Protection history records Defender actions, potentially unwanted software and important services that were turned off. It retains entries for only two weeks according to Microsoft, so a person investigating an alert should capture details promptly. A quarantined file may be a real threat, an unwanted bundle or a false positive. Restoring it simply to make an app run can reintroduce risk. Investigate the detection and vendor provenance first.
Before you start
Keep the item quarantined while reviewing. Note the time the alert appeared, the app you were using and whether the path is under Downloads, a browser cache or a system directory. Do not send a sample containing personal data to a public scanner without understanding its sharing policy. On a managed PC, follow incident-response rules.Do it step by step
- Open Windows Security > Protection history and select the relevant card. Read severity, threat name, affected item, path and action taken; capture a private record before the two-week retention window ends.
- Check whether Defender blocked execution, quarantined a file, removed it or merely warned. Do not call the incident resolved based on a colored icon alone.
- Compare file origin with the software vendor's official distribution. If the user did not deliberately install it, keep the item blocked and inspect surrounding downloads.
- Update security intelligence and run a targeted or full scan as appropriate. If the file is critical and likely clean, ask the vendor to submit a false-positive report to Microsoft.
- Use Allow or Restore only after provenance, expected behavior and detection context are understood; document the reason. Prefer a vendor-provided corrected file over an exception.
- Review related startup entries, browser extensions and recent account activity if the alert was high severity. Change credentials from a trusted device if execution or theft is plausible.