Resource icon

Read Windows Security Protection history before allowing a quarantined file

Protection history records Defender actions, potentially unwanted software and important services that were turned off. It retains entries for only two weeks according to Microsoft, so a person investigating an alert should capture details promptly. A quarantined file may be a real threat, an unwanted bundle or a false positive. Restoring it simply to make an app run can reintroduce risk. Investigate the detection and vendor provenance first.

Before you start​

Keep the item quarantined while reviewing. Note the time the alert appeared, the app you were using and whether the path is under Downloads, a browser cache or a system directory. Do not send a sample containing personal data to a public scanner without understanding its sharing policy. On a managed PC, follow incident-response rules.

Do it step by step​

  1. Open Windows Security > Protection history and select the relevant card. Read severity, threat name, affected item, path and action taken; capture a private record before the two-week retention window ends.
  2. Check whether Defender blocked execution, quarantined a file, removed it or merely warned. Do not call the incident resolved based on a colored icon alone.
  3. Compare file origin with the software vendor's official distribution. If the user did not deliberately install it, keep the item blocked and inspect surrounding downloads.
  4. Update security intelligence and run a targeted or full scan as appropriate. If the file is critical and likely clean, ask the vendor to submit a false-positive report to Microsoft.
  5. Use Allow or Restore only after provenance, expected behavior and detection context are understood; document the reason. Prefer a vendor-provided corrected file over an exception.
  6. Review related startup entries, browser extensions and recent account activity if the alert was high severity. Change credentials from a trusted device if execution or theft is plausible.

Check the result​

The detected item has a justified disposition, the original warning no longer recurs, and any broader exposure has been checked.

If something goes wrong​

If the item reappears, identify the installer or process recreating it rather than repeating Restore. If Protection history lacks the event, check its retention limit and other security logs. A work device may intentionally restrict user actions.

Know the limit​

A quarantine action protects this file but does not guarantee the whole PC or online accounts are safe. Protection history is a short-lived operational record, not a complete forensic log. Microsoft Protection history Virus and threat protection

Decision checkpoint​

Consider what happened before the alert. An unwanted browser extension, fake update and bundled installer call for different cleanup checks. Record the path and detection ID before deleting evidence, especially if you need vendor or IT support. For a possible false positive, submit the original file via the supported route rather than posting it in a public forum. Keep a known-good copy of critical work independent of quarantine and Windows Security history.

Aftercare​

Review the related download or installer that placed the file on the PC. Otherwise the same unwanted component may arrive again on the next update.
Posted by
Jack
Views
1
First release
Last update

Ratings

0.00 star(s) 0 ratings

More resources from Jack