The documentation now explains that Yes disables and No enables catch-up scans because the settings are named “Disable catch-up...”. Full-scan catch-up is disabled when not configured, while quick-scan catch-up is enabled by default; the scan triggers after two missed scheduled scans are also specified.
Defender catch-up scan guidance distinguishes disabled defaults and two-miss triggers
Two device-security updates clarify Defender Antivirus catch-up scans for Intune and Configuration Manager tenant-attached devices. The guidance explains the inverse Yes/No semantics of settings named “Disable catch-up...”, documents different full- and quick-scan defaults, and specifies when catch-up scans run.
- Intune guidance clarifies inverse catch-up scan setting values
Intune · Device security
For settings named “Disable catch-up...”, Yes disables catch-up scans and No enables them. Full-scan catch-up is disabled when not configured, while quick-scan catch-up is enabled by default; catch-up runs after two missed scheduled scans.
- Tenant-attached Configuration Manager guidance changes the documented full-scan default
Configuration Manager · Device security
The documented default for catch-up full scans is now disabled, while catch-up quick scans remain enabled by default. Catch-up scans require a configured scheduled scan and occur after two consecutive missed scheduled scans.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
2 updates
Microsoft Intune
1 updateMicrosoft Configuration Manager
1 updateWindows Antivirus policy settings from Microsoft Defender Antivirus for tenant attached devices
Feature updateThe documented default for catch-up full scans changed to disabled, while catch-up quick scans remain enabled by default. The settings now specify that catch-up scans occur after two consecutive missed scheduled scans and require a configured scheduled scan.