# Do not mistake Linux archive-scan settings for real-time archive inspection

> Does enabling scanArchives make Defender inspect compressed archives during Linux real-time protection?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-363-do-not-mistake-linux-archive-scan-settings-for-real-time-archive-inspection/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:25:53+00:00
- Modified: 2026-09-10T02:01:56+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Explainer
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Does enabling scanArchives make Defender inspect compressed archives during Linux real-time protection?

## Potentially affected

Microsoft Defender for Endpoint on Linux archive-scanning configuration.

## DSE recommendation

Choose an explicit on-demand archive inspection step when the workflow requires a decision before extraction.

## Article

## Source facts

On Linux, Defender for Endpoint’s scanArchives preference affects on-demand antivirus scans only. Microsoft states that archives are not scanned during real-time protection; files inside them are scanned after extraction. Enabling the preference therefore does not add real-time inspection of the compressed archive. The setting is available from Defender version 101.45.00 and defaults to true. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-endpoint/linux-preferences).

## Applicability

Review Microsoft Defender for Endpoint on Linux archive-scanning configuration. Separate a workflow that stores an archive unopened from one that extracts files before processing them. This brief does not claim support for every archive format or promise that a scan finds every threat.

## DSE recommendation

DSE recommends identifying the point at which an archive must be assessed before another process consumes it. Where the required decision precedes extraction, define an approved on-demand inspection step and its failure handling rather than relying on the real-time protection label. Review the effective preference with the endpoint owner and keep it separate from the application’s own acceptance rules. Do not copy unrelated settings from the source’s full configuration example just to enable archive inspection.

## Verification

Use approved harmless test material to distinguish an on-demand scan of the archive from handling its extracted files. Record the agent version, effective preference, scan type and observed completion. Confirm the operational workflow waits for the required result and escalates an incomplete scan. Preserve the two test paths separately so later reviews do not confuse archive storage with extracted-file inspection.

## Official references

[Microsoft Learn: Defender for Endpoint Linux security settings](https://learn.microsoft.com/en-us/defender-endpoint/linux-preferences).

## Primary reference

- Name: Configure security settings in Microsoft Defender for Endpoint on Linux - Microsoft Defender for Endpoint | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/defender-endpoint/linux-preferences
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Do not mistake Linux archive-scan settings for real-time archive inspection,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-363-do-not-mistake-linux-archive-scan-settings-for-real-time-archive-inspection/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
