Microsoft Defender service status
Check whether the provider lists a problem with the feature you use. Look at the update time and any affected regions.
Live Domain Check
Run a live reachability check for defender.microsoft.com. Compare the regional responses with the problem you see in Microsoft Defender.
Find Microsoft Defender help and reporting links, specific checks, and step-by-step guidance below the live result.
Checking reachability from multiple regions.
Share a quick update and see what other visitors are experiencing.
What’s happening? Choose one to send your report.
Loading community reports…
—problem reports
—working reports
No problems reported in this period.
Visitor reports are separate from our automated checks and don’t confirm an outage. How reports work · Privacy
Defender portal access, endpoint protection state and alert ingestion are different checks.
The checker above requests defender.microsoft.com from eight configured locations and shows the responses and measurement times. Compare those observations with the actual Microsoft Defender action that failed. A homepage response alone cannot verify an account, app workflow or transaction.
For a cloud administration or security-console issue, compare the entrypoint involved in your actual workflow: Azure status check, Azure Portal status check. Compare results separately; these links do not establish a shared outage.
Looking for another service? Browse infrastructure checks.
Check whether the provider lists a problem with the feature you use. Look at the update time and any affected regions.
Use the organisation's authorised security/identity administrator and product support.
Open the website in your browser and compare it with the result above.
Open Microsoft Defender help / reporting. Use the provider's customer-service or account-help route for the affected product. Sign-in may be required for private account questions.
Defender product, tenant/device reference privately, alert or portal action, client version and correlation ID.
Attach the checker’s downloaded JSON if it helps show the hostname, regional responses and original timestamps. Describe what happened in your browser or app as well. A report sent to WebsiteDown.org is not automatically forwarded to Microsoft Defender.
These are troubleshooting comparisons, not claims that Microsoft Defender is currently experiencing a particular incident.
Identify the Defender product and compare portal availability with the affected device's reported protection state.
Use the organisation's security administrator and relevant Microsoft service-health information; do not disable protection to test website access.
A 403 Forbidden or 429 Too Many Requests means the host answered but refused or limited that request. A timeout gives no HTTP response. Keep those outcomes separate and check the available-region count before treating the result as broad evidence.
Use these local troubleshooting steps after the down-check workflow when Microsoft Defender seems broken only for you. This section focuses on app, browser, account, and network fixes.
Open defender.microsoft.com in your current browser, then test in a private window or second browser. If only one session fails, compare its account, cookie and extension context before assuming the entire service is unavailable.
Keep an existing working session and preserve unsaved work. For a sign-in failure, use the official account-help route. Avoid repeated password or security resets until you confirm this is not a broader Microsoft Defender issue.
If possible, compare Wi-Fi with mobile data and note which one fails. Leave any required work VPN or security settings in place.
Save timestamp, device, network type, exact error, final URL, and status code. Use the check workflow above before contacting Microsoft Defender support.
Run the defender.microsoft.com check and compare its original timestamps and responses with your actual error. Defender portal access, endpoint protection state and alert ingestion are different checks.
Use the community buttons on this page to share whether the service works for you. For help from Microsoft Defender, use the official help/reporting resource linked above. Use the organisation's authorised security/identity administrator and product support.
Identify the Defender product and compare portal availability with the affected device's reported protection state. Use the organisation's security administrator and relevant Microsoft service-health information; do not disable protection to test website access.
Defender product, tenant/device reference privately, alert or portal action, client version and correlation ID.