How to View or Export URLs Scanned by Microsoft Defender
Question details
The user is looking for a way to view, access, or export a complete historical log of all URLs that have been scanned by Microsoft Defender.

- Product
- Microsoft Defender
- Device & OS
- Windows
- Scenario
- Attempting to retrieve a comprehensive historical record of web activity or URLs processed by the system's security scanner for auditing or troubleshooting.
- Observed behavior
- Microsoft Defender does not provide a complete list of every scanned URL; instead, it only logs detected threats, blocked content, quarantined items, and potentially compromised URLs.
Ensure you have administrative privileges on your Windows computer, as accessing Microsoft Defender reports and Windows Event Viewer logs requires admin rights.
Check Microsoft Defender for Endpoint Reports
Use the Microsoft Defender portal to view alerts and details regarding detected malicious or compromised URLs.
While Microsoft Defender does not log every safe URL you visit, Microsoft Defender for Endpoint captures data on threats, blocked content, and quarantined items. This is the best native method for reviewing problematic web activity.
Navigate to the Microsoft 365 Defender portal in your web browser and sign in with your administrator credentials.
Click on the 'Incidents & alerts' section, then select 'Alerts' to view recent security events triggered by web activity.
Use the filtering options to narrow down the list to web-related threats, blocked content, or potentially compromised URLs.
Select the relevant alerts and click the 'Export' button (if available in your specific Defender tier) to download the detected URL information.

Review Windows Event Viewer Logs
Manually inspect the local Windows Event Viewer for specific warning or error events related to Microsoft Defender scans.
Secure and Manage Your Documents with WPS Office
While managing your system's security settings and Defender logs, you may also need a reliable office suite. WPS Office is a free, lightweight, and highly compatible alternative to Microsoft Office, offering seamless migration and a familiar interface.
- 1. Download the Installer: Visit the official WPS website and download the free installation package for Windows.
- 2. Install the Software: Run the downloaded installer and follow the simple on-screen instructions.
- 3. Open Your Files: Launch WPS Office and instantly open your existing Microsoft Office documents without any formatting loss.

Frequently Asked Questions
Does Microsoft Defender keep a log of every safe URL I visit?
No, Microsoft Defender does not maintain a complete historical log of all scanned URLs. It primarily logs URLs that are detected as threats, blocked by policy, or potentially compromised, in order to save system resources and respect user privacy.
Can I use third-party tools to track all scanned URLs?
Yes. If you need a comprehensive log of all web activity and scanned URLs, you should consider using dedicated Endpoint Detection and Response (EDR) tools or specialized web filtering software, which offer much more extensive logging than default Defender settings.
How do I enable logging for future web activity in Microsoft Defender?
To capture more detailed web activity moving forward, you need to configure Network Protection and Web Content Filtering within Microsoft Defender for Endpoint. Make sure auditing and data retention policies are actively configured before the activity takes place.




