SmartScreen (officially called Microsoft Defender SmartScreen, and formerly Windows SmartScreen, Windows Defender SmartScreen and SmartScreen Filter in different places) is a cloud-based anti-phishing and anti-malware component included in several Microsoft products:
All versions of the Microsoft Windows operating system since Windows 8 Web browsers Internet Explorer and Microsoft Edge Xbox One and Xbox Series X and Series S video game consoles Online services Microsoft 365 (including Microsoft Outlook and Exchange) and Microsoft Bing. SmartScreen as a business unit includes the intelligence platform, backend, serving frontend, UX, policy, expert graders, and closed-loop intelligence (machine learning and statistical techniques) designed to help protect customers from safety threats like social engineering and drive-by downloads.
SmartScreen in Internet Explorer
Internet Explorer 7: Phishing Filter SmartScreen was first introduced in Internet Explorer 7, then known as the Phishing Filter. Phishing Filter does not check every website visited by the user, only those that are known to be suspicious.
Internet Explorer 8: SmartScreen Filter With the release of Internet Explorer 8, the Phishing Filter was renamed to SmartScreen and extended to include protection from socially engineered malware. Every website and download is checked against a local list of popular legitimate websites; if the site is not listed, the entire address is sent to Microsoft for further checks. If it has been labeled as an impostor or harmful, Internet Explorer 8 will show a screen prompting that the site is reported harmful and shouldn't be visited. From there the user can either visit their homepage, visit the previous site, or continue to the unsafe page. If a user attempts to download a file from a location reported harmful, then the download is cancelled. The effectiveness of SmartScreen filtering has been reported to be superior to socially engineered malware protection in other browsers. According to Microsoft, the SmartScreen technology used by Internet Explorer 8 was successful against phishing or other malicious sites and in blocking of socially engineered malware. Beginning with Internet Explorer 8, SmartScreen can be enforced using Group Policy.
Internet Explorer 9: Application Reputation In Internet Explorer 9, SmartScreen added protection against malware downloads by launching SmartScreen Application Reputation to identify both safe and malicious software. The system blocked known malware while warning the user if an executable was not yet known to be safe. The system took into account the download website’s reputation based on SmartScreen’s phishing filter launched in prior web browser versions Internet Explorer 7 and Internet Explorer 8.
Internet Explorer Mobile 10 Internet Explorer Mobile 10 was the first release of Internet Explorer Mobile to support the SmartScreen Filter.
Microsoft Edge
Chromium-based Microsoft Edge includes Microsoft Defender SmartScreen for website and download reputation checks, extending protections first introduced in Internet Explorer. Microsoft Edge Legacy, the original Edge browser built on Microsoft's proprietary engine and shipped with early Windows 10 releases, also included SmartScreen before it was replaced by the Chromium-based browser in 2020. From 2024 onward, Microsoft added Edge-specific protections that complement SmartScreen's cloud reputation service. At Microsoft Ignite 2024, Microsoft announced a scareware blocker that uses a local machine learning model to detect full-screen tech support scam pages before they are indexed by SmartScreen. The feature entered public preview in January 2025 and was enabled by default on most Windows and Mac devices by late 2025. Starting in Microsoft Edge version 142 (November 2025), a scareware sensor can notify SmartScreen immediately when the scareware blocker detects a suspicious full-screen page, without sending screenshots or data beyond what SmartScreen already receives, helping block newly reported scams worldwide more quickly. The sensor was disabled by default as of its introduction; Microsoft stated it intended to enable it for users who have SmartScreen turned on.
Addressed criticisms In October 2017, criticisms regarding URL submission methods were addressed with the creation of the Report unsafe site URL submission page. Prior to 2017, Microsoft required a user to visit a potentially dangerous website to use the in-browser reporting tool, potentially exposing users to dangerous web content. In 2017, Microsoft reversed that policy by adding the URL submission page, allowing a user to submit an arbitrary URL without having to visit the website. SmartScreen Filter in Microsoft Outlook was previously bypassable due to a data gap in Internet Explorer. Some phishing attacks use a phishing email linking to a front-end URL unknown to Microsoft; clicking this URL in the inbox opens the URL in Internet Explorer; the loaded website then, using client-side or server-side redirections, redirects the user to the malicious site. In the original implementation of SmartScreen, the "Report this website" option in Internet Explorer only reported the currently-open page (the final URL in the redirect chain); the original referrer URL in the phishing attack was not reported to Microsoft and remained accessible. This was mitigated beginning with some versions of Microsoft Edge Legacy by sending the full redirection chain to Microsoft for further analysis.
Deprecation in Internet Explorer and IE Mode
Starting with updates released in November 2025 for Windows 11 version 24H2 and later (including Windows Server 2025), Microsoft deprecated SmartScreen in Internet Explorer and Internet Explorer mode on Windows 11. SmartScreen remains active in Microsoft Edge, the Windows shell, and other supported environments, and continues to function in Internet Explorer and IE Mode on older Windows versions. Files downloaded through IE or IE Mode on Windows 11 still receive Mark of the Web tagging; when opened, they are evaluated by SmartScreen in the Windows shell. Microsoft stated that SmartScreen in IE Mode was redundant for its intended use on enterprise-configured trusted intranet sites, and that retaining legacy SmartScreen components in IE would have caused instability after related infrastructure was removed.
SmartScreen in Windows
… excerpt ends here. Continue reading the full article.
