{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-436-use-the-reporting-refresh-time-when-interpreting-defender-antivirus-update-status/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-436-use-the-reporting-refresh-time-when-interpreting-defender-antivirus-update-status/",
        "slug": "dse-20260909-436-use-the-reporting-refresh-time-when-interpreting-defender-antivirus-update-status",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-436-use-the-reporting-refresh-time-when-interpreting-defender-antivirus-update-status/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-436-use-the-reporting-refresh-time-when-interpreting-defender-antivirus-update-status.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-436-use-the-reporting-refresh-time-when-interpreting-defender-antivirus-update-status/"
        },
        "title": "Use the reporting refresh time when interpreting Defender Antivirus update status",
        "summary": "Why can an antivirus update card show Unknown even when another device timestamp looks recent?",
        "format": {
            "slug": "explainer",
            "name": "Explainer"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:24:40+00:00",
        "modified_at": "2026-09-10T02:04:57+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 273,
        "potentially_affected": "Defender Antivirus health reporting for onboarded devices meeting the documented reporting prerequisites.",
        "dse_recommendation": "Check Signature refresh time and reporting prerequisites before classifying an Unknown device as outdated or healthy.",
        "primary_source": {
            "name": "Device health Microsoft Defender Antivirus health report - Microsoft Defender for Endpoint | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/defender-endpoint/device-health-microsoft-defender-antivirus-health",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Defender Antivirus health reporting distinguishes Last seen, Data refresh timestamp and Signature refresh time. The last of these tracks events used for engine, platform and signature update-status reporting. When that reporting has not refreshed for more than seven days, update status becomes Unknown or No data available. Recent device connectivity is therefore a different field from the update report&#8217;s freshness. Eligibility also depends on the documented OS, sensor and component prerequisites. <a href=\"https://learn.microsoft.com/en-us/defender-endpoint/device-health-microsoft-defender-antivirus-health\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Review the relevant update card and device details, not only a general inventory timestamp. Verify the supported operating system and reporting components before treating an empty field as an update failure. Keep this check on current supported deployments; it does not recommend retaining an obsolete OS to troubleshoot its reporting limitation.</p>\n<h2>DSE recommendation</h2>\n<p>Check Signature refresh time and reporting prerequisites before classifying an Unknown device as outdated or healthy. Route a stale reporting condition to the endpoint owner for investigation while separately obtaining the installed version through an approved local check. Preserve both observations and their times. Do not remove Unknown devices from update follow-up merely to improve a compliance percentage, or label them current from another timestamp alone.</p>\n<h2>Verification</h2>\n<p>After resolving the identified reporting issue, compare the new signature-refresh value, reported update status and actual installed component versions. Confirm that the update card now reflects a current observation and retain any disagreement for investigation. In a reporting review, keep Unknown, out-of-date and up-to-date populations distinct. Record the scope and filters used so an apparently improved total can be distinguished from changed coverage.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/defender-endpoint/device-health-microsoft-defender-antivirus-health\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Device health, Microsoft Defender Antivirus health report</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nDefender Antivirus health reporting distinguishes Last seen, Data refresh timestamp and Signature refresh time. The last of these tracks events used for engine, platform and signature update-status reporting. When that reporting has not refreshed for more than seven days, update status becomes Unknown or No data available. Recent device connectivity is therefore a different field from the update report’s freshness. Eligibility also depends on the documented OS, sensor and component prerequisites. Microsoft Learn.\nApplicability\nReview the relevant update card and device details, not only a general inventory timestamp. Verify the supported operating system and reporting components before treating an empty field as an update failure. Keep this check on current supported deployments; it does not recommend retaining an obsolete OS to troubleshoot its reporting limitation.\nDSE recommendation\nCheck Signature refresh time and reporting prerequisites before classifying an Unknown device as outdated or healthy. Route a stale reporting condition to the endpoint owner for investigation while separately obtaining the installed version through an approved local check. Preserve both observations and their times. Do not remove Unknown devices from update follow-up merely to improve a compliance percentage, or label them current from another timestamp alone.\nVerification\nAfter resolving the identified reporting issue, compare the new signature-refresh value, reported update status and actual installed component versions. Confirm that the update card now reflects a current observation and retain any disagreement for investigation. In a reporting review, keep Unknown, out-of-date and up-to-date populations distinct. Record the scope and filters used so an apparently improved total can be distinguished from changed coverage.\nOfficial references\nMicrosoft Learn: Device health, Microsoft Defender Antivirus health report. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nDefender Antivirus health reporting distinguishes Last seen, Data refresh timestamp and Signature refresh time. The last of these tracks events used for engine, platform and signature update-status reporting. When that reporting has not refreshed for more than seven days, update status becomes Unknown or No data available. Recent device connectivity is therefore a different field from the update report’s freshness. Eligibility also depends on the documented OS, sensor and component prerequisites. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-endpoint/device-health-microsoft-defender-antivirus-health).\n\n## Applicability\n\nReview the relevant update card and device details, not only a general inventory timestamp. Verify the supported operating system and reporting components before treating an empty field as an update failure. Keep this check on current supported deployments; it does not recommend retaining an obsolete OS to troubleshoot its reporting limitation.\n\n## DSE recommendation\n\nCheck Signature refresh time and reporting prerequisites before classifying an Unknown device as outdated or healthy. Route a stale reporting condition to the endpoint owner for investigation while separately obtaining the installed version through an approved local check. Preserve both observations and their times. Do not remove Unknown devices from update follow-up merely to improve a compliance percentage, or label them current from another timestamp alone.\n\n## Verification\n\nAfter resolving the identified reporting issue, compare the new signature-refresh value, reported update status and actual installed component versions. Confirm that the update card now reflects a current observation and retain any disagreement for investigation. In a reporting review, keep Unknown, out-of-date and up-to-date populations distinct. Record the scope and filters used so an apparently improved total can be distinguished from changed coverage.\n\n## Official references\n\n[Microsoft Learn: Device health, Microsoft Defender Antivirus health report](https://learn.microsoft.com/en-us/defender-endpoint/device-health-microsoft-defender-antivirus-health). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-436-use-the-reporting-refresh-time-when-interpreting-defender-antivirus-update-status/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-436-use-the-reporting-refresh-time-when-interpreting-defender-antivirus-update-status/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-436-use-the-reporting-refresh-time-when-interpreting-defender-antivirus-update-status/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Use the reporting refresh time when interpreting Defender Antivirus update status",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-436-use-the-reporting-refresh-time-when-interpreting-defender-antivirus-update-status/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-436-use-the-reporting-refresh-time-when-interpreting-defender-antivirus-update-status/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-436-use-the-reporting-refresh-time-when-interpreting-defender-antivirus-update-status/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-436-use-the-reporting-refresh-time-when-interpreting-defender-antivirus-update-status/",
                "headline": "Use the reporting refresh time when interpreting Defender Antivirus update status",
                "description": "Why can an antivirus update card show Unknown even when another device timestamp looks recent?",
                "abstract": "Why can an antivirus update card show Unknown even when another device timestamp looks recent?",
                "articleBody": "Source facts\nDefender Antivirus health reporting distinguishes Last seen, Data refresh timestamp and Signature refresh time. The last of these tracks events used for engine, platform and signature update-status reporting. When that reporting has not refreshed for more than seven days, update status becomes Unknown or No data available. Recent device connectivity is therefore a different field from the update report’s freshness. Eligibility also depends on the documented OS, sensor and component prerequisites. Microsoft Learn.\nApplicability\nReview the relevant update card and device details, not only a general inventory timestamp. Verify the supported operating system and reporting components before treating an empty field as an update failure. Keep this check on current supported deployments; it does not recommend retaining an obsolete OS to troubleshoot its reporting limitation.\nDSE recommendation\nCheck Signature refresh time and reporting prerequisites before classifying an Unknown device as outdated or healthy. Route a stale reporting condition to the endpoint owner for investigation while separately obtaining the installed version through an approved local check. Preserve both observations and their times. Do not remove Unknown devices from update follow-up merely to improve a compliance percentage, or label them current from another timestamp alone.\nVerification\nAfter resolving the identified reporting issue, compare the new signature-refresh value, reported update status and actual installed component versions. Confirm that the update card now reflects a current observation and retain any disagreement for investigation. In a reporting review, keep Unknown, out-of-date and up-to-date populations distinct. Record the scope and filters used so an apparently improved total can be distinguished from changed coverage.\nOfficial references\nMicrosoft Learn: Device health, Microsoft Defender Antivirus health report. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:24:40+00:00",
                "dateModified": "2026-09-10T02:04:57+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-436-use-the-reporting-refresh-time-when-interpreting-defender-antivirus-update-status/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-436-use-the-reporting-refresh-time-when-interpreting-defender-antivirus-update-status/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Use the reporting refresh time when interpreting Defender Antivirus update status"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Explainer",
                    "Information priority"
                ],
                "genre": "Explainer",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 273,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Device health Microsoft Defender Antivirus health report - Microsoft Defender for Endpoint | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/defender-endpoint/device-health-microsoft-defender-antivirus-health"
                }
            }
        ]
    }
}