Additional Microsoft Defender tools and services that provide security across various platforms and environments
Use the supported false-positive submission paths instead of MSRC escalation.
- Submit the file in the Microsoft Defender portal:
- Go to Microsoft Defender portal > Investigation & response > Actions & submissions > Submissions.
- Open the Files tab.
- Select Add new submission.
- Choose Files.
- Upload the file.
- Set The file should have been categorized as to Clean (false positive).
- Set priority as needed: Low, Medium, or High - needs immediate attention.
- Add notes describing the detection names and that the file is legitimate.
- Select Submit.
- If the file cannot be uploaded, submit the file hash instead:
- In the same Submissions page, choose File hash.
- Enter the SHA-256 value.
- Set The file should have been categorized as to Clean (false positive).
- Add notes and submit.
- If the Defender portal path is not available, use the Microsoft Security Intelligence submission site to submit the file for malware analysis.
- After submission, sign in to the Microsoft Security Intelligence submission site to check for updates.
- If Microsoft identifies the file as a false positive and updates definitions, the file should no longer be flagged. If it continues to be flagged after definitions are updated, contact Microsoft Support.
Notes:
- Archive submissions can be encrypted with the password infected.
- The maximum total size for uploaded files in the Defender portal is 500 MB.
- Authenticated customers, especially enterprise customers with valid SAIDs, receive higher priority for analysis.