Microsoft Defender for Endpoint
Endpoint protection

Create a custom gradual rollout process for Microsoft Defender updates

In brief

The documentation now specifies Windows devices and Microsoft Defender Antivirus platform version 4.18.2106.6 or later, revises the rollout channel descriptions and policy paths, and warns that MDM and Group Policy settings can conflict for Defender settings.

What Defender admins need to know

Verify the platform prerequisite and use only one management authority for these settings to avoid configuration conflicts.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Create a custom gradual rollout process for Microsoft Defender updates

This article describes how to createCreate a custom gradual rollout process forto control when Windows devices receive Microsoft Defender updates by usingAntivirus platform, engine, and security intelligence updates. Use Group Policy, Microsoft Intune, or PowerShell. You can control when devices receive platform, engine,PowerShell to assign update channels based on your validation and security intelligence updates by assigning them to specific update channels.production needs. Before you begin, verify the platform version in Prerequisites.

Prerequisites

Before you configure a custom gradual rollout process, make sure your devices meet the following requirement is met:requirements:

  • This functionality requires Windows operating system.
  • Microsoft Defender Antivirus platform version 4.18.2106.X6 or newer.later.

Supported operating systems

Custom gradual rollout

To create your own custom gradual rollout process for Defender updates, you can use

Review Group Policy, Intune, and PowerShell.Policy settings

The following table lists the available group policyGroup Policy settings for configuring update channels:

Setting title Description Location
Select gradualthe channel for Microsoft Defender monthly platform update rollout channelupdates Enable this policy to specifySelect when devices receive Microsoft Defendermonthly platform updates during the monthly gradual rollout.

Beta Channel: Devices set to this channelupdates. Available channels are the first to receive new updates. Select Beta Channel to participate in identifyingBeta, Preview, Staged, Broad, Critical: Time Delay, and reporting issues to Microsoft. Devices in the Windows Insider Program are subscribed to this channel by default. For use in (manual) test environments only and a limited number of devices.

Current Channel (Preview): Devices set to this channel are offered updates earliest during the monthly gradual release cycle. Suggested for pre-production/validation environments.

Current Channel (Staged): Devices are offered updates after the monthly gradual release cycle. Suggested to apply to a small, representative part of your production population (10%).

Current Channel (Broad): Devices are offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in your production population (10-100%).

Critical- Time Delay: Devices are offered updates with a 48-hour delay. Suggested for critical environments only.

If you disable or don't configure this policy, the device stays up to date automatically during the gradual release cycle. Suitable for most devices.Not configured.

Windows Components\Microsoft Defender Antivirus
Select gradualthe channel for Microsoft Defender monthly engine update rollout channelupdates Enable this policy to specifySelect when devices receive Microsoft Defendermonthly engine updates during the monthly gradual rollout.

Beta Channel: Devices set to this channelupdates. Available channels are the first to receive new updates. Select Beta Channel to participate in identifyingBeta, Preview, Staged, Broad, Critical: Time Delay, and reporting issues to Microsoft. Devices in the Windows Insider Program are subscribed to this channel by default. For use in (manual) test environments only and a limited number of devices.

Current Channel (Preview): Devices set to this channel are offered updates earliest during the monthly gradual release cycle. Suggested for pre-production/validation environments.

Current Channel (Staged): Devices are offered updates after the monthly gradual release cycle. Suggested to apply to a small, representative part of your production population (10%).

Current Channel (Broad): Devices are offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in your production population (10-100%).

Critical- Time Delay: Devices are offered updates with a 48-hour delay. Suggested for critical environments only.

If you disable or don't configure this policy, the device stays up to date automatically during the gradual release cycle. Suitable for most devices.Not configured.

Windows Components\Microsoft Defender Antivirus
Select gradualthe channel for Microsoft Defender daily security intelligence updates rollout channel Enable this policy to specify when devices receive Microsoft DefenderSelect Staged, Broad, or Not configured for security intelligence updates during the daily gradual rollout.

Current Channel (Staged): Devices are offered updates after the release cycle. Suggested to apply to a small, representative part of production population (10%).

Current Channel (Broad): Devices are offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in your production population (10-100%).

If you disable or don't configure this policy, the device stays up to date automatically during the daily release cycle. Suitable for most devices.rollout cycles, which occur multiple times each day.

Windows Components\Microsoft Defender Antivirus
Disable gradual rollout of Microsoft Defender updates Enable this policy to disableDisable gradual rollout of Defenderfor monthly and security intelligence updates.

Current Channel (Broad): Devices set to this channel are offered updates last during the gradual release cycle. Best for datacenter machines that only receive limited updates.

Note: This setting applies to both monthly and daily Defender updates and overrides any previously configured channel selections for platform and engine updates.

If you disable or don't configure this policy, the device remains in Current Channel (Default) unless specified otherwise in specific channels for platform and engine updates. Stay up to date automatically during the gradual release cycle. Suitable for most devices.update channels.

Windows Components\Microsoft Defender Antivirus\MpEngine

For monthly platform and engine updates, use the following channels:

  • Beta Channel: Receive prerelease updates first. Use this channel only for a limited number of devices in manual test environments. Devices in the Windows Insider Program are subscribed to this channel by default.
  • Current Channel (Preview): Receive updates earliest during gradual release. Use this channel for preproduction or validation environments.
  • Current Channel (Staged): Receive updates later during gradual release. Use this channel for a small, representative group of production devices.
  • Current Channel (Broad): Receive updates after gradual release completes. Use this channel for a broad group of production devices.
  • Critical: Time Delay: Receive updates with a 48-hour delay. Use this channel only for critical environments.
  • Not configured: Allow Microsoft to assign devices to channels during gradual release. This setting is suitable for most devices.

For security intelligence updates, select Staged, Broad, or Not configured. The Defender CSP currently documents Staged as equivalent to Broad. Don't rely on a timing difference between Staged and Broad without validating the behavior in your environment. For more rollout guidance, see Manage the gradual rollout process for Microsoft Defender updates.

Configure a gradual rollout by using Group Policy

You can use Group Policy to configure and manage Microsoft Defender Antivirus on your endpoints. In general, you can use the following procedure toTo configure or change Microsoft Defender Antivirus group policy settings:an update channel:

  1. On your Group Policy management machine, open the Group Policy Management Console, right-click the Group Policy Object (GPO) you want to configureconfigure, and select Edit.

  2. UsingIn the Group Policy Management EditorEditor, go to Computer configuration.

  3. Select Administrative templates.

  4. Expand the tree to Windows components > Microsoft Defender Antivirus.

  5. Expand the section listed in the Location column of the preceding policy settings table (for example, Windows Components\Microsoft Defender Antivirus) that contains the setting you want to configure,Group Policy settings table, double-click the setting to open it,setting, and make configuration changes.configure the update channel.

  6. Deploy the updated GPO as you normally do. For guidance, see Deploying Group Policy ObjectsGroup Policy.

Configure a gradual rollout by using Microsoft Intune

To createCreate a Windows Settings Catalog policy in Microsoft Intune. In the Defender category, configure one or more of the following settings:

  • Platform Updates Channel
  • Engine Updates Channel
  • Security Intelligence Updates Channel
  • Disable Gradual Release

If you need to use a custom policy in Intune,Open Mobile Alliance Uniform Resource Identifier (OMA-URI) policy, follow the instructions in Add custom settings for Windows 10 devices in Microsoft Intune and use the following values:

SettingOMA-URIAllowed values
Platform updates channel./Device/Vendor/MSFT/Defender/Configuration/PlatformUpdatesChannel0 Not configured, 2 Beta, 3 Preview, 4 Staged, 5 Broad, 6 Critical: Time Delay
Engine updates channel./Device/Vendor/MSFT/Defender/Configuration/EngineUpdatesChannel0 Not configured, 2 Beta, 3 Preview, 4 Staged, 5 Broad, 6 Critical: Time Delay
Security intelligence updates channel./Device/Vendor/MSFT/Defender/Configuration/SecurityIntelligenceUpdatesChannel0 Not configured, 4 Staged, 5 Broad
Disable gradual release./Device/Vendor/MSFT/Defender/Configuration/DisableGradualRelease0 False, 1 True

For more information onabout the Defender CSP used for the gradual rollout process,OMA-URI settings and values, see Defender CSP.

Configure a gradual rollout by using PowerShell

Use the Set-MpPreference cmdlet to configure roll out of the gradual updates.Defender Antivirus update and protection preferences.

Use the following parameters:

  • PlatformUpdatesChannel (Set-MpPreference -PlatformUpdatesChannel Beta|Preview|Staged|Broad|Delayed|NotConfigured -EngineUpdatesChannel Beta|Preview|Staged|Broad|Delayed|NotConfigured -DisableGradualRelease 1|0 -DefinitionUpdatesChannel Staged|Broad|NotConfigured

Example:

Use Set-MpPreference -PlatformUpdatesChannel Beta, Preview, Staged, Broad, Delayed, or NotConfigured)

  • EngineUpdatesChannel (Beta, Preview, Staged, Broad, Delayed, or NotConfigured)
  • DefinitionUpdatesChannel (Staged, Broad, or NotConfigured)
  • DisableGradualRelease ($true or $false)
  • For example, run the following command in an elevated PowerShell session (a PowerShell window you opened by selecting Run as administrator) to configure platform updates to arrive from the Beta Channel.Channel:

    Set-MpPreference -PlatformUpdatesChannel Beta
    

    For more information on the parameters and how to configure them,about these parameters, see Set-MpPreference (Microsoft Defender Antivirus).

    Verify gradual rollout configuration in the registry

    TheseTo verify the effective PowerShell configuration, run Get-MpPreference | Select-Object PlatformUpdatesChannel, EngineUpdatesChannel, DefinitionUpdatesChannel, DisableGradualRelease.

    Policy-backed update channel settings can be confirmed in the registryappear under HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender:

    • EngineRing
    • PlatformRing
    • SignaturesRing

    The DisableGradualRelease value appears under HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\MpEngine.