An Azure service that stores unstructured data in the cloud as blobs.
Hell @ZimElectric-5201
The absence of a verdict isn’t expected merely because the uploaded blob is small. Microsoft doesn’t document a minimum blob size for malware scanning.
A few points are important here:
- On-upload scanning starts only after an operation generates a BlobCreated or BlobRenamed event. For block blobs, individual PutBlock operations don’t trigger scanning; the scan starts after the blocks are committed with PutBlockList.
- Blob-index tags are the default result method, but they can be disabled. Event Grid and Log Analytics delivery must be configured separately. The expected tag values include No threats found, Malicious, Error, and Not scanned.
- A blob can have no result if the storage account exceeds documented scan throughput or blob-size limits. Failed and unsupported scans should normally return an error or Not scanned reason when results are successfully published.
- For Event Grid, confirm that the Defender for Storage settings reference the intended custom topic and that the subscription is receiving Defender malware-scan events. A normal storage BlobCreated subscription isn’t the same as the Defender scan-result configuration.
For retained blobs, use Defender for Storage on-demand malware scanning. It can scan existing data and can target an individual blob, container, path prefix, or the storage account. It doesn’t require re-uploading or replacing the original blob. Check the scan operation’s status and summary through the documented scan-status API instead of treating the initial request response as the verdict.
Capture the exact upload operation, blob URL, UTC upload time, storage-account resource ID, current Defender settings, and any on-demand API response body. If the upload was finalized correctly, blob-index result storage is enabled, limits weren’t exceeded, and neither tags nor configured Event Grid/Log Analytics results appear, this requires an Azure support case to inspect the Defender scanning backend.
There's no verified official documentation identifying a known issue specifically affecting benign small block blobs in East US.
References:
Introduction to malware scanning
Understand malware-scanning results
Configure malware-scan result handling
Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.