Trigger a quick scan after X days without any scans
Verified with Windows 11 25H2 — updated on July 10, 2026
Supported on: At least Windows Server 2012, Windows 8 or Windows RT
Path in the GPO console
Computer Configuration\Administrative Templates\Windows Components\Microsoft Defender Antivirus\Scan Description
This policy setting defines the number of days that can pass since the last scan before an aggresive catchup quick scan is automatically triggered. The value represents the number of days that can pass without any scans being performed before an agressive quick scan will be triggered. Valid values range from 7 to 60 days. If not configured, aggressive quick scans will be disabled. By default, the value is set to 25 days when enabled.
Registry
Software\Policies\Microsoft\Windows Defender\Scan Value name: DaysUntilAggressiveCatchupQuickScan
Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Trigger a quick scan after X days without any scans
; State: Enabled
; Supported on: At least Windows Server 2012, Windows 8 or Windows RT
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows Defender\Scan]
"DaysUntilAggressiveCatchupQuickScan"=dword:00000001
"DaysUntilAggressiveCatchupQuickScan"=dword:00000019 More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Trigger a quick scan after X days without any scans
# State: Enabled
# Supported on: At least Windows Server 2012, Windows 8 or Windows RT
$path = 'HKLM:\Software\Policies\Microsoft\Windows Defender\Scan'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'DaysUntilAggressiveCatchupQuickScan' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'DaysUntilAggressiveCatchupQuickScan' -Value 25 -Type DWord Intune XML
No direct Policy CSP / OMA-URI mapping for this policy. Use the Intune Remediation tab, or ingest the ADMX in Intune. Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Trigger a quick scan after X days without any scans
# State: Enabled
# Supported on: At least Windows Server 2012, Windows 8 or Windows RT
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows Defender\Scan' -Name 'DaysUntilAggressiveCatchupQuickScan' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows Defender\Scan' -Name 'DaysUntilAggressiveCatchupQuickScan' -Expected 25 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Trigger a quick scan after X days without any scans
# State: Enabled
# Supported on: At least Windows Server 2012, Windows 8 or Windows RT
$path = 'HKLM:\Software\Policies\Microsoft\Windows Defender\Scan'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'DaysUntilAggressiveCatchupQuickScan' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'DaysUntilAggressiveCatchupQuickScan' -Value 25 -Type DWord SCCM scripts
# Exported from gporais.com
# Policy: Trigger a quick scan after X days without any scans
# State: Enabled
# Supported on: At least Windows Server 2012, Windows 8 or Windows RT
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Trigger a quick scan after X days without any scans
# State: Enabled
# Supported on: At least Windows Server 2012, Windows 8 or Windows RT
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows Defender\Scan' -Name 'DaysUntilAggressiveCatchupQuickScan' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows Defender\Scan' -Name 'DaysUntilAggressiveCatchupQuickScan' -Expected 25 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Trigger a quick scan after X days without any scans
# State: Enabled
# Supported on: At least Windows Server 2012, Windows 8 or Windows RT
$path = 'HKLM:\Software\Policies\Microsoft\Windows Defender\Scan'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'DaysUntilAggressiveCatchupQuickScan' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'DaysUntilAggressiveCatchupQuickScan' -Value 25 -Type DWord Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.