Ask a read-only question first
Get-MpComputerStatus reports the local Defender Antivirus state. It does not provide a complete verdict about every security product on the computer. Use it alongside Windows Security, especially if a third-party antivirus is installed.
Open Windows PowerShell. An elevated window may be needed for some related operations, but the following status query does not deliberately alter protection.
Get-MpComputerStatus | Select-Object AMRunningMode,
AntivirusEnabled, RealTimeProtectionEnabled,
BehaviorMonitorEnabled, AntivirusSignatureLastUpdated,
QuickScanEndTime, FullScanEndTimeRead the fields in context
AMRunningMode helps distinguish normal operation from other modes. AntivirusEnabled and RealTimeProtectionEnabled describe Defender's own protection. Signature time indicates when the detection data was updated, not when Windows itself was patched. Scan completion times can help establish whether a requested scan finished.
Do not immediately force Defender on because one field is false. Another antivirus product, organisational policy or an unavailable component can explain the result. Check Windows Security's provider information and the vendor's management status.
Investigate a stale signature
- Confirm the computer has internet access through its normal update route.
- Check whether organisational update policies apply.
- If Defender is the intended active provider, use its supported signature update command in an elevated PowerShell window.
Update-MpSignature
Get-MpComputerStatus | Select-Object AntivirusSignatureLastUpdated,
AntivirusSignatureVersion, RealTimeProtectionEnabledVerify your conclusion
Record the before-and-after signature time and expected operating mode. If the timestamp remains stale, keep the actual error message and investigate the update source. On a managed device, escalate to the administrator instead of disabling policy or tamper protection.
Common errors
If the command is not recognised, confirm the operating system and shell rather than downloading a random module with a similar name. Access-denied messages can indicate privilege or policy restrictions. An old FullScanEndTime alone does not mean real-time protection is off.
Limits of the check
Healthy status does not prove there is no compromise. Conversely, Defender being inactive does not by itself prove the machine is unprotected. Identify the intended provider and its own health. This procedure uses built-in local capabilities and does not require Defender for Business or an Endpoint portal subscription.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.