diff --git a/windows/deploy/TOC.md b/windows/deploy/TOC.md
index d31baa9297..a14e1d9f0d 100644
--- a/windows/deploy/TOC.md
+++ b/windows/deploy/TOC.md
@@ -1,4 +1,5 @@
# [Deploy Windows 10](index.md)
+## [What's new in Windows 10 deployment](deploy-whats-new.md)
## [Windows 10 deployment scenarios](windows-10-deployment-scenarios.md)
## [Manage Windows upgrades with Upgrade Readiness](manage-windows-upgrades-with-upgrade-readiness.md)
### [Upgrade Readiness architecture](upgrade-readiness-architecture.md)
@@ -26,6 +27,7 @@
### [Build a distributed environment for Windows 10 deployment](build-a-distributed-environment-for-windows-10-deployment.md)
### [Refresh a Windows 7 computer with Windows 10](refresh-a-windows-7-computer-with-windows-10.md)
### [Replace a Windows 7 computer with a Windows 10 computer](replace-a-windows-7-computer-with-a-windows-10-computer.md)
+### [Perform an in-place upgrade to Windows 10 with MDT](upgrade-to-windows-10-with-the-microsoft-deployment-toolkit.md)
### [Configure MDT settings](configure-mdt-settings.md)
#### [Set up MDT for BitLocker](set-up-mdt-for-bitlocker.md)
#### [Configure MDT deployment share rules](configure-mdt-deployment-share-rules.md)
@@ -48,8 +50,7 @@
### [Monitor the Windows 10 deployment with Configuration Manager](monitor-windows-10-deployment-with-configuration-manager.md)
### [Refresh a Windows 7 SP1 client with Windows 10 using Configuration Manager](refresh-a-windows-7-client-with-windows-10-using-configuration-manager.md)
### [Replace a Windows 7 SP1 client with Windows 10 using Configuration Manager](replace-a-windows-7-client-with-windows-10-using-configuration-manager.md)
-## [Upgrade to Windows 10 with the Microsoft Deployment Toolkit](upgrade-to-windows-10-with-the-microsoft-deployment-toolkit.md)
-## [Upgrade to Windows 10 with System Center Configuration Manager](upgrade-to-windows-10-with-system-center-configuraton-manager.md)
+### [Perform an in-place upgrade to Windows 10 using Configuration Manager](upgrade-to-windows-10-with-system-center-configuraton-manager.md)
## [Resolve Windows 10 upgrade errors](resolve-windows-10-upgrade-errors.md)
## [Convert MBR partition to GPT](mbr-to-gpt.md)
## [Configure a PXE server to load Windows PE](configure-a-pxe-server-to-load-windows-pe.md)
diff --git a/windows/deploy/change-history-for-deploy-windows-10.md b/windows/deploy/change-history-for-deploy-windows-10.md
index a3c2c4364e..f0c32cf285 100644
--- a/windows/deploy/change-history-for-deploy-windows-10.md
+++ b/windows/deploy/change-history-for-deploy-windows-10.md
@@ -17,6 +17,9 @@ The topics in this library have been updated for Windows 10, version 1703 (also
## March 2017
| New or changed topic | Description |
|----------------------|-------------|
+| [What's new in Windows 10 deployment](deploy-whats-new.md) | New |
+| [Upgrade to Windows 10 with the Microsoft Deployment Toolkit](upgrade-to-windows-10-with-the-microsoft-deployment-toolkit.md) | Topic moved under [Deploy Windows 10 with the Microsoft Deployment Toolkit](deploy-windows-10-with-the-microsoft-deployment-toolkit.md) in the table of contents and title adjusted to clarify in-place upgrade. |
+| [Upgrade to Windows 10 with System Center Configuration Manager](upgrade-to-windows-10-with-system-center-configuraton-manager.md) | Topic moved under [Deploy Windows 10 with System Center 2012 R2 Configuration Manager](deploy-windows-10-with-system-center-2012-r2-configuration-manager.md) in the table of contents and title adjusted to clarify in-place upgrade. |
| [Convert MBR partition to GPT](mbr-to-gpt.md) | New |
## February 2017
diff --git a/windows/deploy/deploy-whats-new.md b/windows/deploy/deploy-whats-new.md
new file mode 100644
index 0000000000..9d6a1b0d15
--- /dev/null
+++ b/windows/deploy/deploy-whats-new.md
@@ -0,0 +1,123 @@
+---
+title: What's new in Windows 10 deployment
+description: Changes and new features related to Windows 10 deployment
+keywords: deployment, automate, tools, configure, news
+ms.mktglfcycl: deploy
+localizationpriority: high
+ms.prod: w10
+ms.sitesec: library
+ms.pagetype: deploy
+author: greg-lindsay
+---
+
+# What's new in Windows 10 deployment
+
+**Applies to**
+- Windows 10
+
+
+## In this topic
+
+This topic provides an overview of new solutions and online content related to deploying Windows 10 in your organization.
+
+- For an all-up overview of new features in Windows 10, see [What's new in Windows 10](https://technet.microsoft.com/itpro/windows/whats-new/index).
+- For a detailed list of changes to Windows 10 ITPro TechNet library content, see [Online content change history](#online-content-change-history).
+
+
+## Windows 10 Enterprise upgrade
+
+Windows 10 Enterprise E3 launched in the Cloud Solution Provider (CSP) channel on September 1, 2016. Previously, only organizations with a Microsoft Volume Licensing Agreement could deploy Windows 10 Enterprise to their users. With Windows 10 Enterprise E3 in CSP, small and medium-sized organizations can more easily take advantage of Windows 10 Enterprise features.
+
+For more information, see [Windows 10 Enterprise E3 in CSP Overview](windows-10-enterprise-e3-overview.md)
+
+
+## Deployment solutions and tools
+
+### Upgrade Readiness
+
+The Upgrade Readiness tool moved from public preview to general availability on March 2, 2017.
+
+Upgrade Readiness helps you ensure that applications and drivers are ready for a Windows 10 upgrade. The solution provides up-to-date application and driver inventory, information about known issues, troubleshooting guidance, and per-device readiness and tracking details.
+
+The development of Upgrade Readiness has been heavily influenced by input from the community the development of new features is ongoing. To begin using Upgrade Readiness, add it to an existing Operation Management Suite (OMS) workspace or sign up for a new OMS workspace with the Upgrade Readiness solution enabled.
+
+For more information about Upgrade Readiness, see the following topics:
+
+- [Windows Analytics blog](https://blogs.technet.microsoft.com/upgradeanalytics/)
+- [Manage Windows upgrades with Upgrade Readiness](manage-windows-upgrades-with-upgrade-readiness.md)
+
+
+### Update Compliance
+
+Update Compliance helps you to keep Windows 10 devices in your organization secure and up-to-date.
+
+Update Compliance is a solution built using OMS Logs and Analytics that provides information about installation status of monthly quality and feature updates. Details are provided about the deployment progress of existing updates and the status of future updates. Information is also provided about devices that might need attention to resolve issues.
+
+For more information about Update Compliance, see [Monitor Windows Updates with Update Compliance](../manage/update-compliance-monitor.md).
+
+
+### MBR2GPT
+
+MBR2GPT.EXE converts a disk from Master Boot Record (MBR) to GUID Partition Table (GPT) partition style without modifying or deleting data on the disk. Previously, it was necessary to image, then wipe and reload a disk to change from MBR format to GPT.
+
+There are many benefits to converting the partition style of a disk to GPT, including the use of larger disk partitions, added data reliability, and faster boot and shutdown speeds. The GPT format also enables you to use the Unified Extensible Firmware Interface (UEFI) which replaces the Basic Input/Output System (BIOS) firmware interface. Security features of Windows 10 that require UEFI mode include: Secure Boot, Early Launch Anti-malware (ELAM) driver, Windows Trusted Boot, Measured Boot, Device Guard, Credential Guard, and BitLocker Network Unlock.
+
+For more information, see [MBR2GPT.EXE](mbr-to-gpt.md).
+
+
+### Microsoft Deployment Toolkit (MDT)
+
+MDT build 884 is available, including support for:
+- Deployment and upgrade of Windows 10, version 1607 (including Enterprise LTSB and Education editions) and Windows Server 2016.
+- The Windows ADK for Windows 10, version 1607.
+- Integration with Configuration Manager version 1606.
+
+For more information about MDT, see the [MDT resource page](https://technet.microsoft.com/en-US/windows/dn475741).
+
+
+### Windows Assessment and Deployment Kit (ADK)
+
+The Windows Assessment and Deployment Kit (Windows ADK) contains tools that can be used by IT Pros to deploy Windows. See the following topics:
+
+- [What's new in ADK kits and tools](https://msdn.microsoft.com/windows/hardware/commercialize/what-s-new-in-kits-and-tools)
+- [Windows ADK for Windows 10 scenarios for IT Pros](windows-adk-scenarios-for-it-pros.md)
+
+
+## Testing and validation guidance
+
+### Windows 10 deployment proof of concept (PoC)
+
+The Windows 10 PoC guide enables you to test Windows 10 deployment in a virtual environment and become familiar with deployment tools such as MDT and Configuration Manager. The PoC guide provides step-by-step instructions for installing and using Hyper-V to create a virtual lab environment. The guide makes extensive use of Windows PowerShell to streamline each phase of the installation and setup.
+
+For more information, see the following guides:
+
+- [Step by step guide: Configure a test lab to deploy Windows 10](windows-10-poc.md)
+- [Deploy Windows 10 in a test lab using Microsoft Deployment Toolkit](windows-10-poc-mdt.md)
+- [Deploy Windows 10 in a test lab using System Center Configuration Manager](windows-10-poc-sc-config-mgr.md)
+
+
+## Troubleshooting guidance
+
+[Resolve Windows 10 upgrade errors](resolve-windows-10-upgrade-errors.md) was published in October of 2016 and will continue to be updated with new fixes. The topic provides a detailed explanation of the Windows 10 upgrade process and instructions on how to locate, interpret, and resolve specific errors that can be encountered during the upgrade process.
+
+
+## Online content change history
+
+The following topics provide a change history for Windows 10 ITPro TechNet library content related to deploying and using Windows 10.
+
+[Change history for Deploy Windows 10](change-history-for-deploy-windows-10.md)
+
[Change history for Plan for Windows 10 deployment](../plan/change-history-for-plan-for-windows-10-deployment.md)
+
[Change history for Manage and update Windows 10](../manage/change-history-for-manage-and-update-windows-10.md)
+
[Change history for Keep Windows 10 secure](../keep-secure/change-history-for-keep-windows-10-secure.md)
+
+
+## Related topics
+
+[Overview of Windows as a service](../manage/waas-overview.md)
+
[Windows 10 deployment considerations](../plan/windows-10-deployment-considerations.md)
+
[Windows 10 release information](https://technet.microsoft.com/en-us/windows/release-info.aspx)
+
[Windows 10 Specifications & Systems Requirements](https://www.microsoft.com/en-us/windows/windows-10-specifications)
+
[Windows 10 upgrade paths](windows-10-upgrade-paths.md)
+
[Windows 10 deployment tools](windows-deployment-scenarios-and-tools.md)
+
+
\ No newline at end of file
diff --git a/windows/deploy/index.md b/windows/deploy/index.md
index 8b1846f60e..8058cf8890 100644
--- a/windows/deploy/index.md
+++ b/windows/deploy/index.md
@@ -16,13 +16,12 @@ Learn about deploying Windows 10 for IT professionals.
|Topic |Description |
|------|------------|
+|[What's new in Windows 10 deployment](deploy-whats-new.md) |See this topic for a summary of new features and some recent changes related to deploying Windows 10 in your organization. |
|[Windows 10 deployment scenarios](windows-10-deployment-scenarios.md) |To successfully deploy the Windows 10 operating system in your organization, it is important to understand the different ways that it can be deployed, especially now that there are new scenarios to consider. Choosing among these scenarios, and understanding the key capabilities and limitations of each, is a key task. |
|[Manage Windows upgrades with Upgrade Readiness](manage-windows-upgrades-with-upgrade-readiness.md) |With Upgrade Readiness, enterprises now have the tools to plan and manage the upgrade process end to end, allowing them to adopt new Windows releases more quickly. With Windows telemetry enabled, Upgrade Readiness collects system, application, and driver data for analysis. We then identify compatibility issues that can block an upgrade and suggest fixes when they are known to Microsoft. The Upgrade Readiness workflow steps you through the discovery and rationalization process until you have a list of computers that are ready to be upgraded. |
|[Step by step guide: Configure a test lab to deploy Windows 10](windows-10-poc.md) |This guide contains instructions to configure a proof of concept (PoC) environment requiring a minimum amount of resources. The guide makes extensive use of Windows PowerShell and Hyper-V. Subsequent companion guides contain steps to deploy Windows 10 using the PoC environment. After completing this guide, see the following Windows 10 PoC deployment guides: [Deploy Windows 10 in a test lab using Microsoft Deployment Toolkit](windows-10-poc-mdt.md), [Deploy Windows 10 in a test lab using System Center Configuration Manager](windows-10-poc-sc-config-mgr.md). |
|[Deploy Windows 10 with the Microsoft Deployment Toolkit](deploy-windows-10-with-the-microsoft-deployment-toolkit.md) |This guide will walk you through the process of deploying Windows 10 in an enterprise environment using the Microsoft Deployment Toolkit (MDT). |
|[Deploy Windows 10 with System Center 2012 R2 Configuration Manager](deploy-windows-10-with-system-center-2012-r2-configuration-manager.md) |If you have Microsoft System Center 2012 R2 Configuration Manager in your environment, you will most likely want to use it to deploy Windows 10. This topic will show you how to set up Configuration Manager for operating system deployment and how to integrate Configuration Manager with the Microsoft Deployment Toolkit (MDT) or. |
-|[Upgrade to Windows 10 with the Microsoft Deployment Toolkit](upgrade-to-windows-10-with-the-microsoft-deployment-toolkit.md) |The simplest path to upgrade PCs that are currently running Windows 7, Windows 8, or Windows 8.1 to Windows 10 is through an in-place upgrade. You can use a Microsoft Deployment Toolkit (MDT) task sequence to completely automate the process. |
-|[Upgrade to Windows 10 with System Center Configuration Manager](upgrade-to-windows-10-with-system-center-configuraton-manager.md) |The simplest path to upgrade PCs currently running Windows 7, Windows 8, or Windows 8.1 to Windows 10 is through an in-place upgrade. You can use a System Center Configuration Manager task sequence to completely automate the process. |
|[Resolve Windows 10 upgrade errors](resolve-windows-10-upgrade-errors.md) |This topic provides a brief introduction to Windows 10 installation processes, and provides resolution procedures that IT administrators can use to resolve issues with Windows 10 upgrade. |
|[Convert MBR partition to GPT](mbr-to-gpt.md) |This topic provides detailed instructions for using the MBR2GPT partition conversion tool. |
|[Configure a PXE server to load Windows PE](configure-a-pxe-server-to-load-windows-pe.md) |This guide describes how to configure a PXE server to load Windows PE by booting a client computer from the network. |
diff --git a/windows/deploy/upgrade-readiness-get-started.md b/windows/deploy/upgrade-readiness-get-started.md
index 9f9abda9b2..4829baa632 100644
--- a/windows/deploy/upgrade-readiness-get-started.md
+++ b/windows/deploy/upgrade-readiness-get-started.md
@@ -44,7 +44,7 @@ If you are already using OMS, you’ll find Upgrade Readiness in the Solutions G
If you are not using OMS:
-1. Go to the [Upgrade Readiness page on Microsoft.com](https://go.microsoft.com/fwlink/?LinkID=799190&clcid=0x409) and click **Sign up** to kick off the onboarding process.
+1. Go to the [Upgrade Readiness page on Microsoft.com](https://go.microsoft.com/fwlink/?LinkID=799190&clcid=0x409) and click **New Customers >** to kick off the onboarding process.
2. Sign in to Operations Management Suite (OMS). You can use either a Microsoft Account or a Work or School account to create a workspace. If your company is already using Azure Active Directory (Azure AD), use a Work or School account when you sign in to OMS. Using a Work or School account allows you to use identities from your Azure AD to manage permissions in OMS.
3. Create a new OMS workspace. Enter a name for the workspace, select the workspace region, and provide the email address that you want associated with this workspace. Select **Create**.
4. If your organization already has an Azure subscription, you can link it to your workspace. Note that you may need to request access from your organization’s Azure administrator.
@@ -130,4 +130,4 @@ To ensure that user computers are receiving the most up to date data from Micros
### Distribute the deployment script at scale
-Use a software distribution system such as System Center Configuration Manager to distribute the Upgrade Readiness deployment script at scale. For more information, see the [Upgrade Readiness blog](https://blogs.technet.microsoft.com/upgradeanalytics/2016/09/20/new-version-of-the-upgrade-analytics-deployment-script-available/).
\ No newline at end of file
+Use a software distribution system such as System Center Configuration Manager to distribute the Upgrade Readiness deployment script at scale. For more information, see the [Upgrade Readiness blog](https://blogs.technet.microsoft.com/upgradeanalytics/2016/09/20/new-version-of-the-upgrade-analytics-deployment-script-available/).
diff --git a/windows/deploy/upgrade-to-windows-10-with-system-center-configuraton-manager.md b/windows/deploy/upgrade-to-windows-10-with-system-center-configuraton-manager.md
index 1739910931..4df01c9022 100644
--- a/windows/deploy/upgrade-to-windows-10-with-system-center-configuraton-manager.md
+++ b/windows/deploy/upgrade-to-windows-10-with-system-center-configuraton-manager.md
@@ -1,6 +1,6 @@
---
-title: Upgrade to Windows 10 with System Center Configuration Manager (Windows 10)
-description: The simplest path to upgrade PCs currently running Windows 7, Windows 8, or Windows 8.1 to Windows 10 is through an in-place upgrade. You can use a System Center Configuration Manager task sequence to completely automate the process.
+title: Perform an in-place upgrade to Windows 10 using Configuration Manager (Windows 10)
+description: The simplest path to upgrade PCs currently running Windows 7, Windows 8, or Windows 8.1 to Windows 10 is through an in-place upgrade. Use a System Center Configuration Manager task sequence to completely automate the process.
ms.assetid: F8DF6191-0DB0-4EF5-A9B1-6A11D5DE4878
keywords: upgrade, update, task sequence, deploy
ms.prod: w10
@@ -9,7 +9,7 @@ ms.mktglfcycl: deploy
author: mtniehaus
---
-# Upgrade to Windows 10 with System Center Configuration Manager
+# Perform an in-place upgrade to Windows 10 using Configuration Manager
**Applies to**
diff --git a/windows/deploy/upgrade-to-windows-10-with-the-microsoft-deployment-toolkit.md b/windows/deploy/upgrade-to-windows-10-with-the-microsoft-deployment-toolkit.md
index c3f69f25b9..4deadb668f 100644
--- a/windows/deploy/upgrade-to-windows-10-with-the-microsoft-deployment-toolkit.md
+++ b/windows/deploy/upgrade-to-windows-10-with-the-microsoft-deployment-toolkit.md
@@ -1,5 +1,5 @@
---
-title: Upgrade to Windows 10 with the Microsoft Deployment Toolkit (Windows 10)
+title: Perform an in-place upgrade to Windows 10 with MDT (Windows 10)
description: The simplest path to upgrade PCs that are currently running Windows 7, Windows 8, or Windows 8.1 to Windows 10 is through an in-place upgrade.
ms.assetid: B8993151-3C1E-4F22-93F4-2C5F2771A460
keywords: upgrade, update, task sequence, deploy
@@ -11,7 +11,7 @@ ms.pagetype: mdt
author: mtniehaus
---
-# Upgrade to Windows 10 with the Microsoft Deployment Toolkit
+# Perform an in-place upgrade to Windows 10 with MDT
**Applies to**
- Windows 10
diff --git a/windows/deploy/windows-10-poc-mdt.md b/windows/deploy/windows-10-poc-mdt.md
index 78b5aa1d76..e42cec7206 100644
--- a/windows/deploy/windows-10-poc-mdt.md
+++ b/windows/deploy/windows-10-poc-mdt.md
@@ -5,6 +5,8 @@ ms.prod: w10
ms.mktglfcycl: deploy
ms.sitesec: library
ms.pagetype: deploy
+keywords: deployment, automate, tools, configure, mdt
+localizationpriority: high
author: greg-lindsay
---
diff --git a/windows/deploy/windows-10-poc-sc-config-mgr.md b/windows/deploy/windows-10-poc-sc-config-mgr.md
index ff0b497b45..b7c115e44a 100644
--- a/windows/deploy/windows-10-poc-sc-config-mgr.md
+++ b/windows/deploy/windows-10-poc-sc-config-mgr.md
@@ -5,6 +5,8 @@ ms.prod: w10
ms.mktglfcycl: deploy
ms.sitesec: library
ms.pagetype: deploy
+keywords: deployment, automate, tools, configure, sccm, configuration manager
+localizationpriority: high
author: greg-lindsay
---
diff --git a/windows/deploy/windows-10-poc.md b/windows/deploy/windows-10-poc.md
index 74b8d0f352..3db31d59c4 100644
--- a/windows/deploy/windows-10-poc.md
+++ b/windows/deploy/windows-10-poc.md
@@ -5,6 +5,8 @@ ms.prod: w10
ms.mktglfcycl: deploy
ms.sitesec: library
ms.pagetype: deploy
+keywords: deployment, automate, tools, configure, mdt, sccm
+localizationpriority: high
author: greg-lindsay
---
diff --git a/windows/images/W10-WaaS-poster.PNG b/windows/images/W10-WaaS-poster.PNG
new file mode 100644
index 0000000000..76f843c1b8
Binary files /dev/null and b/windows/images/W10-WaaS-poster.PNG differ
diff --git a/windows/images/front-page-video.PNG b/windows/images/front-page-video.PNG
new file mode 100644
index 0000000000..afe78e3564
Binary files /dev/null and b/windows/images/front-page-video.PNG differ
diff --git a/windows/images/w10-configure.png b/windows/images/w10-configure.png
new file mode 100644
index 0000000000..ebfef8d97b
Binary files /dev/null and b/windows/images/w10-configure.png differ
diff --git a/windows/images/w10-deploy.png b/windows/images/w10-deploy.png
new file mode 100644
index 0000000000..d567f44f1d
Binary files /dev/null and b/windows/images/w10-deploy.png differ
diff --git a/windows/images/w10-manage.png b/windows/images/w10-manage.png
new file mode 100644
index 0000000000..9ace55b79b
Binary files /dev/null and b/windows/images/w10-manage.png differ
diff --git a/windows/images/w10-plan.png b/windows/images/w10-plan.png
new file mode 100644
index 0000000000..045f85e914
Binary files /dev/null and b/windows/images/w10-plan.png differ
diff --git a/windows/images/w10-secure.png b/windows/images/w10-secure.png
new file mode 100644
index 0000000000..7799e94849
Binary files /dev/null and b/windows/images/w10-secure.png differ
diff --git a/windows/images/w10-update.png b/windows/images/w10-update.png
new file mode 100644
index 0000000000..876374904b
Binary files /dev/null and b/windows/images/w10-update.png differ
diff --git a/windows/images/w10-whatsnew.png b/windows/images/w10-whatsnew.png
new file mode 100644
index 0000000000..cc040c45aa
Binary files /dev/null and b/windows/images/w10-whatsnew.png differ
diff --git a/windows/index.md b/windows/index.md
index 08a4bee465..8d86b31add 100644
--- a/windows/index.md
+++ b/windows/index.md
@@ -8,37 +8,94 @@ author: brianlic-msft
---
# Windows 10 and Windows 10 Mobile
+
+This library provides the core content that IT pros need to evaluate, plan, deploy, secure and manage devices running Windows 10 or Windows 10 Mobile.
+
+
+ ![]() What's New? + |
+
+
+ ![]() Plan + |
+
+
+ ![]() Deploy + |
+
+
+ ![]() Manage + |
+
+ + + ![]() Keep Secure + |
+
+ + + ![]() Configure + |
+
+ + + ![]() Update + |
+
+ + + ![]() Try it + |
+
The Windows 10 operating system introduces a new way to build, deploy, and service Windows: Windows as a service. Microsoft has reimagined each part of the process, to simplify the lives of IT pros and maintain a consistent Windows 10 experience for its customers. + + These improvements focus on maximizing customer involvement in Windows development, simplifying the deployment and servicing of Windows client computers, and leveling out the resources needed to deploy and maintain Windows over time. + -[What's new in Windows 10](whats-new/index.md) + * [Read more about Windows as a Service]() + * [Download the WaaS infographic]() -[Plan for Windows 10 deployment](plan/index.md) + | +![]() |
+
Service | +Description | +URL | +
---|---|---|
+ Windows Defender Antivirus cloud-based protection service, also referred to as Microsoft Active Protection Service (MAPS) + | ++ Used by Windows Defender Antivirus to provide cloud-based protection + | +
+*.wdcp.microsoft.com* +*.wdcpalt.microsoft.com* + |
+
+Microsoft Update Service (MU) + | ++Signature and product updates + | ++*.updates.microsoft.com + | +
+ Definition updates alternate download location (ADL) + | ++ Alternate location for Windows Defender Antivirus definition updates if the installed definitions fall out of date (7 or more days behind) + | ++*.download.microsoft.com + | +
+ Malware submission storage + | ++ Upload location for files submitted to Microsoft via the Submission form or automatic sample submission + | ++*.blob.core.windows.net + | +
+Certificate Revocation List (CRL) + | ++Used by Windows when creating the SSL connection to MAPS for updating the CRL + | +
+http://www.microsoft.com/pkiops/crl/ +http://www.microsoft.com/pkiops/certs +http://crl.microsoft.com/pki/crl/products +http://www.microsoft.com/pki/certs + + |
+
+Symbol Store + | ++Used by Windows Defender Antivirus to restore certain critical files during remediation flows + | ++https://msdl.microsoft.com/download/symbols + | +
+Universal Telemetry Client + | ++Used by Windows to send client telemetry, Windows Defender Antivirus uses this for product quality monitoring purposes + | +
+This update uses SSL (TCP Port 443) to download manifests and upload telemetry to Microsoft that uses the following DNS endpoints:
|
+
Method | -Instructions | -
---|---|
WSUS |
-See [Software Updates and Windows Server Update Services Definition Updates](https://technet.microsoft.com/library/gg398036.aspx) in the [Configuring Definition Updates](https://technet.microsoft.com/library/gg412502.aspx) topic that also applies to Windows Defender. |
-
Microsoft Update |
-Set the following fallback order Group Policy to enable Microsoft Update: -
|
-
[Microsoft Malware Protection Center definitions page](http://www.microsoft.com/security/portal/definitions/adl.aspx) |
-Set the following fallback order Group Policy to enable Windows Defender to download updated signatures: -
|
-
File share |
-
-
|
-
Event ID: 1000 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_SCAN_STARTED + |
+||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|
+ Message: + |
+
+ An antimalware scan started. + + |
+|||||||||||
+ Description: + |
+
+ +
|
+|||||||||||
Event ID: 1001 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_SCAN_COMPLETED + |
+||||||||||
+ Message: + |
+
+ An antimalware scan finished. + |
+|||||||||||
+ Description: + |
+
+ +
|
+|||||||||||
Event ID: 1002 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_SCAN_CANCELLED + + |
+||||||||||
+ Message: + |
+
+ An antimalware scan was stopped before it finished. + + |
+|||||||||||
+ Description: + |
+
+ +
|
+|||||||||||
Event ID: 1003 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_SCAN_PAUSED + + |
+||||||||||
+ Message: + |
+
+ An antimalware scan was paused. + + |
+|||||||||||
+ Description: + |
+
+ +
|
+|||||||||||
Event ID: 1004 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_SCAN_RESUMED + + |
+||||||||||
+ Message: + |
+
+ An antimalware scan was resumed. + + |
+|||||||||||
+ Description: + |
+
+ +
|
+|||||||||||
Event ID: 1005 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_SCAN_FAILED + + |
+||||||||||
+ Message: + |
+
+ An antimalware scan failed. + + |
+|||||||||||
+ Description: + |
+
+ +
|
+|||||||||||
+ User action: + |
+
+ The Windows Defender client encountered an error, and the current scan has stopped. The scan might fail due to a client-side issue. This event record includes the scan ID, type of scan (antivirus, antispyware, antimalware), scan parameters, the user that started the scan, the error code, and a description of the error. + +To troubleshoot this event: +
|
+|||||||||||
Event ID: 1006 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_MALWARE_DETECTED + + |
+||||||||||
+ Message: + |
+
+ The antimalware engine found malware or other potentially unwanted software. + + |
+|||||||||||
+ Description: + |
+
+ + For more information please see the following: +
|
+|||||||||||
Event ID: 1007 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_MALWARE_ACTION_TAKEN + + |
+||||||||||
+ Message: + |
+
+ The antimalware platform performed an action to protect your system from malware or other potentially unwanted software. + + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender has taken action to protect this machine from malware or other potentially unwanted software. For more information please see the following: +
|
+|||||||||||
Event ID: 1008 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_MALWARE_ACTION_FAILED + |
+||||||||||
+ Message: + |
+
+ The antimalware platform attempted to perform an action to protect your system from malware or other potentially unwanted software, but the action failed. + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender has encountered an error when taking action on malware or other potentially unwanted software. For more information please see the following: +
|
+|||||||||||
Event ID: 1009 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_QUARANTINE_RESTORE + + |
+||||||||||
+ Message: + |
+
+ The antimalware platform restored an item from quarantine. + + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender has restored an item from quarantine. For more information please see the following: +
|
+|||||||||||
Event ID: 1010 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_QUARANTINE_RESTORE_FAILED + + |
+||||||||||
+ Message: + |
+
+ The antimalware platform could not restore an item from quarantine. + + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender has encountered an error trying to restore an item from quarantine. For more information please see the following: +
|
+|||||||||||
Event ID: 1011 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_QUARANTINE_DELETE + |
+||||||||||
+ Message: + |
+
+ The antimalware platform deleted an item from quarantine. + + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender has deleted an item from quarantine. +For more information please see the following: +
|
+|||||||||||
Event ID: 1012 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_QUARANTINE_DELETE_FAILED + + |
+||||||||||
+ Message: + |
+
+ The antimalware platform could not delete an item from quarantine. + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender has encountered an error trying to delete an item from quarantine. +For more information please see the following: +
|
+|||||||||||
Event ID: 1013 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_MALWARE_HISTORY_DELETE + + |
+||||||||||
+ Message: + |
+
+ The antimalware platform deleted history of malware and other potentially unwanted software. + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender has removed history of malware and other potentially unwanted software. +
|
+|||||||||||
Event ID: 1014 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_MALWARE_HISTORY_DELETE_FAILED + + |
+||||||||||
+ Message: + |
+
+ The antimalware platform could not delete history of malware and other potentially unwanted software. + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender has encountered an error trying to remove history of malware and other potentially unwanted software. +
|
+|||||||||||
Event ID: 1015 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_BEHAVIOR_DETECTED + + |
+||||||||||
+ Message: + |
+
+ The antimalware platform detected suspicious behavior. + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender has detected a suspicious behavior. +For more information please see the following: +
|
+|||||||||||
Event ID: 1116 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_STATE_MALWARE_DETECTED + |
+||||||||||
+ Message: + |
+
+ The antimalware platform detected malware or other potentially unwanted software. + + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender has detected malware or other potentially unwanted software. +For more information please see the following: +
|
+|||||||||||
+ User action: + |
+
+ No action is required. Windows Defender can suspend and take routine action on this threat. If you want to remove the threat manually, in the Windows Defender interface, click Clean Computer. + |
+|||||||||||
Event ID: 1117 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_STATE_MALWARE_ACTION_TAKEN + + |
+||||||||||
+ Message: + |
+
+ The antimalware platform performed an action to protect your system from malware or other potentially unwanted software. + + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender has taken action to protect this machine from malware or other potentially unwanted software. +For more information please see the following: +
NOTE: + Whenever Windows Defender, Microsoft Security Essentials, Malicious Software Removal Tool, or System Center Endpoint Protection detects a malware, it will restore the following system settings and services which the malware might have changed:
|
+|||||||||||
+ User action: + |
+
+ No action is necessary. Windows Defender removed or quarantined a threat. + |
+|||||||||||
Event ID: 1118 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_STATE_MALWARE_ACTION_FAILED + |
+||||||||||
+ Message: + |
+
+ The antimalware platform attempted to perform an action to protect your system from malware or other potentially unwanted software, but the action failed. + + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender has encountered a non-critical error when taking action on malware or other potentially unwanted software. +For more information please see the following: +
|
+|||||||||||
+ User action: + |
+
+ No action is necessary. Windows Defender failed to complete a task related to the malware remediation. This is not a critical failure. + |
+|||||||||||
Event ID: 1119 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_STATE_MALWARE_ACTION_CRITICALLY_FAILED + + |
+||||||||||
+ Message: + |
+
+ The antimalware platform encountered a critical error when trying to take action on malware or other potentially unwanted software. There are more details in the event message. + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender has encountered a critical error when taking action on malware or other potentially unwanted software. +For more information please see the following: +
|
+|||||||||||
+ User action: + |
+
+ The Windows Defender client encountered this error due to critical issues. The endpoint might not be protected. Review the error description then follow the relevant User action steps below. +
+ If this event persists:
|
+|||||||||||
Event ID: 1120 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_THREAT_HASH + |
+||||||||||
+ Message: + |
+
+ Windows Defender has deduced the hashes for a threat resource. + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender client is up and running in a healthy state. +
|
+|||||||||||
+ |
+ Note This event will only be logged if the following policy is set: ThreatFileHashLogging unsigned.
+ |
+|||||||||||
Event ID: 1150 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_SERVICE_HEALTHY + |
+||||||||||
+ Message: + |
+
+ If your antimalware platform reports status to a monitoring platform, this event indicates that the antimalware platform is running and in a healthy state. + + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender client is up and running in a healthy state. +
|
+|||||||||||
+ User action: + |
+
+ No action is necessary. The Windows Defenderclient is in a healthy state. This event is reported on an hourly basis. + |
+|||||||||||
Event ID: 2000 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_SIGNATURE_UPDATED + + |
+||||||||||
+ Message: + |
+
+ The antimalware definitions updated successfully. + + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender signature version has been updated. +
|
+|||||||||||
+ User action: + |
+
+ No action is necessary. The Windows Defender client is in a healthy state. This event is reported when signatures are successfully updated. + |
+|||||||||||
Event ID: 2001 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_SIGNATURE_UPDATE_FAILED + |
+||||||||||
+ Message: + |
+
+ The antimalware definition update failed. + + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender has encountered an error trying to update signatures. +
|
+|||||||||||
+ User action: + |
+
+ This error occurs when there is a problem updating definitions. +To troubleshoot this event: +
|
+|||||||||||
Event ID: 2002 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_ENGINE_UPDATED + |
+||||||||||
+ Message: + |
+
+ The antimalware engine updated successfully. + + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender engine version has been updated. +
|
+|||||||||||
+ User action: + |
+
+ No action is necessary. The Windows Defender client is in a healthy state. This event is reported when the antimalware engine is successfully updated. + |
+|||||||||||
Event ID: 2003 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_ENGINE_UPDATE_FAILED + |
+||||||||||
+ Message: + |
+
+ The antimalware engine update failed. + + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender has encountered an error trying to update the engine. +
|
+|||||||||||
+ User action: + |
+
+ The Windows Defender client update failed. This event occurs when the client fails to update itself. This event is usually due to an interruption in network connectivity during an update. +To troubleshoot this event: +
|
+|||||||||||
Event ID: 2004 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_SIGNATURE_REVERSION + |
+||||||||||
+ Message: + |
+
+ There was a problem loading antimalware definitions. The antimalware engine will attempt to load the last-known good set of definitions. + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures. +
|
+|||||||||||
+ User action: + |
+
+ The Windows Defender client attempted to download and install the latest definitions file and failed. This error can occur when the client encounters an error while trying to load the definitions, or if the file is corrupt. Windows Defender will attempt to revert back to a known-good set of definitions. +To troubleshoot this event: +
|
+|||||||||||
Event ID: 2005 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_ENGINE_UPDATE_PLATFORMOUTOFDATE + |
+||||||||||
+ Message: + |
+
+ The antimalware engine failed to load because the antimalware platform is out of date. The antimalware platform will load the last-known good antimalware engine and attempt to update. + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender could not load antimalware engine because current platform version is not supported. Windows Defender will revert back to the last known-good engine and a platform update will be attempted. +
|
+|||||||||||
Event ID: 2006 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_PLATFORM_UPDATE_FAILED + + |
+||||||||||
+ Message: + |
+
+ The platform update failed. + + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender has encountered an error trying to update the platform. +
|
+|||||||||||
Event ID: 2007 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_PLATFORM_ALMOSTOUTOFDATE + |
+||||||||||
+ Message: + |
+
+ The platform will soon be out of date. Download the latest platform to maintain up-to-date protection. + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender will soon require a newer platform version to support future versions of the antimalware engine. Download the latest Windows Defender platform to maintain the best level of protection available. +
|
+|||||||||||
Event ID: 2010 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_SIGNATURE_FASTPATH_UPDATED + + |
+||||||||||
+ Message: + |
+
+ The antimalware engine used the Dynamic Signature Service to get additional definitions. + + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender used Dynamic Signature Service to retrieve additional signatures to help protect your machine. +
|
+|||||||||||
Event ID: 2011 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_SIGNATURE_FASTPATH_DELETED + + |
+||||||||||
+ Message: + |
+
+ The Dynamic Signature Service deleted the out-of-date dynamic definitions. + + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender used Dynamic Signature Service to discard obsolete signatures. +
|
+|||||||||||
+ User action: + |
+
+ No action is necessary. The Windows Defender client is in a healthy state. This event is reported when the Dynamic Signature Service successfully deletes out-of-date dynamic definitions. + |
+|||||||||||
Event ID: 2012 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_SIGNATURE_FASTPATH_UPDATE_FAILED + + |
+||||||||||
+ Message: + |
+
+ The antimalware engine encountered an error when trying to use the Dynamic Signature Service. + + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender has encountered an error trying to use Dynamic Signature Service. +
|
+|||||||||||
+ User action: + |
+
+ Check your Internet connectivity settings. + |
+|||||||||||
Event ID: 2013 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_SIGNATURE_FASTPATH_DELETED_ALL + + |
+||||||||||
+ Message: + |
+
+ The Dynamic Signature Service deleted all dynamic definitions. + + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender discarded all Dynamic Signature Service signatures. +
|
+|||||||||||
Event ID: 2020 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_CLOUD_CLEAN_RESTORE_FILE_DOWNLOADED + + |
+||||||||||
+ Message: + |
+
+ The antimalware engine downloaded a clean file. + + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender downloaded a clean file. +
|
+|||||||||||
Event ID: 2021 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_CLOUD_CLEAN_RESTORE_FILE_DOWNLOAD_FAILED + |
+||||||||||
+ Message: + |
+
+ The antimalware engine failed to download a clean file. + + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender has encountered an error trying to download a clean file. +
|
+|||||||||||
+ User action: + |
+
+ Check your Internet connectivity settings. + +The Windows Defender client encountered an error when using the Dynamic Signature Service to download the latest definitions to a specific threat. This error is likely caused by a network connectivity issue. + + |
+|||||||||||
Event ID: 2030 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_OFFLINE_SCAN_INSTALLED + |
+||||||||||
+ Message: + |
+
+ The antimalware engine was downloaded and is configured to run offline on the next system restart. + |
+|||||||||||
+ Description: + |
+
+ Windows Defender downloaded and configured Windows Defender Offline to run on the next reboot. + |
+|||||||||||
Event ID: 2031 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_OFFLINE_SCAN_INSTALL_FAILED + + |
+||||||||||
+ Message: + |
+
+ The antimalware engine was unable to download and configure an offline scan. + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender has encountered an error trying to download and configure Windows Defender Offline. +
|
+|||||||||||
Event ID: 2040 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_OS_EXPIRING + + |
+||||||||||
+ Message: + |
+
+ Antimalware support for this operating system version will soon end. + + |
+|||||||||||
+ Description: + |
+
+ The support for your operating system will expire shortly. Running Windows Defender on an out of support operating system is not an adequate solution to protect against threats. + |
+|||||||||||
Event ID: 2041 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_OS_EOL + + |
+||||||||||
+ Message: + |
+
+ Antimalware support for this operating system has ended. You must upgrade the operating system for continued support. + + |
+|||||||||||
+ Description: + |
+
+ The support for your operating system has expired. Running Windows Defender on an out of support operating system is not an adequate solution to protect against threats. + |
+|||||||||||
Event ID: 2042 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_PROTECTION_EOL + + |
+||||||||||
+ Message: + |
+
+ The antimalware engine no longer supports this operating system, and is no longer protecting your system from malware. + + |
+|||||||||||
+ Description: + |
+
+ The support for your operating system has expired. Windows Defender is no longer supported on your operating system, has stopped functioning, and is not protecting against malware threats. + |
+|||||||||||
Event ID: 3002 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_RTP_FEATURE_FAILURE + + |
+||||||||||
+ Message: + |
+
+ Real-time protection encountered an error and failed. + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender Real-Time Protection feature has encountered an error and failed. +
|
+|||||||||||
+ User action: + |
+
+ You should restart the system then run a full scan because it’s possible the system was not protected for some time. + +The Windows Defender client’s real-time protection feature encountered an error because one of the services failed to start. + +If it is followed by a 3007 event ID, the failure was temporary and the antimalware client recovered from the failure. + + |
+|||||||||||
Event ID: 3007 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_RTP_FEATURE_RECOVERED + |
+||||||||||
+ Message: + |
+
+ Real-time protection recovered from a failure. We recommend running a full system scan when you see this error. + + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender Real-time Protection has restarted a feature. It is recommended that you run a full system scan to detect any items that may have been missed while this agent was down. +
|
+|||||||||||
+ User action: + |
+
+ The real-time protection feature has restarted. If this event happens again, contact Microsoft Technical Support. + |
+|||||||||||
Event ID: 5000 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_RTP_ENABLED + + |
+||||||||||
+ Message: + |
+
+ Real-time protection is enabled. + + |
+|||||||||||
+ Description: + |
+
+ Windows Defender Real-time Protection scanning for malware and other potentially unwanted software was enabled. + |
+|||||||||||
Event ID: 5001 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_RTP_DISABLED + |
+||||||||||
+ Message: + |
+
+ Real-time protection is disabled. + + |
+|||||||||||
+ Description: + |
+
+ Windows Defender Real-time Protection scanning for malware and other potentially unwanted software was disabled. + |
+|||||||||||
Event ID: 5004 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_RTP_FEATURE_CONFIGURED + + |
+||||||||||
+ Message: + |
+
+ The real-time protection configuration changed. + + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender Real-time Protection feature configuration has changed. +
|
+|||||||||||
Event ID: 5007 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_CONFIG_CHANGED + + |
+||||||||||
+ Message: + |
+
+ The antimalware platform configuration changed. + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender Configuration has changed. If this is an unexpected event you should review the settings as this may be the result of malware. +
|
+|||||||||||
Event ID: 5008 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_ENGINE_FAILURE + |
+||||||||||
+ Message: + |
+
+ The antimalware engine encountered an error and failed. + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender engine has been terminated due to an unexpected error. +
|
+|||||||||||
+ User action: + |
+
+ To troubleshoot this event:
|
+|||||||||||
+ User action: + |
+
+ The Windows Defender client engine stopped due to an unexpected error. +To troubleshoot this event: +
|
+|||||||||||
Event ID: 5009 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_ANTISPYWARE_ENABLED + + |
+||||||||||
+ Message: + |
+
+ Scanning for malware and other potentially unwanted software is enabled. + + |
+|||||||||||
+ Description: + |
+
+ Windows Defender scanning for malware and other potentially unwanted software has been enabled. + |
+|||||||||||
Event ID: 5010 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_ANTISPYWARE_DISABLED + + |
+||||||||||
+ Message: + |
+
+ Scanning for malware and other potentially unwanted software is disabled. + |
+|||||||||||
+ Description: + |
+
+ Windows Defender scanning for malware and other potentially unwanted software is disabled. + |
+|||||||||||
Event ID: 5011 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_ANTIVIRUS_ENABLED + |
+||||||||||
+ Message: + |
+
+ Scanning for viruses is enabled. + |
+|||||||||||
+ Description: + |
+
+ Windows Defender scanning for viruses has been enabled. + |
+|||||||||||
Event ID: 5012 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_ANTIVIRUS_DISABLED + + |
+||||||||||
+ Message: + |
+
+ Scanning for viruses is disabled. + + |
+|||||||||||
+ Description: + |
+
+ Windows Defender scanning for viruses is disabled. + |
+|||||||||||
Event ID: 5100 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_EXPIRATION_WARNING_STATE + + |
+||||||||||
+ Message: + |
+
+ The antimalware platform will expire soon. + + |
+|||||||||||
+ Description: + |
+
+ + Windows Defender has entered a grace period and will soon expire. After expiration, this program will disable protection against viruses, spyware, and other potentially unwanted software. +
|
+|||||||||||
Event ID: 5101 | +
+ Symbolic name: + |
+
+ MALWAREPROTECTION_DISABLED_EXPIRED_STATE + + |
+||||||||||
+ Message: + |
+
+ The antimalware platform is expired. + + |
+|||||||||||
+ Description:: + |
+
+ + Windows Defender grace period has expired. Protection against viruses, spyware, and other potentially unwanted software is disabled. +
|
+
External error codes | +|||
---|---|---|---|
Error code | +Message displayed | +Possible reason for error | +What to do now | +
+ 0x80508007 + + |
+
+ ERR_MP_NO_MEMORY + + |
+
+ This error indicates that you might have run out of memory. + + |
+
+ +
|
+
+ 0x8050800C + |
+
+ ERR_MP_BAD_INPUT_DATA + |
+
+ This error indicates that there might be a problem with your security product. + |
+
+ +
|
+
+ 0x80508020 + |
+
+ ERR_MP_BAD_CONFIGURATION + + |
+
+ This error indicates that there might be an engine configuration error; commonly, this is related to input +data that does not allow the engine to function properly. + + |
+|
+ 0x805080211 + + |
+
+ ERR_MP_QUARANTINE_FAILED + + |
+
+ This error indicates that Windows Defender failed to quarantine a threat. + + |
+|
+ 0x80508022 + + |
+
+ ERR_MP_REBOOT_REQUIRED + + |
+
+ This error indicates that a reboot is required to complete threat removal. + + |
+|
+ 0x80508023 + + |
+
+ ERR_MP_THREAT_NOT_FOUND + + |
+
+ This error indicates that the threat might no longer be present on the media, or malware might be stopping you from scanning your device. + + |
+
+ Run the Microsoft Safety Scanner then update your security software and try again. + + |
+
+ ERR_MP_FULL_SCAN_REQUIRED + + |
+
+ This error indicates that a full system scan might be required. + + |
+
+ Run a full system scan. + + |
+|
+ 0x80508024 + + |
+|||
+ 0x80508025 + + |
+
+ ERR_MP_MANUAL_STEPS_REQUIRED + + |
+
+ This error indicates that manual steps are required to complete threat removal. + + |
+
+ Follow the manual remediation steps outlined in the Microsoft Malware Protection Encyclopedia. You can find a threat-specific link in the event history. + + |
+
+ 0x80508026 + + |
+
+ ERR_MP_REMOVE_NOT_SUPPORTED + + |
+
+ This error indicates that removal inside the container type might not be not supported. + + |
+
+ Windows Defender is not able to remediate threats detected inside the archive. Consider manually removing the detected resources. + + |
+
+ 0x80508027 + + |
+
+ ERR_MP_REMOVE_LOW_MEDIUM_DISABLED + + |
+
+ This error indicates that removal of low and medium threats might be disabled. + + |
+
+ Check the detected threats and resolve them as required. + + |
+
+ 0x80508029 + + |
+
+ ERROR_MP_RESCAN_REQUIRED + + |
+
+ This error indicates a rescan of the threat is required. + + |
+
+ Run a full system scan. + + |
+
+ 0x80508030 + + |
+
+ ERROR_MP_CALLISTO_REQUIRED + + |
+
+ This error indicates that an offline scan is required. + + |
+
+ Run Windows Defender Offline. You can read about how to do this in the Windows Defender Offline +article. + |
+
+ 0x80508031 + + |
+
+ ERROR_MP_PLATFORM_OUTDATED + + |
+
+ This error indicates that Windows Defender does not support the current version of the platform and requires a new version of the platform. + + |
+
+ You can only use Windows Defender in Windows 10. For Windows 8, Windows 7 and Windows Vista, you can use System Center Endpoint Protection. + + |
+
Internal error codes | +|||
---|---|---|---|
Error code | +Message displayed | +Possible reason for error | +What to do now | +
+ 0x80501004 + |
+
+ ERROR_MP_NO_INTERNET_CONN + + |
+
+ Check your Internet connection, then run the scan again. + |
+
+ Check your Internet connection, then run the scan again. + |
+
+ 0x80501000 + |
+
+ ERROR_MP_UI_CONSOLIDATION_BASE + |
+
+ This is an internal error. The cause is not clearly defined. + |
+
+ +
|
+
+ 0x80501001 + |
+
+ ERROR_MP_ACTIONS_FAILED + |
+||
+ 0x80501002 + |
+
+ ERROR_MP_NOENGINE + |
+||
+ 0x80501003 + |
+
+ ERROR_MP_ACTIVE_THREATS + |
+||
+ 0x805011011 + |
+
+ MP_ERROR_CODE_LUA_CANCELLED + |
+||
+ 0x80501101 + |
+
+ ERROR_LUA_CANCELLATION + |
+||
+ 0x80501102 + |
+
+ MP_ERROR_CODE_ALREADY_SHUTDOWN + |
+||
+ 0x80501103 + |
+
+ MP_ERROR_CODE_RDEVICE_S_ASYNC_CALL_PENDING + |
+||
+ 0x80501104 + |
+
+ MP_ERROR_CODE_CANCELLED + |
+||
+ 0x80501105 + |
+
+ MP_ERROR_CODE_NO_TARGETOS + |
+||
+ 0x80501106 + |
+
+ MP_ERROR_CODE_BAD_REGEXP + |
+||
+ 0x80501107 + |
+
+ MP_ERROR_TEST_INDUCED_ERROR + |
+||
+ 0x80501108 + |
+
+ MP_ERROR_SIG_BACKUP_DISABLED + |
+||
+ 0x80508001 + |
+
+ ERR_MP_BAD_INIT_MODULES + |
+||
+ 0x80508002 + |
+
+ ERR_MP_BAD_DATABASE + |
+||
+ 0x80508004 + |
+
+ ERR_MP_BAD_UFS + |
+||
+ 0x8050800C + |
+
+ ERR_MP_BAD_INPUT_DATA + |
+||
+ 0x8050800D + |
+
+ ERR_MP_BAD_GLOBAL_STORAGE + |
+||
+ 0x8050800E + |
+
+ ERR_MP_OBSOLETE + |
+||
+ 0x8050800F + |
+
+ ERR_MP_NOT_SUPPORTED + |
+||
+ 0x8050800F +0x80508010 + + |
+
+ ERR_MP_NO_MORE_ITEMS + |
+||
+ 0x80508011 + |
+
+ ERR_MP_DUPLICATE_SCANID + |
+||
+ 0x80508012 + |
+
+ ERR_MP_BAD_SCANID + |
+||
+ 0x80508013 + |
+
+ ERR_MP_BAD_USERDB_VERSION + |
+||
+ 0x80508014 + |
+
+ ERR_MP_RESTORE_FAILED + |
+||
+ 0x80508016 + |
+
+ ERR_MP_BAD_ACTION + |
+||
+ 0x80508019 + |
+
+ ERR_MP_NOT_FOUND + |
+||
+ 0x80509001 + |
+
+ ERR_RELO_BAD_EHANDLE + |
+||
+ 0x80509003 + |
+
+ ERR_RELO_KERNEL_NOT_LOADED + |
+||
+ 0x8050A001 + |
+
+ ERR_MP_BADDB_OPEN + |
+||
+ 0x8050A002 + |
+
+ ERR_MP_BADDB_HEADER + |
+||
+ 0x8050A003 + |
+
+ ERR_MP_BADDB_OLDENGINE + |
+||
+ 0x8050A004 + |
+
+ ERR_MP_BADDB_CONTENT + |
+||
+ 0x8050A005 + |
+
+ ERR_MP_BADDB_NOTSIGNED + |
+||
+ 0x8050801 + |
+
+ ERR_MP_REMOVE_FAILED + |
+
+ This is an internal error. It might be triggered when malware removal is not successful. + + |
+|
+ 0x80508018 + + |
+
+ ERR_MP_SCAN_ABORTED + + |
+
+ This is an internal error. It might have triggered when a scan fails to complete. + + |
+
Event ID: 1000 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_SCAN_STARTED - |
-||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|
- Message: - |
-
- An antimalware scan started. - - |
-|||||||||||
- Description: - |
-
- -
|
-|||||||||||
Event ID: 1001 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_SCAN_COMPLETED - |
-||||||||||
- Message: - |
-
- An antimalware scan finished. - |
-|||||||||||
- Description: - |
-
- -
|
-|||||||||||
Event ID: 1002 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_SCAN_CANCELLED - - |
-||||||||||
- Message: - |
-
- An antimalware scan was stopped before it finished. - - |
-|||||||||||
- Description: - |
-
- -
|
-|||||||||||
Event ID: 1003 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_SCAN_PAUSED - - |
-||||||||||
- Message: - |
-
- An antimalware scan was paused. - - |
-|||||||||||
- Description: - |
-
- -
|
-|||||||||||
Event ID: 1004 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_SCAN_RESUMED - - |
-||||||||||
- Message: - |
-
- An antimalware scan was resumed. - - |
-|||||||||||
- Description: - |
-
- -
|
-|||||||||||
Event ID: 1005 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_SCAN_FAILED - - |
-||||||||||
- Message: - |
-
- An antimalware scan failed. - - |
-|||||||||||
- Description: - |
-
- -
|
-|||||||||||
- User action: - |
-
- The Windows Defender client encountered an error, and the current scan has stopped. The scan might fail due to a client-side issue. This event record includes the scan ID, type of scan (antivirus, antispyware, antimalware), scan parameters, the user that started the scan, the error code, and a description of the error. - -To troubleshoot this event: -
|
-|||||||||||
Event ID: 1006 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_MALWARE_DETECTED - - |
-||||||||||
- Message: - |
-
- The antimalware engine found malware or other potentially unwanted software. - - |
-|||||||||||
- Description: - |
-
- - For more information please see the following: -
|
-|||||||||||
Event ID: 1007 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_MALWARE_ACTION_TAKEN - - |
-||||||||||
- Message: - |
-
- The antimalware platform performed an action to protect your system from malware or other potentially unwanted software. - - |
-|||||||||||
- Description: - |
-
- - Windows Defender has taken action to protect this machine from malware or other potentially unwanted software. For more information please see the following: -
|
-|||||||||||
Event ID: 1008 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_MALWARE_ACTION_FAILED - |
-||||||||||
- Message: - |
-
- The antimalware platform attempted to perform an action to protect your system from malware or other potentially unwanted software, but the action failed. - |
-|||||||||||
- Description: - |
-
- - Windows Defender has encountered an error when taking action on malware or other potentially unwanted software. For more information please see the following: -
|
-|||||||||||
Event ID: 1009 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_QUARANTINE_RESTORE - - |
-||||||||||
- Message: - |
-
- The antimalware platform restored an item from quarantine. - - |
-|||||||||||
- Description: - |
-
- - Windows Defender has restored an item from quarantine. For more information please see the following: -
|
-|||||||||||
Event ID: 1010 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_QUARANTINE_RESTORE_FAILED - - |
-||||||||||
- Message: - |
-
- The antimalware platform could not restore an item from quarantine. - - |
-|||||||||||
- Description: - |
-
- - Windows Defender has encountered an error trying to restore an item from quarantine. For more information please see the following: -
|
-|||||||||||
Event ID: 1011 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_QUARANTINE_DELETE - |
-||||||||||
- Message: - |
-
- The antimalware platform deleted an item from quarantine. - - |
-|||||||||||
- Description: - |
-
- - Windows Defender has deleted an item from quarantine. -For more information please see the following: -
|
-|||||||||||
Event ID: 1012 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_QUARANTINE_DELETE_FAILED - - |
-||||||||||
- Message: - |
-
- The antimalware platform could not delete an item from quarantine. - |
-|||||||||||
- Description: - |
-
- - Windows Defender has encountered an error trying to delete an item from quarantine. -For more information please see the following: -
|
-|||||||||||
Event ID: 1013 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_MALWARE_HISTORY_DELETE - - |
-||||||||||
- Message: - |
-
- The antimalware platform deleted history of malware and other potentially unwanted software. - |
-|||||||||||
- Description: - |
-
- - Windows Defender has removed history of malware and other potentially unwanted software. -
|
-|||||||||||
Event ID: 1014 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_MALWARE_HISTORY_DELETE_FAILED - - |
-||||||||||
- Message: - |
-
- The antimalware platform could not delete history of malware and other potentially unwanted software. - |
-|||||||||||
- Description: - |
-
- - Windows Defender has encountered an error trying to remove history of malware and other potentially unwanted software. -
|
-|||||||||||
Event ID: 1015 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_BEHAVIOR_DETECTED - - |
-||||||||||
- Message: - |
-
- The antimalware platform detected suspicious behavior. - |
-|||||||||||
- Description: - |
-
- - Windows Defender has detected a suspicious behavior. -For more information please see the following: -
|
-|||||||||||
Event ID: 1116 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_STATE_MALWARE_DETECTED - |
-||||||||||
- Message: - |
-
- The antimalware platform detected malware or other potentially unwanted software. - - |
-|||||||||||
- Description: - |
-
- - Windows Defender has detected malware or other potentially unwanted software. -For more information please see the following: -
|
-|||||||||||
- User action: - |
-
- No action is required. Windows Defender can suspend and take routine action on this threat. If you want to remove the threat manually, in the Windows Defender interface, click Clean Computer. - |
-|||||||||||
Event ID: 1117 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_STATE_MALWARE_ACTION_TAKEN - - |
-||||||||||
- Message: - |
-
- The antimalware platform performed an action to protect your system from malware or other potentially unwanted software. - - |
-|||||||||||
- Description: - |
-
- - Windows Defender has taken action to protect this machine from malware or other potentially unwanted software. -For more information please see the following: -
NOTE: - Whenever Windows Defender, Microsoft Security Essentials, Malicious Software Removal Tool, or System Center Endpoint Protection detects a malware, it will restore the following system settings and services which the malware might have changed:
|
-|||||||||||
- User action: - |
-
- No action is necessary. Windows Defender removed or quarantined a threat. - |
-|||||||||||
Event ID: 1118 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_STATE_MALWARE_ACTION_FAILED - |
-||||||||||
- Message: - |
-
- The antimalware platform attempted to perform an action to protect your system from malware or other potentially unwanted software, but the action failed. - - |
-|||||||||||
- Description: - |
-
- - Windows Defender has encountered a non-critical error when taking action on malware or other potentially unwanted software. -For more information please see the following: -
|
-|||||||||||
- User action: - |
-
- No action is necessary. Windows Defender failed to complete a task related to the malware remediation. This is not a critical failure. - |
-|||||||||||
Event ID: 1119 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_STATE_MALWARE_ACTION_CRITICALLY_FAILED - - |
-||||||||||
- Message: - |
-
- The antimalware platform encountered a critical error when trying to take action on malware or other potentially unwanted software. There are more details in the event message. - |
-|||||||||||
- Description: - |
-
- - Windows Defender has encountered a critical error when taking action on malware or other potentially unwanted software. -For more information please see the following: -
|
-|||||||||||
- User action: - |
-
- The Windows Defender client encountered this error due to critical issues. The endpoint might not be protected. Review the error description then follow the relevant User action steps below. -
- If this event persists:
|
-|||||||||||
Event ID: 1120 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_THREAT_HASH - |
-||||||||||
- Message: - |
-
- Windows Defender has deduced the hashes for a threat resource. - |
-|||||||||||
- Description: - |
-
- - Windows Defender client is up and running in a healthy state. -
|
-|||||||||||
- |
- Note This event will only be logged if the following policy is set: ThreatFileHashLogging unsigned.
- |
-|||||||||||
Event ID: 1150 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_SERVICE_HEALTHY - |
-||||||||||
- Message: - |
-
- If your antimalware platform reports status to a monitoring platform, this event indicates that the antimalware platform is running and in a healthy state. - - |
-|||||||||||
- Description: - |
-
- - Windows Defender client is up and running in a healthy state. -
|
-|||||||||||
- User action: - |
-
- No action is necessary. The Windows Defenderclient is in a healthy state. This event is reported on an hourly basis. - |
-|||||||||||
Event ID: 2000 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_SIGNATURE_UPDATED - - |
-||||||||||
- Message: - |
-
- The antimalware definitions updated successfully. - - |
-|||||||||||
- Description: - |
-
- - Windows Defender signature version has been updated. -
|
-|||||||||||
- User action: - |
-
- No action is necessary. The Windows Defender client is in a healthy state. This event is reported when signatures are successfully updated. - |
-|||||||||||
Event ID: 2001 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_SIGNATURE_UPDATE_FAILED - |
-||||||||||
- Message: - |
-
- The antimalware definition update failed. - - |
-|||||||||||
- Description: - |
-
- - Windows Defender has encountered an error trying to update signatures. -
|
-|||||||||||
- User action: - |
-
- This error occurs when there is a problem updating definitions. -To troubleshoot this event: -
|
-|||||||||||
Event ID: 2002 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_ENGINE_UPDATED - |
-||||||||||
- Message: - |
-
- The antimalware engine updated successfully. - - |
-|||||||||||
- Description: - |
-
- - Windows Defender engine version has been updated. -
|
-|||||||||||
- User action: - |
-
- No action is necessary. The Windows Defender client is in a healthy state. This event is reported when the antimalware engine is successfully updated. - |
-|||||||||||
Event ID: 2003 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_ENGINE_UPDATE_FAILED - |
-||||||||||
- Message: - |
-
- The antimalware engine update failed. - - |
-|||||||||||
- Description: - |
-
- - Windows Defender has encountered an error trying to update the engine. -
|
-|||||||||||
- User action: - |
-
- The Windows Defender client update failed. This event occurs when the client fails to update itself. This event is usually due to an interruption in network connectivity during an update. -To troubleshoot this event: -
|
-|||||||||||
Event ID: 2004 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_SIGNATURE_REVERSION - |
-||||||||||
- Message: - |
-
- There was a problem loading antimalware definitions. The antimalware engine will attempt to load the last-known good set of definitions. - |
-|||||||||||
- Description: - |
-
- - Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures. -
|
-|||||||||||
- User action: - |
-
- The Windows Defender client attempted to download and install the latest definitions file and failed. This error can occur when the client encounters an error while trying to load the definitions, or if the file is corrupt. Windows Defender will attempt to revert back to a known-good set of definitions. -To troubleshoot this event: -
|
-|||||||||||
Event ID: 2005 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_ENGINE_UPDATE_PLATFORMOUTOFDATE - |
-||||||||||
- Message: - |
-
- The antimalware engine failed to load because the antimalware platform is out of date. The antimalware platform will load the last-known good antimalware engine and attempt to update. - |
-|||||||||||
- Description: - |
-
- - Windows Defender could not load antimalware engine because current platform version is not supported. Windows Defender will revert back to the last known-good engine and a platform update will be attempted. -
|
-|||||||||||
Event ID: 2006 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_PLATFORM_UPDATE_FAILED - - |
-||||||||||
- Message: - |
-
- The platform update failed. - - |
-|||||||||||
- Description: - |
-
- - Windows Defender has encountered an error trying to update the platform. -
|
-|||||||||||
Event ID: 2007 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_PLATFORM_ALMOSTOUTOFDATE - |
-||||||||||
- Message: - |
-
- The platform will soon be out of date. Download the latest platform to maintain up-to-date protection. - |
-|||||||||||
- Description: - |
-
- - Windows Defender will soon require a newer platform version to support future versions of the antimalware engine. Download the latest Windows Defender platform to maintain the best level of protection available. -
|
-|||||||||||
Event ID: 2010 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_SIGNATURE_FASTPATH_UPDATED - - |
-||||||||||
- Message: - |
-
- The antimalware engine used the Dynamic Signature Service to get additional definitions. - - |
-|||||||||||
- Description: - |
-
- - Windows Defender used Dynamic Signature Service to retrieve additional signatures to help protect your machine. -
|
-|||||||||||
Event ID: 2011 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_SIGNATURE_FASTPATH_DELETED - - |
-||||||||||
- Message: - |
-
- The Dynamic Signature Service deleted the out-of-date dynamic definitions. - - |
-|||||||||||
- Description: - |
-
- - Windows Defender used Dynamic Signature Service to discard obsolete signatures. -
|
-|||||||||||
- User action: - |
-
- No action is necessary. The Windows Defender client is in a healthy state. This event is reported when the Dynamic Signature Service successfully deletes out-of-date dynamic definitions. - |
-|||||||||||
Event ID: 2012 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_SIGNATURE_FASTPATH_UPDATE_FAILED - - |
-||||||||||
- Message: - |
-
- The antimalware engine encountered an error when trying to use the Dynamic Signature Service. - - |
-|||||||||||
- Description: - |
-
- - Windows Defender has encountered an error trying to use Dynamic Signature Service. -
|
-|||||||||||
- User action: - |
-
- Check your Internet connectivity settings. - |
-|||||||||||
Event ID: 2013 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_SIGNATURE_FASTPATH_DELETED_ALL - - |
-||||||||||
- Message: - |
-
- The Dynamic Signature Service deleted all dynamic definitions. - - |
-|||||||||||
- Description: - |
-
- - Windows Defender discarded all Dynamic Signature Service signatures. -
|
-|||||||||||
Event ID: 2020 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_CLOUD_CLEAN_RESTORE_FILE_DOWNLOADED - - |
-||||||||||
- Message: - |
-
- The antimalware engine downloaded a clean file. - - |
-|||||||||||
- Description: - |
-
- - Windows Defender downloaded a clean file. -
|
-|||||||||||
Event ID: 2021 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_CLOUD_CLEAN_RESTORE_FILE_DOWNLOAD_FAILED - |
-||||||||||
- Message: - |
-
- The antimalware engine failed to download a clean file. - - |
-|||||||||||
- Description: - |
-
- - Windows Defender has encountered an error trying to download a clean file. -
|
-|||||||||||
- User action: - |
-
- Check your Internet connectivity settings. - -The Windows Defender client encountered an error when using the Dynamic Signature Service to download the latest definitions to a specific threat. This error is likely caused by a network connectivity issue. - - |
-|||||||||||
Event ID: 2030 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_OFFLINE_SCAN_INSTALLED - |
-||||||||||
- Message: - |
-
- The antimalware engine was downloaded and is configured to run offline on the next system restart. - |
-|||||||||||
- Description: - |
-
- Windows Defender downloaded and configured Windows Defender Offline to run on the next reboot. - |
-|||||||||||
Event ID: 2031 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_OFFLINE_SCAN_INSTALL_FAILED - - |
-||||||||||
- Message: - |
-
- The antimalware engine was unable to download and configure an offline scan. - |
-|||||||||||
- Description: - |
-
- - Windows Defender has encountered an error trying to download and configure Windows Defender Offline. -
|
-|||||||||||
Event ID: 2040 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_OS_EXPIRING - - |
-||||||||||
- Message: - |
-
- Antimalware support for this operating system version will soon end. - - |
-|||||||||||
- Description: - |
-
- The support for your operating system will expire shortly. Running Windows Defender on an out of support operating system is not an adequate solution to protect against threats. - |
-|||||||||||
Event ID: 2041 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_OS_EOL - - |
-||||||||||
- Message: - |
-
- Antimalware support for this operating system has ended. You must upgrade the operating system for continued support. - - |
-|||||||||||
- Description: - |
-
- The support for your operating system has expired. Running Windows Defender on an out of support operating system is not an adequate solution to protect against threats. - |
-|||||||||||
Event ID: 2042 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_PROTECTION_EOL - - |
-||||||||||
- Message: - |
-
- The antimalware engine no longer supports this operating system, and is no longer protecting your system from malware. - - |
-|||||||||||
- Description: - |
-
- The support for your operating system has expired. Windows Defender is no longer supported on your operating system, has stopped functioning, and is not protecting against malware threats. - |
-|||||||||||
Event ID: 2050 | Symbolic name: | MALWAREPROTECTION_SAMPLESUBMISSION_UPLOAD | ||||||||||
Message: | The antimalware engine has uploaded a file for further analysis. | |||||||||||
Description: | A file was uploaded to the Windows Defender Antimalware cloud for further analysis or processing. | |||||||||||
Event ID: 2051 | Symbolic name: | MALWAREPROTECTION_SAMPLESUBMISSION_UPLOADED_FAILED | ||||||||||
Message: | The antimalware engine has encountered an error trying to upload a suspicious file for further analysis. | |||||||||||
Description: | A file could not be uploaded to the Windows Defender Antimalware cloud. | |||||||||||
User action: | You can attempt to manually submit the file. | |||||||||||
Event ID: 3002 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_RTP_FEATURE_FAILURE - - |
-||||||||||
- Message: - |
-
- Real-time protection encountered an error and failed. - |
-|||||||||||
- Description: - |
-
- - Windows Defender Real-Time Protection feature has encountered an error and failed. -
|
-|||||||||||
- User action: - |
-
- You should restart the system then run a full scan because it’s possible the system was not protected for some time. - -The Windows Defender client’s real-time protection feature encountered an error because one of the services failed to start. - -If it is followed by a 3007 event ID, the failure was temporary and the antimalware client recovered from the failure. - - |
-|||||||||||
Event ID: 3007 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_RTP_FEATURE_RECOVERED - |
-||||||||||
- Message: - |
-
- Real-time protection recovered from a failure. We recommend running a full system scan when you see this error. - - |
-|||||||||||
- Description: - |
-
- - Windows Defender Real-time Protection has restarted a feature. It is recommended that you run a full system scan to detect any items that may have been missed while this agent was down. -
|
-|||||||||||
- User action: - |
-
- The real-time protection feature has restarted. If this event happens again, contact Microsoft Technical Support. - |
-|||||||||||
Event ID: 5000 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_RTP_ENABLED - - |
-||||||||||
- Message: - |
-
- Real-time protection is enabled. - - |
-|||||||||||
- Description: - |
-
- Windows Defender Real-time Protection scanning for malware and other potentially unwanted software was enabled. - |
-|||||||||||
Event ID: 5001 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_RTP_DISABLED - |
-||||||||||
- Message: - |
-
- Real-time protection is disabled. - - |
-|||||||||||
- Description: - |
-
- Windows Defender Real-time Protection scanning for malware and other potentially unwanted software was disabled. - |
-|||||||||||
Event ID: 5004 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_RTP_FEATURE_CONFIGURED - - |
-||||||||||
- Message: - |
-
- The real-time protection configuration changed. - - |
-|||||||||||
- Description: - |
-
- - Windows Defender Real-time Protection feature configuration has changed. -
|
-|||||||||||
Event ID: 5007 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_CONFIG_CHANGED - - |
-||||||||||
- Message: - |
-
- The antimalware platform configuration changed. - |
-|||||||||||
- Description: - |
-
- - Windows Defender Configuration has changed. If this is an unexpected event you should review the settings as this may be the result of malware. -
|
-|||||||||||
Event ID: 5008 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_ENGINE_FAILURE - |
-||||||||||
- Message: - |
-
- The antimalware engine encountered an error and failed. - |
-|||||||||||
- Description: - |
-
- - Windows Defender engine has been terminated due to an unexpected error. -
|
-|||||||||||
- User action: - |
-
- To troubleshoot this event:
|
-|||||||||||
- User action: - |
-
- The Windows Defender client engine stopped due to an unexpected error. -To troubleshoot this event: -
|
-|||||||||||
Event ID: 5009 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_ANTISPYWARE_ENABLED - - |
-||||||||||
- Message: - |
-
- Scanning for malware and other potentially unwanted software is enabled. - - |
-|||||||||||
- Description: - |
-
- Windows Defender scanning for malware and other potentially unwanted software has been enabled. - |
-|||||||||||
Event ID: 5010 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_ANTISPYWARE_DISABLED - - |
-||||||||||
- Message: - |
-
- Scanning for malware and other potentially unwanted software is disabled. - |
-|||||||||||
- Description: - |
-
- Windows Defender scanning for malware and other potentially unwanted software is disabled. - |
-|||||||||||
Event ID: 5011 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_ANTIVIRUS_ENABLED - |
-||||||||||
- Message: - |
-
- Scanning for viruses is enabled. - |
-|||||||||||
- Description: - |
-
- Windows Defender scanning for viruses has been enabled. - |
-|||||||||||
Event ID: 5012 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_ANTIVIRUS_DISABLED - - |
-||||||||||
- Message: - |
-
- Scanning for viruses is disabled. - - |
-|||||||||||
- Description: - |
-
- Windows Defender scanning for viruses is disabled. - |
-|||||||||||
Event ID: 5100 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_EXPIRATION_WARNING_STATE - - |
-||||||||||
- Message: - |
-
- The antimalware platform will expire soon. - - |
-|||||||||||
- Description: - |
-
- - Windows Defender has entered a grace period and will soon expire. After expiration, this program will disable protection against viruses, spyware, and other potentially unwanted software. -
|
-|||||||||||
Event ID: 5101 | -
- Symbolic name: - |
-
- MALWAREPROTECTION_DISABLED_EXPIRED_STATE - - |
-||||||||||
- Message: - |
-
- The antimalware platform is expired. - - |
-|||||||||||
- Description:: - |
-
- - Windows Defender grace period has expired. Protection against viruses, spyware, and other potentially unwanted software is disabled. -
|
-
External error codes | -|||
---|---|---|---|
Error code | -Message displayed | -Possible reason for error | -What to do now | -
- 0x80508007 - - |
-
- ERR_MP_NO_MEMORY - - |
-
- This error indicates that you might have run out of memory. - - |
-
- -
|
-
- 0x8050800C - |
-
- ERR_MP_BAD_INPUT_DATA - |
-
- This error indicates that there might be a problem with your security product. - |
-
- -
|
-
- 0x80508020 - |
-
- ERR_MP_BAD_CONFIGURATION - - |
-
- This error indicates that there might be an engine configuration error; commonly, this is related to input -data that does not allow the engine to function properly. - - |
-|
- 0x805080211 - - |
-
- ERR_MP_QUARANTINE_FAILED - - |
-
- This error indicates that Windows Defender failed to quarantine a threat. - - |
-|
- 0x80508022 - - |
-
- ERR_MP_REBOOT_REQUIRED - - |
-
- This error indicates that a reboot is required to complete threat removal. - - |
-|
- 0x80508023 - - |
-
- ERR_MP_THREAT_NOT_FOUND - - |
-
- This error indicates that the threat might no longer be present on the media, or malware might be stopping you from scanning your device. - - |
-
- Run the Microsoft Safety Scanner then update your security software and try again. - - |
-
- ERR_MP_FULL_SCAN_REQUIRED - - |
-
- This error indicates that a full system scan might be required. - - |
-
- Run a full system scan. - - |
-|
- 0x80508024 - - |
-|||
- 0x80508025 - - |
-
- ERR_MP_MANUAL_STEPS_REQUIRED - - |
-
- This error indicates that manual steps are required to complete threat removal. - - |
-
- Follow the manual remediation steps outlined in the Microsoft Malware Protection Encyclopedia. You can find a threat-specific link in the event history. - - |
-
- 0x80508026 - - |
-
- ERR_MP_REMOVE_NOT_SUPPORTED - - |
-
- This error indicates that removal inside the container type might not be not supported. - - |
-
- Windows Defender is not able to remediate threats detected inside the archive. Consider manually removing the detected resources. - - |
-
- 0x80508027 - - |
-
- ERR_MP_REMOVE_LOW_MEDIUM_DISABLED - - |
-
- This error indicates that removal of low and medium threats might be disabled. - - |
-
- Check the detected threats and resolve them as required. - - |
-
- 0x80508029 - - |
-
- ERROR_MP_RESCAN_REQUIRED - - |
-
- This error indicates a rescan of the threat is required. - - |
-
- Run a full system scan. - - |
-
- 0x80508030 - - |
-
- ERROR_MP_CALLISTO_REQUIRED - - |
-
- This error indicates that an offline scan is required. - - |
-
- Run Windows Defender Offline. You can read about how to do this in the Windows Defender Offline -article. - |
-
- 0x80508031 - - |
-
- ERROR_MP_PLATFORM_OUTDATED - - |
-
- This error indicates that Windows Defender does not support the current version of the platform and requires a new version of the platform. - - |
-
- You can only use Windows Defender in Windows 10. For Windows 8, Windows 7 and Windows Vista, you can use System Center Endpoint Protection. - - |
-
-
Internal error codes | -|||
---|---|---|---|
Error code | -Message displayed | -Possible reason for error | -What to do now | -
- 0x80501004 - |
-
- ERROR_MP_NO_INTERNET_CONN - - |
-
- Check your Internet connection, then run the scan again. - |
-
- Check your Internet connection, then run the scan again. - |
-
- 0x80501000 - |
-
- ERROR_MP_UI_CONSOLIDATION_BASE - |
-
- This is an internal error. The cause is not clearly defined. - |
-
- -
|
-
- 0x80501001 - |
-
- ERROR_MP_ACTIONS_FAILED - |
-||
- 0x80501002 - |
-
- ERROR_MP_NOENGINE - |
-||
- 0x80501003 - |
-
- ERROR_MP_ACTIVE_THREATS - |
-||
- 0x805011011 - |
-
- MP_ERROR_CODE_LUA_CANCELLED - |
-||
- 0x80501101 - |
-
- ERROR_LUA_CANCELLATION - |
-||
- 0x80501102 - |
-
- MP_ERROR_CODE_ALREADY_SHUTDOWN - |
-||
- 0x80501103 - |
-
- MP_ERROR_CODE_RDEVICE_S_ASYNC_CALL_PENDING - |
-||
- 0x80501104 - |
-
- MP_ERROR_CODE_CANCELLED - |
-||
- 0x80501105 - |
-
- MP_ERROR_CODE_NO_TARGETOS - |
-||
- 0x80501106 - |
-
- MP_ERROR_CODE_BAD_REGEXP - |
-||
- 0x80501107 - |
-
- MP_ERROR_TEST_INDUCED_ERROR - |
-||
- 0x80501108 - |
-
- MP_ERROR_SIG_BACKUP_DISABLED - |
-||
- 0x80508001 - |
-
- ERR_MP_BAD_INIT_MODULES - |
-||
- 0x80508002 - |
-
- ERR_MP_BAD_DATABASE - |
-||
- 0x80508004 - |
-
- ERR_MP_BAD_UFS - |
-||
- 0x8050800C - |
-
- ERR_MP_BAD_INPUT_DATA - |
-||
- 0x8050800D - |
-
- ERR_MP_BAD_GLOBAL_STORAGE - |
-||
- 0x8050800E - |
-
- ERR_MP_OBSOLETE - |
-||
- 0x8050800F - |
-
- ERR_MP_NOT_SUPPORTED - |
-||
- 0x8050800F -0x80508010 - - |
-
- ERR_MP_NO_MORE_ITEMS - |
-||
- 0x80508011 - |
-
- ERR_MP_DUPLICATE_SCANID - |
-||
- 0x80508012 - |
-
- ERR_MP_BAD_SCANID - |
-||
- 0x80508013 - |
-
- ERR_MP_BAD_USERDB_VERSION - |
-||
- 0x80508014 - |
-
- ERR_MP_RESTORE_FAILED - |
-||
- 0x80508016 - |
-
- ERR_MP_BAD_ACTION - |
-||
- 0x80508019 - |
-
- ERR_MP_NOT_FOUND - |
-||
- 0x80509001 - |
-
- ERR_RELO_BAD_EHANDLE - |
-||
- 0x80509003 - |
-
- ERR_RELO_KERNEL_NOT_LOADED - |
-||
- 0x8050A001 - |
-
- ERR_MP_BADDB_OPEN - |
-||
- 0x8050A002 - |
-
- ERR_MP_BADDB_HEADER - |
-||
- 0x8050A003 - |
-
- ERR_MP_BADDB_OLDENGINE - |
-||
- 0x8050A004 - |
-
- ERR_MP_BADDB_CONTENT - |
-||
- 0x8050A005 - |
-
- ERR_MP_BADDB_NOTSIGNED - |
-||
- 0x8050801 - |
-
- ERR_MP_REMOVE_FAILED - |
-
- This is an internal error. It might be triggered when malware removal is not successful. - - |
-|
- 0x80508018 - - |
-
- ERR_MP_SCAN_ABORTED - - |
-
- This is an internal error. It might have triggered when a scan fails to complete. - - |
-
Drivers
No driver-specific controls
Drivers can be selectively excluded from Windows Update for Business.