Review Files That Microsoft Defender Will Send to Microsoft: Safe Response

Brendan Smith
Brendan Smith - Cybersecurity Analyst
13 Min Read
A document stops at a cloud consent gate before Microsoft Defender sample submission.
A Defender sample request is a privacy and security decision, not an automatic malware verdict.

“Review files that Microsoft Defender will send to Microsoft” is a cloud-analysis request, not by itself a malware detection. When the notification opens the Windows Security app, Defender is asking permission to submit one or more files because cloud metadata did not produce a conclusive verdict. The request does not prove the file is malicious, and clicking Send files is not the same as allowing, restoring, or running it. Review the path and file type first, then check Protection History for a separate named detection.

  • Verify the source: use the Review button or open Windows Security from Start; a browser page with a phone number is not this workflow.
  • Check what would leave the PC: do not submit a document, configuration file, archive, database, or project file until you know it contains no private data or secrets.
  • Separate the signals: a sample request asks for more evidence; a named item in Protection History is a different security decision.
  • Keep protection on: do not add a broad exclusion or disable cloud protection merely to silence the prompt.

What the Defender “Review files” prompt means

Microsoft Defender Antivirus can ask its cloud service about an unfamiliar or suspicious file. Microsoft says the first query can use file and context metadata. If the cloud service still cannot decide whether the item is malware or not a threat, Defender can request a copy of the file for deeper analysis.

That explains why the request can appear after installing or updating a game, browser, creative app, driver utility, chat client, or developer tool. A newly written updater cache, configuration file, library, or executable may simply be uncommon. It can also be tampered with or come from the wrong source. The notification alone does not choose between those explanations.

What you find Risk and what to do
A newly created cache or update file under the expected signed vendor app, with no named detection A normal submission request is plausible. Verify the app and path, consider whether the file contains private data, then send or dismiss it deliberately.
A document, browser profile file, password export, developer configuration, project archive, or customer file Do not send it before reviewing the privacy risk. Dismiss the request, keep the file closed if its safety is unknown, and ask the owner, vendor, or IT team how to handle it.
An unknown download, crack, mod, script, attachment, or file that already ran Do not treat submission as permission to trust it. Keep it blocked, check Protection History, remove the untrusted source, and run a full scan.
Protection History shows a detection name, severity, affected item, and action Follow the detection response. Keep quarantine unless source, signature, behavior, and vendor evidence support a false positive.
The same request returns after reboot or every time one app starts Update Windows, Defender, and the app; record the repeated path and time; repair the trusted app or investigate what recreates the item.

Verify that the notification is really from Windows Security

  1. Open Windows Security independently. Use Start, search for Windows Security, and open Virus & threat protection. Do not rely on a web page that merely copies Microsoft branding.
  2. Use Review only to inspect the requested list. Record the file name, full path, extension, and the app or update you used just before the request. Do not open an unknown file to inspect its contents.
  3. Open Protection History separately. Look for an event at the same time. A card with an exact detection label and affected path requires a quarantine/restore decision; the sample request by itself does not supply that verdict. Our Microsoft Defender detection-name guide explains how to read those labels.
  4. Check the notification behavior. A real flow stays inside Windows Security. A browser tab, loud countdown, support phone number, payment request, or remote-access instruction matches a fake Defender security warning, not a normal sample-submission request.

The words can be copied by a scam, so the app destination matters more than the sentence alone. If the Review button does nothing, open Windows Security yourself and check recent events instead of clicking repeated toasts.

What privacy check should you make before sending a file?

Microsoft distinguishes the initial metadata query from a full file sample. Its current documentation says the small metadata payload is intended not to include personally identifiable information and that information such as filenames is hashed. If Defender needs the file itself and the file type is likely to contain personal information, the default “send safe samples” mode asks for consent.

Consent still requires a human decision. A file can contain more than its name suggests. Before sending, ask whether it could hold:

  • passwords, API keys, session tokens, private keys, recovery codes, or authentication cookies;
  • customer records, work documents, legal or medical information, or other regulated data;
  • source code, unpublished research, internal scripts, build secrets, or proprietary configuration;
  • personal photos, messages, browser history, account data, or identifying file paths;
  • an archive or database whose contents you have not inspected safely.

If any of those are possible, choose Dismiss for now. Do not upload the same sensitive file to a public multi-scanner as a workaround. On a managed computer, send the path and notification time—not the file itself—to the security or IT team and follow the organization’s data-handling rules.

Should you click Send files or Dismiss?

Send files can be reasonable when the requested item is the expected file from a trusted update or installation, the path and publisher make sense, and you are comfortable sharing its contents for analysis. Submission gives Microsoft evidence for a verdict; it does not certify the file as safe and does not tell Windows to run it.

Dismiss is the safer temporary choice when the source is unknown, the file may contain private data, a named detection exists, or you cannot explain why the app created it. Dismissal also is not a clean verdict. Keep an unknown file closed while you verify the source.

If Defender or another security product has already named a detection and you believe the file is legitimate, collect the source, signer, hash, exact label, and affected path. Then use the false-positive reporting checklist and the official Microsoft submission route instead of restoring first or excluding an entire folder.

Why the review-files notification keeps coming back

A repeated request usually means the same item is being rewritten, a new item is appearing under the same app, or the previous submission did not resolve the local trigger. Do not jump straight to switching off automatic sample submission.

  1. Install current Windows updates and Microsoft Defender security intelligence.
  2. Update or repair the app that owns the requested path, using its official installer or built-in repair option.
  3. Restart Windows, then record the next requested path and exact time.
  4. If it is a trusted app cache, close the app and use the vendor’s documented cache-reset or reinstall procedure. Do not delete random Windows Security data.
  5. If the request changes files, appears after an unknown installer, returns with redirects or disabled settings, or is accompanied by a named detection, investigate it as a security problem rather than a notification problem.

The clean-scan popup checklist helps separate a stale Windows Security card, a browser imitation, and activity that recreates the same warning. Avoid adding exclusions for Downloads, AppData, Temp, an entire game folder, a browser profile, or a developer workspace just to stop the request. A broad exclusion can hide the next genuinely malicious file in that location.

When the request is a malware-cleanup signal

A one-time request for an expected vendor cache does not automatically call for a malware scan. A scan becomes appropriate when the file came from an untrusted source, already ran, has a named detection, returns after reboot, or appears with unexpected exclusions, startup entries, scheduled tasks, services, browser changes, redirects, or other symptoms.

In those cases, Defender may be showing one visible file while an updater, loader, task, service, browser component, exclusion, or bundled module keeps creating it. Run a full Microsoft Defender scan first. A follow-up Gridinsoft Anti-Malware scan can check for detections, hidden files, startup entries, scheduled tasks, bundled apps, browser changes, and persistence that may recreate the request. Remove confirmed detections, restart, and scan again if the activity returns. A clean result adds evidence but cannot prove that no compromise occurred.

Check what Defender may have left behind.

Defender can quarantine the visible file, but repeated alerts may mean a loader, scheduled task, service, browser change, or bundled component is recreating it. Scan the PC before trusting the cleanup.

Check the PC if the prompt keeps returning

If security settings changed or an unknown file ran, complete the Windows security audit after malware before trusting the device with important accounts.

FAQ

Does “Review files that Microsoft Defender will send” mean I have a virus?

No. It means Defender wants a file sample because the cloud service needs more evidence. A named detection in Protection History, the file source, path, signature, and repeat behavior are stronger risk signals.

Is it safe to click Send files?

It can be safe for an expected vendor file that contains no private data, but review the path and file type first. Do not send documents, archives, browser data, or configuration files that may contain passwords, tokens, customer data, or other secrets.

What happens if I click Dismiss?

Dismiss closes or postpones the request; it does not mark the file safe. Keep an unknown file closed and verify its source. The prompt may return if the same file is requested again or an app rewrites it.

Should I turn off Automatic sample submission?

Not as the first fix. Microsoft says disabling sample submission limits cloud file analysis and disables Block at First Sight sample analysis. Resolve the file, app, privacy, or recurrence reason instead of weakening protection globally.

Why does Defender ask about a trusted game or app update?

Updaters can create new or uncommon cache files, libraries, executables, and configuration data. That makes a normal cloud request plausible, but the app name alone is not proof. Verify the vendor, path, signer, and Protection History before deciding.

References

  1. Microsoft. “Cloud protection and sample submission at Microsoft Defender Antivirus.” Microsoft Learn, updated October 20, 2025, accessed August 20, 2026. Microsoft Defender cloud protection and sample submission.
  2. Microsoft. “Submit files for analysis.” Microsoft Learn, updated February 13, 2025, accessed August 20, 2026. Microsoft file-analysis submission guidance.
Share This Article
Cybersecurity Analyst
Follow:
Brendan Smith has spent over 15 years knee-deep in cybersecurity, chasing down malware from the gritty reverse-engineering of old-school trojans all the way to wrangling full-blown incident responses for small-to-medium businesses that couldn’t afford a full-blown breach. Over at Gridinsoft, he’s the guy piecing together those double-checked guides on nasty stuff like AsyncRAT ransomware—take last year, for instance, when his breakdowns caught more than 200 sneaky variants right in live scans, knocking user cleanup jobs down by a solid 40% and saving folks hours of headache.
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?