How to Fix SharePoint Server Antivirus Not Detecting EICAR Files
Question details
The user needs to resolve an issue where SharePoint Server fails to detect the EICAR antivirus test file upon document upload.

- Product
- SharePoint Server
- Device & OS
- not provided
- Scenario
- Testing backend document scanning security by uploading a standard EICAR test file to a SharePoint Server environment.
- Observed behavior
- Enabling the 'Scan documents on upload' feature alone does not result in the EICAR file being blocked or detected by the server.
Ensure you have farm administrator privileges in SharePoint Central Administration and administrative access to the physical or virtual servers hosting your SharePoint environment.
Verify Antivirus Configuration and SharePoint Services
Ensure that a compatible antivirus engine is installed, correctly integrated with SharePoint, and that all necessary scanning services are running.
SharePoint Server's built-in 'Scan documents on upload' setting only enables the integration bridge. It does not include a native antivirus engine. You must install a third-party antivirus solution specifically designed for SharePoint Server to actively scan files.
Verify that your supported antivirus solution is properly installed and licensed on every required server in your SharePoint farm, particularly the Web Front End (WFE) servers handling user uploads.
Open SharePoint Central Administration, navigate to Security > General Security > Manage antivirus settings, and confirm that both 'Scan documents on upload' and 'Scan documents on download' are checked.
Press Win + R, type 'services.msc', and press Enter. Locate the 'SharePoint Timer Service' and your specific third-party Antivirus scanning services. Ensure their status is set to 'Running'.
Open the Windows Event Viewer and check the Application and System logs for any errors or warnings related to SharePoint document scanning or the antivirus engine failing to initialize.
If the EICAR file is still not detected after configuration, post your specific environment details and event logs in the Microsoft SharePoint Server Management community for advanced troubleshooting.
Try WPS Office for Secure and Lightweight Document Management
While SharePoint Server requires complex backend configurations for file security, WPS Office offers a free, lightweight, and user-friendly alternative for creating, editing, and managing your daily documents securely locally. It provides seamless compatibility with Microsoft Office formats without the need for extensive server maintenance.
- 1. Download the software: Visit the official WPS Office website and download the free installation package for your operating system.
- 2. Install WPS Office: Run the downloaded installer and follow the simple on-screen instructions to set up the software on your device.
- 3. Open your files securely: Launch WPS Office and open your existing Microsoft Office documents. You can instantly apply local passwords and encryption to protect your sensitive data.

Frequently Asked Questions
What is an EICAR file and why use it for testing?
The EICAR file is a standard, safe test string developed by the European Institute for Computer Antivirus Research. It allows administrators to test if their antivirus software is functioning and detecting threats correctly without risking exposure to actual malware.
Why doesn't the 'Scan documents on upload' setting work by itself?
The setting in SharePoint Central Administration only tells SharePoint to route uploaded files through an antivirus API. If no compatible third-party antivirus engine is installed on the server to receive and process these files, the scan will fail or be bypassed.
Which servers in my SharePoint farm need the antivirus software installed?
Typically, the antivirus software and the SharePoint integration components must be installed and properly configured on every Web Front End (WFE) server, as these are the servers that process user uploads and downloads.




