Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

You can update Microsoft Defender Antivirus, run scans, check protection status, and start an offline scan from Windows 10’s command line. Use MpCmdRun.exe in Command Prompt for direct executable commands, or Defender’s PowerShell cmdlets for task-specific options such as scanning a chosen folder. For commands that require elevation, open the shell with Run as administrator.

This guide covers the antivirus component, Microsoft Defender Antivirus—not broader Microsoft Defender products or Defender for Endpoint management plans. Available commands can vary with the Windows build and Defender platform installed on your PC, so check local help before relying on a particular switch.

Choose Command Prompt or PowerShell

Both shells can perform common Defender Antivirus tasks. Use Command Prompt with MpCmdRun.exe when you want the executable’s switches or need to call it from a script or scheduled task. PowerShell offers task-oriented cmdlets with named parameters, including a scan-path parameter for custom scans. Microsoft describes these as alternative command-line approaches; the installed Windows and Defender platform version determine which commands are available.

Use case Command Prompt and MpCmdRun.exe PowerShell
Run a scan Uses MpCmdRun scan switches; confirm accepted syntax with local help. Uses Start-MpScan with explicit scan types and an optional scan path.
Update security intelligence Uses -SignatureUpdate; supports documented source options. Uses Update-MpSignature; follows configured fallback sources or default behavior.
Check status and detections Command availability varies; consult local help. Includes Get-MpComputerStatus, Get-MpThreat, and Get-MpThreatDetection.
Run Defender Offline Not presented here as a universal MpCmdRun procedure; check local help. Start-MpWDOScan starts an offline scan and restarts the PC; verify the cmdlet is available on your Windows 10 build.

Open an elevated shell

For MpCmdRun operations that require elevation, use an administrator Command Prompt. Use elevated PowerShell for Defender operations that require elevation, especially configuration changes or protection actions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Open Start and type cmd for Command Prompt, or PowerShell for PowerShell.
  2. Right-click the matching app and select Run as administrator.
  3. Approve the User Account Control prompt.

Microsoft’s MpCmdRun guidance specifies an elevated Command Prompt as a prerequisite. Its PowerShell guidance also illustrates elevated PowerShell for configuration work. Microsoft’s MpCmdRun instructions and PowerShell cmdlet guidance describe the respective approaches.

Where is MpCmdRun.exe?

MpCmdRun.exe is not normally on the PATH, so typing its name from an arbitrary directory can produce “not recognized as an internal or external command.” On 64-bit Windows, Microsoft lists the current platform copy under C:ProgramDataMicrosoftWindows DefenderPlatform<platform-version>. If that location is unavailable, check C:Program FilesWindows Defender.

In File Explorer, you can open the Platform folder and select the versioned directory, then use that folder in Command Prompt. Alternatively, invoke the executable using its full path. Microsoft also provides a directory-selection command that chooses the newest platform-version folder and falls back to Program Files; use the exact sample in its documentation because the loop-variable form differs between an interactive Command Prompt and a batch file. In an interactive prompt, the sample uses %d; in a .bat file, use the batch form %%d.

After changing to the folder containing the executable, inspect commands supported by that installation:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
MpCmdRun.exe -?

The -h switch also displays help. Platform and Windows versions can affect the available commands, so local help is the best check before using a less common switch. See Microsoft’s MpCmdRun command reference.

How do I run a quick, full, or custom scan?

PowerShell is the clearest option when you want to specify a scan type or target folder. Open elevated PowerShell, then run the command for the scan you need. The Start-MpScan reference lists these scan types and the -ScanPath parameter.

Quick scan

Start-MpScan -ScanType QuickScan

Full scan

Start-MpScan -ScanType FullScan

Custom scan of a folder

Replace the example path with the folder you want Defender to scan. Keep the path in single quotes if it contains spaces.

Start-MpScan -ScanType CustomScan -ScanPath 'C:Users<name>Downloads'

Microsoft’s Start-MpScan reference documents these values. If you prefer Command Prompt, Microsoft documents this full-scan example:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
HP 2020 15.6" Touchscreen Laptop Computer/ 10th Gen Intel Quard-Core i5 1035G1 up to 3.6GHz/ 12GB DDR4 RAM/ 256GB PCIe SSD/ 802.11ac WiFi/Bluetooth 4.2/ USB 3.1 Type-C/HDMI/Silver/Windows 10 Home
  • 10th Generation Intel Core i5-1035G1 processor
  • 12GB system memory for full-power multitasking
  • 256GB Solid State Drive
  • 15.6" Micro-edge touchscreen display
MpCmdRun.exe -Scan -ScanType 2

For quick or custom MpCmdRun scans, inspect MpCmdRun.exe -? on your computer rather than assuming the numeric values or syntax are identical across platform versions.

How do I update Windows Defender from cmd?

In an elevated Command Prompt opened in the folder containing MpCmdRun.exe, run:

MpCmdRun.exe -SignatureUpdate

The PowerShell equivalent is:

Update-MpSignature

Update-MpSignature follows configured signature fallback sources; if none are configured, it uses the default source behavior. Administrators managing update distribution can specify sources supported by the cmdlet, including MicrosoftUpdateServer, MMPC, InternalDefinitionUpdateServer, and FileShares. MpCmdRun also documents examples for a UNC share and MMPC:

MpCmdRun.exe -SignatureUpdate -UNC \FileServerShareName
MpCmdRun.exe -SignatureUpdate -MMPC

Use alternate sources only when they match the update arrangement for your network. See Microsoft’s Update-MpSignature reference and security intelligence update instructions.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Dell Latitude 7480 Laptop 14 - Intel Core i7 6th Gen - i7-6600U - 3.4Ghz - 256GB SSD - 16GB RAM - 1920x1080 FHD - Windows 10 Pro (Renewed)
  • Latitude 7480 Laptop 14"
  • Intel Core i7 6th Gen i7-6600U -Core Processor 2.6GHz (3.4GHz With Turbo Boost)
  • 256 GB SSD Hard Drive & 16GB Memory
  • 1920x1080 FHD resolution Non-Touch with Webcam and an integrated graphics chip
  • Wireless Wifi & Bluetooth

How do I check Defender status and detections?

In PowerShell, these cmdlets provide a starting point for reviewing local protection information:

  • Get-MpComputerStatus — inspect Defender Antivirus status and protection settings.
  • Get-MpThreat — review threat information.
  • Get-MpThreatDetection — review detection records.

For cloud-protection connectivity, Microsoft documents the MpCmdRun validation command:

MpCmdRun.exe -ValidateMapsConnection

This checks communication with the Microsoft Defender Antivirus cloud service; it is a connectivity check, not a scan. Microsoft’s command reference documents the switch.

How do I start a Windows Defender Offline scan?

Windows Defender Offline runs outside the normal Windows environment. In elevated PowerShell, first save open work, then run:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Start-MpWDOScan

The command restarts the computer into the offline scanning environment and begins scanning. The Microsoft cmdlet page is shown in a Windows Server 2025 documentation view, so its presence and exact availability on a particular Windows 10 build should not be assumed. Check for the cmdlet on the target PC before using it. See the Start-MpWDOScan reference.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why is MpCmdRun not recognized, or why does a command fail?

“MpCmdRun is not recognized”

This usually means the executable’s folder is not on PATH. Change to the current Platform version folder or the Program Files fallback, or call MpCmdRun.exe by its full path.

Help does not show the switch you expected

Run MpCmdRun.exe -? or -h from the executable’s folder. Installed Defender platform and Windows versions can differ, and Microsoft documentation may describe commands not present on an older installation.

-ValidateMapsConnection returns 0x80070667

Microsoft says this validation command is unsupported on older Windows versions and identifies Windows 10 version 1703 or later as supported for this specific check. That threshold applies to this command, not to every Defender switch.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

ValidateMapsConnection fails with 800106BA or 0x800106BA

Microsoft lists a disabled Microsoft Defender Antivirus service as one possible cause. Check the service and the device’s management policy; on a work-managed PC, do not override centrally controlled settings yourself.

What should I know before changing Defender settings?

Before changing protection settings, record the existing configuration with Get-MpPreference and/or Get-MpComputerStatus. That gives you a baseline to compare if a change has an unintended effect. Avoid disabling real-time protection or adding broad exclusions as routine troubleshooting; use the specific error and the documented diagnostic route instead. Microsoft’s PowerShell evaluation guidance recommends capturing settings before changes.

On a work-managed computer, local cmdlets do not replace central policy management through Intune, Group Policy, or Configuration Manager. A policy may control whether a local change is allowed or retained. Ask your organization’s administrator about managed settings rather than trying to bypass policy. Microsoft’s cmdlet administration guidance explains the limits of managing Defender with individual local commands.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.