Professional Documents
Culture Documents
The Protection History page shows detections by Windows Defender and provides detailed and easier to
understand information about threats and available actions. Starting with Build 18305, it includes Controlled
Folder Access blocks, along with any blocks which were made through the organizational configuration of
Attack Surface Reduction Rules. In this post, we will show you how to manually clear protection history in
Windows Defender on Windows 10.
If you use the Windows Defender Offline scanning tool, any detections it makes will now also show in this
history. Additionally, you will see any pending recommendations (red or yellow states from throughout the
app) in the history list.
However, if you want to clear the protection history manually, you can do so in any of the three following
1 of 4 1/9/2021, 7:57 PM
How to clear Windows Defender Protection History in Windows 10
ways;
Let’s take a look at the steps involved in relation to each of the listed methods.
The Set-MpPreference cmdlet configures preferences for Windows Defender scans and updates. You can
modify exclusion file name extensions, paths, or processes, and specify the default action for high,
moderate, and low threat levels.
You can specify a different delay period (in days) by running the cmdlet below in PowerShell admin mode
(press Win+X and then tap A on the keyboard):
Set-MpPreference -ScanPurgeItemsAfterDelay 1
The specified number 1 is the number of days after which the protection history log and items in the log
folder will be cleared.
To manually clear the protection history, this method requires you to delete the Service folder under the
Windows Defender folder on the local drive.
Here’s how:
Now, right-click the Service folder in that location and select Delete.
Next, open Windows Security > Virus & threat protection > Manage settings.
Toggle the button to Off then to On again for Real-Time protection and Cloud-delivered
protection.
2 of 4 1/9/2021, 7:57 PM
How to clear Windows Defender Protection History in Windows 10
To manually clear the Windows Defender protection history using the Event Viewer (eventvwr), do the
following:
And the above listed are the 3 known ways to manually clear Windows Defender protection history in
Windows 10.
3 of 4 1/9/2021, 7:57 PM
How to clear Windows Defender Protection History in Windows 10
4 of 4 1/9/2021, 7:57 PM