Microsoft Defender problems often get described as a broken antivirus service. The real issue may be an intelligence-update failure, an outdated command path, passive mode alongside another security product, or a managed policy. Start by recording the protection state and exact error before attempting a reset.
Inspect Defender state and recent events
Get-MpComputerStatus | Select-Object AMServiceEnabled, AMRunningMode,
AntivirusEnabled, RealTimeProtectionEnabled,
AntivirusSignatureVersion, AntivirusSignatureLastUpdated
Get-WinEvent -FilterHashtable @{
LogName = "Microsoft-Windows-Windows Defender/Operational"
StartTime = (Get-Date).AddHours(-4)
} | Select-Object -First 30 TimeCreated, Id, MessageUse an elevated PowerShell terminal for repair operations. Compare the reported mode with the installed security products and management configuration. Passive mode can be intentional. Tamper protection and centrally managed settings are reasons to use the approved management path, rather than editing registry values to force a result.
Find the current command-line executable
Defender platform updates can place MpCmdRun.exe under a versioned Platform directory. Using a hard-coded old path can run an older binary. Select by the executable’s version rather than alphabetically sorting folder names:
$PlatformRoot = Join-Path $env:ProgramData "Microsoft\Windows Defender\Platform"
$Candidates = Get-ChildItem -Path $PlatformRoot -Filter MpCmdRun.exe `
-Recurse -ErrorAction SilentlyContinue |
Sort-Object { [version]$_.VersionInfo.FileVersion } -Descending
$MpCmdRun = $Candidates | Select-Object -First 1 -ExpandProperty FullName
if (-not $MpCmdRun) {
$MpCmdRun = Join-Path $env:ProgramFiles "Windows Defender\MpCmdRun.exe"
}
if (-not (Test-Path -LiteralPath $MpCmdRun)) {
throw "MpCmdRun.exe was not found; inspect the Defender installation."
}
& $MpCmdRun -?Read the installed tool’s help and capture the executable version with the incident notes. Available switches vary across platform versions; a command from an old article may not describe the binary on this system.
Try an ordinary intelligence update first
Update-MpSignature
Get-MpComputerStatus | Select-Object AntivirusSignatureVersion,
AntivirusSignatureLastUpdatedIf the update fails, save the error and inspect time synchronization, proxy configuration, update-source policy, and access to the organization’s permitted update service. A proxy or policy error will survive a definition reset.
The command-line alternative provides a process exit code that can be recorded alongside the Defender event:
& $MpCmdRun -SignatureUpdate
$UpdateExitCode = $LASTEXITCODE
$UpdateExitCodeReset definitions only for a diagnosed corruption case
Definition removal changes protection data. Use this only when the update source is reachable and you have a recovery plan; it is not the first response to a disabled service or passive mode.
& $MpCmdRun -RemoveDefinitions -All
if ($LASTEXITCODE -ne 0) {
throw "Definition removal failed; inspect the error before continuing."
}
& $MpCmdRun -SignatureUpdate
if ($LASTEXITCODE -ne 0) {
throw "Definition update failed; protection data needs attention."
}Recheck the signature version and timestamp immediately. If the update still fails, preserve the evidence and use the supported endpoint-management or repair process. Avoid repeatedly removing definitions when no working update path exists.
Verify scans and repair Windows only when warranted
Start-MpScan -ScanType QuickScan
Get-MpComputerStatus | Select-Object QuickScanStartTime, QuickScanEndTimeConfirm completion in status and the Operational log rather than assuming that issuing the command completed a scan. If Windows component corruption is supported by the evidence, use the standard system repair sequence and review its result:
DISM.exe /Online /Cleanup-Image /RestoreHealth
sfc.exe /scannowThese commands can take time and may need an approved repair source. Afterward, repeat the update and scan tests. The repair is complete when the intended protection mode, current intelligence, and a completed scan are all confirmed—not merely when a service starts.
References
- Microsoft: Defender command-line arguments
- Microsoft: Get-MpComputerStatus
- Microsoft: Windows system-file repair