# Use the reporting refresh time when interpreting Defender Antivirus update status

> Why can an antivirus update card show Unknown even when another device timestamp looks recent?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-436-use-the-reporting-refresh-time-when-interpreting-defender-antivirus-update-status/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:24:40+00:00
- Modified: 2026-09-10T02:04:57+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Explainer
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Why can an antivirus update card show Unknown even when another device timestamp looks recent?

## Potentially affected

Defender Antivirus health reporting for onboarded devices meeting the documented reporting prerequisites.

## DSE recommendation

Check Signature refresh time and reporting prerequisites before classifying an Unknown device as outdated or healthy.

## Article

## Source facts

Defender Antivirus health reporting distinguishes Last seen, Data refresh timestamp and Signature refresh time. The last of these tracks events used for engine, platform and signature update-status reporting. When that reporting has not refreshed for more than seven days, update status becomes Unknown or No data available. Recent device connectivity is therefore a different field from the update report’s freshness. Eligibility also depends on the documented OS, sensor and component prerequisites. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-endpoint/device-health-microsoft-defender-antivirus-health).

## Applicability

Review the relevant update card and device details, not only a general inventory timestamp. Verify the supported operating system and reporting components before treating an empty field as an update failure. Keep this check on current supported deployments; it does not recommend retaining an obsolete OS to troubleshoot its reporting limitation.

## DSE recommendation

Check Signature refresh time and reporting prerequisites before classifying an Unknown device as outdated or healthy. Route a stale reporting condition to the endpoint owner for investigation while separately obtaining the installed version through an approved local check. Preserve both observations and their times. Do not remove Unknown devices from update follow-up merely to improve a compliance percentage, or label them current from another timestamp alone.

## Verification

After resolving the identified reporting issue, compare the new signature-refresh value, reported update status and actual installed component versions. Confirm that the update card now reflects a current observation and retain any disagreement for investigation. In a reporting review, keep Unknown, out-of-date and up-to-date populations distinct. Record the scope and filters used so an apparently improved total can be distinguished from changed coverage.

## Official references

[Microsoft Learn: Device health, Microsoft Defender Antivirus health report](https://learn.microsoft.com/en-us/defender-endpoint/device-health-microsoft-defender-antivirus-health). Source reviewed September 9, 2026.

## Primary reference

- Name: Device health Microsoft Defender Antivirus health report - Microsoft Defender for Endpoint | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/defender-endpoint/device-health-microsoft-defender-antivirus-health
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Use the reporting refresh time when interpreting Defender Antivirus update status,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-436-use-the-reporting-refresh-time-when-interpreting-defender-antivirus-update-status/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
