Additional Microsoft Defender tools and services that provide security across various platforms and environments
If full scan completes successfully and shows No threats found, that indicates the scan itself finished. In Microsoft Defender Antivirus, scan completion can be confirmed by status sources such as Event Viewer, Defender portal reporting, or exported health data.
A practical way to verify whether the scan truly completed on the device is to check Event Viewer for these Microsoft Defender Antivirus scan events:
- Event ID 1000 = scan started
- Event ID 1001 = scan finished
- Event ID 1002 = scan stopped before completion
If the device shows 1001, the full scan completed successfully even if the Windows Security UI still shows “Last scan not available.” That points to the displayed scan details not reflecting the completed scan, rather than the scan failing.
Also check whether the scan might have been interrupted by conditions that can stop or cancel scans, such as:
- Device restart during or around the scan
- Battery power during a scheduled full scan
- Power state changes such as sleep, hibernate, or resume
- Scan timeout for scheduled or
MpCmdRun-initiated scans
Since the same result appears after restart and another full scan, the next useful validation is:
- Open Event Viewer on the device.
- Review Microsoft Defender Antivirus scan events for 1000/1001/1002.
- If needed, also review System log restart events 6005, 6006, 6007, 6008 and power-related events 107, 42, 507, 506, 105 to rule out interruption.
- If available in the environment, check the Device health / Recent antivirus scan results view in Microsoft Defender reporting to confirm whether the latest full scan is marked Completed, Canceled, or Failed.
For scan behavior differences, Windows Security supports Quick scan, Full scan, Custom scan, and Microsoft Defender Antivirus offline scan. A full scan checks every file and program on the device.