Let’s check the Antivirus Agent Status Intune Report available in Intune Portal (Endpoint Manager portal). The Antivirus agent status report provides the agent status of your organization’s devices. The report is available from the primary Microsoft Defender Antivirus workload, and provides filtering, searching, paging, and sorting.
The data found in this report is timely and shows the following details:
- If a device has real-time or network protection, as well as the state
- The status of Windows Defender
- If Tamper protection is enabled
- If the device is a virtual machine, or a physical device.
- Calls out the unhealthy device, the user name, and severity.
Antivirus Agent Status Report – Intune Portal
To view the Antivirus agent status report use the following steps:
- Sign in to the Microsoft Endpoint Manager admin center.
- Select Reports > Microsoft Defender Antivirus to open the default reports view which is the Summary page. The Summary page displays aggregate details for the Antivirus reports, supports a Refresh, and reflects the data found in Antivirus agent status report. If there are no devices in any of the states, you will be informed that there are no results to display.

- Select the Reports tab > Antivirus agent status to open the report to see the agent status of your devices.

- You can start by selecting the filter for device state (i.e. Clean, Full scan pending, Reboot pending, Manual steps pending, Offline scan pending, Critical etc.) and select the columns you wish to have in view. Click Generate report (or Generate again) to retrieve current data.

- A notification will be appear automatically in the top right-hand corner with message Generating Antivirus agent status report.

- Once the report has been generated. You see the state of the device and additional information. The information for this report is based on details available from the Defender CSP.
Note – The data within the report will remain in your console up to 3 days before requiring you to generate again.

- Use the Columns property to add or remove columns from the generated report. Click on the Columns, A flyout displays, here you can Check or Uncheck the columns that you want to include. Select Apply to update and Click Generate report (or Generate again) to update report.

- To export reporting data generated. Click on the Export. The popup will appear with the following message when exporting generated Antivirus agent status report, Click Yes. This will export data to a comma-separated values (.csv) file.
Note – A notification will appear automatically in the top right-hand corner with the message Export is in progress. The report will be downloaded in a .zip file format to your browsers and a notification message will appear Export completed. Extract the downloaded file to view the report.

Resources
- Antivirus agent status – Intune report (Organizational)
- Intune Device Compliance Reports | Endpoint Manager
- Intune Co-management Eligibility Report | Endpoint Manager
- Intune Windows 10 MDM Firewall Status Report | Endpoint Manager
- Windows 10 Feature Update Intune Report | Endpoint Manager
Hello @Jitesh,
Does this Antivirus agent status report work for MacOS devices. the issue is none of the MacOS devices are showing under this report. Please help