Skip to content

Latest commit

 

History

History
74 lines (46 loc) · 4.74 KB

File metadata and controls

74 lines (46 loc) · 4.74 KB

title: Cloud protection and Microsoft Defender Antivirus description: Learn about cloud protection and Microsoft Defender Antivirus ms.service: defender-endpoint ms.localizationpriority: medium author: chrisda ms.author: chrisda ms.reviewer: mkaminska manager: bagol ms.custom: nextgen ms.subservice: ngp ms.topic: concept-article ms.date: 10/20/2025 ms.collection:

  • m365-security
  • tier2
  • mde-ngp search.appverid: met150 appliesto:
    • Microsoft Defender for Endpoint Plan 1
    • Microsoft Defender for Endpoint Plan 2
    • Microsoft Defender for Business
    • Microsoft Defender for Individuals

Cloud protection and Microsoft Defender Antivirus

Next-generation technologies in Microsoft Defender Antivirus provide near-instant, automated protection against new and emerging threats. To identify new threats dynamically, next-generation technologies work with large sets of interconnected data in the Microsoft Intelligent Security Graph and powerful artificial intelligence (AI) systems driven by advanced machine learning models. Cloud protection works together with Microsoft Defender Antivirus to deliver accurate, real-time, and intelligent protection.

:::image type="content" source="media/mde-cloud-protection.png" alt-text="Diagram showing how cloud protection works together with Microsoft Defender Antivirus" lightbox="media/mde-cloud-protection.png":::

Tip

We recommend keeping cloud protection turned on. To learn more, see Why cloud protection should be turned on.

Prerequisites

Supported operating systems

  • Windows

How cloud protection works

Microsoft Defender Antivirus works seamlessly with Microsoft cloud services. These cloud protection services, also referred to as Microsoft Advanced Protection Service (MAPS), enhance standard real-time protection. With cloud protection, next-generation technologies provide rapid identification of new threats, sometimes even before a single endpoint is infected.

The following blog posts illustrate how cloud protection works:

Note

The Microsoft Defender Antivirus cloud service is a mechanism for delivering updated protection to your network and endpoints. As a cloud service, it is not simply protection for files stored in the cloud; instead, the cloud service uses distributed resources and machine learning to deliver protection to your endpoints at a rate that is far faster than traditional security intelligence updates.

How to get cloud protection

Cloud protection is enabled by default. However, you might need to re-enable it if it has been disabled as part of previous organizational policies. To learn more, see Turn on cloud protection.

If your subscription includes Windows 10 E5, you can take advantage of emergency dynamic intelligence updates, which provide near real-time protection from emerging threats. When you turn on cloud protection, fixes for malware issues can be delivered via the cloud within minutes, instead of waiting for the next update. See Configure Microsoft Defender Antivirus to automatically receive new protection updates based on reports from our cloud service.