Windows Defender Definition Update Failed

Summary :

Many users have complained of Windows Defender not updating on Windows 10 regardless of whether the update being downloaded and installed is a small definitions update or a large, chunky update. Read this post from MiniTool to get the methods.

Trigger a definition update for Windows Defender Antivirus. Open the Settings app. Go to Update & security - Windows Update. On the right, click Check for updates. Windows 10 will download and install definitions for Defender (if available).

Sometimes, your Windows Defender update failed and Windows Defender stated that the reason behind the failures was “connectivity problems”, even though the computer has a completely healthy internet connection.

Luckily, there are some solutions to this issue, and you can follow the three most effective solutions to get rid of this issue.

Troubled by Windows Defender not turning on? Here are full solutions to repair Windows Defender in Windows 10/8/7 and the best way for PC protection.

How to Fix That Windows Defender Update Failed?

Solution 1: Update Windows Defender Using Windows Update

If you have encountered the “Windows Defender won’t update” issue because of “connectivity problems”, the most logical solution for the issue would certainly be trying to use Windows Update to update Windows Defender. You can follow the steps below:

Step 1: Open the Search menu to input Settings and search for it, then open it.

Step 2: Click the Update & Security tab in the Settings interface.

Step 3: Then you should click Windows Update in the left pane.

Step 4: Click Check for updates in the right pane. Your computer will now check for any and all available updates.

The available updates for Windows Defender will automatically start being downloaded as soon as they are detected. Once the updates are downloaded, they will be installed successfully. Then you can check if the “Windows Defender update failed” issue still exists.

Why my Windows 10 won’t update? Why Windows 10 update failed? Here we list 7 ways to fix Win 10 update error and force Windows 10 Update normally.

Solution 2: Update Windows Defender Using Command Prompt

The second solution is to try updating Windows Defender using an elevated Command Prompt. Here is the tutorial. Star wars empire at war absolute corruption mod.

Step 1: Input command prompt in the Search menu and click Command Prompt.

Step 2: Then click Run as administrator to open an elevated Command Prompt.

Step 3: Type the following command into the Command Prompt and press the Enter key.

cd /d “Program FilesWindows Defender”

Step 4: Then type exe -signatureupdate into the Command Prompt and press the Enter key.

This will initiate a Windows Defender update and you can see if the Windows Defender won’t update again. If yes, you can try the next solution.

Solution 3: Set Windows Defender Service as Automatic

This solution is to set Windows Defender Service as automatic. Here is how to do this.

Step 1: Right-click the Start menu and select Run.

Lagu Kenangan Nostalgia 80an 90an Terbaik Sepanjang Masa Jadi ingat Masa Lalu kumpulan lagu lagu lawas, lagu kenangan, lagu nostalgia, lagu SMP SMA tahun 80an 90an yang tak pernah lekang oleh. The Best of Tommy J Pisa Full Album Audio Jernih, Kumpulan lagu lagu kenangan nostalgia terbaik sepanjang masa Tommy J Pisa tembang kenangan terpopuler tahun 80-90an. Lagu kenangan terbaik, lagu. 50+ videos Play all Mix - Tembang Kenangan Kompilasi Nostalgia 80 90an Lagu Kenangan Indonesia YouTube KOMPILASI LAGU KENANGAN; JADUL NOSTALGIA; TAPI DISUKAI KAUM MILLENIAL SEKARANG - Duration: 1. 80an

Step 2: Type services.msc in the Run box and click OK to open Services.

Step 3: Find Windows Defender Antivirus Service and right-click it, then you should click Properties.

Step 4: You should make sure that Service status is Running.

Step 5: Then ensure Startup type is Automatic (if not, select Startup type as Automatic and click Start)

Step 6: Click Apply, then click OK.

Now, you can check if the Windows Defender not updating on Windows 10 issue is still existing.

Final Words

I think the issue must be fixed by the solutions above. If you encounter such an issue, you just need to try the solutions one by one. Then you can find the appropriate one.

-->

Applies to:

Keeping your antivirus protection up to date is critical. There are two components to managing protection updates for Windows Defender Antivirus:

  • Where the updates are downloaded from; and
  • When updates are downloaded and applied.

This article describes how to specify from where updates should be downloaded (this is also known as the fallback order). See Manage Windows Defender Antivirus updates and apply baselines topic for an overview on how updates work, and how to configure other aspects of updates (such as scheduling updates).

Important

Microsoft Defender Antivirus Security intelligence updates are delivered through Windows Update and starting Monday, October 21, 2019, all security intelligence updates will be SHA-2 signed exclusively. Your devices must be updated to support SHA-2 in order to update your security intelligence. To learn more, see 2019 SHA-2 Code Signing Support requirement for Windows and WSUS.

Fallback order

Typically, you configure endpoints to individually download updates from a primary source followed by other sources in order of priority, based on your network configuration. Updates are obtained from sources in the order you specify. If a source is not available, the next source in the list is used immediately.

When updates are published, some logic is applied to minimize the size of the update. In most cases, only the differences between the latest update and the update that is currently installed (this is referred to as the delta) on the device is downloaded and applied. However, the size of the delta depends on two main factors:

  • The age of the last update on the device; and
  • The source used to download and apply updates.

The older the updates on an endpoint, the larger the download will be. However, you must also consider download frequency as well. A more frequent update schedule can result in more network usage, whereas a less-frequent schedule can result in larger file sizes per download.

There are five locations where you can specify where an endpoint should obtain updates:

  • Security intelligence updates for Windows Defender Antivirus and other Microsoft antimalware (Your policy and registry might have this listed as Microsoft Malware Protection Center (MMPC) security intelligence, its former name.)

To ensure the best level of protection, Microsoft Update allows for rapid releases, which means smaller downloads on a frequent basis. The Windows Server Update Service, Microsoft Endpoint Configuration Manager, and Microsoft security intelligence updates sources deliver less frequent updates. Thus, the delta can be larger, resulting in larger downloads.

Important

If you have set Microsoft Malware Protection Center Security intelligence page (MMPC) updates as a fallback source after Windows Server Update Service or Microsoft Update, updates are only downloaded from security intelligence updates when the current update is considered out-of-date. (By default, this is 14 consecutive days of not being able to apply updates from the Windows Server Update Service or Microsoft Update services).You can, however, set the number of days before protection is reported as out-of-date.

Starting Monday, October 21, 2019, security intelligence updates will be SHA-2 signed exclusively. Devices must be updated to support SHA-2 in order to get the latest security intelligence updates. To learn more, see 2019 SHA-2 Code Signing Support requirement for Windows and WSUS.

Each source has typical scenarios that depend on how your network is configured, in addition to how often they publish updates, as described in the following table:

LocationSample scenario
Windows Server Update ServiceYou are using Windows Server Update Service to manage updates for your network.
Microsoft UpdateYou want your endpoints to connect directly to Microsoft Update. This can be useful for endpoints that irregularly connect to your enterprise network, or if you do not use Windows Server Update Service to manage your updates.
File shareYou have non-Internet-connected devices (such as VMs). You can use your Internet-connected VM host to download the updates to a network share, from which the VMs can obtain the updates. See the VDI deployment guide for how file shares can be used in virtual desktop infrastructure (VDI) environments.
Microsoft Endpoint Configuration ManagerYou are using Microsoft Endpoint Configuration Manager to update your endpoints.
Security intelligence updates for Windows Defender Antivirus and other Microsoft antimalware (formerly referred to as MMPC)Make sure your devices are updated to support SHA-2. Microsoft Defender Antivirus Security intelligence updates are delivered through Windows Update, and starting Monday October 21, 2019 security intelligence updates will be SHA-2 signed exclusively.
Download the latest protection updates because of a recent infection or to help provision a strong, base image for VDI deployment. This option should generally be used only as a final fallback source, and not the primary source. It will only be used if updates cannot be downloaded from Windows Server Update Service or Microsoft Update for a specified number of days.

You can manage the order in which update sources are used with Group Policy, Microsoft Endpoint Configuration Manager, PowerShell cmdlets, and WMI.

Important

If you set Windows Server Update Service as a download location, you must approve the updates, regardless of the management tool you use to specify the location. You can set up an automatic approval rule with Windows Server Update Service, which might be useful as updates arrive at least once a day. To learn more, see synchronize endpoint protection updates in standalone Windows Server Update Service.

The procedures in this article first describe how to set the order, and then how to set up the File share option if you have enabled it.

Use Group Policy to manage the update location

  1. On your Group Policy management machine, open the Group Policy Management Console, right-click the Group Policy Object you want to configure and click Edit.

  2. In the Group Policy Management Editor go to Computer configuration.

  3. Click Policies then Administrative templates.

  4. Expand the tree to Windows components > Windows Defender > Signature updates and configure the following settings:

    1. Double-click the Define the order of sources for downloading security intelligence updates setting and set the option to Enabled.

    2. Enter the order of sources, separated by a single pipe, for example: InternalDefinitionUpdateServer MicrosoftUpdateServer MMPC, as shown in the following screenshot.

    1. Click OK. This will set the order of protection update sources.

    2. Double-click the Define file shares for downloading security intelligence updates setting and set the option to Enabled.

    3. Enter the file share source. If you have multiple sources, enter each source in the order they should be used, separated by a single pipe. Use standard UNC notation for denoting the path, for example: host-name1share-nameobject-name host-name2share-nameobject-name. If you do not enter any paths, then this source will be skipped when the VM downloads updates.

    4. Click OK. This will set the order of file shares when that source is referenced in the Define the order of sources.. group policy setting.

Note

For Windows 10, versions 1703 up to and including 1809, the policy path is Windows Components > Windows Defender Antivirus > Signature UpdatesFor Windows 10, version 1903, the policy path is Windows Components > Windows Defender Antivirus > Security Intelligence Updates

Use Configuration Manager to manage the update location

See Configure Security intelligence Updates for Endpoint Protection for details on configuring Microsoft Endpoint Configuration Manager (current branch).

Use PowerShell cmdlets to manage the update location

Use the following PowerShell cmdlets to set the update order.

See the following articles for more information:

Use Windows Management Instruction (WMI) to manage the update location

Use the Set method of the MSFT_MpPreference class for the following properties:

See the following articles for more information:

Use Mobile Device Management (MDM) to manage the update location

See Policy CSP - Defender/SignatureUpdateFallbackOrder for details on configuring MDM.

What if we're using a third-party vendor?

This article describes how to configure and manage updates for Windows Defender Antivirus. However, third-party vendors can be used to perform these tasks.

For example, suppose that Contoso has hired Fabrikam to manage their security solution, which includes Windows Defender Antivirus. Fabrikam typically uses Windows Management Instrumentation, PowerShell cmdlets, or Windows command-line to deploy patches and updates.

Note

Microsoft does not test third-party solutions for managing Windows Defender Antivirus.

Related articles