---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure Run Antivirus Scan capability

# Configure Run Antivirus Scan capability in Microsoft Defender for Endpoint {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

Remotely initiate an antivirus scan to help identify and remediate malware that might
be present on a compromised device. Run the scan as part of the investigation or response
process.

## Antes de Iniciar

Role required: sn_si.admin or sn_si.analyst  
{#run-antivirus-scan-capability-ms-defender__table_ybd_pt2_jsb__entry__2}

| Input | Description |
|-|-|
| Scan Type | (Required) Type of the Scan (Full or Quick). |
| Comment | (Required) Comment to associate with the action. |
[Tabela 1. Requirements for Run Antivirus Scan capability]

{#run-antivirus-scan-capability-ms-defender__table_ybd_pt2_jsb}

## Procedimento

1. Navigate to Security IncidentsShow All Incidents.
2. Select the security incident that you want to review with the Microsoft Defender for Endpoint information.
   1. In the related links section, click Run Additional Actions on Endpoint.
   2. Browse and select the required capability.  
      For example, click Run Antivirus Scan capability.

   Figura 1. Run Antivirus Scan  
   Alternatively, you can perform the following steps:
   1. In the related lists section, click Show All Related Lists.
   2. Click the Configuration Item related list.
   3. Select the added configuration items, and from the Actions on selected rows, select Run Additional Actions on Endpoint.
   {#run-antivirus-scan-capability-ms-defender__ol_y4j_m45_wsb}  
   After you select the Run Antivirus Scan capability implementation, the Additional Scan Type and Comment input fields are displayed.
3. Select the Scan type that you want to run (Quick or Full), and add a comment before executing the scan.
4. To initiate the antivirus scan, click Run Additional Action.
5. View the automation activities of the execution, and validate them.
6. Validate the status of the action on the Additional Actions on Endpoint related lists.
**Tarefas relacionadas**   

* [Configure Isolate Host capability in Microsoft Defender for Endpoint](https://servicenow-prod.fluidtopics.net/4WEUXPrSaGx8_Hr2a5LTiw "Isolate the host from accessing the network in Microsoft Defender for Endpoint based on the severity of the attack. Isolating the host from the network enables you to prevent any other malicious activities or potential attacks on other hosts.")
* [Configure Remove Host Isolation capability in Microsoft Defender for Endpoint](https://servicenow-prod.fluidtopics.net/W3JPO2ZoO5C8UgYQPFg1Hg "If needed, remove the isolation of a host that was previously isolated from the network in Microsoft Defender for Endpoint. You can prevent any other malicious activities or potential attacks on other hosts.")
* [Configure Restrict App Execution capability in Microsoft Defender for Endpoint](https://servicenow-prod.fluidtopics.net/tqIYbsXCAw8GJV_p31Lwrg "To contain an attack, restrict or lock a device and prevent subsequent attempts of potentially malicious programs from running.")
* [Configure Remove App Restriction capability in Microsoft Defender for Endpoint](https://servicenow-prod.fluidtopics.net/7bQM~DzjjqFOQcLJI8OADw "If needed, remove the restrictions of any application on the device.")
* [Configure Get Related Machines from Defender Capability in Microsoft Defender for Endpoint](https://servicenow-prod.fluidtopics.net/iva~qzHYfs9RrWVGl45Czg "Get the list of related machines of specific observables.")
* [Configure Stop and Quarantine File capability in Microsoft Defender for Endpoint](https://servicenow-prod.fluidtopics.net/zoVqNs24OW3cXvxdRMXxIQ "Stop and quarantine files from the Microsoft Defender platform.")

