{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-534-check-antivirus-mode-before-troubleshooting-an-ignored-signature-update-schedule/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-534-check-antivirus-mode-before-troubleshooting-an-ignored-signature-update-schedule/",
        "slug": "dse-20260909-534-check-antivirus-mode-before-troubleshooting-an-ignored-signature-update-schedule",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-534-check-antivirus-mode-before-troubleshooting-an-ignored-signature-update-schedule/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-534-check-antivirus-mode-before-troubleshooting-an-ignored-signature-update-schedule.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-534-check-antivirus-mode-before-troubleshooting-an-ignored-signature-update-schedule/"
        },
        "title": "Check antivirus mode before troubleshooting an ignored signature-update schedule",
        "summary": "Which update settings govern Defender Antivirus security intelligence in passive mode?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:23:02+00:00",
        "modified_at": "2026-09-10T02:11:18+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 247,
        "potentially_affected": "Windows endpoints running Microsoft Defender Antivirus in passive mode alongside another primary antivirus product.",
        "dse_recommendation": "Confirm the effective antivirus mode and examine the applicable Windows Update configuration before changing Defender-specific schedules.",
        "primary_source": {
            "name": "Microsoft Defender Antivirus compatibility with other security products - Microsoft Defender for Endpoint | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-compatibility",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>In Defender Antivirus passive mode, Windows Update settings control security-intelligence update timing. Defender-specific daily, weekly and interval schedules apply in active mode and are ignored in passive mode. Microsoft still directs administrators to keep antivirus updates current in passive mode. The AMRunningMode property returned by Get-MpComputerStatus distinguishes Normal, Passive and EDR Block Mode. <a href=\"https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-compatibility\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>This is a scheduling investigation for Windows endpoints where another product supplies primary antivirus protection and Defender Antivirus remains installed. Establish the actual mode rather than inferring it from the presence of a process or a saved policy. Do not generalize this Windows behavior to another operating system.</p>\n<h2>DSE recommendation</h2>\n<p>Confirm the effective antivirus mode and examine the applicable Windows Update configuration before changing Defender-specific schedules. Ask the endpoint owner to compare the intended update timing with the controls that apply in that mode. Avoid repeatedly shortening an inactive schedule or switching the antivirus mode merely to make a scheduling test pass. Keep primary antivirus ownership unchanged unless a separate migration is approved.</p>\n<h2>Verification</h2>\n<p>Record the observed mode, relevant update configuration and actual intelligence-update evidence across the expected interval. Compare the result with the mode-specific plan and investigate failed or stale updates through the responsible update path. Keep a separate record of whether the endpoint is reporting fresh data; this check concerns which settings schedule an update, not whether a dashboard timestamp alone proves current protection.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-compatibility\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Defender Antivirus coexistence and operating modes</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nIn Defender Antivirus passive mode, Windows Update settings control security-intelligence update timing. Defender-specific daily, weekly and interval schedules apply in active mode and are ignored in passive mode. Microsoft still directs administrators to keep antivirus updates current in passive mode. The AMRunningMode property returned by Get-MpComputerStatus distinguishes Normal, Passive and EDR Block Mode. Microsoft Learn.\nApplicability\nThis is a scheduling investigation for Windows endpoints where another product supplies primary antivirus protection and Defender Antivirus remains installed. Establish the actual mode rather than inferring it from the presence of a process or a saved policy. Do not generalize this Windows behavior to another operating system.\nDSE recommendation\nConfirm the effective antivirus mode and examine the applicable Windows Update configuration before changing Defender-specific schedules. Ask the endpoint owner to compare the intended update timing with the controls that apply in that mode. Avoid repeatedly shortening an inactive schedule or switching the antivirus mode merely to make a scheduling test pass. Keep primary antivirus ownership unchanged unless a separate migration is approved.\nVerification\nRecord the observed mode, relevant update configuration and actual intelligence-update evidence across the expected interval. Compare the result with the mode-specific plan and investigate failed or stale updates through the responsible update path. Keep a separate record of whether the endpoint is reporting fresh data; this check concerns which settings schedule an update, not whether a dashboard timestamp alone proves current protection.\nOfficial references\nMicrosoft Learn: Defender Antivirus coexistence and operating modes. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nIn Defender Antivirus passive mode, Windows Update settings control security-intelligence update timing. Defender-specific daily, weekly and interval schedules apply in active mode and are ignored in passive mode. Microsoft still directs administrators to keep antivirus updates current in passive mode. The AMRunningMode property returned by Get-MpComputerStatus distinguishes Normal, Passive and EDR Block Mode. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-compatibility).\n\n## Applicability\n\nThis is a scheduling investigation for Windows endpoints where another product supplies primary antivirus protection and Defender Antivirus remains installed. Establish the actual mode rather than inferring it from the presence of a process or a saved policy. Do not generalize this Windows behavior to another operating system.\n\n## DSE recommendation\n\nConfirm the effective antivirus mode and examine the applicable Windows Update configuration before changing Defender-specific schedules. Ask the endpoint owner to compare the intended update timing with the controls that apply in that mode. Avoid repeatedly shortening an inactive schedule or switching the antivirus mode merely to make a scheduling test pass. Keep primary antivirus ownership unchanged unless a separate migration is approved.\n\n## Verification\n\nRecord the observed mode, relevant update configuration and actual intelligence-update evidence across the expected interval. Compare the result with the mode-specific plan and investigate failed or stale updates through the responsible update path. Keep a separate record of whether the endpoint is reporting fresh data; this check concerns which settings schedule an update, not whether a dashboard timestamp alone proves current protection.\n\n## Official references\n\n[Microsoft Learn: Defender Antivirus coexistence and operating modes](https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-compatibility). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-534-check-antivirus-mode-before-troubleshooting-an-ignored-signature-update-schedule/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-534-check-antivirus-mode-before-troubleshooting-an-ignored-signature-update-schedule/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-534-check-antivirus-mode-before-troubleshooting-an-ignored-signature-update-schedule/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Check antivirus mode before troubleshooting an ignored signature-update schedule",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-534-check-antivirus-mode-before-troubleshooting-an-ignored-signature-update-schedule/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-534-check-antivirus-mode-before-troubleshooting-an-ignored-signature-update-schedule/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-534-check-antivirus-mode-before-troubleshooting-an-ignored-signature-update-schedule/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-534-check-antivirus-mode-before-troubleshooting-an-ignored-signature-update-schedule/",
                "headline": "Check antivirus mode before troubleshooting an ignored signature-update schedule",
                "description": "Which update settings govern Defender Antivirus security intelligence in passive mode?",
                "abstract": "Which update settings govern Defender Antivirus security intelligence in passive mode?",
                "articleBody": "Source facts\nIn Defender Antivirus passive mode, Windows Update settings control security-intelligence update timing. Defender-specific daily, weekly and interval schedules apply in active mode and are ignored in passive mode. Microsoft still directs administrators to keep antivirus updates current in passive mode. The AMRunningMode property returned by Get-MpComputerStatus distinguishes Normal, Passive and EDR Block Mode. Microsoft Learn.\nApplicability\nThis is a scheduling investigation for Windows endpoints where another product supplies primary antivirus protection and Defender Antivirus remains installed. Establish the actual mode rather than inferring it from the presence of a process or a saved policy. Do not generalize this Windows behavior to another operating system.\nDSE recommendation\nConfirm the effective antivirus mode and examine the applicable Windows Update configuration before changing Defender-specific schedules. Ask the endpoint owner to compare the intended update timing with the controls that apply in that mode. Avoid repeatedly shortening an inactive schedule or switching the antivirus mode merely to make a scheduling test pass. Keep primary antivirus ownership unchanged unless a separate migration is approved.\nVerification\nRecord the observed mode, relevant update configuration and actual intelligence-update evidence across the expected interval. Compare the result with the mode-specific plan and investigate failed or stale updates through the responsible update path. Keep a separate record of whether the endpoint is reporting fresh data; this check concerns which settings schedule an update, not whether a dashboard timestamp alone proves current protection.\nOfficial references\nMicrosoft Learn: Defender Antivirus coexistence and operating modes. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:23:02+00:00",
                "dateModified": "2026-09-10T02:11:18+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-534-check-antivirus-mode-before-troubleshooting-an-ignored-signature-update-schedule/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-534-check-antivirus-mode-before-troubleshooting-an-ignored-signature-update-schedule/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Check antivirus mode before troubleshooting an ignored signature-update schedule"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 247,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Microsoft Defender Antivirus compatibility with other security products - Microsoft Defender for Endpoint | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-compatibility"
                }
            }
        ]
    }
}