- Open a PowerShell (or Terminal) as Administrator
- Run the following command: Update-MpSignature -UpdateSource MicrosoftUpdateServer
For everyone implementing Microsoft Windows Defender Antivirus, here's a quick note where to find the client logs and how to use them:

With more and more enterprises embracing digitalization and also the Microsoft Cloud solutions, there’s a nice add-on to Microsoft 365 subscriptions (or if you’re using E5 tier) called Windows Defender Advanced Threat Protection or WDATP.
WDATP is a unified, cloud based platform for, preventative protection, post breach detection, automated investigation and response.
You can read a little bit more about it here:
Microsoft 365 - Windows Defender Advanced Threat Protection – Overview
But this post is about what you need to do to implement it in your organization.
Below are direct links to Microsoft documentation that helps to easily implement and troubleshoot WDATP:
WDATP - Onboard Windows 10 machine
WDATP - Run a detection test on a newly onboarded Windows Defender ATP machine
WDATP - Configure machine proxy and Internet connectivity settings
WDATP - Enable access to Windows Defender ATP service URLs in the proxy server
WDATP - Troubleshoot Windows Defender Advanced Threat Protection onboarding issues

Although nowadays you could (err…should) configure event viewer (or centralized logging) for your Windows Defender Firewall, here’s a tip for something I’ve noticed when changed the default Windows Defender Firewall location.
When applying a GPO to do this, you must keep in mind that MpsSvc service account is responsible to write down the Windows Firewall log, so, if you change the default location (%windir%\System32\LogFiles\Firewall) you need to give it the right NTFS permissions.
So basically what you need to do:
And…you’re done!
![]()
Here’s a nice tip for those that for some reason need to configure Windows Firewall (or Windows Defender Firewall on Windows 10).
The recommended way to do this should be using a group policy but because you may have a non-domain joined machine on your network, here’s how to do it.
If for any reason you need to reset firewall rules to default values just type:
netsh advfirewall reset