logo
search
Data Protection Issues

How to View or Export URLs Scanned by Microsoft Defender

Maira MehtabMaira Mehtab Sep 30, 2026 869 views

Question details

The user is looking for a way to view, access, or export a complete historical log of all URLs that have been scanned by Microsoft Defender.

How to View or Export URLs Scanned by Microsoft Defender
Product
Microsoft Defender
Device & OS
Windows
Scenario
Attempting to retrieve a comprehensive historical record of web activity or URLs processed by the system's security scanner for auditing or troubleshooting.
Observed behavior
Microsoft Defender does not provide a complete list of every scanned URL; instead, it only logs detected threats, blocked content, quarantined items, and potentially compromised URLs.
Before you start

Ensure you have administrative privileges on your Windows computer, as accessing Microsoft Defender reports and Windows Event Viewer logs requires admin rights.

Solution 1Recommended

Check Microsoft Defender for Endpoint Reports

Use the Microsoft Defender portal to view alerts and details regarding detected malicious or compromised URLs.

While Microsoft Defender does not log every safe URL you visit, Microsoft Defender for Endpoint captures data on threats, blocked content, and quarantined items. This is the best native method for reviewing problematic web activity.

1
Open the Defender Portal

Navigate to the Microsoft 365 Defender portal in your web browser and sign in with your administrator credentials.

2
Access Alerts and Reports

Click on the 'Incidents & alerts' section, then select 'Alerts' to view recent security events triggered by web activity.

3
Filter Web Threats

Use the filtering options to narrow down the list to web-related threats, blocked content, or potentially compromised URLs.

4
Export the Data

Select the relevant alerts and click the 'Export' button (if available in your specific Defender tier) to download the detected URL information.

Check Microsoft Defender for Endpoint Reports
Configuration Required: If you require a complete historical record of all URLs for compliance purposes, you must configure advanced auditing, network protection, or implement a dedicated Endpoint Detection and Response (EDR) solution before the web activity occurs.
Free Microsoft Office alternative

Secure and Manage Your Documents with WPS Office

While managing your system's security settings and Defender logs, you may also need a reliable office suite. WPS Office is a free, lightweight, and highly compatible alternative to Microsoft Office, offering seamless migration and a familiar interface.

  1. 1. Download the Installer: Visit the official WPS website and download the free installation package for Windows.
  2. 2. Install the Software: Run the downloaded installer and follow the simple on-screen instructions.
  3. 3. Open Your Files: Launch WPS Office and instantly open your existing Microsoft Office documents without any formatting loss.
Fully compatible with Microsoft Word, Excel, and PowerPoint formats.Lightweight design that minimizes system resource usage.Built-in PDF reader and editor for secure document handling.Familiar, easy-to-use user interface requiring no learning curve.
microsoft office alternative - wps office

Frequently Asked Questions

Does Microsoft Defender keep a log of every safe URL I visit?

No, Microsoft Defender does not maintain a complete historical log of all scanned URLs. It primarily logs URLs that are detected as threats, blocked by policy, or potentially compromised, in order to save system resources and respect user privacy.

Can I use third-party tools to track all scanned URLs?

Yes. If you need a comprehensive log of all web activity and scanned URLs, you should consider using dedicated Endpoint Detection and Response (EDR) tools or specialized web filtering software, which offer much more extensive logging than default Defender settings.

How do I enable logging for future web activity in Microsoft Defender?

To capture more detailed web activity moving forward, you need to configure Network Protection and Web Content Filtering within Microsoft Defender for Endpoint. Make sure auditing and data retention policies are actively configured before the activity takes place.