Endpoint security or endpoint protection is an approach to the protection of computer networks that are remotely bridged to client devices. The connection of endpoint devices such as laptops, tablets, mobile phones, Internet-of-things devices, and other wireless devices to corporate networks creates attack paths for security threats. Symantec Endpoint Protection 11.0 combines Symantec AntiVirus with advanced threat prevention to deliver unmatched defense against malware for laptops, desktops and servers. It seamlessly integrates essential security technologies in a single agent and management console, increasing protection and helping lower total cost of ownership.
-->Applies to: Configuration Manager (current branch)
If you come across problems with Windows Defender or Endpoint Protection, use this article to troubleshoot the following problems:
Windows Defender or Endpoint Protection works automatically with Microsoft Update to make sure that your virus and spyware definitions are kept up-to-date.
This section addresses common issues with automatic updates, including the following situations:
You see error messages indicating that updates have failed.
When you check for updates, you receive an error message that the virus and spyware definition updates can't be checked, downloaded, or installed.
Even though your device is connected to the internet, the updates fail.
Updates aren't automatically installing as scheduled.
The most common causes for update issues are problems with internet connectivity. If you know your device is connected to the internet because you can browse to other Web sites, the issue might be caused by conflicts with your internet settings in Windows.
Exit all open programs, including the web browser.
Note
When you reset these internet settings, it may delete your browser temporary files, cookies, browsing history, and online passwords. It doesn't delete your favorites.
Go to the Start menu, and open inetcpl.cpl
.
Switch to the Advanced tab.
In the section to Reset Internet Explorer settings, select Reset, and then select Reset again to confirm.
Select OK when the settings are reset.
Try to update Windows Defender again.
If the issue persists, continue to the next step.
If the error message contains the code 0x80072f8f, the problem is most likely caused by an incorrect date or time setting on your computer. Go to the Start menu, select Settings, select Time & language, and select Date & time.
Stop the Windows Update service.
Go to Start, and open services.msc.
Select the Windows Update service. Go to the Action menu, and select Stop.
Rename the SoftwareDistribution directory.
Open a command prompt as an administrator.
Enter the following commands:
Restart the Windows Update service.
Switch back to the Services window.
Select the Windows Update service. Go to the Action menu, and select Start.
Close the Services window.
Open a command prompt as an administrator.
Enter the following commands:
Restart the computer.
Try to update Windows Defender again.
If the issue persists, continue to the next step.
Manually download the latest updates.
If these steps didn't resolve the issue, contact Microsoft support. For more information, see Support options and community resources.
You receive a message notifying you that Windows Defender or Endpoint Protection isn't monitoring your computer because the program's service stopped. You should restart it now.
Close all applications and restart your computer.
Go to Start, and open services.msc.
Select the Windows Defender Antivirus Service.
Make sure that the Startup Type is set to Automatic.
Go to the Action menu and select Start.
Note any errors that may appear during this process. Contact Microsoft Support and provide the error information.
Note
Some security applications don't uninstall completely. You may need to download and run a cleanup utility for your previous security application to completely remove it.
Go to Start and open appwiz.cpl.
In the list of installed programs, uninstall any third-party security programs.
Restart your computer.
Caution
When you remove security programs, your computer may be unprotected. If you have problems installing Windows Defender after you remove existing security programs, contact Microsoft Support. Select the Security product family, and then the Windows Defender product.
For your computer to receive the latest updates from Windows Update, connect it to the internet.
Go to Start and open ncpa.cpl.
Open the connection name to view the connection Status.
If your computer is connected, the IPv4 connectivity and/or IPv6 connectivity status is Internet.
If your computer doesn't appear to be connected, select the connection name, and select Diagnose this connection.
Close any open programs and restart your computer.
When Windows Defender or Endpoint Protection detects a potential threat, it tries to mitigate the threat by quarantining or removing the threat. These threats can hide inside a compressed archive (.zip
) or in a network share.
If the detected threat was in a compressed archive file, browse to the file. Delete the file, or manually scan it. Right-click the file and select Scan with Windows Defender. If Windows Defender detects additional threats in the file, it notifies you. Then you can choose an appropriate action.
If the detected threat was in a network share, open the share, and manually scan it. Right-click the file and select Scan with Windows Defender. If Windows Defender detects additional threats in the network share, it notifies you. Then you can choose an appropriate action.
If you're not sure of the file's origin, run a full scan on your computer. A full scan may take some time to complete.