Jump to content

I'm still new to servers but should windows defender have to be updated everyday? It seems like everyday I login to pulseway it says the definitions need to be updated, I'm worrying that defender isn't protecting my server. Could this be a bug with pulseway? Is there a way to force windows server 2016 to auto update defender?

Link to comment
Share on other sites

Link to post
Share on other sites

I don't think its everyday, but there are pretty often updates, you need it to be updated to find the latest threats.

 

You can force updates with GP

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

You don't need to update it everyday, though really, the more frequently you can update, the better. 

 

Patching is often done monthly or quarterly. At work, we tend to have a quarterly patch session for customers unless there is an update that fixes or protects again a major bug that was just found. 

 

You can force/automate updates through a GPO, but getting it to only update Windows defender automatically can't be done through GPO alone as far as I know. You can use WSUS for managing updates and set it to auto approve Windows Defender definitions and then schedule them through GPO. If you're wanting to get more familiar with Windows Server, then that may be a good thing to set up.

Link to comment
Share on other sites

Link to post
Share on other sites

Daily updates are normal. It’s just the antivirus product updating its database of new viruses that get discovered.

Link to comment
Share on other sites

Link to post
Share on other sites

Thanks, I was worrying that server wasn't updating at all do to some error either on my phone or in windows.

I don't like.the make sure it's always up to date since it's just me that does the up.keep in my stomach are time and the auto I will definitely try out that auto update.

Link to comment
Share on other sites

Link to post
Share on other sites

It's not defender you're updating, its the virus definitions. And it should be updated at least every few days. 

In enterprise environments we push them out via CCM/WSUS, or if you have McAfee Trend then its via ePO or OfficeScan XG

 

Im on Server 2019 (i think 2016 is the same) so my definitions update automatically even though my Windows Update is set to manual. 

If that's not happening (i dont think that happens on 2012 or earlier), you could schedule a daily task under the Task Scheduler.

Run "C:\Program Files\Windows Defender\MpCmdRun.exe" with the Argument -SignatureUpdate and schedule it to check once a day.

 

Windows Security updates, I just do once a month on my Patching Day (when I do all my Windows & Linux server reboots)

Spoiler

Desktop: Ryzen9 5950X | ASUS ROG Crosshair VIII Hero (Wifi) | EVGA RTX 3080Ti FTW3 | 32GB (2x16GB) Corsair Dominator Platinum RGB Pro 3600Mhz | EKWB EK-AIO 360D-RGB | EKWB EK-Vardar RGB Fans | 1TB Samsung 980 Pro, 4TB Samsung 980 Pro | Corsair 5000D Airflow | Corsair HX850 Platinum PSU | Asus ROG 42" OLED PG42UQ + LG 32" 32GK850G Monitor | Roccat Vulcan TKL Pro Keyboard | Logitech G Pro X Superlight  | MicroLab Solo 7C Speakers | Audio-Technica ATH-M50xBT2 LE Headphones | TC-Helicon GoXLR | Audio-Technica AT2035 | LTT Desk Mat | XBOX-X Controller | Windows 11 Pro

 

Spoiler

Server: Fractal Design Define R6 | Ryzen 3950x | ASRock X570 Taichi | EVGA GTX1070 FTW | 64GB (4x16GB) Corsair Vengeance LPX 3000Mhz | Corsair RM850v2 PSU | Fractal S36 Triple AIO + 4 Additional Venturi 120mm Fans | 14 x 20TB Seagate Exos X22 20TB | 500GB Aorus Gen4 NVMe | 2 x 2TB Samsung 970 Evo Plus NVMe | LSI 9211-8i HBA

 

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×