Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
This page contains archived platform-specific build and version history for Microsoft Defender for Endpoint components. For current releases, see Microsoft Defender for Endpoint release notes. For archived feature announcements, see What's new in Microsoft Defender for Endpoint archive.
Windows releases
May-2024 (Release version: 10.8750.27558.1004)
| OS | KB | Release version |
|---|---|---|
| Windows Server 2012 R2, 2016 | KB5005292 | 10.8750.27558.1004 |
What's new
Configuration Management
- Fixed an issue that caused empty policies to appear in the UI.
- Configured Windows Defender Application Control (WDAC) policies to block undesired applications from running on the device.
Feb-2024 (Release version: 10.8735.26020.1009)
| OS | KB | Release version |
|---|---|---|
| Windows Server 2012 R2, 2016 | KB5005292 | 10.8735.26020.1009 |
What's new
Endpoint Detection and Response
- Enabled support for IPV6 connections in Live Response connection commands.
- Fixed an issue in Downlevel Unified Agent that caused ServerRoles not to be populated.
Threat Vulnerability Management
- An issue related to the agent's monitoring of deleted registry keys no longer occurs.
- Added a new capability to enable/disable registry monitoring through configuration settings.
Network Detection and Response (NDR) Performance Enhancements
- Introduced performance enhancements to minimize the CPU and memory footprint of the agent.
- Enhanced the accuracy of network detections.
Data Loss Prevention (DLP)
- Introduced multiple performance and stability fixes.
Security Configuration Management
- Policies that include special characters are now supported.
Dec-2023 (Release version: 10.8672.25926.1019)
| OS | KB | Release version |
|---|---|---|
| Windows Server 2012 R2, 2016 | KB5005292 | 10.8672.25926.1019 |
What's new
- Supports Expanded User Contain capabilities
Sept-2023 (Release version: 10.8560.25364.1036)
| OS | KB | Release version |
|---|---|---|
| Windows Server 2012 R2, 2016 | KB5005292 | 10.8560.25364.1036 |
What's new
- Supports User Contain availability
May-2023 (Release version: 10.8295.22621.1023)
| OS | KB | Release version |
|---|---|---|
| Windows Server 2012 R2, 2016 | KB5005292 | 10.8295.22621.1023 |
What's new
- Supports new security settings management capabilities
Jan/Feb-2023 (Release version: 10.8295.22621.1019)
| OS | KB | Release version |
|---|---|---|
| Windows Server 2012 R2, 2016 | KB5005292 | 10.8295.22621.1019 |
What's new
- Improved command and control security, quality fixes
Dec-2022 (Release version: 10.8210.22621.1016)
| OS | KB | Release version |
|---|---|---|
| Windows Server 2012 R2, 2016 | KB5005292 | 10.8210.22621.1016 |
What's new
- Bug fixes and stability improvements
Aug-2022 (Release version: 10.8210.*)
| OS | KB | Release version |
|---|---|---|
| Windows Server 2012 R2, 2016 | KB5005292 | 10.8210.22621.1011 |
| Windows 11 21H2 (Cobalt) (Windows 11 SV 21H2) |
KB5016691 | 10.8210.22000.918 |
| Server 2022 (Iron) | KB5016693 | 10.8210.20348.946 |
| Windows 10 20H2/21H1/21H2 Windows Server 20H2 (Vibranium) |
KB5016688 | 10.8210.19041.1949 |
| Windows Server 2019 (RS5) | KB5016690 | 10.8210.17763.3346 |
What's new
- Added a fix to resolve a missing intermediate certificate issue with the use of "TelemetryProxyServer" on Windows Server 2012 R2 running the unified agent.
- Enhanced Endpoint DLP with ability to protect password protected and encrypted files and not label files.
- Enhanced Endpoint DLP with support for context data in audit telemetry (short evidence).
- Improved Microsoft Defender for Endpoint client authentication support for VDI devices.
- Enhanced Microsoft Defender for Endpoint's ability to identify and intercept ransomware and advanced attacks.
- The Contain feature now supports more desktop and server versions to perform contain actions and block discovered devices when such devices are contained.
- Expanded the troubleshooting mode feature to more desktop and server versions. For a complete list of supported OS versions and more information about prerequisites, see Get started with troubleshooting mode in Microsoft Defender for Endpoint.
- Live Response improvements include reduced session creation latency when using proxies, an undo remediation manual command, support for OneDrive shares in
FindFileaction, and improved isolation and stability. - Security Management for Microsoft Defender for Endpoint now provides the ability to sync the device configuration on demand instead of waiting for a specific cadence.
Note
Update package KB5005292 is on a gradual rollout schedule through Windows Update. Towards the end of this schedule, the package will be published completely, including to the update catalog for manual download. For the current release, this will be in the second half of October. If you want to test the package sooner, you can use gradual rollout controls for platform updates to select the Preview channel.
macOS releases
macOS | August 2025 | 101.25062.0006
Release details
| Release version | Engine version | Signature version |
|---|---|---|
| 20.125062.6.0 | 1.1.25070.3000 | 1.435.357.0 |
Enhancements and features
| Feature area | Update summary |
|---|---|
| General | Bug and performance fixes. |
Jul-2025 (Build: 101.25062.0005 | Release version: 20.125062.5.0)
| Build: | 101.25062.0005 |
|---|---|
| Release version: | 20.125062.5.0 |
| Engine version: | 1.1.25040.3000 |
| Signature version: | 1.427.248.0 |
What's new
- Bug and performance fixes
Jun-2025 (Build: 101.25052.0012 | Release version: 20.125052.12.0)
| Build: | 101.25052.0012 |
|---|---|
| Release version: | 20.125052.12.0 |
| Engine version: | 1.1.25060.3000 |
| Signature version: | 1.431.226.0 |
What's new
- Bug and performance fixes
May-2025 (Build: 101.25042.0009 | Release version: 20.125042.9.0)
| Build: | 101.25042.0009 |
|---|---|
| Release version: | 20.125042.9.0 |
| Engine version: | 1.1.25040.3000 |
| Signature version: | 1.429.521.0 |
What's new
mdatp health --details edrnow includes Azure Active Directory information- Bug and performance fixes
Apr-2025 (Build: 101.25032.0006 | Release version: 20.125032.6.0)
| Build: | 101.25032.0006 |
|---|---|
| Release version: | 20.125032.6.0 |
| Engine version: | 1.1.25020.3000 |
| Signature version: | 1.427.158.0 |
What's new
- Hardware UUID is now displayed in the Security Portal
- Bug and performance fixes
- (GA) Behavior Monitoring for macOS: For information on Behavior Monitoring for Microsoft Defender for Endpoint on macOS, see Behavior Monitoring in Microsoft Defender for Endpoint on macOS.
Mar-2025 (Build: 101.25022.0003 | Release version: 20.125022.3.0)
| Build: | 101.25022.0003 |
|---|---|
| Release version: | 20.125022.3.0 |
| Engine version: | 1.1.24090.12 |
| Signature version: | 1.423.249.0 |
What's new
- Bug and performance fixes
Mar-2025 (Build: 101.25012.0008 | Release version: 20.125012.7.0)
| Build: | 101.25012.0008 |
|---|---|
| Release version: | 20.125012.7.0 |
| Engine version: | 1.1.25020.3000 |
| Signature version: | 1.423.211.0 |
What's new
- Bug fixes and performance improvements
Feb-2025 (Build: 101.24122.0011 | Release version: 20.124122.11.0)
| Build: | 101.24122.0011 |
|---|---|
| Release version: | 20.124122.11.0 |
| Engine version: | 1.1.24080.11 |
| Signature version: | 1.419.351.0 |
What's new
- Fixed an issue with the auth prompt during new installation on macOS with multiple active users
- Improved stability when using the antivirus engine in passive mode
Jan-2025 (Build: 101.24122.0005 | Release version: 20.124122.5.0)
| Build: | 101.24122.0005 |
|---|---|
| Release version: | 20.124122.4.0 |
| Engine version: | 1.1.24080.11 |
| Signature version: | 1.419.351.0 |
What's new
- Removed support of macOS 12, the minimal requirement is now macOS 13.0 or later
- Fix: Defender quarantines a file even if it's marked as immutable
mdatp healthcan returnout_of_datestatus fordefinitions_status- Bug and performance fixes
Dec-2024 (Build: 101.24102.0018 | Release version: 20.124102.18.0)
| Build: | 101.24102.0018 |
|---|---|
| Release version: | 20.124102.18.0 |
| Engine version: | 1.1.24080.10 |
| Signature version: | 1.419.298.0 |
What's new
- Improved User/Group Permission Handling - Added reporting in
mdatp-healthfor user/group permission issues for Defender files. On restart Defender attempts to cure these issues. - Bug and performance fixes.
Oct-2024 (Build: 101.24092.0004 | Release version: 20.124092.4.0)
| Build: | 101.24092.0004 |
|---|---|
| Release version: | 20.124092.4.0 |
| Engine version: | 1.1.24080.11 |
| Signature version: | 1.421.14.0 |
What's new
- Bug and performance fixes
Oct-2024 (Build: 101.24082.0009 | Release version: 20.124082.9.0)
| Build: | 101.24082.0009 |
|---|---|
| Release version: | 20.124082.9.0 |
| Engine version: | 1.1.24080.9 |
| Signature version: | 1.411.410.0 |
What's new
- Product improvements and performance fixes
Sep-2024 (Build: 101.24072.0007 | Release version: 20.124072.7)
| Build: | 101.24072.0007 |
|---|---|
| Release version: | 20.124072.7 |
| Engine version: | 1.1.24080.9 |
| Signature version: | 1.411.410.0 |
What's new
- Resolved the issue causing outdated vulnerability assessments impacting some macOS devices
Aug-2024 (Build: 101.24072.0006 | Release version: 20.124072.6.0)
| Build: | 101.24072.0006 |
|---|---|
| Release version: | 20.124072.6.0 |
| Engine version: | 1.1.24060.7 |
| Signature version: | 1.417.325.0 |
What's new
- Product improvements and performance fixes
Jul-2024 (Build: 101.24062.0009 | Release version: 20.124062.9.0)
| Build: | 101.24062.0009 |
|---|---|
| Release version: | 20.124062.9.0 |
| Engine version: | 1.1.24050.7 |
| Signature version: | 1.411.410.0 |
What's new
- Product improvements and performance fixes
Jun-2024 (Build: 101.24052.0013 | Release version: 20.124052.13.0)
| Build: | 101.24052.0013 |
|---|---|
| Release version: | 20.124052.13.0 |
| Engine version: | 1.1.24040.2 |
| Signature version: | 1.411.153.0 |
What's new
- [device control] Secure Digital cards aren't recognized on newer macOS
- Product improvements and performance fixes
May-2024 (Build: 101.24042.0008 | Release version: 20.124042.8.0)
| Build: | 101.24042.0008 |
|---|---|
| Release version: | 20.124042.8.0 |
| Engine version: | 1.1.24040.1 |
| Signature version: | 1.413.13.0 |
What's new
- Product improvements and performance fixes
Apr-2024 (Build: 101.24032.0006 | Release version: 20.124032.06.0)
| Build: | 101.24032.0006 |
|---|---|
| Release version: | 20.124012.10.0 |
| Engine version: | 1.1.24030.4 |
| Signature version: | 1.407.521.0 |
What's new
Improvements to
mdatp threatcommandRemove Big Sur from supported versions of macOS
[device control] Fix Bluetooth support on Sonoma (see the note later in this section)
Product improvements and performance fixes
(GA) Troubleshooting mode for macOS. Troubleshooting mode helps you identify instances where antivirus might be causing issues with your applications or system resources. To learn more, see Troubleshooting mode in Microsoft Defender for Endpoint on macOS.
Mar-2024 (Build: 101.24012.0010 | Release version: 20.124012.10.0)
| Build: | 101.24012.0010 |
|---|---|
| Release version: | 20.124012.10.0 |
| Engine version: | 1.1.24020.3 |
| Signature version: | 1.405.788.0 |
What's new
- Product improvements and performance fixes
- (GA) Built-in Scheduled Scan for macOS: For information on Scheduled Scan built-in for Microsoft Defender for Endpoint on macOS, see How to schedule scans with Microsoft Defender for Endpoint on macOS.
Jan-2024 (Build: 101.23122.0005 | Release version: 20.123122.5.0)
| Build: | 101.23122.0005 |
|---|---|
| Release version: | 20.123122.5.0 |
| Engine version: | 1.1.23100.2010 |
| Signature version: | 1.403.3022.0 |
What's new
- [device control] Fixes for Bluetooth devices support
- Product improvements and performance fixes
Dec-2023 (Build: 101.23102.0020 | Release version: 20.123102.20.0)
| Build: | 101.23102.0020 |
|---|---|
| Release version: | 20.123102.20.0 |
| Engine version: | 1.1.23090.2005 |
| Signature version: | 1.401.1729.0 |
What's new
- Product improvements and performance fixes
Nov-2023 (Build: 101.23092.0007 | Release version: 20.123092.7.0)
| Build: | 101.23092.0007 |
|---|---|
| Release version: | 20.123092.7.0 |
| Engine version: | 1.1.23090.2005 |
| Signature version: | 1.399.1196.0 |
What's new
- [device control] set policy for DCv2 via 'mdatp config'
- Configuration loading - error logged to /Library/Logs/Microsoft/mdatp/microsoft_defender_core_err.log includes bad property name in JSON
Note
If you use Device Control v1, consider migrating to v2 (that includes all v1 functionality and more).
Device Control v1 will be considered deprecated in the nearest future.
To check, run the [mdatp health --details device_control](mac-device-control-overview.md#status) command, and inspect the active property. It shouldn't contain "v1".
Oct-2023 (Build: 101.23082.0018 | Release version: 20.123082.18.0)
| Build: | 101.23082.0018 |
|---|---|
| Release version: | 20.123082.18.0 |
| Engine version: | 1.1.23070.1002 |
| Signature version: | 1.399.384.0 |
What's new
- [device control] Detailed status with
mdatp health --details device_control - [device control]
mdatp config device-control policyto set policy on a nonmanaged machine - Product improvements and performance fixes
Sep-2023 (Build: 101.23072.0025 | Release version: 20.123072.25.0)
| Build: | 101.23072.0025 |
|---|---|
| Release version: | 20.123072.25.0 |
| Engine version: | 1.1.23050.3 |
| Signature version: | 1.397.911.0 |
What's new
- Product improvements and performance fixes
- Fix: Security Portal events might have missed ancestors details for short lived processes
- Fix: Major performance issues on macOS when Network Protection is set to Audit mode
- (GA) macOS devices receive built-in protection. Tamper protection is turned on in block mode by default. This setting helps secure your Mac against threats. To learn more, see Protect macOS security settings with tamper protection.
Aug-2023 (Build: 101.23062.0016 | Release version: 20.123062.16.0)
| Build: | 101.23062.0016 |
|---|---|
| Release version: | 20.123062.16.0 |
| Engine version: | 1.1.23050.3 |
| Signature version: | 1.395.436.0 |
What's new
- Product improvements and performance fixes
- Fix: macOS complains that uninstall background task is from unidentified developer
Jul-2023 (Build: 101.23052.0004 | Release version: 20.123052.4.0)
| Build: | 101.23052.0004 |
|---|---|
| Release version: | 20.123052.4.0 |
| Engine version: | 1.1.20100.7 |
| Signature version: | 1.391.2163.0 |
What's new
- Client version schema change
- Fix: Defender doesn't start on a machine with certain versions of Microsoft Edge due to directory permission issue
- Product improvements and performance fixes
Jun-2023 (Build: 101.98.84 | Release version: 20.123042.19884.0)
| Build: | 101.98.84 |
|---|---|
| Release version: | 20.123042.19884.0 |
| Engine version: | 1.1.20300.4 |
| Signature version: | 1.391.221.0 |
What's new
- System Extensions health command
mdatp health --details system_extensions - Product improvements and performance fixes
- (GA) Network protection available for macOS
Network protection for macOS is now available for all Mac devices onboarded to Defender for Endpoint. Devices must meet the minimum requirements. To learn more, see Use network protection to help prevent macOS connections to bad sites.
May-2023 (Build: 101.98.71 | Release version: 20.123032.19871.0)
| Build: | 101.98.71 |
|---|---|
| Release version: | 20.123032.19871.0 |
| Engine version: | 1.1.20300.4 |
| Signature version: | 1.389.1872.0 |
What's new
- Tamper Protection health command
mdatp health --details tamper_protection - Tamper Protection - MDM processes exclusions
- Fix: Remove Codesigned Artifact from App Bundle
- Product improvements and performance fixes
May-2023 (Build: 101.98.70 | Release version: 20.123022.19870.0)
| Build: | 101.98.70 |
|---|---|
| Release version: | 20.123022.19870.0 |
| Engine version: | 1.1.20300.4 |
| Signature version: | 1.389.1396.0 |
What's new
- Product improvements and performance fixes
Mar-2023 (Build: 101.98.30 | Release version: 20.123012.19830.0)
| Build: | 101.98.30 |
|---|---|
| Release version: | 20.123012.19830.0 |
| Engine version: | 1.1.20100.6 |
| Signature version: | 1.385.924.0 |
What's new
- Product improvements and performance fixes
Feb-2023 (Build: 101.97.94 | Release version: 20.123011.19794.0)
| Build: | 101.97.94 |
|---|---|
| Release version: | 20.123011.19794.0 |
| Engine version: | 1.1.20000.2 |
| Signature version: | 1.383.104.0 |
What's new
- Improved performance, stability, and security
- Product improvements
- Discontinued support macOS Catalina [10.15]
Jan-2023
What's new
- (GA) Live Response available for macOS
Live Response for macOS is now available for all Mac devices onboarded to Defender for Endpoint. Devices must meet the minimum requirements. To learn more, see Investigate entities on devices using live response
Nov-2022 (Build: 101.87.30 | Release version: 20.122082.18681.0)
Released: Nov 5, 2022
Published: Nov 5, 2022
Build: 101.87.30
Release version: 20.122082.18681.0
Engine version: 1.1.19700.3
Signature version: 1.379.17.0
What's new
- Fix for some users experiencing performance issues and temporary system hangs
- Product improvements and performance fixes
Oct-2022 (Build: 101.86.81 | Release version: 20.122082.18681.0)
Released: Oct 25, 2022
Published: Oct 25, 2022
Build: 101.86.81
Release version: 20.122082.18681.0
Engine version: 1.1.19700.3
Signature version: 1.377.636.0
What's new
- Issue resolution: Upgrade fails if
\_mdatpuser is a member of\_lpadmingroup
Important
This is a minimal recommended MDE version for macOS Ventura.
Oct-2022 (Build: 101.82.21 | Release version: 20.122082.18221.0)
Build: 101.82.21
Release version: 20.122082.18221.0
Engine version: 1.1.19400.3
Signature version: 1.369.962.0
What's new
- Fix - macOS TP in Block mode causing device hang on shutdown/crashes on reboot
- Add a mdatp command-line switch to view the on-demand scan history
- Improve Performance of Device Owner on macOS
- Ready for macOS Ventura (13.0)
- Fixes for product and performance issues
Sep-2022 (Build: 101.78.13)
Build: 101.78.13
Release version: 20.122072.17813.0
Engine version: 1.1.19500.2
Signature version: 1.373.556.0
What's new
- Fix for uninstaller to properly delete Application Support folder
- Fix for Network Protection not filtering Safari when Firewall or iCloud Private Relay is on
- Fix for osqueryui zombie processes
- Fix for UI crash on Ventura
- Fix for definitions not getting downloaded right after install
- Other Product improvements
Aug-2022 (Build: 101.75.90 | Release version: 20.122071.17590.0)
Released: Aug 3, 2022
Published: Aug 3, 2022
Build: 101.75.90
Release version: 20.122071.17590.0
Engine version: 1.1.19300.3
Signature version: 1.369.395.0
What's new
- Added a new field in the output of
mdatp healththat can be used to query the enforcement level of the network protection feature. The new field is callednetwork_protection_enforcement_leveland can take one of the following values:audit,block, ordisabled. - Addressed a product issue where multiple detections of the same content could lead to duplicate entries in the threat history.
- Other product improvements.
Jul-2022 (Build: 101.73.77 | Release version: 20.122062.17377.0)
Released: Jul 21, 2022
Published: Jul 21, 2022
Build: 101.73.77
Release version: 20.122062.17377.0
Engine version: 1.1.19200.3
Signature version: 1.367.1011.0
What's new
- Addressed an issue where printing couldn't be completed successfully due to the network extension
- Added an option to configure file hash computation
- From this build onwards, the product has the new anti-malware engine by default
- Performance improvements for file copy operations
- Product improvements
Jul-2022 (Build: 101.71.18 | Release version: 20.122052.17118.0)
Released: Jul 7, 2022
Published: Jul 7, 2022
Build: 101.71.18
Release version: 20.122052.17118.0
What's new
mdatp connectivity testadded an extra URL. The new URL is https://go.microsoft.com/fwlink/?linkid=2144709.- Up until now, the product log level didn't persist between product restarts. Beginning in this version, there's a new command-line tool switch that persists the log level. The new command is
mdatp log level persist --level <level>. - Resolved an issue in the product installation package that in rare cases could lead a loss of product state during updates
- Performance improvements for file copy operations and built-in macOS applications
- Product improvements
Jun-2022 (Build: 101.70.19 | Release version: 20.122051.17019.0)
Released: Jun 14, 2022
Published: Jun 14, 2022
Build: 101.70.19
Release version: 20.122051.17019.0
What's new
- Resolved an issue where threat-related notifications weren't always presented to the end user.
- Performance improvements & other updates.
Jun-2022 (Build: 101.70.18 | Release version: 20.122042.17018.0)
Released: Jun 2, 2022
Published: Jun 2, 2022
Build: 101.70.18
Release version: 20.122042.17018.0
What's new
- Resolved an issue where the installation package was sometimes hanging indefinitely during product updates
- Resolved an issue where the product sometimes was incorrectly detecting files inside the quarantine folder
- Performance improvements & other product improvements
May-2022 (Build: 101.66.54 | Release version: 20.122041.16654.0)
Released: May 11, 2022
Published: May 11, 2022
Build: 101.66.54
Release version: 20.122041.16654.0
What's new
- Addressed an issue where
mdatp diagnostic real-time-protection-statisticswasn't printing the correct process path in some cases. - Product improvements
Apr-2022 (Build: 101.64.15 | Release version: 20.122032.16415.0)
Released: Apr 26, 2022
Published: Apr 26, 2022
Build: 101.64.15
Release version: 20.122032.16415.0
What's new
- Fixed a regression introduced in version 101.61.69 where the status menu icon was sometimes showing an error icon, even though no action was required from the end user
- Improved the
conflicting_applicationsfield inmdatp healthto show only the most recent 10 processes and also to include the process names. This improvement makes it easier to identify which processes are potentially conflicting with Microsoft Defender for Endpoint for macOS. - Resolved an issue in
mdatp device-control removable-media policy listwhere vendor ID and product ID were displayed as decimal instead of hexadecimal - Performance improvements & other product improvements
Mar-2022 (Build: 101.61.69 | Release version: 20.122022.16169.0)
Released: Mar 25, 2022
Published: Mar 25, 2022
Build: 101.61.69
Release version: 20.122022.16169.0
What's new
- Product improvements
Mar-2022 (Build: 101.60.91 | Release version: 20.122021.16091.0)
Released: Mar 8, 2022
Published: Mar 8, 2022
Build: 101.60.91
Release version: 20.122021.16091.0
What's new
- This version contains a security update for CVE-2022-23278
Feb-2022 (Build: 101.59.50 | Release version: 20.122021.15950.0)
Released: Feb 28, 2022
Published: Feb 28, 2022
Build: 101.59.50
Release version: 20.122021.15950.0
What's new
- This version adds support for macOS 12.3. Starting with macOS 12.3, Apple is removing Python 2.7. There's no Python version preinstalled on macOS by default. ACTION NEEDED:
- Users must update Microsoft Defender for Endpoint for Mac to version 101.59.50 (or newer) before updating their devices to macOS Monterey 12.3 (or newer). This minimal version 101.59.50 is a prerequisite to eliminating Python-related issues with Microsoft Defender for Endpoint for macOS devices on macOS Monterey.
- For remote deployments, existing MDM setups must be updated to Microsoft Defender for Endpoint for macOS version 101.59.50 (or newer). Pushing via MDM an older Microsoft Defender for Endpoint for macOS version to macOS Monterey 12.3 (or newer) results in an installation failure.
Feb-2022 (Build: 101.59.10 | Release version: 20.122012.15910.0)
Released: Feb 22, 2022
Published: Feb 22, 2022
Build: 101.59.10
Release version: 20.122012.15910.0
What's new
- The command-line tool now supports restoring quarantined files to a location other than the one where the file was originally detected. Restoration can be done through
mdatp threat quarantine restore --id [threat-id] --path [destination-folder]. - Extended device control to handle devices connected over Thunderbolt 3
- Improved the handling of device control policies containing invalid vendor IDs and product IDs. Before this version, if the policy contained one or more invalid IDs, the entire policy was ignored. Beginning with this version, only the invalid portions of the policy are ignored. Issues with the policy are surfaced through
mdatp device-control removable-media policy list. - Product improvements
Feb-2022 (Build: 101.56.62 | Release version: 20.121122.15662.0)
Released: Feb 7, 2022
Published: Feb 7, 2022
Build: 101.56.62
Release version: 20.121122.15662.0
What's new
- Product improvements
Jan-2022 (Build: 101.56.35 | Release version: 20.121121.15635.0)
Released: Jan 30, 2022
Published: Jan 30, 2022
Build: 101.56.35
Release version: 20.121121.15635.0
What's new
- The application is renamed from Microsoft Defender ATP to Microsoft Defender. End users observe the following changes:
- The application installation path changed from
/Application/Microsoft Defender ATP.appto/Applications/Microsoft Defender.app. - Within the user experience, occurrences of Microsoft Defender ATP are replaced by Microsoft Defender
- The application installation path changed from
- Resolved an issue where some VPN applications couldn't connect due to the network content filter that is distributed with Microsoft Defender for Endpoint for macOS.
- Addressed an issue discovered in macOS 12.2 preview 2 where the installation package couldn't be opened due to a change in the operating system (OS) that prevents installation of packages with certain characteristics. While it appears that this OS change isn't included in the final release of macOS 12.2, it's likely that it will be reintroduced in a future macOS version. As such, we encourage all enterprise administrators to refresh the Microsoft Defender for Endpoint package in their management console to this product version (or a newer version).
- Addressed an issue seen on some M1 devices where the product was stuck with invalid anti-malware definitions and couldn't successfully update to a working set of definitions.
mdatp healthoutput has been extended with a more attribute calledfull_disk_access_enabledthat can be used to determine whether Full Disk Access has been granted to all components of Microsoft Defender for Endpoint for macOS.- Performance improvements & Product improvements
Jan-2022 (Build: 101.54.16 | Release version: 20.121111.15416.0)
Released: Jan 12, 2022
Published: Jan 12, 2022
Build: 101.54.16
Release version: 20.121111.15416.0
What's new
- macOS 10.14 (Mojave) is no longer supported
- After a product setting stops being managed by the administrator through MDM, it now reverts to the value it had before it was managed (the value configured locally by the end user or, if no such local value was explicitly provided, the default value used by the product). Prior to this change, after a setting stopped being managed, its managed value persisted and was still used by the product.
- Performance improvements & Product improvements
Nov-2021 (Build: 101.49.25)
Build: 101.49.25
Release version: 20.121092.14925.0
What's new
- Added a new switch to the command-line tool to control whether archives are scanned during on-demand scans. This can be configured through
mdatp config scan-archives --value [enabled/disabled]. By default, this is set to enabled. - Product improvements
Oct-2021 (Build: 101.47.27)
Build: 101.47.27
Release version: 20.121082.14727.0
What's new
- Fix for a system freeze occurring on shutdown on macOS Mojave and macOS Catalina.
Oct-2021 (Build: 101.43.84)
Build: 101.43.84
Release version: 20.121082.14384.0
What's new
- Candidate build for macOS 12 (Monterey)
- Product improvements
Sep-2021 (Build: 101.41.10)
Build: 101.41.10
Release version: 20.121072.14110.0
What's new
- Added new switches to the command-line tool:
- Control degree of parallelism for on-demand scans. This can be configured through
mdatp config maximum-on-demand-scan-threads --value [number-between-1-and-64]. By default, a degree of parallelism of 2 is used. - Control whether scans after security intelligence updates are enabled or disabled. This can be configured through
mdatp config scan-after-definition-update --value [enabled/disabled]. By default, this is set to enabled.
- Control degree of parallelism for on-demand scans. This can be configured through
- Changing the product log level now requires elevation.
- Performance improvements & Product improvements
Aug-2021 (Build: 101.40.84)
Build: 101.40.84
Release version: 20.121071.14084.0
What's new
- M1 chip native support
- Performance improvements & Product improvements
Jul-2021 (Build: 101.37.97)
Build: 101.37.97
Release version: 20.121062.13797.0
What's new
- Performance improvements & Product improvements
Jun-2021 (Build: 101.34.28)
Build: 101.34.28
Release version: 20.121061.13428.0
What's new
- Product improvements
Jun-2021 (Build: 101.34.27)
Build: 101.34.27
Release version: 20.121052.13427.0
What's new
- Product improvements
May-2021 (Build: 101.34.20)
Build: 101.34.20
Release version: 20.121051.13420.0
What's new
- Device control for macOS is now in general availability.
- Addressed an issue where a quick scan couldn't be started from the status menu on macOS 11 (Big Sur).
- Other Product improvements
Apr-2021 (Build: 101.32.69)
Build: 101.32.69
Release version: 20.121042.13269.0
What's new
- Addressed an issue where concurrent access to the keychain from Microsoft Defender for Endpoint and other applications can lead to keychain corruption.
Mar-2021 (Build: 101.29.64)
Build: 101.29.64
Release version: 20.121042.12964.0
What's new
- Starting with this version, threats detected during on-demand antivirus scans triggered through the command-line client are automatically remediated. Threats detected during scans triggered through the user interface still require manual action.
mdatp diagnostic real-time-protection-statisticsnow supports two other switches:--sort: sorts the output descending by total number of files scanned--top N: displays the top N results (only works if--sortis also specified)
- Performance improvements (specifically for when
YARNis used) & Product improvements
Feb-2021 (Build: 101.27.50)
Build: 101.27.50
Release version: 20.121022.12750.0
What's new
- Fix to accommodate for Apple certificate expiration for macOS Catalina and earlier. This fix restores Microsoft Defender Vulnerability Management (MDVM) functionality.
Feb-2021 (Build: 101.25.69)
Build: 101.25.69
Release version: 20.121022.12569.0
What's new
- Microsoft Defender for Endpoint on macOS is now available in preview for US Government customers. For more information, see Microsoft Defender for Endpoint for US Government customers.
- Performance improvements (specifically for the situation when the XCode Simulator app is used) & Product improvements.
Jan-2021 (Build: 101.23.64)
Build: 101.23.64
Release version: 20.121021.12364.0
What's new
- Added a new option to the command-line tool to view information about the last on-demand scan. To view information about the last on-demand scan, run
mdatp health --details antivirus. - Performance improvements & Product improvements
Dec-2020 (Build: 101.22.79)
Build: 101.22.79
Release version: 20.121012.12279.0
What's new
- Performance improvements & Product improvements
Nov-2020 (Build: 101.19.88)
Build: 101.19.88
Release version: 20.121011.11988.0
What's new
- Performance improvements & Product improvements
Nov-2020 (Build: 101.19.48)
Build: 101.19.48
Release version: 20.120121.11948.0
What's new
Note
The old command-line tool syntax has been deprecated with this release. For information on the new syntax, see Resources.
- Added a new command-line switch to disable the network extension:
mdatp system-extension network-filter disable. This command can be useful to troubleshoot networking issues that could be related to Microsoft Defender for Endpoint on Mac. - Performance improvements & Product improvements
Oct-2020 (Build: 101.19.21)
Build: 101.19.21
Release version: 20.120101.11921.0
What's new
- Product improvements
Oct-2020 (Build: 101.15.26)
Build: 101.15.26
Release version: 20.120102.11526.0
What's new
- Improved the reliability of the agent when running on macOS 11 Big Sur.
- Added a new command-line switch (
--ignore-exclusions) to ignore AV exclusions during custom scans (mdatp scan custom). - Performance improvements & Product improvements
Sep-2020 (Build: 101.13.75)
Build: 101.13.75
Release version: 20.120101.11375.0
What's new
- Removed conditions when Microsoft Defender for Endpoint was triggering a macOS 11 (Big Sur) issue that manifests into a kernel panic.
- Fixed a memory leak in the Endpoint Security system extension when running on macOS 11 (Big Sur).
- Product improvements
Aug-2020 (Build: 101.10.72)
Build: 101.10.72
What's new
- Product improvements
Jul-2020 (Build: 101.09.61)
Build: 101.09.61
What's new
- Added a new managed preference for disabling the option to send feedback.
- Status menu icon now shows a healthy state when the product settings are managed. Previously, the status menu icon was displaying a warning or error state, even though the product settings were managed by the administrator.
- Performance improvements & Product improvements
Jul-2020 (Build: 101.09.50)
Build: 101.09.50
What's new
- This product version is validated on macOS Big Sur 11 preview 9.
- The new syntax for the mdatp command-line tool is now the default one. For more information on the new syntax, see Resources for Microsoft Defender for Endpoint on macOS.
Note
The old command-line tool syntax will be removed from the product on January 1st, 2021.
- Extended
mdatp diagnostic createwith a new parameter (--path [directory]) that allows the diagnostic logs to be saved to a different directory. - Performance improvements & Product improvements
Jul-2020 (Build: 101.09.49)
Build: 101.09.49
What's new
- User interface improvements to differentiate exclusions that are managed by the IT administrator versus exclusions defined by the local user.
- Improved CPU utilization during on-demand scans.
- Performance improvements & Product improvements
Jun-2020 (Build: 101.07.23)
Build: 101.07.23
What's new
Added new fields to the output of
mdatp --healthfor checking the status of passive mode and the EDR group ID.Note
mdatp --healthwill be replaced withmdatp healthin a future product update.Resolved an issue where automatic sample submission wasn't marked as managed in the user interface.
Added new settings for controlling the retention of items in the antivirus scan history. You can now specify the number of days to retain items in the scan history and specify the maximum number of items in the scan history.
Product improvements
May-2020 (Build: 101.06.63)
Build: 101.06.63
What's new
- Addressed a performance regression introduced in version
101.05.17. The regression was introduced with the fix to eliminate the kernel panics some customers observed when accessing SMB shares. We reverted this code change and are investigating alternative ways to eliminate the kernel panics.
May-2020 (Build: 101.05.17)
Build: 101.05.17
What's new
Important
We're working on a new and enhanced syntax for the mdatp command-line tool. The new syntax is currently the default in the Insider Fast and Insider Slow update channels. We encourage you to familiarize yourself with this new syntax.
We continue supporting the old syntax in parallel with the new syntax and provide more communications around the deprecation plan for the old syntax in the upcoming months.
- Addressed a kernel panic that occurred sometimes when accessing SMB file shares.
- Performance improvements & Product improvements
Apr-2020 (Build: 101.05.16)
Build: 101.05.16
What's new
- Improvements to quick scan logic to significantly reduce the number of scanned files.
- Added autocompletion support for the command-line tool.
- Product improvements
Mar-2020 (Build: 101.03.12)
Build: 101.03.12
What's new
- Performance improvements & Product improvements
Feb-2020 (Build: 101.01.54)
Build: 101.01.54
What's new
- Improvements around compatibility with Time Machine
- Accessibility improvements
- Performance improvements & Product improvements
Jan-2020 (Build: 101.00.31)
Build: 101.00.31
What's new
- Improved product onboarding experience for Intune users
- Antivirus exclusions now support wildcards
- Added the ability to trigger antivirus scans from the macOS contextual menu. You can now right-click a file or a folder in Finder and select Scan with Microsoft Defender for Endpoint.
- In-place product downgrades are now explicitly disallowed by the installer. If you need to downgrade, first uninstall the existing version and reconfigure your device.
- Other performance improvements & Product improvements
2019 releases (Build: 100.90.27)
Build: 100.90.27
What's new
- You can now set an update channel for Microsoft Defender for Endpoint on macOS that is different from the system-wide update channel.
- New product icon
- Other user experience improvements
- Product improvements
2019 releases (Build: 100.86.92)
Build: 100.86.92
What's new
- Improvements around compatibility with Time Machine
- Addressed an issue where the product was sometimes not cleaning all files under
/Library/Application Support/Microsoft/Defenderduring uninstallation. - Reduced the CPU utilization of the product when Microsoft products are updated through Microsoft AutoUpdate.
- Other performance improvements & Product improvements
2019 releases (Build: 100.86.91)
Build: 100.86.91
What's new
Caution
To ensure the most complete protection for your macOS devices and in alignment with Apple stopping delivery of macOS native security updates to OS versions older than [current - 2], MDATP for macOS deployment and updates will no longer be supported on macOS Sierra [10.12]. MDATP for macOS updates and enhancements are delivered to devices running versions Catalina [10.15], Mojave [10.14], and High Sierra [10.13].
If you already have MDATP for macOS devices deployed to your Sierra [10.12] devices, upgrade to the latest macOS version to eliminate risks of losing protection.
- Performance improvements & Product improvements
2019 releases (Build: 100.83.73)
Build: 100.83.73
What's new
- Added more controls for IT administrators around management of exclusions, management of threat type settings, and disallowed threat actions.
- When Full Disk Access isn't enabled on the device, a warning is now displayed in the status menu.
- Performance improvements & Product improvements
2019 releases (Build: 100.82.60)
Build: 100.82.60
What's new
- Addressed an issue where the product fails to start following a definition update.
2019 releases (Build: 100.80.42)
Build: 100.80.42
What's new
- Product improvements
2019 releases (Build: 100.79.42)
Build: 100.79.42
What's new
Fixed an issue where Microsoft Defender for Endpoint on macOS was sometimes interfering with Time Machine.
Added a new switch to the command-line utility for testing the connectivity with the backend service
mdatp connectivity testAdded ability to view the full threat history in the user interface (can be accessed from the Protection history view).
Performance improvements & Product improvements
2019 releases (Build: 100.72.15)
Build: 100.72.15
What's new
- Product improvements
2019 releases (Build: 100.70.99)
Build: 100.70.99
What's new
- Addressed an issue that impacts the ability of some users to upgrade to macOS Catalina when real-time protection is enabled. This sporadic issue was caused by Microsoft Defender for Endpoint locking files within Catalina upgrade package while scanning them for threats, which led to failures in the upgrade sequence.
2019 releases (Build: 100.68.99)
Build: 100.68.99
What's new
- Added the ability to configure the antivirus functionality to run in passive mode.
- Performance improvements & Product improvements
2019 releases (Build: 100.65.28)
Build: 100.65.28
What's new
- Added support for macOS Catalina.
Caution
macOS 10.15 (Catalina) contains new security and privacy enhancements. Beginning with this version, by default, applications aren't able to access certain locations on disk (such as Documents, Downloads, Desktop, etc.) without explicit consent. In the absence of this consent, Microsoft Defender for Endpoint isn't able to fully protect your device. The mechanism for granting this consent depends on how you deployed Microsoft Defender for Endpoint:
- For manual deployments, see the updated instructions in the Manual deployment article.
- For managed deployments, see the updated instructions in the JAMF-based deployment and Microsoft Intune-based deployment articles.
- Performance improvements & Product improvements
Linux releases
July-2025 Build: 101.25052.0007 | Release version: 30.125052.0007.0
| Build: | 101.25052.0007 |
|---|---|
| Released: | July 22, 2025 |
| Published: | July 22, 2025 |
| Release version: | 30.125052.0007.0 |
| Engine version: | 1.1.25020.4000 |
| Signature version: | 1.427.370.0 |
What's new
- Fixed issue to generate unique Machine identifiers to ensure each onboarded device is uniquely identified.
- Other stability improvements and bug fixes.
June-2025 Build: 101.25042.0003 | Release version: 30.125042.0003.0
| Build: | 101.25042.0003 |
|---|---|
| Released: | June 30, 2025 |
| Published: | June 30, 2025 |
| Release version: | 30.125042.0003.0 |
| Engine version: | 1.1.25020.4000 |
| Signature version: | 1.427.370.0 |
What's new
- The Defender for Endpoint package rollout into production happens gradually. From the time the release notes are published, it might take up to a week for the package to be pushed to all production machines.
- Removed external dependency of uuid-runtime from the Defender for Endpoint package
- Other stability improvements and bug fixes
May-2025 Build: 101.25032.0010 | Release version: 30.125032.0010.0
| Build: | 101.25032.0010 |
|---|---|
| Released: | May 23, 2025 |
| Published: | May 23, 2025 |
| Release version: | 30.125032.0010.0 |
| Engine version: | 1.1.25020.4000 |
| Signature version: | 1.427.370.0 |
What's new
Removed external dependency of MDE Netfilter and libpcre from MDE package
Fix for Python script executing unverified binaries with root-level privileges to identify Java processes using outdated versions of log4j (CVE-2025-26684) has been addressed.
Added detection mechanism for CVE-2025-31324 affecting the "Visual Composer" component of the SAP NetWeaver application server.
April-2025 Build: 101.25022.0002 | Release version: 30.125022.0001.0
| Build: | 101.25022.0002 |
|---|---|
| Released: | April 07, 2025 |
| Published: | April 07, 2025 |
| Release version: | 30.125022.0001.0 |
| Engine version: | 1.1.24090.13 |
| Signature version: | 1.421.226.0 |
What's new
mdatp diagnostic ebpf-statistics command requires sudo privilege now
Manage dynamic signature file share source by setting URL and update interval
Other stability improvements and bug fixes
Support for ARM64 Linux servers
Mar-2025 Build: 101.25012.0000 | Release version: 30.125012.0000.0
| Build: | 101.25012.0000 |
|---|---|
| Released: | March 11, 2025 |
| Published: | March 11, 2025 |
| Release version: | 30.125012.0000.0 |
| Engine version: | 1.1.24090.13 |
| Signature version: | 1.421.226.0 |
What's new
The MDATP package rollout into production will be done gradually. From the time the release notes are published, it might take up to a week for the package to be pushed to all production machines.
The vulnerability in curl, CVE-2024-7264, has been addressed.
Other stability improvements and bug fixes.
Known Issues
There's a known issue where MDE is deleting the configuration file located at /etc/systemd/system/mdatp.service.d on each service start. As a workaround, customers can use the Immutable attribute that prevents the files from being modified or deleted.
To set the file to be unmodifiable, execute the following command:
sudo chattr +i /etc/systemd/system/mdatp.service.d/[file name]
This command makes the file unchangeable. If you need to restore modification permissions, use the following command:
sudo chattr -i /etc/systemd/system/mdatp.service.d/[file name]
Note that the chattr command can only be used on supported file systems, such as ext4.
If you need further assistance, you can reach out to our support team with your organization ID, and we can implement a temporary mitigation to prevent deletion. A permanent fix for this issue is available in MDE version 101.25032.0000.
Feb-2025 Build: 101.24122.0008 | Release version: 30.124112.0008.0
| Build: | 101.24122.0008 |
|---|---|
| Released: | February 20, 2025 |
| Published: | February 20, 2025 |
| Release version: | 30.124122.0008.0 |
| Engine version: | 1.1.24090.13 |
| Signature version: | 1.421.226.0 |
What's new
- The MDATP package
101.24122.0008is rolling out gradually for each distribution. - Other stability improvements and bug fixes
Feb-2025 Build: 101.24112.0003 | Release version: 30.124112.0003.0
| Build: | 101.24112.0003 |
|---|---|
| Released: | February 04, 2025 |
| Published: | February 04, 2025 |
| Release version: | 30.124112.0003.0 |
| Engine version: | 1.1.24090.13 |
| Signature version: | 1.421.1681.0 |
What's new
- Fixed a bug that incorrectly reported the DefenderEngineVersion to the security portal.
- The MDATP package
101.24112.0003is rolling out gradually for each distribution.
Jan-2025 Build: 101.24112.0001 | Release version: 30.124112.0001.0
| Build: | 101.24112.0001 |
|---|---|
| Released: | January 13, 2025 |
| Published: | January 13, 2025 |
| Release version: | 30.124112.0001.0 |
| Engine version: | 1.1.24090.13 |
| Signature version: | 1.421.226.0 |
What's new
Upgraded the Bond version to 13.0.1 to address security vulnerabilities in versions 12 or lower.
Mdatp package no longer has a dependency on SELinux packages.
Users can now query the status of supplementary event provider eBPF using the threat hunting query in
DeviceTvmInfoGathering. To learn more about this query check: Use eBPF-based sensor for Microsoft Defender for Endpoint on Linux. The result of this query can return the following two values as eBPF status:- Enabled: When eBPF is enabled as working as expected.
- Disabled: When eBPF is disabled due to one of the following reasons:
- When MDE is using auditD as a supplementary sensor
- When eBPF isn't present and we fall back to Net link as supplementary event provider
- There's no supplementary sensor present.
Beginning with 2411, the MDATP package release to Production on
packages.microsoft.comfollows a gradual rollout mechanism which spans over a week. The other release rings, insiderFast, and insiderSlow, are unaffected by this change.Stability and performance improvements.
Critical bugs fixes around definition update flow.
Jan-2025 Build: 101.24102.0000 | Release version: 30.124102.0000.0
| Build: | 101.24102.0000 |
|---|---|
| Released: | January 8, 2025 |
| Published: | January 8, 2025 |
| Release version: | 30.124102.0000.0 |
| Engine version: | 1.1.24080.11 |
| Signature version: | 1.419.351.0 |
What's new
The default engine version has been updated to
1.1.24080.11, and the default signature version has been updated to1.419.351.0.Improved the reporting of command-line threat information for short lived processes on the security portal.
Nov-2024 Build: 101.24092.0002 | Release version: 30.124092.0002.0
| Build: | 101.24092.0002 |
|---|---|
| Released: | November 14, 2024 |
| Published: | November 14, 2024 |
| Release version: | 30.124092.0002.0 |
| Engine version: | 1.1.24080.9 |
| Signature version: | 1.417.659.0 |
What's new
To support hardened installations with nonexecutable
/varpartitions, mdatp antivirus definitions now install to/opt/microsoft/mdatp/definitions.noindexinstead of/varif the latter is detected as nonexecutable. During upgrades, the installer attempts to migrate older definitions to the new path upon detecting a nonexecutable/var, unless it finds that the path has already been customized (usingmdatp definitions path set).Beginning with this version, Defender for Endpoint on Linux no longer needs executable permissions for
/var/log. If these permissions aren't available, log files are automatically redirected to/opt.
Oct-2024 Build: 101.24082.0004 | Release version: 30.124082.0004.0
| Build: | 101.24082.0004 |
|---|---|
| Released: | October 15, 2024 |
| Published: | October 15, 2024 |
| Release version: | 30.124082.0004 |
| Engine version: | 1.1.24080.9 |
| Signature version: | 1.417.659.0 |
What's new
Starting with this version, Defender for Endpoint on Linux no longer supports
AuditDas a supplementary event provider. For improved stability and performance, we have transitioned to eBPF. If you disable eBPF, or in the event eBPF isn't supported on any specific kernel, Defender for Endpoint on Linux automatically switches back to Net link as a fallback supplementary event provider. Net link provides reduced functionality and tracks only process-related events. In this case, all process operations continue to flow seamlessly, but you could miss specific file and socket-related events that eBPF would otherwise capture. For more information, see Use eBPF-based sensor for Microsoft Defender for Endpoint on Linux. If you have any concerns or need assistance during this transition, contact support.Stability and performance improvements
Other bug fixes
Sept-2024 Build: 101.24072.0001 | Release version: 30.124072.0001.0
| Build: | 101.24072.0001 |
|---|---|
| Released: | September 23, 2024 |
| Published: | September 23, 2024 |
| Release version: | 30.124072.0001.0 |
| Engine version: | 1.1.24060.6 |
| Signature version: | 1.415.228.0 |
What's new
Added support for Ubuntu 24.04
Updated default engine version to
1.1.24060.6and default signatures version to1.415.228.0.
July-2024 Build: 101.24062.0001 | Release version: 30.124062.0001.0
| Build: | 101.24072.0001 |
|---|---|
| Released: | July 31, 2024 |
| Published: | July 31, 2024 |
| Release version: | 30.124062.0001.0 |
| Engine version: | 1.1.24050.7 |
| Signature version: | 1.411.410.0 |
What's new
There are multiple fixes and new changes in this release.
Fixes bug in which infected command-line threat information wasn't showing correctly in security portal.
Fixes a bug where disabling a preview feature required a Defender of Endpoint to disable it.
Global Exclusions feature using managed JSON is now in Public Preview. available in insiders slow from 101.23092.0012. For more information, see linux-exclusions.
Updated the Linux default engine version to 1.1.24050.7 and default signature version to 1.411.410.0.
Stability and performance improvements.
Other bug fixes.
June-2024 Build: 101.24052.0002 | Release version: 30.124052.0002.0
| Build: | 101.24052.0002 |
|---|---|
| Released: | June 24, 2024 |
| Published: | June 24, 2024 |
| Release version: | 30.124052.0002.0 |
| Engine version: | 1.1.24040.2 |
| Signature version: | 1.411.153.0 |
What's new
There are multiple fixes and new changes in this release.
This release fixes a bug related to high memory usage eventually leading to high CPU due to eBPF memory leak in kernel space resulting in servers going into unusable states. This only affected the kernel versions 3.10x and <= 4.16x, majorly on RHEL/CentOS distros. Update to the latest MDE version to avoid any impact.
We have now simplified the output of
mdatp health --detail featuresStability and performance improvements.
Other bug fixes.
May-2024 Build: 101.24042.0002 | Release version: 30.124042.0002.0
| Build: | 101.24042.0002 |
|---|---|
| Released: | May 29, 2024 |
| Published: | May 29, 2024 |
| Release version: | 30.124042.0002.0 |
| Engine version: | 1.1.24030.4 |
| Signature version: | 1.407.521.0 |
What's new
There are multiple fixes and new changes in this release:
In version 24032.0007, there was a known issue where the enrollment of devices to MDE Security Management failed when using the "Device Tagging" mechanism via the mdatp_managed.json file. This issue has been resolved in the current release.
Stability and performance improvements.
Other bug fixes.
May-2024 Build: 101.24032.0007 | Release version: 30.124032.0007.0
| Build: | 101.24032.0007 |
|---|---|
| Released: | May 15, 2024 |
| Published: | May 15, 2024 |
| Release version: | 30.124032.0007.0 |
| Engine version: | 1.1.24020.3 |
| Signature version: | 1.403.3500.0 |
What's new
There are multiple fixes and new changes in this release:
In passive and on-demand modes, antivirus engine remains in idle state and is used only during scheduled custom scans. Thus as part of performance improvements, we have made changes to keep the AV engine down in passive and on-demand mode except during scheduled custom scans. If the real time protection is enabled, antivirus engine will always be up and running. This has no impact on your server protection in any mode.
To keep users informed of the state of antivirus engine, we have introduced a new field called "engine_load_status" as part of MDATP health. It indicates whether antivirus engine is currently running or not.
Field nameengine_load_statusPossible values Engine not loaded (AV engine process is down), Engine load succeeded (AV engine process up and running) Healthy scenarios:
- If RTP is enabled, engine_load_status should be "Engine load succeeded"
- If MDE is in on-demand or passive mode, and custom scan isn't running then "engine_load_status" should be "Engine not loaded"
- If MDE is in on-demand or passive mode, and custom scan is running then "engine_load_status" should be "Engine load succeeded"
Bug fix to enhance behavioral detections.
Stability and performance improvements.
Other bug fixes.
Known Issues
There's a known issue where enrolling devices to MDE Security Management via "Device Tagging" mechanism using mdatp_managed.json is failing in 24032.0007. To mitigate this issue, use the following mdatp CLI command to tag devices:
sudo mdatp edr tag set --name GROUP --value MDE-ManagementThe issue has been fixed in Build: 101.24042.0002
March-2024 Build: 101.24022.0001 | Release version: 30.124022.0001.0
| Build: | 101.24022.0001 |
|---|---|
| Released: | March 22,2024 |
| Published: | March 22,2024 |
| Release version: | 30.124022.0001.0 |
| Engine version: | 1.1.23110.4 |
| Signature version: | 1.403.87.0 |
What's new
There are multiple fixes and new changes in this release:
The addition of a new log file -
microsoft_defender_scan_skip.log. This logs the filenames that were skipped from various antivirus scans by Microsoft Defender for Endpoint due to any reason.Stability and performance improvements.
Bug fixes.
March-2024 Build: 101.24012.0001 | Release version: 30.124012.0001.0
| Build: | 101.24012.0001 |
|---|---|
| Released: | March 12,2024 |
| Published: | March 12,2024 |
| Release version: | 30.124012.0001.0 |
| Engine version: | 1.1.23110.4 |
| Signature version: | 1.403.87.0 |
What's new
There are multiple fixes and new changes in this release:
Updated default engine version to
1.1.23110.4, and default signatures version to1.403.87.0.Stability and performance improvements.
Bug fixes.
February-2024 Build: 101.23122.0002 | Release version: 30.123122.0002.0
| Build: | 101.23122.0002 |
|---|---|
| Released: | February 5,2024 |
| Published: | February 5,2024 |
| Release version: | 30.123122.0002.0 |
| Engine version: | 1.1.23100.2010 |
| Signature version: | 1.399.1389.0 |
What's new
There are multiple fixes and new changes in this release:
Updated default engine version to
1.1.23100.2010, and default signatures version to1.399.1389.0.General stability and performance improvements.
Bug fixes.
Microsoft Defender for Endpoint on Linux now officially supports the following distros and versions:
Distro & version Ring Package Mariner 2 Production https://packages.microsoft.com/cbl-mariner/2.0/prod/extras/x86_64/config.repo Rocky 8.7 and higher Insiders Slow https://packages.microsoft.com/config/rocky/8/insiders-slow.repo Rocky 9.2 and higher Insiders Slow https://packages.microsoft.com/config/rocky/9/insiders-slow.repo Alma 8.4 and higher Insiders Slow https://packages.microsoft.com/config/alma/8/insiders-slow.repo Alma 9.2 and higher Insiders Slow https://packages.microsoft.com/config/alma/9/insiders-slow.repo
If you already have Defender for Endpoint running on any of these distros and facing any issues in the older versions, upgrade to the latest Defender for Endpoint version from the corresponding ring mentioned above.
Note
Known issues:
Microsoft Defender for Endpoint for Linux on Rocky and Alma currently has the following known issues:
- Live Response and Threat Vulnerability Management are currently not supported (work in progress).
- Operating system info for devices isn't visible in the Microsoft Defender portal
January-2024 Build: 101.23112.0009 | Release version: 30.123112.0009.0
| Build: | 101.23112.0009 |
|---|---|
| Released: | January 29,2024 |
| Published: | January 29,2024 |
| Release version: | 30.123112.0009.0 |
| Engine version: | 1.1.23100.2010 |
| Signature version: | 1.399.1389.0 |
What's new
Updated default engine version to
1.1.23110.4, and default signatures version to1.403.1579.0.General stability and performance improvements.
Bug fix for behavior monitoring configuration.
Bug fixes.
November-2023 Build: 101.23102.0003 | Release version: 30.123102.0003.0
| Build: | 101.23102.0003 |
|---|---|
| Released: | November 28,2023 |
| Published: | November 28,2023 |
| Release version: | 30.123102.0003.0 |
| Engine version: | 1.1.23090.2008 |
| Signature version: | 1.399.690.0 |
What's new
Updated default engine version to
1.1.23090.2008, and default signatures version to1.399.690.0.Updated libcurl library to version
8.4.0to fix recently disclosed vulnerabilities with the older version.Updated Openssl library to version
3.1.1to fix recently disclosed vulnerabilities with the older version.General stability and performance improvements.
Bug fixes.
November-2023 Build: 101.23092.0012 | Release version: 30.123092.0012.0
| Build: | 101.23092.0012 |
|---|---|
| Released: | November 14,2023 |
| Published: | November 14,2023 |
| Release version: | 30.123092.0012.0 |
| Engine version: | 1.1.23080.2007 |
| Signature version: | 1.395.1560.0 |
What's new
There are multiple fixes and new changes in this release:
Support added to restore threat based on original path using the following command:
sudo mdatp threat quarantine restore threat-path --path [threat-original-path] --destination-path [destination-folder]From this release, Microsoft Defender for Endpoint on Linux will no longer be shipping a solution for RHEL 6.
RHEL 6 'Extended end of life support' is poised to end by June 30, 2024 and customers are advised to plan their RHEL upgrades accordingly aligned with guidance from Red Hat. Customers who need to run Defender for Endpoint on RHEL 6 servers can continue to use version 101.23082.0011 (doesn't expire before June 30, 2024) supported on kernel versions 2.6.32-754.49.1.el6.x86_64 or prior.
- Engine Update to
1.1.23080.2007and Signatures Ver:1.395.1560.0. - Streamlined device connectivity experience is now in public preview mode. public blog
- Performance improvements & bug fixes.
- Engine Update to
Known issues
- CPU lock-up seen on kernel version 5.15.0-0.30.20 in ebpf mode, see Use eBPF-based sensor for Microsoft Defender for Endpoint on Linux for details and Mitigation options.
November-2023 Build: 101.23082.0011 | Release version: 30.123082.0011.0
| Build: | 101.23082.0011 |
|---|---|
| Released: | November 1,2023 |
| Published: | November 1,2023 |
| Release version: | 30.123082.0011.0 |
| Engine version: | 1.1.23070.1002 |
| Signature version: | 1.393.1305.0 |
What's new
This new release is built over October 2023 release (101.23082.0009) with addition of following changes. There's no change for other customers and upgrading is optional.
Fix for immutable mode of auditd when supplementary subsystem is ebpf: In ebpf mode all mdatp audit rules should be cleaned after switching to ebpf and rebooting. After the reboot, mdatp audit rules weren't cleaned due to which it was resulting in hang of the server. The fix cleans these rules, user shouldn't see any mdatp rules loaded on reboot
Fix for MDE not starting up on RHEL 6.
Known issues
When upgrading from mdatp version 101.75.43 or 101.78.13, you might encounter a kernel hang. Run the following commands before attempting to upgrade to version 101.98.05. More information about the underlying issue can be found at System hang due to blocked tasks in fanotify code.
There are two ways to mitigate this upgrade issue:
Use your package manager to uninstall the
101.75.43or101.78.13mdatp version.Example:
sudo apt purge mdatp sudo apt-get install mdatpAs an alternative you can follow the instructions to uninstall, then install the latest version of the package.
If you don't want to uninstall mdatp, you can disable rtp and mdatp in sequence before upgrading. Some customers (<1%) experience issues with this method.
sudo mdatp config real-time-protection --value=disabled
sudo systemctl disable mdatp
October-2023 Build: 101.23082.0009 | Release version: 30.123082.0009.0
| Build: | 101.23082.0009 |
|---|---|
| Released: | October 9,2023 |
| Published: | October 9,2023 |
| Release version: | 30.123082.0009.0 |
| Engine version: | 1.1.23070.1002 |
| Signature version: | 1.393.1305.0 |
What's new
- This new release is built over October 2023 release (
101.23082.0009) with addition of new CA Certificates. There's no change for other customers and upgrading is optional.
Known issues
When upgrading from mdatp version 101.75.43 or 101.78.13, you might encounter a kernel hang. Run the following commands before attempting to upgrade to version 101.98.05. More information about the underlying issue can be found at System hang due to blocked tasks in fanotify code.
There are two ways to mitigate this upgrade issue:
Use your package manager to uninstall the
101.75.43or101.78.13mdatp version.Example:
sudo apt purge mdatp sudo apt-get install mdatpAs an alternative you can follow the instructions to uninstall, then install the latest version of the package.
If you don't want to uninstall mdatp, you can disable rtp and mdatp in sequence before upgrading. Some customers (<1%) experience issues with this method.
sudo mdatp config real-time-protection --value=disabled
sudo systemctl disable mdatp
October-2023 Build: 101.23082.0006 | Release version: 30.123082.0006.0
| Build: | 101.23082.0006 |
|---|---|
| Released: | October 9,2023 |
| Published: | October 9,2023 |
| Release version: | 30.123082.0006.0 |
| Engine version: | 1.1.23070.1002 |
| Signature version: | 1.393.1305.0 |
What's new
Feature updates and new changes
eBPF sensor is now the default supplementary event provider for endpoints
Microsoft Intune tenant attach feature is in public preview (as of mid July)
- You must add "*.dm.microsoft.com" to firewall exclusions for the feature to work correctly
Defender for Endpoint is now available for Debian 12 and Amazon Linux 2023
Support to enable Signature verification of updates downloaded
You must update the manajed.json as shown:
"features":{ "OfflineDefinitionUpdateVerifySig":"enabled" }Prerequisite to enable feature
- Engine version on the device must be "1.1.23080.007" or above. Check your engine version by using the following command.
mdatp health --field engine_version
- Engine version on the device must be "1.1.23080.007" or above. Check your engine version by using the following command.
Option to support monitoring of NFS and FUSE mount points. These are ignored by default. The following example shows how to monitor all filesystem while ignoring only NFS:
"antivirusEngine": { "unmonitoredFilesystems": ["nfs"] }Example to monitor all filesystems including NFS and FUSE:
"antivirusEngine": { "unmonitoredFilesystems": [] }Other performance improvements
Bug Fixes
Known issues
- When upgrading from mdatp version 101.75.43 or 101.78.13, you might encounter a kernel hang. Run the following commands before attempting to upgrade to version 101.98.05. More information about the underlying issue can be found at System hang due to blocked tasks in fanotify code. There are two ways to mitigate this upgrade issue:
Use your package manager to uninstall the
101.75.43or101.78.13mdatp version.Example:
sudo apt purge mdatp sudo apt-get install mdatpAs an alternative you can follow the instructions to uninstall, then install the latest version of the package.
If you don't want to uninstall mdatp, you can disable rtp and mdatp in sequence before upgrading. Some customers (<1%) experience issues with this method.
sudo mdatp config real-time-protection --value=disabled
sudo systemctl disable mdatp
September-2023 Build: 101.23072.0021 | Release version: 30.123072.0021.0
| Build: | 101.23072.0021 |
|---|---|
| Released: | September 11,2023 |
| Published: | September 11,2023 |
| Release version: | 30.123072.0021.0 |
| Engine version: | 1.1.20100.7 |
| Signature version: | 1.385.1648.0 |
What's new
There are multiple fixes and new changes in this release:
In
mde_installer.shv0.6.3, users can use the--channelargument to provide the channel of the configured repository during cleanup. For example,sudo ./mde_installer --clean --channel prodThe Network Extension can now be reset by administrators using
mdatp network-protection reset.Other performance improvements
Bug Fixes
Known issues
- While upgrading from mdatp version
101.75.43or101.78.13, you might encounter a kernel hang. Run the following commands before attempting to upgrade to version101.98.05. For more information, see System hang due to blocked tasks in fanotify code.
There are two ways to mitigate this upgrade issue:
Use your package manager to uninstall the
101.75.43or101.78.13mdatp version.Example:
sudo apt purge mdatp sudo apt-get install mdatpAs an alternative you can follow the instructions to uninstall, then install the latest version of the package.
If you don't want to uninstall mdatp, you can disable rtp and mdatp in sequence before upgrading. Some customers (<1%) experience issues with this method.
sudo mdatp config real-time-protection --value=disabled
sudo systemctl disable mdatp
July-2023 Build: 101.23062.0010 | Release version: 30.123062.0010.0
| Build: | 101.23062.0010 |
|---|---|
| Released: | July 26,2023 |
| Published: | July 26,2023 |
| Release version: | 30.123062.0010.0 |
| Engine version: | 1.1.20100.7 |
| Signature version: | 1.385.1648.0 |
What's new
There are multiple fixes and new changes in this release
If a proxy is set for Defender for Endpoint, then it's visible in the
mdatp healthcommand output. With this release we provided two options in mdatp diagnostic hot-event-sources:- Files
- Executables
Network Protection: Connections that are blocked by Network Protection and have the block overridden by users is now correctly reported to Microsoft Defender XDR
Improved logging in Network Protection block and audit events for debugging
Other fixes and improvements
- From this version, enforcementLevel are in passive mode by default giving admins more control over where they want 'RTP on' within their estate
- This change only applies to fresh MDE deployments, for example, servers where Defender for Endpoint is being deployed for the first time. In update scenarios, servers that have Defender for Endpoint deployed with RTP ON, continue operating with RTP ON even post update to version 101.23062.0010
Bug fix: RPM database corruption issue in Defender Vulnerability Management baseline is fixed.
Other performance improvements
Known issues
While upgrading from mdatp version 101.75.43 or 101.78.13, you might encounter a kernel hang. Run the following commands before attempting to upgrade to version 101.98.05. For more information, see System hang due to blocked tasks in fanotify code.
There are two ways to mitigate this upgrade issue:
Use your package manager to uninstall the
101.75.43or101.78.13mdatp version.Example:
sudo apt purge mdatp sudo apt-get install mdatpAs an alternative you can follow the instructions to uninstall, then install the latest version of the package.
If you don't want to uninstall mdatp, you can disable rtp and mdatp in sequence before upgrading. Some customers (<1%) experience issues with this method.
sudo mdatp config real-time-protection --value=disabled
sudo systemctl disable mdatp
July-2023 Build: 101.23052.0009 | Release version: 30.123052.0009.0
| Build: | 101.23052.0009 |
|---|---|
| Released: | July 10,2023 |
| Published: | July 10,2023 |
| Release version: | 30.123052.0009.0 |
| Engine version: | 1.1.20100.7 |
| Signature version: | 1.385.1648.0 |
What's new
- There are multiple fixes and new changes in this release
- The build version schema is updated from this release. While the major version number remains same as 101, the minor version number now has five digits followed by four digit patch number that is,
101.xxxxx.yyy- Improved Network Protection memory consumption under stress- Updated the engine version to
1.1.20300.5and signature version to1.391.2837.0. - Bug fixes.
- Updated the engine version to
Known issues
While upgrading from mdatp version 101.75.43 or 101.78.13, you might encounter a kernel hang. Run the following commands before attempting to upgrade to version 101.98.05. For more information, see System hang due to blocked tasks in fanotify code.
There are two ways to mitigate this upgrade issue:
Use your package manager to uninstall the
101.75.43or101.78.13mdatp version.Example:
sudo apt purge mdatp sudo apt-get install mdatpAs an alternative you can follow the instructions to uninstall, then install the latest version of the package.
If you don't want to uninstall mdatp, you can disable rtp and mdatp in sequence before upgrading. Some customers (<1%) experience issues with this method.
sudo mdatp config real-time-protection --value=disabled
sudo systemctl disable mdatp
June-2023 Build: 101.98.89 | Release version: 30.123042.19889.0
| Build: | 101.98.89 |
|---|---|
| Released: | June 12,2023 |
| Published: | June 12,2023 |
| Release version: | 30.123042.19889.0 |
| Engine version: | 1.1.20100.7 |
| Signature version: | 1.385.1648.0 |
What's new
There are multiple fixes and new changes in this release
Improved Network Protection Proxy handling.
In Passive mode, Defender for Endpoint no longer scans when Definition update happens.
Devices continue to be protected even after Defender for Endpoint agent is expired. We recommend upgrading the Defender for Endpoint Linux agent to the latest available version to receive bug fixes, features, and performance improvements.
Removed semanage package dependency.
Engine Update to
1.1.20100.7and Signatures Ver:1.385.1648.0.Bug fixes.
Known issues
- While upgrading from mdatp version
101.75.43or101.78.13, you might encounter a kernel hang. Run the following commands before attempting to upgrade to version101.98.05. For more information, see System hang due to blocked tasks in fanotify code.
There are two ways to mitigate this upgrade issue:
Use your package manager to uninstall the
101.75.43or101.78.13mdatp version.Example:
sudo apt purge mdatp sudo apt-get install mdatpAs an alternative you can follow the instructions to uninstall, then install the latest version of the package.
If you don't want to uninstall mdatp, you can disable rtp and mdatp in sequence before upgrading. Some customers (<1%) experience issues with this method.
sudo mdatp config real-time-protection --value=disabled
sudo systemctl disable mdatp
May-2023 Build: 101.98.64 | Release version: 30.123032.19864.0
| Build: | 101.98.64 |
|---|---|
| Released: | May 3,2023 |
| Published: | May 3,2023 |
| Release version: | 30.123032.19864.0 |
| Engine version: | 1.1.20100.6 |
| Signature version: | 1.385.68.0 |
What's new
There are multiple fixes and new changes in this release
Health message improvements to capture details about auditd failures.
Improvements to handle augenrules, which was causing installation failure.
Periodic memory cleanup in engine process.
Fix for memory issue in mdatp audisp plugin.
Handled missing plugin directory path during installation.
When conflicting application is using blocking fanotify, with default configuration mdatp health shows unhealthy. This is now fixed.
Support for ICMP traffic inspection in BM.
Engine Update to
1.1.20100.6and Signatures Ver:1.385.68.0.Bug fixes.
Known issues
- While upgrading from mdatp version
101.75.43or101.78.13, you might encounter a kernel hang. Run the following commands before attempting to upgrade to version101.98.05. For more information, see System hang due to blocked tasks in fanotify code.
There are two ways to mitigate this upgrade issue:
Use your package manager to uninstall the
101.75.43or101.78.13mdatp version.Example:
sudo apt purge mdatp sudo apt-get install mdatpAs an alternative you can follow the instructions to uninstall, then install the latest version of the package.
If you don't want to uninstall mdatp, you can disable rtp and mdatp in sequence before upgrading. Caution: Some customers (<1%) experience issues with this method.
sudo mdatp config real-time-protection --value=disabled
sudo systemctl disable mdatp
April-2023 Build: 101.98.58 | Release version: 30.123022.19858.0
| Build: | 101.98.58 |
|---|---|
| Released: | April 20,2023 |
| Published: | April 20,2023 |
| Release version: | 30.123022.19858.0 |
| Engine version: | 1.1.20000.2 |
| Signature version: | 1.381.3067.0 |
What's new
There are multiple fixes and new changes in this release
Logging and error reporting improvements for auditd.
Handle failure in reload of auditd configuration.
Handling for empty auditd rule files during MDE install.
Engine Update to
1.1.20000.2and Signatures Ver:1.381.3067.0.Addressed a health issue in mdatp that occurs due to selinux denials.
Bug fixes.
Known issues
While upgrading mdatp to version
101.94.13or later, you might notice that health is false, with health_issues as "no active supplementary event provider". This can happen due to misconfigured/conflicting auditd rules on existing machines. To mitigate the issue, the auditd rules on the existing machines need to be fixed. The following commands can help you to identify such auditd rules (commands need to be run as super user). Take a backup of following file: /etc/audit/rules.d/audit.rules as these steps are only to identify failures.echo -c >> /etc/audit/rules.d/audit.rules augenrules --loadWhile upgrading from mdatp version
101.75.43or101.78.13, you could encounter a kernel hang. Run the following commands before attempting to upgrade to version101.98.05. For more information, see System hang due to blocked tasks in fanotify code.
There are two ways to mitigate this upgrade issue:
Use your package manager to uninstall the
101.75.43or101.78.13mdatp version.Example:
sudo apt purge mdatp sudo apt-get install mdatpAs an alternative you can follow the instructions to uninstall, then install the latest version of the package.
If you don't want to uninstall mdatp, you can disable rtp and mdatp in sequence before upgrading. Caution: Some customers (<1%) experience issues with this method.
sudo mdatp config real-time-protection --value=disabled
sudo systemctl disable mdatp
March-2023 Build: 101.98.30 | Release version: 30.123012.19830.0
| Build: | 101.98.30 |
|---|---|
| Released: | March 20, 2023 |
| Published: | March 20, 2023 |
| Release version: | 30.123012.19830.0 |
| Engine version: | 1.1.19900.2 |
| Signature version: | 1.379.1299.0 |
What's new
- This new release is built over March 2023 release (
101.98.05) with a fix for Live response commands failing for one of our customers. There's no change for other customers and upgrade is optional.
Known issues
- With mdatp version 101.98.30 you might see a health false issue in some of the cases, because SELinux rules aren't defined for certain scenarios. The health warning could look something like this:
Found SELinux denials within last one day. If the MDATP is recently installed, clear the existing audit logs or wait for a day for this issue to autoresolve. Use command: "sudo ausearch -i -c 'mdatp_audisp_pl' | grep "type=AVC" | grep " denied" to find details
The issue could be mitigated by running the following commands.
sudo ausearch -c 'mdatp_audisp_pl' --raw | sudo audit2allow -M my-mdatpaudisppl_v1
sudo semodule -i my-mdatpaudisppl_v1.pp
Here, my-mdatpaudisppl_v1 represents the policy module name. After you run the commands, either wait for 24 hours or clear/archive the audit logs. The audit logs could be archived by running the following command
sudo service auditd stop
sudo systemctl stop mdatp
cd /var/log/audit
sudo gzip audit.*
sudo service auditd start
sudo systemctl start mdatp
mdatp health
In case the issue reappears with some different denials. We need to run the mitigation again with a different module name (for example, my-mdatpaudisppl_v2).
March-2023 Build: 101.98.05 | Release version: 30.123012.19805.0
| Build: | 101.98.05 |
|---|---|
| Released: | March 08, 2023 |
| Published: | March 08, 2023 |
| Release version: | 30.123012.19805.0 |
| Engine version: | 1.1.19900.2 |
| Signature version: | 1.379.1299.0 |
What's new
Improved Data Completeness for Network Connection events
Improved Data Collection capabilities for file ownership/permissions changes
seManage in part of the package, to that seLinux policies can be configured in different distro (fixed).
Improved enterprise daemon stability
AuditD stop path clean-up
Improved the stability of mdatp stop flow.
Added new field to wdavstate to keep track of platform update time.
Stability improvements to parsing Defender for Endpoint onboarding blob.
Scan doesn't proceed if a valid license isn't present (fixed)
Added performance tracing option to xPlatClientAnalyzer, with tracing enabled mdatp process dumps the flow in all_process.zip file that can be used for analysis of performance issues.
Added support in Defender for Endpoint for the following RHEL-6 kernel versions:
2.6.32-754.43.1.el6.x86_642.6.32-754.49.1.el6.x86_64
Other fixes
Known issues
While upgrading mdatp to version 101.94.13, you might notice that health is false, with health_issues as "no active supplementary event provider". This can happen due to misconfigured/conflicting auditd rules on existing machines. To mitigate the issue, the auditd rules on the existing machines need to be fixed. The following steps can help you to identify such auditd rules (these commands need to be run as super user). Make sure to back up following file: /etc/audit/rules.d/audit.rules as these steps are only to identify failures.
echo -c >> /etc/audit/rules.d/audit.rules
augenrules --load
- While upgrading from mdatp version
101.75.43or101.78.13, you might encounter a kernel hang. Run the following commands before attempting to upgrade to version101.98.05. For more information, see System hang due to blocked tasks in fanotify code
There are two ways to mitigate the problem in upgrading.
Use your package manager to uninstall the 101.75.43 or 101.78.13 mdatp version.
Example:
sudo apt purge mdatp
sudo apt-get install mdatp
As an alternative, you can follow the instructions to uninstall, then install the latest version of the package.
In case you don't want to uninstall mdatp you can disable rtp and mdatp in sequence before upgrade. Caution: Some customers(<1%) are experiencing issues with this method.
sudo mdatp config real-time-protection --value=disabled
sudo systemctl disable mdatp
Jan-2023 Build: 101.94.13 | Release version: 30.122112.19413.0
| Build: | 101.94.13 |
|---|---|
| Released: | January 10, 2023 |
| Published: | January 10, 2023 |
| Release version: | 30.122112.19413.0 |
| Engine version: | 1.1.19700.3 |
| Signature version: | 1.377.550.0 |
What's new
- There are multiple fixes and new changes in this release
- Skip quarantine of threats in passive mode by default.
- New config, nonExecMountPolicy, can now be used to specify behavior of RTP on mount point marked as noexec.
- New config, unmonitoredFilesystems, can be used to unmonitor certain filesystems.
- Improved performance under high load and in speed test scenarios.
- Fixes an issue with accessing SMB shares behind Cisco AnyConnect VPN connections.
- Fixes an issue with Network Protection and SMB.
- lttng performance tracing support.
- TVM, eBPF, auditd, telemetry, and mdatp cli improvements.
- mdatp health now reports behavior_monitoring
- Other fixes.
Known issues
While upgrading mdatp to version
101.94.13, you might notice that health is false, with health_issues as "no active supplementary event provider. This can happen due to misconfigured/conflicting auditd rules on existing machines. To mitigate the issue, the auditd rules on the existing machines need to be fixed. The following steps can help you to identify such auditd rules (these commands need to be run as super user). Take a backup of following file:/etc/audit/rules.d/audit.rulesas these steps are only to identify failures.echo -c >> /etc/audit/rules.d/audit.rules augenrules --loadWhile upgrading from mdatp version
101.75.43or101.78.13, you might encounter a kernel hang. Run the following commands before attempting to upgrade to version 101.94.13. For more information, see System hang due to blocked tasks in fanotify code
There are two ways to mitigate the problem in upgrading.
Use your package manager to uninstall the 101.75.43 or 101.78.13 mdatp version.
Example:
sudo apt purge mdatp
sudo apt-get install mdatp
As an alternative, you can follow the instructions to uninstall, then install the latest version of the package.
In case you don't want to uninstall mdatp you can disable rtp and mdatp in sequence before upgrade. Caution: Some customers(<1%) are experiencing issues with this method.
sudo mdatp config real-time-protection --value=disabled
sudo systemctl disable mdatp
Nov-2022 Build: 101.85.27 | Release version: 30.122092.18527.0
| Build: | 101.85.27 |
|---|---|
| Released: | November 02, 2022 |
| Published: | November 02, 2022 |
| Release version: | 30.122092.18527.0 |
| Engine version: | 1.1.19500.2 |
| Signature version: | 1.371.1369.0 |
What's new
- There are multiple fixes and new changes in this release
- V2 engine is default with this release and V1 engine bits are removed for enhanced security.
- V2 engine support configuration path for AV definitions. (mdatp definition set path)
- Removed external packages dependencies from MDE package. Removed dependencies are libatomic1, libselinux, libseccomp, libfuse, and libuuid
- In case crash collection is disabled by configuration, crash monitoring process isn't launched.
- Performance fixes to optimally use system events for AV capabilities.
- Stability improvement when restarting mdatp and load epsext issues.
- Other fixes
Known issues
- While upgrading from mdatp version
101.75.43or101.78.13, you might encounter a kernel hang. Run the following commands before attempting to upgrade to version 101.85.21. For more information, see System hang due to blocked tasks in fanotify code
There are two ways to mitigate the problem in upgrading.
Use your package manager to uninstall the 101.75.43 or 101.78.13 mdatp version.
Example:
sudo apt purge mdatp
sudo apt-get install mdatp
As an alternative approach, follow the instructions to uninstall, then install the latest version of the package.
In case you don't want to uninstall mdatp you can disable rtp and mdatp in sequence before upgrade. Caution: Some customers(<1%) are experiencing issues with this method.
sudo mdatp config real-time-protection --value=disabled
sudo systemctl disable mdatp
Sep-2022 Build: 101.80.97 | Release version: 30.122072.18097.0
| Build: | 101.80.97 |
|---|---|
| Released: | September 14, 2022 |
| Published: | September 14, 2022 |
| Release version: | 30.122072.18097.0 |
| Engine version: | 1.1.19300.3 |
| Signature version: | 1.369.395.0 |
What's new
- Fixes a kernel hang observed on select customer workloads running mdatp version
101.75.43. After RCA, this was attributed to a race condition while releasing the ownership of a sensor file descriptor. The race condition was exposed due to a recent product change in the shutdown path. Customers on newer Kernel versions (5.1+) aren't impacted by this issue. For more information, see System hang due to blocked tasks in fanotify code.
Known issues
When upgrading from mdatp version
101.75.43or101.78.13, you might encounter a kernel hang. Run the following commands before attempting to upgrade to version101.80.97. This action should prevent the issue from occurring.sudo mdatp config real-time-protection --value=disabled sudo systemctl disable mdatp
After executing the commands, use your package manager to perform the upgrade.
As an alternative approach, follow the instructions to uninstall, then install the latest version of the package.
Aug-2022 Build: 101.78.13 | Release version: 30.122072.17813.0
| Build: | 101.78.13 |
|---|---|
| Released: | August 24, 2022 |
| Published: | August 24, 2022 |
| Release version: | 30.122072.17813.0 |
| Engine version: | 1.1.19300.3 |
| Signature version: | 1.369.395.0 |
What's new
- Rolled back due to reliability issues
Aug-2022 (Build: 101.75.43 | Release version: 30.122071.17543.0)
| Build: | 101.75.43 |
|---|---|
| Released: | August 2, 2022 |
| Published: | August 2, 2022 |
| Release version: | 30.122071.17543.0 |
| Engine version: | 1.1.19300.3 |
| Signature version: | 1.369.395.0 |
What's new
- Added support for Red Hat Enterprise Linux version 9.0
- Added a new field in the output of
mdatp healththat can be used to query the enforcement level of the network protection feature. The new field is callednetwork_protection_enforcement_leveland can take one of the following values:audit,block, ordisabled. - Addressed a product bug where multiple detections of the same content could lead to duplicate entries in the threat history
- Addressed an issue where one of the processes spawned by the product (
mdatp_audisp_plugin) was sometimes not properly terminated when the service was stopped - Other bug fixes
Jul-2022 Build: 101.73.77 | Release version: 30.122062.17377.0
| Build: | 101.73.77 |
|---|---|
| Released: | July 21, 2022 |
| Published: | July 21, 2022 |
| Release version: | 30.122062.17377.0 |
| Engine version: | 1.1.19200.3 |
| Signature version: | 1.367.1011.0 |
What's new
- Added an option to configure file hash computation
- From this build onwards, the product has the new anti-malware engine by default
- Performance improvements for file copy operations
- Bug fixes
Jun-2022 Build: 101.71.18 | Release version: 30.122052.17118.0
| Build: | 101.71.18 |
|---|---|
| Released: | June 24, 2022 |
| Published: | June 24, 2022 |
| Release version: | 30.122052.17118.0 |
What's new
- Fix to support definitions storage in nonstandard locations (outside of /var) for v2 definition updates
- Fixed an issue in the product sensor used on RHEL 6 that could lead to an OS hang
mdatp connectivity testwas extended with an extra URL that the product requires to function correctly. The new URL is https://go.microsoft.com/fwlink/?linkid=2144709.- Up until now, the product log level wasn't persisted between product restarts. Beginning with this version, there's a new command-line tool switch that persists the log level. The new command is
mdatp log level persist --level <level>. - Removed the dependency on
pythonfrom the product installation package - Performance improvements for file copy operations and processing of network events originating from
auditd - Bug fixes
May-2022 Build: 101.68.80 | Release version: 30.122042.16880.0
| Build: | 101.68.80 |
|---|---|
| Released: | May 23, 2022 |
| Published: | May 23, 2022 |
| Release version: | 30.122042.16880.0 |
What's new
- Added support for kernel version
2.6.32-754.47.1.el6.x86_64when running on RHEL 6 - On RHEL 6, product can now be installed on devices running Unbreakable Enterprise Kernel (UEK)
- Fixed an issue where the process name was sometimes incorrectly displayed as
unknownwhen runningmdatp diagnostic real-time-protection-statistics - Fixed a bug where the product sometimes was incorrectly detecting files inside the quarantine folder
- Fixed an issue where the
mdatpcommand-line tool wasn't working when/optwas mounted as a soft-link - Performance improvements & bug fixes
May-2022 Build: 101.65.77 | Release version: 30.122032.16577.0
| Build: | 101.65.77 |
|---|---|
| Released: | May 2, 2022 |
| Published: | May 2, 2022 |
| Release version: | 30.122032.16577.0 |
What's new
- Improved the
conflicting_applicationsfield inmdatp healthto show only the most recent 10 processes and also to include the process names. This makes it easier to identify which processes are potentially conflicting with Microsoft Defender for Endpoint for Linux. - Bug fixes
Mar-2022 (Build: 101.62.74 | Release version: 30.122022.16274.0)
| Build: | 101.62.74 |
|---|---|
| Released: | Mar 24, 2022 |
| Published: | Mar 24, 2022 |
| Release version: | 30.122022.16274.0 |
What's new
- Addressed an issue where the product would incorrectly block access to files greater than 2 GB in size when running on older kernel versions
- Bug fixes
Mar-2022 Build: 101.60.93 | Release version: 30.122012.16093.0
| Build: | 101.60.93 |
|---|---|
| Released: | Mar 9, 2022 |
| Published: | Mar 9, 2022 |
| Release version: | 30.122012.16093.0 |
What's new
- This version contains a security update for CVE-2022-23278.
Mar-2022 Build: 101.60.05 | Release version: 30.122012.16005.0
| Build: | 101.60.05 |
|---|---|
| Released: | Mar 3, 2022 |
| Published: | Mar 3, 2022 |
| Release version: | 30.122012.16005.0 |
What's new
- Added support for kernel version 2.6.32-754.43.1.el6.x86_64 for RHEL 6.10
- Bug fixes
Feb-2022 Build: 101.58.80 | Release version: 30.122012.15880.0
| Build: | 101.58.80 |
|---|---|
| Released: | Feb 20, 2022 |
| Published: | Feb 20, 2022 |
| Release version: | 30.122012.15880.0 |
What's new
- The command-line tool now supports restoring quarantined files to a location other than the one where the file was originally detected. This can be done through
mdatp threat quarantine restore --id [threat-id] --path [destination-folder]. - Beginning with this version, network protection for Linux can be evaluated on demand
- Bug fixes
Jan-2022 Build: 101.56.62 | Release version: 30.121122.15662.0
| Build: | 101.56.62 |
|---|---|
| Released: | Jan 26, 2022 |
| Published: | Jan 26, 2022 |
| Release version: | 30.121122.15662.0 |
What's new
- Fixed a product crash introduced in 101.53.02 that affected multiple customers
Jan-2022 Build: 101.53.02 | Release version: 30.121112.15302.0
| Build: | 101.53.02 |
|---|---|
| Released: | Jan 8, 2022 |
| Published: | Jan 8, 2022 |
| Release version: | 30.121112.15302.0 |
What's new
- Performance improvements & bug fixes
2021 releases
Build: 101.52.57 | Release version: 30.121092.15257.0
| Build: | 101.52.57 |
|---|---|
| Release version: | 30.121092.15257.0 |
What's new
- Added a capability to detect vulnerable Log4j jars in use by Java applications. The machine is periodically inspected for running Java processes with loaded Log4j jars. The information is reported to the Microsoft Defender for Endpoint backend and is exposed in the Vulnerability Management area of the portal.
Build: 101.47.76 | Release version: 30.121092.14776.0
| Build: | 101.47.76 |
|---|---|
| Release version: | 30.121092.14776.0 |
What's new
Added a new switch to the command-line tool to control whether archives are scanned during on-demand scans. This can be configured through mdatp config scan-archives--value [enabled/disabled]. By default, this setting is set to enabled.
Bug fixes
Build: 101.45.13 | Release version: 30.121082.14513.0
| Build: | 101.45.13 |
|---|---|
| Release version: | 30.121082.14513.0 |
What's new
Beginning with this version, we're bringing Microsoft Defender for Endpoint support to the following distros:
- RHEL6.7-6.10 and CentOS6.7-6.10 versions.
- Amazon Linux 2
- Fedora 33 or higher
Bug fixes
Build: 101.45.00 | Release version: 30.121072.14500.0
| Build: | 101.45.00 |
|---|---|
| Release version: | 30.121072.14500.0 |
What's new
- Added new switches to the command-line tool:
- Control degree of parallelism for on-demand scans. This can be configured through
mdatp config maximum-on-demand-scan-threads --value [number-between-1-and-64]. By default, a degree of parallelism of2is used. - Control whether scans after security intelligence updates are enabled or disabled. This can be configured through
mdatp config scan-after-definition-update --value [enabled/disabled]. By default, this setting is set toenabled. - Changing the product log level now requires elevation
- Bug fixes
- Control degree of parallelism for on-demand scans. This can be configured through
Build: 101.39.98 | Release version: 30.121062.13998.0
| Build: | 101.39.98 |
|---|---|
| Release version: | 30.121062.13998.0 |
What's new
- Performance improvements & bug fixes
Build: 101.34.27 | Release version: 30.121052.13427.0
| Build: | 101.34.27 |
|---|---|
| Release version: | 30.121052.13427.0 |
What's new
- Performance improvements & bug fixes
Build: 101.29.64 | Release version: 30.121042.12964.0
| Build: | 101.29.64 |
|---|---|
| Release version: | 30.121042.12964.0 |
What's new
- Beginning with this version, threats detected during on-demand antivirus scans triggered through the command-line client are automatically remediated. Threats detected during scans triggered through the user interface still require manual action.
mdatp diagnostic real-time-protection-statisticsnow supports two more switches:--sort: sorts the output descending by total number of files scanned--top N: displays the top N results (only works if--sortis also specified)- Performance improvements & bug fixes
Build: 101.25.72 | Release version: 30.121022.12563.0
| Build: | 101.25.72 |
|---|---|
| Release version: | 30.121022.12563.0 |
What's new
- Microsoft Defender for Endpoint on Linux is now available in preview for US Government customers. For more information, see Microsoft Defender for Endpoint for US Government customers.
- Fixed an issue where usage of Microsoft Defender for Endpoint on Linux on systems with FUSE filesystems was leading to OS hang
- Performance improvements & other bug fixes
Build: 101.25.63 | Release version: 30.121022.12563.0
| Build: | 101.25.63 |
|---|---|
| Release version: | 30.121022.12563.0 |
What's new
- Performance improvements & bug fixes
Build: 101.23.64 | Release version: 30.121021.12364.0
| Build: | 101.23.64 |
|---|---|
| Release version: | 30.121021.12364.0 |
What's new
- Performance improvement for the situation where an entire mount point is added to the antivirus exclusion list. Prior to this version, the product processed file activity originating from the mount point. Beginning with this version, file activity for excluded mount points is suppressed, leading to better product performance
- Added a new option to the command-line tool to view information about the last on-demand scan. To view information about the last on-demand scan, run
mdatp health --details antivirus - Other performance improvements & bug fixes
Build: 101.18.53
What's new
EDR for Linux is now generally available
Added a new command-line switch (
--ignore-exclusions) to ignore AV exclusions during custom scans (mdatp scan custom)Extended
mdatp diagnostic createwith a new parameter (--path [directory]) that allows the diagnostic logs to be saved to a different directoryPerformance improvements & bug fixes
iOS releases
1.1.28250101
- Integration with Tunnel - Microsoft Defender for Endpoint on iOS can now integrate with Microsoft Tunnel, a VPN gateway solution to enable security and connectivity in a single app. For more information, see Microsoft Tunnel Overview.
- Zero-touch onboard for enrolled iOS devices enrolled through Microsoft Intune is generally available. For more information, see Zero touch onboarding of Microsoft Defender for Endpoint.
- Bug fixes.
1.1.24210103
- Resolved internet connectivity issues on supervised devices. For more information, see Deploy Defender for Endpoint on enrolled iOS devices.
- Bug fixes.
1.1.23250104
- Performance optimizations - Test battery performance with this version and let us know your feedback.
- Zero-touch onboard for enrolled iOS devices - With this version, the preview of Zero-touch onboards for devices enrolled through Microsoft Intune has been added. For more information, see Zero-touch (Silent) onboarding of Microsoft Defender for Endpoint.
- Privacy Controls - Configure privacy controls for phish alert report. For more information, see Configure iOS features.
1.1.23010101
- Bug fixes and performance improvements
- Performance optimizations were made in this release. Test battery performance with this version and let us know your feedback.
1.1.20240103
- Device Health card - Device Health card notifies end-users about any pending software updates.
- Usability enhancements - End-users can now disable the Defender for Endpoint VPN from the Microsoft Defender app itself. Prior to this update, end-users had to disable VPN only from the Settings app.
- Bug fixes.
1.1.20020101
- UX Enhancements - Microsoft Defender for Endpoint has a new look.
- Bug fixes.
1.1.17240101
- Support for Mobile Application Management (MAM) via Intune is generally available with this version. For more information, see Microsoft Defender for Endpoint risk signals available for your App protection policies.
- Jailbreak Detection is generally available. For more information, see Setup Conditional Access Policy based on device risk signals.
- Auto-setup of VPN profile for enrolled devices via Microsoft Intune is generally available. For more information, see Auto-Setup VPN profile for enrolled iOS devices.
- Bug fixes.
1.1.15140101
- Jailbreak Detection is in preview. For more information, see Setup Conditional Access Policy based on device risk signals.
- Auto-setup of VPN profile is in preview for enrolled devices via Microsoft Intune. For more information, see Auto-Setup VPN profile for enrolled iOS devices.
- The Microsoft Defender ATP product name has now been updated to Microsoft Defender for Endpoint in the app store.
- Improved sign-in experience.
- Bug fixes.
1.1.15010101
- With this version, we're announcing support for iPadOS/iPad devices.
- Bug fixes.