Update Windows Defender and perform a scan

By default the Windows Update service is deactivated on Beckhoff standard systems with Windows 10. This is the only way to ensure that updates are not automatically installed and can thus negatively affect the controller.

So that the Windows Defender definition files can be updated as shown here, the Windows Update service must be temporarily activated. As the update process itself runs differently depending on the update, it may be useful to set TwinCAT to CONFIG mode.

1. Open Windows Run with the shortcut [Windows + R] and enter "services.msc". Confirm the dialog with OK.
Update Windows Defender and perform a scan 1:
The Services dialog opens.
2. Double-click on the Windows Update service to open the associated settings.
Update Windows Defender and perform a scan 2:
3. Set the Windows Update service to Automatic and confirm the dialog with OK.
Update Windows Defender and perform a scan 3:
4. Open the Update tab in Windows Defender.
Update Windows Defender and perform a scan 4:
5. Update the Windows Defender definition files using the Update definitions button.
Update Windows Defender and perform a scan 5:
Windows Defender is updated.
Update Windows Defender and perform a scan 6:
6. To deactivate the Windows Update service, double-click again on the Windows Update service to open the settings.
Update Windows Defender and perform a scan 7:
7. Set the Windows Update service to Disabled and confirm the dialog with OK.
Update Windows Defender and perform a scan 8:
8. Start the Windows Defender scan procedure with the Scan now button.
Update Windows Defender and perform a scan 9:
The computer is scanned.
Update Windows Defender and perform a scan 10:
Update Windows Defender and perform a scan 11:

Windows Defender with automated updates

If you decide, contrary to the recommendation given at the beginning, to use Windows Defender with automatic updates, familiarize yourself with the configuration in the MSDN.

This includes in particular the following properties:

  • Time / frequency of the procurement of updates
  • Time / frequency of the system scan
  • The version of the definition files that was acquired.
  • The last point in particular is relevant for the avoidance of negative effects on the operation of controllers. Because several new versions are sometimes published on the same day, there is no checking of where which version is in use in the case of direct acquisition. For controllers it is advantageous to check a certain version of the definition files first and then to install them in production. Microsoft describes different ways to do this: https://docs.microsoft.com/.... They allow the definition files to be downloaded first, tried out on a system and then distributed efficiently.