Additional Microsoft Defender tools and services that provide security across various platforms and environments
The behavior described typically occurs when a prerequisite for Microsoft Defender Offline is not fully met, even if it appears correct at first glance. Use the following checks and fixes in order:
- Confirm Microsoft Defender Antivirus is the primary AV
- Microsoft Defender Offline only runs if Microsoft Defender Antivirus is the primary antivirus (not in passive/disabled mode).
- If any third‑party antivirus is installed (for example, McAfee or similar), uninstall it completely and restart, then try the offline scan again.
- Ensure real‑time protection and other Defender components are enabled and healthy.
- Re‑verify Windows Recovery Environment (WinRE) Even if WinRE appears enabled, explicitly confirm and re‑enable it:
- Open an elevated Command Prompt (Run as administrator).
- Check status:
reagentc /info - If Windows RE status is Disabled, enable it:
reagentc /enable - Restart the PC and try the offline scan again (from Windows Security or
Start-MpWDOScan).
If WinRE is disabled, Microsoft Defender Offline will not run and there is no error; the system simply restarts normally. Re‑enabling WinRE is sufficient to fix this behavior.
- Ensure user is local administrator
- The account starting the offline scan must have local administrator privileges.
- Sign in with a local admin account, then trigger the offline scan again.
- Trigger the scan using supported methods Once the above are confirmed:
- From PowerShell (elevated):
This should restart the device into the offline environment and start the scan.Start-MpWDOScan
If, after confirming Defender is primary, WinRE is enabled (reagentc /info shows Enabled), and the account is an administrator, but the system still only performs a normal restart, collect logs and open a support case, as the documented conditions for the offline scan to run are then satisfied.
References: