To minimize the impact that on-access scans have on a system, select options to avoid impacting system performance and scan only what you need to.
Tip
Best practice: For information about troubleshooting high CPU usage with the on-access scanner, see KB89354. For suggestions on how to improve Endpoint Security performance, see KB88205.
Choose performance options
Some scan options can negatively affect system performance. For this reason, select these options only if you need to scan specific items. Select or deselect these options in the On-Access Scan settings.
Scan processes on service startup and content update — Rescans all processes that are currently in memory each time:
You re-enable on-access scans.
Content files are updated.
The Threat Prevention service starts.
The system starts.
Because some programs or executables start automatically when you start your system, deselect this option to improve system startup time.
Scan trusted installers — Scans MSI files (installed by msiexec.exe and signed by Trellix or Microsoft) or Windows Trusted Installer service files.
Deselect this option to improve the performance of large Microsoft application installers.
Scan only what you need to
Scanning some types of files can negatively affect system performance. For this reason, select these options only if you need to scan specific types of files. Select or deselect these options in the What to Scan section of the On-Access Scan settings.
On network drives — Scans resources on mapped network drives.
If you deselect this option, Adaptive Threat Protection won't scan files on network drives.
Opened for backups — Scans files when accessed by backup software.
For most environments, you don't need to select this setting.
Compressed archive files —
Even if an archive contains infected files, the files can't infect the system until the archive is extracted. Once the archive is extracted, the On-Access Scan examines the files and detects any malware.
Tip
For information about solving slow performance with Java-based applications, see KB58727.