirus and qualifying third-party antivirus solutions registered with the Windows Security Center.
The recommended state for this setting is: Require.
Antivirus software provides a foundational layer of malware detection and prevention by scanning files, processes, and memory for known malicious signatures and suspicious behaviors. Without active antivirus protection, endpoints are vulnerable to a wide range of malware including ransomware, trojans, and infostealers that rely on signature-detectable payloads. Compliance verification ensures that antivirus is not only installed but actively running at the time of each device check-in, detecting scenarios where protection has been disabled or has expired.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
To establish the recommended configuration from Microsoft Intune Admin Center:
- Navigate to Endpoint security > Compliance policies.
- Create or edit a Compliance policy.
- Under System Security\Device Security, set Antivirus to Require.
Impact:
Devices where an antivirus solution is absent, stopped, or not reporting to Windows Security Center will be marked non-compliant. Third-party antivirus products must be WSC-integrated; solutions that do not register with WSC will fail this check even if functionally active. Microsoft Defender Antivirus may be automatically suppressed when a third-party AV is installed, this is expected and does not cause a compliance failure if the third-party solution registers correctly.