How to Access Protection History in Windows 11
Protection history in Windows 11 shows you the threats Microsoft Defender Antivirus found and got rid of.
Microsoft Defender Antivirus is the security program built right into your Windows PC. It works all the time to spot and remove harmful software.
This protection history is like a diary of security events. You can find it in the Windows Security app under “Virus & threat protection,” then by clicking “Protection history.”
This screen lists the names of threats, what Defender did about them (like putting them in quarantine or deleting them), and when they were found. For example, Defender might have removed a threat on October 26, 2023.
Open Windows Security, click “Virus & threat protection,” then select “Protection history” to view detected threats and actions taken by Microsoft Defender Antivirus. This log shows what has been quarantined or blocked.
Why check 🪟 Windows 11 Protection History?
Why check Windows 11 Protection History? This log shows you what Microsoft Defender has done to keep your computer safe from viruses and malware.
What happens when you are done?
What happens when you are done? After checking, you’ll know if your computer is safe. You’ll also know if you need to address any security warnings. This helps keep your system running fast and clean.
How to view your security history
Windows 11 Protection History lets you check past virus scans and blocked threats on your computer. You can view your security history by opening the Windows Security app from the taskbar search box, selecting virus and threat protection, and clicking on the history list to see recent actions taken by your device.
- Click the search box on your taskbar.
- Type Windows Security and click the app.

- Click Virus & threat protection on the left.
- Click Protection history.

You'll see a list of recent actions. A red badge indicates a serious issue. A yellow badge means you should look into it soon.

Managing Protection History logs
Managing Protection History logs helps you clear out old clutter and free up space when the list gets too long. You can clean these files out using File Explorer, but you need administrator privileges to delete the specific folders stored deep inside the Windows Defender directory.
[ADMIN PRIVILEGES REQUIRED]
- Open File Explorer.
- Navigate to C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\DetectionHistory.
- Delete all files inside this folder.
This action clears the history displayed in the Windows Security app. Keep in mind that the Windows Defender Service will create new logs as it identifies new threats.
Understanding threat statuses
- Quarantined: The file is locked in a safe folder. It cannot run or harm your PC.
- Blocked: The threat was stopped before it could start.
- Remediation Incomplete: The system tried to fix the issue but needs your help. You may need to restart your PC.
Advanced settings and troubleshooting
Advanced settings and troubleshooting for Windows 11 Protection History require you to check that your core security services are running properly. You should verify that Tamper Protection (a setting that stops unwanted changes to your security) is turned on so that malicious apps cannot alter your configuration.
Ensure that Tamper Protection is enabled in your settings. This stops malicious applications from altering your security configurations. Controlled folder access can also prevent programs from modifying your files without authorization.
Summary
Your Windows 11 Protection History acts as a key tool for tracking security actions taken by Microsoft Defender, helping you understand what threats have been blocked or quarantined.
How do I delete old protection history logs in 🪟 Windows 11?
Why does Windows Security show a threat that I already removed?
Can I recover files from the Protection History quarantine?
Can you delete Windows protection history?
Manually deleting Windows Security protection history: Navigate to the Windows Defender protection history folder (C:\ProgramData\Microsoft\Windows Defender\Scans\History), delete the Service folder to clear stored threat logs, and restart the device.
Was this guide helpful?
About the Author
Richard
Tech Writer, IT Professional
Richard, a writer for Geek Rewind, is a tech enthusiast who loves breaking down complex IT topics into simple, easy-to-understand ideas. With years of hands-on experience in system administration and enterprise IT operations, he’s developed a knack for offering practical tips and solutions. Richard aims to make technology more accessible and actionable. He's deeply committed to the Geek Rewind community, always ready to answer questions and engage in discussions.
No comments yet — be the first to share your thoughts!