The archive metadata date was updated to August 25, 2026. Release tables were reformatted, KB5005292 links were updated, and the “What’s new” heading was adjusted.
What Defender admins need to know
Administrators consulting the archive will find updated KB links and presentation; no action is specified.
Summaries are generated from the documentation change itself.
Live Response improvements include reduced session creation latency when using proxies, an undo remediation manual command, support for OneDrive shares in FindFile action, and improved isolation and stability.
Improved User/Group Permission Handling - Added reporting in mdatp-health for user/group permission issues for Defender files. On restart Defender attempts to cure these issues.
Device Control v1 will be considered deprecated in the nearest future.
To check, run the [mdatp health --details device_control](mac-device-control-overview.md#status) command, and inspect the active property. It shouldn't contain "v1".
Fix: Major performance issues on macOS when Network Protection is set to Audit mode
(GA) macOS devices receive built-in protection. Tamper protection is turned on in block mode by default. This setting helps secure your Mac against threats. To learn more, see Protect macOS security settings with tamper protection.
Live Response for macOS is now available for all Mac devices onboarded to Defender for Endpoint. Devices must meet the minimum requirements. To learn more, see Investigate entities on devices using live response
Added a new field in the output of mdatp health that can be used to query the enforcement level of the network protection feature. The new field is called network_protection_enforcement_level and can take one of the following values: audit, block, or disabled.
Addressed a product issue where multiple detections of the same content could lead to duplicate entries in the threat history.
Up until now, the product log level didn't persist between product restarts. Beginning in this version, there's a new command-line tool switch that persists the log level. The new command is mdatp log level persist --level <level>.
Fixed a regression introduced in version 101.61.69 where the status menu icon was sometimes showing an error icon, even though no action was required from the end user
Improved the conflicting_applications field in mdatp health to show only the most recent 10 processes and also to include the process names. This improvement makes it easier to identify which processes are potentially conflicting with Microsoft Defender for Endpoint for macOS.
This version adds support for macOS 12.3. Starting with macOS 12.3, Apple is removing Python 2.7. There's no Python version preinstalled on macOS by default. ACTION NEEDED:
Users must update Microsoft Defender for Endpoint for Mac to version 101.59.50 (or newer) before updating their devices to macOS Monterey 12.3 (or newer). This minimal version 101.59.50 is a prerequisite to eliminating Python-related issues with Microsoft Defender for Endpoint for macOS devices on macOS Monterey.
The command-line tool now supports restoring quarantined files to a location other than the one where the file was originally detected. Restoration can be done through mdatp threat quarantine restore --id [threat-id] --path [destination-folder].
Extended device control to handle devices connected over Thunderbolt 3
The application is renamed from Microsoft Defender ATP to Microsoft Defender. End users observe the following changes:
The application installation path changed from /Application/Microsoft Defender ATP.app to /Applications/Microsoft Defender.app.
Within the user experience, occurrences of Microsoft Defender ATP are replaced by Microsoft Defender
Resolved an issue where some VPN applications couldn't connect due to the network content filter that is distributed with Microsoft Defender for Endpoint for macOS.
Addressed an issue discovered in macOS 12.2 preview 2 where the installation package couldn't be opened due to a change in the operating system (OS) that prevents installation of packages with certain characteristics. While it appears that this OS change isn't included in the final release of macOS 12.2, it's likely that it will be reintroduced in a future macOS version. As such, we encourage all enterprise administrators to refresh the Microsoft Defender for Endpoint package in their management console to this product version (or a newer version).
Addressed an issue seen on some M1 devices where the product was stuck with invalid anti-malware definitions and couldn't successfully update to a working set of definitions.
After a product setting stops being managed by the administrator through MDM, it now reverts to the value it had before it was managed (the value configured locally by the end user or, if no such local value was explicitly provided, the default value used by the product). Prior to this change, after a setting stopped being managed, its managed value persisted and was still used by the product.
Nov-2021 (Build: 101.49.25)
Build:
101.49.25
Release version:
20.121092.14925.0
What's new
Added a new switch to the command-line tool to control whether archives are scanned during on-demand scans. This can be configured through mdatp config scan-archives --value [enabled/disabled]. By default, this is set to enabled.
Product improvements
Oct-2021 (Build: 101.47.27)
Build:
101.47.27
Release version:
20.121082.14727.0
What's new
Fix for a system freeze occurring on shutdown on macOS Mojave and macOS Catalina.
Oct-2021 (Build: 101.43.84)
Build:
101.43.84
Release version:
20.121082.14384.0
What's new
Candidate build for macOS 12 (Monterey)
Product improvements
Sep-2021 (Build: 101.41.10)
Build:
101.41.10
Release version:
20.121072.14110.0
What's new
Added new switches to the command-line tool:
Control degree of parallelism for on-demand scans. This can be configured through mdatp config maximum-on-demand-scan-threads --value [number-between-1-and-64]. By default, a degree of parallelism of 2 is used.
Addressed an issue where a quick scan couldn't be started from the status menu on macOS 11 (Big Sur).
Apr-2021 (Build: 101.32.69)
Build:
101.32.69
Release version:
20.121042.13269.0
What's new
Addressed an issue where concurrent access to the keychain from Microsoft Defender for Endpoint and other applications can lead to keychain corruption.
Mar-2021 (Build: 101.29.64)
Build:
101.29.64
Release version:
20.121042.12964.0
What's new
Starting with this version, threats detected during on-demand antivirus scans triggered through the command-line client are automatically remediated. Threats detected during scans triggered through the user interface still require manual action.
mdatp diagnostic real-time-protection-statistics now supports two other switches:
Feb-2021 (Build: 101.27.50)
Build:
101.27.50
Release version:
20.121022.12750.0
What's new
Fix to accommodate for Apple certificate expiration for macOS Catalina and earlier. This fix restores Microsoft Defender Vulnerability Management (MDVM) functionality.
Performance improvements (specifically for the situation when the XCode Simulator app is used) & Product improvements.
Jan-2021 (Build: 101.23.64)
Build:
101.23.64
Release version:
20.121021.12364.0
What's new
Added a new option to the command-line tool to view information about the last on-demand scan. To view information about the last on-demand scan, run mdatp health --details antivirus.
Performance improvements & Product improvements
Dec-2020 (Build: 101.22.79)
Build:
101.22.79
Release version:
20.121012.12279.0
What's new
Performance improvements & Product improvements
Nov-2020 (Build: 101.19.88)
Build:
101.19.88
Release version:
20.121011.11988.0
What's new
Performance improvements & Product improvements
Nov-2020 (Build: 101.19.48)
Build:
101.19.48
Release version:
20.120121.11948.0
What's new
Oct-2020 (Build: 101.19.21)
Build:
101.19.21
Release version:
20.120101.11921.0
What's new
Product improvements
Oct-2020 (Build: 101.15.26)
Build:
101.15.26
Release version:
20.120102.11526.0
What's new
Improved the reliability of the agent when running on macOS 11 Big Sur.
Added a new command-line switch (--ignore-exclusions) to ignore AV exclusions during custom scans (mdatp scan custom).
Sep-2020 (Build: 101.13.75)
Build:
101.13.75
Release version:
20.120101.11375.0
What's new
Removed conditions when Microsoft Defender for Endpoint was triggering a macOS 11 (Big Sur) issue that manifests into a kernel panic.
Fixed a memory leak in the Endpoint Security system extension when running on macOS 11 (Big Sur).
Status menu icon now shows a healthy state when the product settings are managed. Previously, the status menu icon was displaying a warning or error state, even though the product settings were managed by the administrator.
Jul-2020 (Build: 101.09.50)
Build:
101.09.50
What's new
This product version is validated on macOS Big Sur 11 preview 9.
Extended mdatp diagnostic create with a new parameter (--path [directory]) that allows the diagnostic logs to be saved to a different directory.
Performance improvements & Product improvements
Jul-2020 (Build: 101.09.49)
Build:
101.09.49
What's new
User interface improvements to differentiate exclusions that are managed by the IT administrator versus exclusions defined by the local user.
Improved CPU utilization during on-demand scans.
Jun-2020 (Build: 101.07.23)
Build:
101.07.23
What's new
Added new fields to the output of mdatp --health for checking the status of passive mode and the EDR group ID.
May-2020 (Build: 101.06.63)
Build:
101.06.63
What's new
Addressed a performance regression introduced in version 101.05.17. The regression was introduced with the fix to eliminate the kernel panics some customers observed when accessing SMB shares. We reverted this code change and are investigating alternative ways to eliminate the kernel panics.
May-2020 (Build: 101.05.17)
Build:
101.05.17
What's new
Addressed a kernel panic that occurred sometimes when accessing SMB file shares.
Performance improvements & Product improvements
Apr-2020 (Build: 101.05.16)
Build:
101.05.16
What's new
Improvements to quick scan logic to significantly reduce the number of scanned files.
When Full Disk Access isn't enabled on the device, a warning is now displayed in the status menu.
2019 releases (Build: 100.82.60)
Build:
100.82.60
What's new
Addressed an issue where the product fails to start following a definition update.
2019 releases (Build: 100.80.42)
Build:
100.80.42
What's new
Product improvements
2019 releases (Build: 100.79.42)
Build:
100.79.42
What's new
Fixed an issue where Microsoft Defender for Endpoint on macOS was sometimes interfering with Time Machine.
Added a new switch to the command-line utility for testing the connectivity with the backend service
2019 releases (Build: 100.72.15)
Build:
100.72.15
What's new
Product improvements
2019 releases (Build: 100.70.99)
Build:
100.70.99
What's new
Addressed an issue that impacts the ability of some users to upgrade to macOS Catalina when real-time protection is enabled. This sporadic issue was caused by Microsoft Defender for Endpoint locking files within Catalina upgrade package while scanning them for threats, which led to failures in the upgrade sequence.
2019 releases (Build: 100.68.99)
Build:
100.68.99
What's new
Added the ability to configure the antivirus functionality to run in passive mode.
The Defender for Endpoint package rollout into production happens gradually. From the time the release notes are published, it might take up to a week for the package to be pushed to all production machines.
Removed external dependency of uuid-runtime from the Defender for Endpoint package
Removed external dependency of MDE Netfilter and libpcre from MDE package
Fix for Python script executing unverified binaries with root-level privileges to identify Java processes using outdated versions of log4j (CVE-2025-26684) has been addressed.
Added detection mechanism for CVE-2025-31324 affecting the "Visual Composer" component of the SAP NetWeaver application server.
The MDATP package rollout into production will be done gradually. From the time the release notes are published, it might take up to a week for the package to be pushed to all production machines.
The vulnerability in curl, CVE-2024-7264, has been addressed.
Other stability improvements and bug fixes.
Known Issues
There's a known issue where MDE is deleting the configuration file located at /etc/systemd/system/mdatp.service.d on each service start. As a workaround, customers can use the Immutable attribute that prevents the files from being modified or deleted.
To set the file to be unmodifiable, execute the following command:
Note that the chattr command can only be used on supported file systems, such as ext4.
If you need further assistance, you can reach out to our support team with your organization ID, and we can implement a temporary mitigation to prevent deletion. A permanent fix for this issue is available in MDE version 101.25032.0000.
Upgraded the Bond version to 13.0.1 to address security vulnerabilities in versions 12 or lower.
Mdatp package no longer has a dependency on SELinux packages.
Users can now query the status of supplementary event provider eBPF using the threat hunting query in DeviceTvmInfoGathering. To learn more about this query check: Use eBPF-based sensor for Microsoft Defender for Endpoint on Linux. The result of this query can return the following two values as eBPF status:
Enabled: When eBPF is enabled as working as expected.
Disabled: When eBPF is disabled due to one of the following reasons:
Starting with this version, Defender for Endpoint on Linux no longer supports AuditD as a supplementary event provider. For improved stability and performance, we have transitioned to eBPF. If you disable eBPF, or in the event eBPF isn't supported on any specific kernel, Defender for Endpoint on Linux automatically switches back to Net link as a fallback supplementary event provider. Net link provides reduced functionality and tracks only process-related events. In this case, all process operations continue to flow seamlessly, but you could miss specific file and socket-related events that eBPF would otherwise capture. For more information, see Use eBPF-based sensor for Microsoft Defender for Endpoint on Linux. If you have any concerns or need assistance during this transition, contact support.
There are multiple fixes and new changes in this release.
Fixes bug in which infected command-line threat information wasn't showing correctly in security portal.
Fixes a bug where disabling a preview feature required a Defender of Endpoint to disable it.
Global Exclusions feature using managed JSON is now in Public Preview. available in insiders slow from 101.23092.0012. For more information, see linux-exclusions.
Updated the Linux default engine version to 1.1.24050.7 and default signature version to 1.411.410.0.
This release fixes a bug related to high memory usage eventually leading to high CPU due to eBPF memory leak in kernel space resulting in servers going into unusable states. This only affected the kernel versions 3.10x and <= 4.16x, majorly on RHEL/CentOS distros. Update to the latest MDE version to avoid any impact.
We have now simplified the output of mdatp health --detail features
There are multiple fixes and new changes in this release:
In version 24032.0007, there was a known issue where the enrollment of devices to MDE Security Management failed when using the "Device Tagging" mechanism via the mdatp_managed.json file. This issue has been resolved in the current release.
There are multiple fixes and new changes in this release:
In passive and on-demand modes, antivirus engine remains in idle state and is used only during scheduled custom scans. Thus as part of performance improvements, we have made changes to keep the AV engine down in passive and on-demand mode except during scheduled custom scans. If the real time protection is enabled, antivirus engine will always be up and running. This has no impact on your server protection in any mode.
To keep users informed of the state of antivirus engine, we have introduced a new field called "engine_load_status" as part of MDATP health. It indicates whether antivirus engine is currently running or not.
Field name
engine_load_status
Possible values
Engine not loaded (AV engine process is down), Engine load succeeded (AV engine process up and running)
Healthy scenarios:
If RTP is enabled, engine_load_status should be "Engine load succeeded"
If MDE is in on-demand or passive mode, and custom scan isn't running then "engine_load_status" should be "Engine not loaded"
If MDE is in on-demand or passive mode, and custom scan is running then "engine_load_status" should be "Engine load succeeded"
Bug fix to enhance behavioral detections.
Stability and performance improvements.
Other bug fixes.
Known Issues
sudo mdatp edr tag set --name GROUP --value MDE-Management
**
The issue has been fixed in Build: 101.24042.0002**
There are multiple fixes and new changes in this release:
The addition of a new log file - microsoft_defender_scan_skip.log. This logs the filenames that were skipped from various antivirus scans by Microsoft Defender for Endpoint due to any reason.
If you already have Defender for Endpoint running on any of these distros and facing any issues in the older versions, upgrade to the latest Defender for Endpoint version from the corresponding ring mentioned above.
From this release, Microsoft Defender for Endpoint on Linux will no longer be shipping a solution for RHEL 6.
RHEL 6 'Extended end of life support' is poised to end by June 30, 2024 and customers are advised to plan their RHEL upgrades accordingly aligned with guidance from Red Hat. Customers who need to run Defender for Endpoint on RHEL 6 servers can continue to use version 101.23082.0011 (doesn't expire before June 30, 2024) supported on kernel versions 2.6.32-754.49.1.el6.x86_64 or prior.
Engine Update to 1.1.23080.2007 and Signatures Ver: 1.395.1560.0.
Streamlined device connectivity experience is now in public preview mode. public blog
Known issues:
Microsoft Defender for Endpoint for Linux on Rocky and Alma currently has the following known issues:
Live Response and Threat Vulnerability Management are currently not supported (work in progress).
Operating system info for devices isn't visible in the Microsoft Defender portal
From this release, Microsoft Defender for Endpoint on Linux will no longer be shipping a solution for RHEL 6.
RHEL 6 'Extended end of life support' is poised to end by June 30, 2024 and customers are advised to plan their RHEL upgrades accordingly aligned with guidance from Red Hat. Customers who need to run Defender for Endpoint on RHEL 6 servers can continue to use version 101.23082.0011 (doesn't expire before June 30, 2024) supported on kernel versions 2.6.32-754.49.1.el6.x86_64 or prior.
Engine Update to 1.1.23080.2007 and Signatures Ver: 1.395.1560.0.
Streamlined device connectivity experience is now in public preview mode. public blog
This new release is built over October 2023 release (101.23082.0009) with addition of following changes. There's no change for other customers and upgrading is optional.
Fix for immutable mode of auditd when supplementary subsystem is ebpf: In ebpf mode all mdatp audit rules should be cleaned after switching to ebpf and rebooting. After the reboot, mdatp audit rules weren't cleaned due to which it was resulting in hang of the server. The fix cleans these rules, user shouldn't see any mdatp rules loaded on reboot
Fix for MDE not starting up on RHEL 6.
Known issues
sudo apt purge mdatp
sudo apt-get install mdatp
As an alternative you can follow the instructions to uninstall, then install the latest version of the package.
If you don't want to uninstall mdatp, you can disable rtp and mdatp in sequence before upgrading. Some customers (<1%) experience issues with this method.
This new release is built over October 2023 release (101.23082.0009) with addition of new CA Certificates. There's no change for other customers and upgrading is optional.
Engine version on the device must be "1.1.23080.007" or above. Check your engine version by using the following command.
mdatp health --field engine_version
Option to support monitoring of NFS and FUSE mount points. These are ignored by default.
The following example shows how to monitor all filesystem while ignoring only NFS:
There are multiple fixes and new changes in this release:
In mde_installer.sh v0.6.3, users can use the --channel argument to provide the channel of the configured repository during cleanup. For example, sudo ./mde_installer --clean --channel prod
The Network Extension can now be reset by administrators using mdatp network-protection reset.
There are multiple fixes and new changes in this releaserelease:
If a proxy is set for Defender for Endpoint, then it's visible in the mdatp health command output. With this release we provided two options in mdatp diagnostic hot-event-sources:
Files
Executables
Network Protection: Connections that are blocked by Network Protection and have the block overridden by users is now correctly reported to Microsoft Defender XDR
Improved logging in Network Protection block and audit events for debugging
Other fixes and improvements
From this version, enforcementLevel are in passive mode by default giving admins more control over where they want 'RTP on' within their estate
This change only applies to fresh MDE deployments, for example, servers where Defender for Endpoint is being deployed for the first time. In update scenarios, servers that have Defender for Endpoint deployed with RTP ON, continue operating with RTP ON even post update to version 101.23062.0010
Bug fix: RPM database corruption issue in Defender Vulnerability Management baseline is fixed.
There are multiple fixes and new changes in this release
- release:
The build version schema is updated from this release. While the major version number remains same as 101, the minor version number now has five digits followed by four digit patch number that is, 101.xxxxx.yyy
-
Improved Network Protection memory consumption under stress
Updated the engine version to 1.1.20300.5 and signature version to 1.391.2837.0.
There are multiple fixes and new changes in this release release:
Improved Network Protection Proxy handling.
In Passive mode, Defender for Endpoint no longer scans when Definition update happens.
Devices continue to be protected even after Defender for Endpoint agent is expired. We recommend upgrading the Defender for Endpoint Linux agent to the latest available version to receive bug fixes, features, and performance improvements.
Removed semanage package dependency.
Engine Update to 1.1.20100.7 and Signatures Ver: 1.385.1648.0.
Bug fixes.
Known issues
As an alternative you can follow the instructions to uninstall, then install the latest version of the package.
If you don't want to uninstall mdatp, you can disable rtp and mdatp in sequence before upgrading.
Some customers (<1%) experience issues with this method.
sudo mdatp config real-time-protection --value=disabled
### May-2023 Build: 101.98.64 | Release version: 30.123032.19864.0
|Build:| Build: | ****101.98.64**|
|--------------------|-----------------------|
|Released:| Released: | ****May 3,2023**|
|Published:| Published: | ****May 3,2023**|
|Release version:| Release version: | ****30.123032.19864.0**|
|Engine version:| Engine version: | ****1.1.20100.6**|
|Signature version:| Signature version: | ****1.385.68.0**|
#### What's new
There are multiple fixes and new changes in this releaserelease:
- Health message improvements to capture details about auditd failures.
- Improvements to handle augenrules, which was causing installation failure.
- Periodic memory cleanup in engine process.
- Fix for memory issue in mdatp audisp plugin.
- Handled missing plugin directory path during installation.
- When conflicting application is using blocking fanotify, with default configuration mdatp health shows unhealthy. This is now fixed.
- Support for ICMP traffic inspection in BM.
- Engine Update to `1.1.20100.6` and Signatures Ver: `1.385.68.0`.
- Bug fixes.
#### Known issues
2. As an alternative you can follow the instructions to [uninstall](./linux-off-board-endpoints.md#uninstall-the-defender-application-from-a-linux-server), then [install](linux-install-manually.md#application-installation) the latest version of the package.
If you don't want to uninstall mdatp, you can disable rtp and mdatp in sequence before upgrading.
Caution: Some customers (<1%) experience issues with this method.
```bash
sudo mdatp config real-time-protection --value=disabled
### April-2023 Build: 101.98.58 | Release version: 30.123022.19858.0
|Build:| Build: | ****101.98.58**|
|--------------------|-----------------------|
|Released:| Released: | ****April 20,2023**|
|Published:| Published: | ****April 20,2023**|
|Release version:| Release version: | ****30.123022.19858.0**|
|Engine version:| Engine version: | ****1.1.20000.2**|
|Signature version:| Signature version: | ****1.381.3067.0**|
#### What's new
There are multiple fixes and new changes in this releaserelease:
- Logging and error reporting improvements for auditd.
- Handle failure in reload of auditd configuration.
- Handling for empty auditd rule files during MDE install.
- Engine Update to `1.1.20000.2` and Signatures Ver: `1.381.3067.0`.
- Addressed a health issue in mdatp that occurs due to selinux denials.
- Bug fixes.
#### Known issues
```bash
echo -c >> /etc/audit/rules.d/audit.rules
augenrules --load
There are two ways to mitigate this upgrade issue:
Use your package manager to uninstall the 101.75.43 or 101.78.13 mdatp version.
Example:
sudo apt purge mdatp
sudo apt-get install mdatp
As an alternative you can follow the instructions to uninstall, then install the latest version of the package.
If you don't want to uninstall mdatp, you can disable rtp and mdatp in sequence before upgrading.
Caution: Some customers (<1%) experience issues with this method.
This new release is built over March 2023 release (101.98.05) with a fix for Live response commands failing for one of our customers. There's no change for other customers and upgrade is optional.
Known issues
With mdatp version 101.98.30 you might see a health false issue in some of the cases, because SELinux rules aren't defined for certain scenarios. The health warning could look something like this:
Improved Data Completeness for Network Connection events
Improved Data Collection capabilities for file ownership/permissions changes
seManage in part of the package, to that seLinux policies can be configured in different distro (fixed).
Improved enterprise daemon stability
AuditD stop path clean-up
Improved the stability of mdatp stop flow.
Added new field to wdavstate to keep track of platform update time.
Stability improvements to parsing Defender for Endpoint onboarding blob.
Scan doesn't proceed if a valid license isn't present (fixed)
Added performance tracing option to xPlatClientAnalyzer, with tracing enabled mdatp process dumps the flow in all_process.zip file that can be used for analysis of performance issues.
Added support in Defender for Endpoint for the following RHEL-6 kernel versions:
2.6.32-754.43.1.el6.x86_64
2.6.32-754.49.1.el6.x86_64
Other fixes
Known issues
While upgrading mdatp to version 101.94.13, you might notice that health is false, with health_issues as "no active supplementary event provider". This can happen due to misconfigured/conflicting auditd rules on existing machines. To mitigate the issue, the auditd rules on the existing machines need to be fixed. The following steps can help you to identify such auditd rules (these commands need to be run as super user). Make sure to back up following file: /etc/audit/rules.d/audit.rules as these steps are only to identify failures.
As an alternative, you can follow the instructions to uninstall, then install the latest version of the package.
In case you don't want to uninstall mdatp you can disable rtp and mdatp in sequence before upgrade.
Caution: Some customers(<1%) are experiencing issues with this method.
sudo mdatp config real-time-protection --value=disabled
### Jan-2023 Build: 101.94.13 | Release version: 30.122112.19413.0
|Build:| Build: | ****101.94.13**|
|--------------------|-----------------------|
|Released:| Released: | ****January 10, 2023**|
|Published:| Published: | ****January 10, 2023**|
|Release version:| Release version: | ****30.122112.19413.0**|
|Engine version:| Engine version: | ****1.1.19700.3**|
|Signature version:| Signature version: | ****1.377.550.0**|
#### What's new
-
There are multiple fixes and new changes in this releaserelease:
- Skip quarantine of threats in passive mode by default.
- New config, nonExecMountPolicy, can now be used to specify behavior of RTP on mount point marked as noexec.
- New config, unmonitoredFilesystems, can be used to unmonitor certain filesystems.
- Improved performance under high load and in speed test scenarios.
- Fixes an issue with accessing SMB shares behind Cisco AnyConnect VPN connections.
- Fixes an issue with Network Protection and SMB.
- lttng performance tracing support.
- TVM, eBPF, auditd, telemetry, and mdatp cli improvements.
- mdatp health now reports behavior_monitoring
- Other fixes.
#### Known issues
```bash
sudo apt purge mdatp
sudo apt-get install mdatp
Added a capability to detect vulnerable Log4j jars in use by Java applications. The machine is periodically inspected for running Java processes with loaded Log4j jars. The information is reported to the Microsoft Defender for Endpoint backend and is exposed in the Vulnerability Management area of the portal.
Added a new switch to the command-line tool to control whether archives are scanned during on-demand scans. This can be configured through mdatp config scan-archives--value [enabled/disabled]. By default, this setting is set to enabled.
Added a new command-line switch (--ignore-exclusions) to ignore AV exclusions during custom scans (mdatp scan custom)
Extended mdatp diagnostic create with a new parameter (--path [directory]) that allows the diagnostic logs to be saved to a different directory
Performance improvements & bug fixes
1.1.15010101
With this version, we're announcing support for iPadOS/iPad devices.
Bug fixes.
\ No newline at end of file
Bug fixes.
@@ -6,7 +6,7 @@ ms.subservice: reference ms.author: lwainstein author: limwainstein ms.localizationpriority: medium-ms.date: 02/18/2026+ms.date: 08/25/2026 ai-usage: ai-assisted ms.collection: - m365-security@@ -26,22 +26,22 @@ This page contains archived platform-specific build and version history for Micr ### May-2024 (Release version: 10.8750.27558.1004)-|OS |KB |Release version |-| -------- | -------- | -------- |-|Windows Server 2012 R2, 2016 |[KB5005292](https://support.microsoft.com/topic/microsoft-defender-for-endpoint-update-for-edr-sensor-f8f69773-f17f-420f-91f4-a8e5167284ac)|10.8750.27558.1004|+|OS|KB|Release version|+|---|---|---|+|Windows Server 2012 R2, 2016|[KB5005292](https://support.microsoft.com/servicing/Management-Tools/microsoft-defender/update/microsoft-defender-for-endpoint-update-for-edr-sensor)|10.8750.27558.1004| #### What's new ##### Configuration Management-- Fixed an issue that caused empty policies to appear in the UI. -- Configured Windows Defender Application Control (WDAC) policies to block undesired applications from running on the device. +- Fixed an issue that caused empty policies to appear in the UI.+- Configured Windows Defender Application Control (WDAC) policies to block undesired applications from running on the device. ### Feb-2024 (Release version: 10.8735.26020.1009)-|OS |KB |Release version |-|---------|---------|---------|-|Windows Server 2012 R2, 2016 |[KB5005292](https://support.microsoft.com/topic/microsoft-defender-for-endpoint-update-for-edr-sensor-f8f69773-f17f-420f-91f4-a8e5167284ac)|10.8735.26020.1009|+|OS|KB|Release version|+|---|---|---|+|Windows Server 2012 R2, 2016|[KB5005292](https://support.microsoft.com/servicing/Management-Tools/microsoft-defender/update/microsoft-defender-for-endpoint-update-for-edr-sensor)|10.8735.26020.1009| #### What's new@@ -49,7 +49,7 @@ This page contains archived platform-specific build and version history for Micr - Enabled support for IPV6 connections in Live Response connection commands. - Fixed an issue in Downlevel Unified Agent that caused ServerRoles not to be populated.- + ##### Threat Vulnerability Management - An issue related to the agent's monitoring of deleted registry keys no longer occurs.@@ -59,20 +59,20 @@ This page contains archived platform-specific build and version history for Micr - Introduced performance enhancements to minimize the CPU and memory footprint of the agent. - Enhanced the accuracy of network detections.- + ##### Data Loss Prevention (DLP) - Introduced multiple performance and stability fixes.- + ##### Security Configuration Management-- Policies that include special characters are now supported. +- Policies that include special characters are now supported. ### Dec-2023 (Release version: 10.8672.25926.1019)-|OS |KB |Release version |-|---------|---------|---------|-|Windows Server 2012 R2, 2016 |[KB5005292](https://support.microsoft.com/topic/microsoft-defender-for-endpoint-update-for-edr-sensor-f8f69773-f17f-420f-91f4-a8e5167284ac)|10.8672.25926.1019|+|OS|KB|Release version|+|---|---|---|+|Windows Server 2012 R2, 2016|[KB5005292](https://support.microsoft.com/servicing/Management-Tools/microsoft-defender/update/microsoft-defender-for-endpoint-update-for-edr-sensor)|10.8672.25926.1019| #### What's new@@ -80,9 +80,9 @@ This page contains archived platform-specific build and version history for Micr ### Sept-2023 (Release version: 10.8560.25364.1036)-|OS |KB |Release version |-|---------|---------|---------|-|Windows Server 2012 R2, 2016 |[KB5005292](https://support.microsoft.com/topic/microsoft-defender-for-endpoint-update-for-edr-sensor-f8f69773-f17f-420f-91f4-a8e5167284ac)|10.8560.25364.1036|+|OS|KB|Release version|+|---|---|---|+|Windows Server 2012 R2, 2016|[KB5005292](https://support.microsoft.com/servicing/Management-Tools/microsoft-defender/update/microsoft-defender-for-endpoint-update-for-edr-sensor)|10.8560.25364.1036| #### What's new@@ -90,9 +90,9 @@ This page contains archived platform-specific build and version history for Micr ### May-2023 (Release version: 10.8295.22621.1023)-|OS |KB |Release version |-|---------|---------|---------|-|Windows Server 2012 R2, 2016 |[KB5005292](https://support.microsoft.com/topic/microsoft-defender-for-endpoint-update-for-edr-sensor-f8f69773-f17f-420f-91f4-a8e5167284ac)|10.8295.22621.1023|+|OS|KB|Release version|+|---|---|---|+|Windows Server 2012 R2, 2016|[KB5005292](https://support.microsoft.com/servicing/Management-Tools/microsoft-defender/update/microsoft-defender-for-endpoint-update-for-edr-sensor)|10.8295.22621.1023| #### What's new@@ -100,9 +100,9 @@ This page contains archived platform-specific build and version history for Micr ### Jan/Feb-2023 (Release version: 10.8295.22621.1019)-|OS |KB |Release version |-|---------|---------|---------|-|Windows Server 2012 R2, 2016 |[KB5005292](https://support.microsoft.com/topic/microsoft-defender-for-endpoint-update-for-edr-sensor-f8f69773-f17f-420f-91f4-a8e5167284ac)|10.8295.22621.1019|+|OS|KB|Release version|+|---|---|---|+|Windows Server 2012 R2, 2016|[KB5005292](https://support.microsoft.com/servicing/Management-Tools/microsoft-defender/update/microsoft-defender-for-endpoint-update-for-edr-sensor)|10.8295.22621.1019| #### What's new@@ -110,23 +110,23 @@ This page contains archived platform-specific build and version history for Micr ### Dec-2022 (Release version: 10.8210.22621.1016)-|OS |KB |Release version |-|---------|---------|---------|-|Windows Server 2012 R2, 2016 |[KB5005292](https://support.microsoft.com/topic/microsoft-defender-for-endpoint-update-for-edr-sensor-f8f69773-f17f-420f-91f4-a8e5167284ac)|10.8210.22621.1016|+|OS|KB|Release version|+|---|---|---|+|Windows Server 2012 R2, 2016|[KB5005292](https://support.microsoft.com/servicing/Management-Tools/microsoft-defender/update/microsoft-defender-for-endpoint-update-for-edr-sensor)|10.8210.22621.1016|-**What's new**+#### What's new - Bug fixes and stability improvements ### Aug-2022 (Release version: 10.8210.*)-|OS |KB |Release version |-|---------|---------|---------|-|Windows Server 2012 R2, 2016 |[KB5005292](https://support.microsoft.com/topic/microsoft-defender-for-endpoint-update-for-edr-sensor-f8f69773-f17f-420f-91f4-a8e5167284ac)|10.8210.22621.1011|-|Windows 11 21H2 (Cobalt)<br> (Windows 11 SV 21H2) | [KB5016691](https://support.microsoft.com/topic/august-25-2022-kb5016691-os-build-22000-918-preview-59097044-915a-49a0-8870-49823236adbd) | 10.8210.22000.918 |-|Server 2022 (Iron) | [KB5016693](https://support.microsoft.com/topic/august-16-2022-kb5016693-os-build-20348-946-preview-ee90d0bc-c162-4124-b7c6-f963ee7b17ed) |10.8210.20348.946 |-|Windows 10 20H2/21H1/21H2<br> Windows Server 20H2 (Vibranium) | [KB5016688](https://support.microsoft.com/topic/august-26-2022-kb5016688-os-builds-19042-1949-19043-1949-and-19044-1949-preview-ec31ebdc-067d-44dd-beb0-eabcc984d843) | 10.8210.19041.1949 |-|Windows Server 2019 (RS5) |[KB5016690](https://support.microsoft.com/topic/august-23-2022-kb5016690-os-build-17763-3346-preview-b81d1ac5-75c7-42c1-b638-f13aa4242f42) |10.8210.17763.3346 |+|OS|KB|Release version|+|---|---|---|+|Windows Server 2012 R2, 2016|[KB5005292](https://support.microsoft.com/servicing/Management-Tools/microsoft-defender/update/microsoft-defender-for-endpoint-update-for-edr-sensor)|10.8210.22621.1011|+|Windows 11 21H2 (Cobalt) <br> (Windows 11 SV 21H2)|[KB5016691](https://support.microsoft.com/servicing/os/windows-11/2022/08/august-25-2022-kb5016691-os-build-22000-918-preview)|10.8210.22000.918|+|Server 2022 (Iron)|[KB5016693](https://support.microsoft.com/servicing/os/windows-server/2022/08/august-16-2022-kb5016693-os-build-20348-946-preview)|10.8210.20348.946|+|Windows 10 20H2/21H1/21H2 <br> Windows Server 20H2 (Vibranium)|[KB5016688](https://support.microsoft.com/servicing/os/windows-10/2022/08/august-26-2022-kb5016688-os-builds-19042-1949-19043-1949-and-19044-1949-preview)|10.8210.19041.1949|+|Windows Server 2019 (RS5)|[KB5016690](https://support.microsoft.com/servicing/os/windows-10/2022/08/august-23-2022-kb5016690-os-build-17763-3346-preview)|10.8210.17763.3346| #### What's new@@ -140,7 +140,7 @@ This page contains archived platform-specific build and version history for Micr - Live Response improvements include reduced session creation latency when using proxies, an undo remediation manual command, support for OneDrive shares in `FindFile` action, and improved isolation and stability. - [Security Management for Microsoft Defender for Endpoint](/intune/intune-service/protect/mde-security-integration#configure-your-tenant-to-support-microsoft-defender-for-endpoint-security-configuration-management) now provides the ability to sync the device configuration on demand instead of waiting for a specific cadence.- > [!NOTE] + > [!NOTE] > Update package KB5005292 is on a gradual rollout schedule through Windows Update. Towards the end of this schedule, the package will be published completely, including to the update catalog for manual download. For the current release, this will be in the second half of October. If you want to test the package sooner, you can use [gradual rollout controls for platform updates](configure-updates.md) to select the Preview channel. ## macOS releases@@ -149,225 +149,224 @@ This page contains archived platform-specific build and version history for Micr #### Release details-| Release version | Engine version | Signature version |-| -------- | -------- |-------- |-|20.125062.6.0 |1.1.25070.3000 |1.435.357.0 |+|Release version|Engine version|Signature version|+|---|---|---|+|20.125062.6.0|1.1.25070.3000|1.435.357.0| #### Enhancements and features-| Feature area | Update summary |-|--------------|---------------|-| General | Bug and performance fixes. |+|Feature area|Update summary|+|---|---|+|General|Bug and performance fixes.|-### Jul-2025 (Build: 101.25062.0005 | Release version: 20.125062.5.0)+### Jul-2025 (Build: 101.25062.0005 | Release version: 20.125062.5.0)-| Build: | **101.25062.0005** |-|--------------------|----------------------|-| Release version: | **20.125062.5.0** |-| Engine version: | **1.1.25040.3000** |-| Signature version: | **1.427.248.0** |+|Build:|**101.25062.0005**|+|---|---|+|Release version:|**20.125062.5.0**|+|Engine version:|**1.1.25040.3000**|+|Signature version:|**1.427.248.0**|-##### What's new+#### What's new - Bug and performance fixes-### Jun-2025 (Build: 101.25052.0012 | Release version: 20.125052.12.0)+### Jun-2025 (Build: 101.25052.0012 | Release version: 20.125052.12.0)-| Build: | **101.25052.0012** |-|--------------------|----------------------|-| Release version: | **20.125052.12.0** |-| Engine version: | **1.1.25060.3000** |-| Signature version: | **1.431.226.0** |+|Build:|**101.25052.0012**|+|---|---|+|Release version:|**20.125052.12.0**|+|Engine version:|**1.1.25060.3000**|+|Signature version:|**1.431.226.0**|-##### What's new+#### What's new - Bug and performance fixes-### May-2025 (Build: 101.25042.0009 | Release version: 20.125042.9.0)+### May-2025 (Build: 101.25042.0009 | Release version: 20.125042.9.0)-| Build: | **101.25042.0009** |-|--------------------|----------------------|-| Release version: | **20.125042.9.0** |-| Engine version: | **1.1.25040.3000** |-| Signature version: | **1.429.521.0** |+|Build:|**101.25042.0009**|+|---|---|+|Release version:|**20.125042.9.0**|+|Engine version:|**1.1.25040.3000**|+|Signature version:|**1.429.521.0**|-##### What's new+#### What's new - `mdatp health --details edr` now includes Azure Active Directory information - Bug and performance fixes-### Apr-2025 (Build: 101.25032.0006 | Release version: 20.125032.6.0)+### Apr-2025 (Build: 101.25032.0006 | Release version: 20.125032.6.0)-| Build: | **101.25032.0006** |-|--------------------|----------------------|-| Release version: | **20.125032.6.0** |-| Engine version: | **1.1.25020.3000** |-| Signature version: | **1.427.158.0** |+|Build:|**101.25032.0006**|+|---|---|+|Release version:|**20.125032.6.0**|+|Engine version:|**1.1.25020.3000**|+|Signature version:|**1.427.158.0**|-##### What's new+#### What's new - Hardware UUID is now displayed in the Security Portal - Bug and performance fixes - **(GA) Behavior Monitoring for macOS**: For information on Behavior Monitoring for Microsoft Defender for Endpoint on macOS, see [Behavior Monitoring in Microsoft Defender for Endpoint on macOS](behavior-monitor-macos.md).-### Mar-2025 (Build: 101.25022.0003 | Release version: 20.125022.3.0)+### Mar-2025 (Build: 101.25022.0003 | Release version: 20.125022.3.0)-| Build: | **101.25022.0003** |-|--------------------|-----------------------|-| Release version: | **20.125022.3.0** |-| Engine version: | **1.1.24090.12** |-| Signature version: | **1.423.249.0** |+|Build:|**101.25022.0003**|+|---|---|+|Release version:|**20.125022.3.0**|+|Engine version:|**1.1.24090.12**|+|Signature version:|**1.423.249.0**|-##### What's new+#### What's new - Bug and performance fixes-### Mar-2025 (Build: 101.25012.0008 | Release version: 20.125012.7.0)+### Mar-2025 (Build: 101.25012.0008 | Release version: 20.125012.7.0)-| Build: | **101.25012.0008** |-|--------------------|-----------------------|-| Release version: | **20.125012.7.0** |-| Engine version: | **1.1.25020.3000** |-| Signature version: | **1.423.211.0** |+|Build:|**101.25012.0008**|+|---|---|+|Release version:|**20.125012.7.0**|+|Engine version:|**1.1.25020.3000**|+|Signature version:|**1.423.211.0**|-##### What's new+#### What's new - Bug fixes and performance improvements-### Feb-2025 (Build: 101.24122.0011 | Release version: 20.124122.11.0)+### Feb-2025 (Build: 101.24122.0011 | Release version: 20.124122.11.0)-| Build: | **101.24122.0011** |-|--------------------|-----------------------|-| Release version: | **20.124122.11.0** |-| Engine version: | **1.1.24080.11** |-| Signature version: | **1.419.351.0** |+|Build:|**101.24122.0011**|+|---|---|+|Release version:|**20.124122.11.0**|+|Engine version:|**1.1.24080.11**|+|Signature version:|**1.419.351.0**|-##### What's new+#### What's new - Fixed an issue with the auth prompt during new installation on macOS with multiple active users - Improved stability when using the antivirus engine in passive mode-### Jan-2025 (Build: 101.24122.0005 | Release version: 20.124122.5.0)+### Jan-2025 (Build: 101.24122.0005 | Release version: 20.124122.5.0)-| Build: | **101.24122.0005** |-|--------------------|-----------------------|-| Release version: | **20.124122.4.0** |-| Engine version: | **1.1.24080.11** |-| Signature version: | **1.419.351.0** |+|Build:|**101.24122.0005**|+|---|---|+|Release version:|**20.124122.4.0**|+|Engine version:|**1.1.24080.11**|+|Signature version:|**1.419.351.0**|-##### What's new+#### What's new - Removed support of macOS 12, the minimal requirement is now macOS 13.0 or later - Fix: Defender quarantines a file even if it's marked as immutable - `mdatp health` can return [`out_of_date`](device-health-microsoft-defender-antivirus-health.md#up-to-date-definitions) status for `definitions_status` - Bug and performance fixes-### Dec-2024 (Build: 101.24102.0018 | Release version: 20.124102.18.0)+### Dec-2024 (Build: 101.24102.0018 | Release version: 20.124102.18.0)-| Build: | **101.24102.0018** |-|--------------------|-----------------------|-| Release version: | **20.124102.18.0** |-| Engine version: | **1.1.24080.10** |-| Signature version: | **1.419.298.0** |+|Build:|**101.24102.0018**|+|---|---|+|Release version:|**20.124102.18.0**|+|Engine version:|**1.1.24080.10**|+|Signature version:|**1.419.298.0**|-##### What's new+#### What's new - **Improved User/Group Permission Handling** - Added reporting in `mdatp-health` for user/group permission issues for Defender files. On restart Defender attempts to cure these issues. - Bug and performance fixes.-### Oct-2024 (Build: 101.24092.0004 | Release version: 20.124092.4.0)+### Oct-2024 (Build: 101.24092.0004 | Release version: 20.124092.4.0)-| Build: | **101.24092.0004** |-|--------------------|-----------------------|-| Release version: | **20.124092.4.0** |-| Engine version: | **1.1.24080.11** |-| Signature version: | **1.421.14.0** |+|Build:|**101.24092.0004**|+|---|---|+|Release version:|**20.124092.4.0**|+|Engine version:|**1.1.24080.11**|+|Signature version:|**1.421.14.0**|-##### What's new+#### What's new - Bug and performance fixes-### Oct-2024 (Build: 101.24082.0009 | Release version: 20.124082.9.0)+### Oct-2024 (Build: 101.24082.0009 | Release version: 20.124082.9.0)-| Build: | **101.24082.0009** |-|--------------------|-----------------------|-| Release version: | **20.124082.9.0** |-| Engine version: | **1.1.24080.9** |-| Signature version: | **1.411.410.0** |+|Build:|**101.24082.0009**|+|---|---|+|Release version:|**20.124082.9.0**|+|Engine version:|**1.1.24080.9**|+|Signature version:|**1.411.410.0**|-##### What's new+#### What's new - Product improvements and performance fixes-### Sep-2024 (Build: 101.24072.0007 | Release version: 20.124072.7)+### Sep-2024 (Build: 101.24072.0007 | Release version: 20.124072.7)-| Build: | **101.24072.0007** |-|--------------------|-----------------------|-| Release version: | **20.124072.7** |-| Engine version: | **1.1.24080.9** |-| Signature version: | **1.411.410.0** |+|Build:|**101.24072.0007**|+|---|---|+|Release version:|**20.124072.7**|+|Engine version:|**1.1.24080.9**|+|Signature version:|**1.411.410.0**|-##### What's new+#### What's new - Resolved the issue causing outdated vulnerability assessments impacting some macOS devices-### Aug-2024 (Build: 101.24072.0006 | Release version: 20.124072.6.0)+### Aug-2024 (Build: 101.24072.0006 | Release version: 20.124072.6.0)-| Build: | **101.24072.0006** |-|--------------------|-----------------------|-| Release version: | **20.124072.6.0** |-| Engine version: | **1.1.24060.7** |-| Signature version: | **1.417.325.0** |+|Build:|**101.24072.0006**|+|---|---|+|Release version:|**20.124072.6.0**|+|Engine version:|**1.1.24060.7**|+|Signature version:|**1.417.325.0**|-##### What's new+#### What's new - Product improvements and performance fixes-### Jul-2024 (Build: 101.24062.0009 | Release version: 20.124062.9.0)+### Jul-2024 (Build: 101.24062.0009 | Release version: 20.124062.9.0)-| Build: | **101.24062.0009** |-|--------------------|-----------------------|-| Release version: | **20.124062.9.0** |-| Engine version: | **1.1.24050.7** |-| Signature version: | **1.411.410.0** |+|Build:|**101.24062.0009**|+|---|---|+|Release version:|**20.124062.9.0**|+|Engine version:|**1.1.24050.7**|+|Signature version:|**1.411.410.0**|-##### What's new+#### What's new - Product improvements and performance fixes-### Jun-2024 (Build: 101.24052.0013 | Release version: 20.124052.13.0)+### Jun-2024 (Build: 101.24052.0013 | Release version: 20.124052.13.0)-| Build: | **101.24052.0013** |-|--------------------|-----------------------|-| Release version: | **20.124052.13.0** |-| Engine version: | **1.1.24040.2** |-| Signature version: | **1.411.153.0** |+|Build:|**101.24052.0013**|+|---|---|+|Release version:|**20.124052.13.0**|+|Engine version:|**1.1.24040.2**|+|Signature version:|**1.411.153.0**|-##### What's new+#### What's new - [[device control](mac-device-control-overview.md)] Secure Digital cards aren't recognized on newer macOS - Product improvements and performance fixes-### May-2024 (Build: 101.24042.0008 | Release version: 20.124042.8.0)+### May-2024 (Build: 101.24042.0008 | Release version: 20.124042.8.0)-| Build: | **101.24042.0008** |-|--------------------|----------------------|-| Release version: | **20.124042.8.0** |-| Engine version: | **1.1.24040.1** |-| Signature version: | **1.413.13.0** |+|Build:|**101.24042.0008**|+|---|---|+|Release version:|**20.124042.8.0**|+|Engine version:|**1.1.24040.1**|+|Signature version:|**1.413.13.0**| #### What's new - Product improvements and performance fixes-### Apr-2024 (Build: 101.24032.0006 | Release version: 20.124032.06.0)--| Build: | **101.24032.0006** |-|--------------------|-----------------------|-| Release version: | **20.124012.10.0** |-| Engine version: | **1.1.24030.4** |-| Signature version: | **1.407.521.0** |+### Apr-2024 (Build: 101.24032.0006 | Release version: 20.124032.06.0)+|Build:|**101.24032.0006**|+|---|---|+|Release version:|**20.124012.10.0**|+|Engine version:|**1.1.24030.4**|+|Signature version:|**1.407.521.0**| #### What's new@@ -375,32 +374,32 @@ This page contains archived platform-specific build and version history for Micr - Remove Big Sur from supported versions of macOS - [[device control](mac-device-control-overview.md)] Fix Bluetooth support on Sonoma (see the note later in this section) - Product improvements and performance fixes-- **(GA) Troubleshooting mode for macOS**. Troubleshooting mode helps you identify instances where antivirus might be causing issues with your applications or system resources. To learn more, see [Troubleshooting mode in Microsoft Defender for Endpoint on macOS](mac-troubleshoot-mode.md). +- **(GA) Troubleshooting mode for macOS**. Troubleshooting mode helps you identify instances where antivirus might be causing issues with your applications or system resources. To learn more, see [Troubleshooting mode in Microsoft Defender for Endpoint on macOS](mac-troubleshoot-mode.md). > [!NOTE] > You need to deploy a new MDM configuration profile for Defender to access Bluetooth. > See details for [JAMF](mac-jamfpro-policies.md#step-10-grant-bluetooth-permissions) and [Intune](mac-install-with-intune.md#step-7-bluetooth-permissions).-### Mar-2024 (Build: 101.24012.0010 | Release version: 20.124012.10.0)+### Mar-2024 (Build: 101.24012.0010 | Release version: 20.124012.10.0)-| Build: | **101.24012.0010** |-|--------------------|-----------------------|-| Release version: | **20.124012.10.0** |-| Engine version: | **1.1.24020.3** |-| Signature version: | **1.405.788.0** |+|Build:|**101.24012.0010**|+|---|---|+|Release version:|**20.124012.10.0**|+|Engine version:|**1.1.24020.3**|+|Signature version:|**1.405.788.0**| #### What's new - Product improvements and performance fixes - **(GA) Built-in Scheduled Scan for macOS**: For information on Scheduled Scan built-in for Microsoft Defender for Endpoint on macOS, see [How to schedule scans with Microsoft Defender for Endpoint on macOS](mac-schedule-scan.md).-### Jan-2024 (Build: 101.23122.0005 | Release version: 20.123122.5.0)+### Jan-2024 (Build: 101.23122.0005 | Release version: 20.123122.5.0)-| Build: | **101.23122.0005** |-|--------------------|-----------------------|-| Release version: | **20.123122.5.0** |-| Engine version: | **1.1.23100.2010** |-| Signature version: | **1.403.3022.0** |+|Build:|**101.23122.0005**|+|---|---|+|Release version:|**20.123122.5.0**|+|Engine version:|**1.1.23100.2010**|+|Signature version:|**1.403.3022.0**| #### What's new@@ -409,11 +408,11 @@ This page contains archived platform-specific build and version history for Micr ### Dec-2023 (Build: 101.23102.0020 | Release version: 20.123102.20.0)-| Build: | **101.23102.0020** |-|--------------------|--------------------|-| Release version: | **20.123102.20.0** |-| Engine version: | **1.1.23090.2005** |-| Signature version: | **1.401.1729.0** |+|Build:|**101.23102.0020**|+|---|---|+|Release version:|**20.123102.20.0**|+|Engine version:|**1.1.23090.2005**|+|Signature version:|**1.401.1729.0**| #### What's new@@ -421,11 +420,11 @@ This page contains archived platform-specific build and version history for Micr ### Nov-2023 (Build: 101.23092.0007 | Release version: 20.123092.7.0)-| Build: | **101.23092.0007** |-|--------------------|----------------------------|-| Release version: | **20.123092.7.0** |-| Engine version: | **1.1.23090.2005** |-| Signature version: | **1.399.1196.0** |+|Build:|**101.23092.0007**|+|---|---|+|Release version:|**20.123092.7.0**|+|Engine version:|**1.1.23090.2005**|+|Signature version:|**1.399.1196.0**| #### What's new@@ -437,13 +436,13 @@ This page contains archived platform-specific build and version history for Micr > Device Control v1 will be considered deprecated in the nearest future. > To check, run the `[mdatp health --details device_control](mac-device-control-overview.md#status)` command, and inspect the `active` property. It shouldn't contain "v1".-### Oct-2023 (Build: 101.23082.0018 | Release version: 20.123082.18.0)+### Oct-2023 (Build: 101.23082.0018 | Release version: 20.123082.18.0)-| Build: | **101.23082.0018** |-|--------------------|----------------------------|-| Release version: | **20.123082.18.0** |-| Engine version: | **1.1.23070.1002** |-| Signature version: | **1.399.384.0** |+|Build:|**101.23082.0018**|+|---|---|+|Release version:|**20.123082.18.0**|+|Engine version:|**1.1.23070.1002**|+|Signature version:|**1.399.384.0**| #### What's new@@ -453,11 +452,11 @@ This page contains archived platform-specific build and version history for Micr ### Sep-2023 (Build: 101.23072.0025 | Release version: 20.123072.25.0)-| Build: | **101.23072.0025** |-|--------------------|-----------------------|-| Release version: | **20.123072.25.0** |-| Engine version: | **1.1.23050.3** |-| Signature version: | **1.397.911.0** |+|Build:|**101.23072.0025**|+|---|---|+|Release version:|**20.123072.25.0**|+|Engine version:|**1.1.23050.3**|+|Signature version:|**1.397.911.0**| #### What's new@@ -466,26 +465,26 @@ This page contains archived platform-specific build and version history for Micr - Fix: Major performance issues on macOS when Network Protection is set to Audit mode - **(GA) macOS devices receive built-in protection**. Tamper protection is turned on in block mode by default. This setting helps secure your Mac against threats. To learn more, see [Protect macOS security settings with tamper protection](built-in-protection.md).-### Aug-2023 (Build: 101.23062.0016 | Release version: 20.123062.16.0)+### Aug-2023 (Build: 101.23062.0016 | Release version: 20.123062.16.0)-| Build: | **101.23062.0016** |-|--------------------|-----------------------|-| Release version: | **20.123062.16.0** |-| Engine version: | **1.1.23050.3** |-| Signature version: | **1.395.436.0** |+|Build:|**101.23062.0016**|+|---|---|+|Release version:|**20.123062.16.0**|+|Engine version:|**1.1.23050.3**|+|Signature version:|**1.395.436.0**| #### What's new - Product improvements and performance fixes - Fix: macOS complains that uninstall background task is from unidentified developer-### Jul-2023 (Build: 101.23052.0004 | Release version: 20.123052.4.0)+### Jul-2023 (Build: 101.23052.0004 | Release version: 20.123052.4.0)-| Build: | **101.23052.0004** |-|--------------------|-----------------------|-| Release version: | **20.123052.4.0** |-| Engine version: | **1.1.20100.7** |-| Signature version: | **1.391.2163.0** |+|Build:|**101.23052.0004**|+|---|---|+|Release version:|**20.123052.4.0**|+|Engine version:|**1.1.20100.7**|+|Signature version:|**1.391.2163.0**| #### What's new@@ -493,13 +492,13 @@ This page contains archived platform-specific build and version history for Micr - Fix: Defender doesn't start on a machine with certain versions of Microsoft Edge due to directory permission issue - Product improvements and performance fixes-### Jun-2023 (Build: 101.98.84 | Release version: 20.123042.19884.0)+### Jun-2023 (Build: 101.98.84 | Release version: 20.123042.19884.0)-| Build: | **101.98.84** |-|--------------------|-----------------------|-| Release version: | **20.123042.19884.0** |-| Engine version: | **1.1.20300.4** |-| Signature version: | **1.391.221.0** |+|Build:|**101.98.84**|+|---|---|+|Release version:|**20.123042.19884.0**|+|Engine version:|**1.1.20300.4**|+|Signature version:|**1.391.221.0**| #### What's new@@ -509,13 +508,13 @@ This page contains archived platform-specific build and version history for Micr Network protection for macOS is now available for all Mac devices onboarded to Defender for Endpoint. Devices must meet the minimum requirements. To learn more, see [Use network protection to help prevent macOS connections to bad sites](network-protection-macos.md).-### May-2023 (Build: 101.98.71 | Release version: 20.123032.19871.0)+### May-2023 (Build: 101.98.71 | Release version: 20.123032.19871.0)-| Build: | **101.98.71** |-|--------------------|-----------------------|-| Release version: | **20.123032.19871.0** |-| Engine version: | **1.1.20300.4** |-| Signature version: | **1.389.1872.0** |+|Build:|**101.98.71**|+|---|---|+|Release version:|**20.123032.19871.0**|+|Engine version:|**1.1.20300.4**|+|Signature version:|**1.389.1872.0**| #### What's new@@ -524,37 +523,37 @@ Network protection for macOS is now available for all Mac devices onboarded to D - Fix: Remove Codesigned Artifact from App Bundle - Product improvements and performance fixes-### May-2023 (Build: 101.98.70 | Release version: 20.123022.19870.0)+### May-2023 (Build: 101.98.70 | Release version: 20.123022.19870.0)-| Build: | **101.98.70** |-|--------------------|-----------------------|-| Release version: | **20.123022.19870.0** |-| Engine version: | **1.1.20300.4** |-| Signature version: | **1.389.1396.0** |+|Build:|**101.98.70**|+|---|---|+|Release version:|**20.123022.19870.0**|+|Engine version:|**1.1.20300.4**|+|Signature version:|**1.389.1396.0**| #### What's new - Product improvements and performance fixes-### Mar-2023 (Build: 101.98.30 | Release version: 20.123012.19830.0)+### Mar-2023 (Build: 101.98.30 | Release version: 20.123012.19830.0)-| Build: | **101.98.30** |-|--------------------|-----------------------|-| Release version: | **20.123012.19830.0** |-| Engine version: | **1.1.20100.6** |-| Signature version: | **1.385.924.0** |+|Build:|**101.98.30**|+|---|---|+|Release version:|**20.123012.19830.0**|+|Engine version:|**1.1.20100.6**|+|Signature version:|**1.385.924.0**| #### What's new - Product improvements and performance fixes-### Feb-2023 (Build: 101.97.94 | Release version: 20.123011.19794.0)+### Feb-2023 (Build: 101.97.94 | Release version: 20.123011.19794.0)-| Build: | **101.97.94** |-|--------------------|-----------------------|-| Release version: | **20.123011.19794.0** |-| Engine version: | **1.1.20000.2** |-| Signature version: | **1.383.104.0** |+|Build:|**101.97.94**|+|---|---|+|Release version:|**20.123011.19794.0**|+|Engine version:|**1.1.20000.2**|+|Signature version:|**1.383.104.0**| #### What's new@@ -568,46 +567,49 @@ Network protection for macOS is now available for all Mac devices onboarded to D - **(GA) Live Response available for macOS**-Live Response for macOS is now available for all Mac devices onboarded to Defender for Endpoint. Devices must meet the minimum requirements. To learn more, see [Investigate entities on devices using live response](live-response.md) +Live Response for macOS is now available for all Mac devices onboarded to Defender for Endpoint. Devices must meet the minimum requirements. To learn more, see [Investigate entities on devices using live response](live-response.md) ### Nov-2022 (Build: 101.87.30 | Release version: 20.122082.18681.0)- Released: **Nov 5, 2022**<br/>- Published: **Nov 5, 2022**<br/>- Build: **101.87.30**<br/>- Release version: **20.122082.18681.0**<br/>- Engine version: **1.1.19700.3**<br/>- Signature version: **1.379.17.0**<br/>+|Build:|**101.87.30**|+|---|---|+|Released:|**Nov 5, 2022**|+|Published:|**Nov 5, 2022**|+|Release version:|**20.122082.18681.0**|+|Engine version:|**1.1.19700.3**|+|Signature version:|**1.379.17.0**|-**What's new**+#### What's new - Fix for some users experiencing performance issues and temporary system hangs - Product improvements and performance fixes ### Oct-2022 (Build: 101.86.81 | Release version: 20.122082.18681.0)- Released: **Oct 25, 2022**<br/>- Published: **Oct 25, 2022**<br/>- Build: **101.86.81**<br/>- Release version: **20.122082.18681.0**<br/>- Engine version: **1.1.19700.3**<br/>- Signature version: **1.377.636.0**<br/>+|Build:|**101.86.81**|+|---|---|+|Released:|**Oct 25, 2022**|+|Published:|**Oct 25, 2022**|+|Release version:|**20.122082.18681.0**|+|Engine version:|**1.1.19700.3**|+|Signature version:|**1.377.636.0**|-**What's new**+#### What's new - Issue resolution: Upgrade fails if `\_mdatp` user is a member of `\_lpadmin` group > [!IMPORTANT] > This is a minimal recommended MDE version for macOS Ventura.-### Oct-2022 (Build: 101.82.21 | Release version: 20.122082.18221.0)+### Oct-2022 (Build: 101.82.21 | Release version: 20.122082.18221.0)- Build: **101.82.21**<br/>- Release version: **20.122082.18221.0**<br/>- Engine version: **1.1.19400.3**<br/>- Signature version: **1.369.962.0**<br/>+|Build:|**101.82.21**|+|---|---|+|Release version:|**20.122082.18221.0**|+|Engine version:|**1.1.19400.3**|+|Signature version:|**1.369.962.0**|-**What's new**+#### What's new - Fix - macOS TP in Block mode causing device hang on shutdown/crashes on reboot - Add a mdatp command-line switch to view the on-demand scan history@@ -617,12 +619,13 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### Sep-2022 (Build: 101.78.13)- Build: **101.78.13**<br/>- Release version: **20.122072.17813.0**<br/>- Engine version: **1.1.19500.2**<br/>- Signature version: **1.373.556.0**<br/>+|Build:|**101.78.13**|+|---|---|+|Release version:|**20.122072.17813.0**|+|Engine version:|**1.1.19500.2**|+|Signature version:|**1.373.556.0**|-**What's new**+#### What's new - Fix for uninstaller to properly delete Application Support folder - Fix for Network Protection not filtering Safari when Firewall or iCloud Private Relay is on@@ -633,14 +636,15 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### Aug-2022 (Build: 101.75.90 | Release version: 20.122071.17590.0)- Released: **Aug 3, 2022**<br/>- Published: **Aug 3, 2022**<br/>- Build: **101.75.90**<br/>- Release version: **20.122071.17590.0**<br/>- Engine version: **1.1.19300.3**<br/>- Signature version: **1.369.395.0**<br/>+|Build:|**101.75.90**|+|---|---|+|Released:|**Aug 3, 2022**|+|Published:|**Aug 3, 2022**|+|Release version:|**20.122071.17590.0**|+|Engine version:|**1.1.19300.3**|+|Signature version:|**1.369.395.0**|-**What's new**+#### What's new - Added a new field in the output of `mdatp health` that can be used to query the enforcement level of the network protection feature. The new field is called `network_protection_enforcement_level` and can take one of the following values: `audit`, `block`, or `disabled`. - Addressed a product issue where multiple detections of the same content could lead to duplicate entries in the threat history.@@ -648,14 +652,15 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### Jul-2022 (Build: 101.73.77 | Release version: 20.122062.17377.0)- Released: **Jul 21, 2022**<br/>- Published: **Jul 21, 2022**<br/>- Build: **101.73.77**<br/>- Release version: **20.122062.17377.0**<br/>- Engine version: **1.1.19200.3**<br/>- Signature version: **1.367.1011.0**<br/>+|Build:|**101.73.77**|+|---|---|+|Released:|**Jul 21, 2022**|+|Published:|**Jul 21, 2022**|+|Release version:|**20.122062.17377.0**|+|Engine version:|**1.1.19200.3**|+|Signature version:|**1.367.1011.0**|-**What's new**+#### What's new - Addressed an issue where printing couldn't be completed successfully due to the network extension - Added an option to [configure file hash computation](mac-preferences.md#configure-file-hash-computation-feature)@@ -665,12 +670,13 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### Jul-2022 (Build: 101.71.18 | Release version: 20.122052.17118.0)- Released: **Jul 7, 2022**<br/>- Published: **Jul 7, 2022**<br/>- Build: **101.71.18**<br/>- Release version: **20.122052.17118.0**<br/>+|Build:|**101.71.18**|+|---|---|+|Released:|**Jul 7, 2022**|+|Published:|**Jul 7, 2022**|+|Release version:|**20.122052.17118.0**|-**What's new**+#### What's new - `mdatp connectivity test` added an extra URL. The new URL is [https://go.microsoft.com/fwlink/?linkid=2144709](https://go.microsoft.com/fwlink/?linkid=2144709). - Up until now, the product log level didn't persist between product restarts. Beginning in this version, there's a new command-line tool switch that persists the log level. The new command is `mdatp log level persist --level <level>`.@@ -680,24 +686,26 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### Jun-2022 (Build: 101.70.19 | Release version: 20.122051.17019.0)- Released: **Jun 14, 2022**<br/>- Published: **Jun 14, 2022**<br/>- Build: **101.70.19**<br/>- Release version: **20.122051.17019.0**<br/>+|Build:|**101.70.19**|+|---|---|+|Released:|**Jun 14, 2022**|+|Published:|**Jun 14, 2022**|+|Release version:|**20.122051.17019.0**|-**What's new**+#### What's new - Resolved an issue where threat-related notifications weren't always presented to the end user. - Performance improvements & other updates. ### Jun-2022 (Build: 101.70.18 | Release version: 20.122042.17018.0)- Released: **Jun 2, 2022**<br/>- Published: **Jun 2, 2022**<br/>- Build: **101.70.18**<br/>- Release version: **20.122042.17018.0**<br/>+|Build:|**101.70.18**|+|---|---|+|Released:|**Jun 2, 2022**|+|Published:|**Jun 2, 2022**|+|Release version:|**20.122042.17018.0**|-**What's new**+#### What's new - Resolved an issue where the installation package was sometimes hanging indefinitely during product updates - Resolved an issue where the product sometimes was incorrectly detecting files inside the quarantine folder@@ -705,24 +713,26 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### May-2022 (Build: 101.66.54 | Release version: 20.122041.16654.0)- Released: **May 11, 2022**<br/>- Published: **May 11, 2022**<br/>- Build: **101.66.54**<br/>- Release version: **20.122041.16654.0**<br/>+|Build:|**101.66.54**|+|---|---|+|Released:|**May 11, 2022**|+|Published:|**May 11, 2022**|+|Release version:|**20.122041.16654.0**|-**What's new**+#### What's new - Addressed an issue where `mdatp diagnostic real-time-protection-statistics` wasn't printing the correct process path in some cases. - Product improvements ### Apr-2022 (Build: 101.64.15 | Release version: 20.122032.16415.0)- Released: **Apr 26, 2022**<br/>- Published: **Apr 26, 2022**<br/>- Build: **101.64.15**<br/>- Release version: **20.122032.16415.0**<br/>+|Build:|**101.64.15**|+|---|---|+|Released:|**Apr 26, 2022**|+|Published:|**Apr 26, 2022**|+|Release version:|**20.122032.16415.0**|-**What's new**+#### What's new - Fixed a regression introduced in version 101.61.69 where the status menu icon was sometimes showing an error icon, even though no action was required from the end user - Improved the `conflicting_applications` field in `mdatp health` to show only the most recent 10 processes and also to include the process names. This improvement makes it easier to identify which processes are potentially conflicting with Microsoft Defender for Endpoint for macOS.@@ -731,34 +741,37 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### Mar-2022 (Build: 101.61.69 | Release version: 20.122022.16169.0)- Released: **Mar 25, 2022**<br/>- Published: **Mar 25, 2022**<br/>- Build: **101.61.69**<br/>- Release version: **20.122022.16169.0**<br/>+|Build:|**101.61.69**|+|---|---|+|Released:|**Mar 25, 2022**|+|Published:|**Mar 25, 2022**|+|Release version:|**20.122022.16169.0**|-**What's new**+#### What's new - Product improvements ### Mar-2022 (Build: 101.60.91 | Release version: 20.122021.16091.0)- Released: **Mar 8, 2022**<br/>- Published: **Mar 8, 2022**<br/>- Build: **101.60.91**<br/>- Release version: **20.122021.16091.0**<br/>+|Build:|**101.60.91**|+|---|---|+|Released:|**Mar 8, 2022**|+|Published:|**Mar 8, 2022**|+|Release version:|**20.122021.16091.0**|-**What's new**+#### What's new - This version contains a security update for [CVE-2022-23278](https://msrc-blog.microsoft.com/2022/03/guidance-for-cve-2022-23278-spoofing-in-microsoft-defender-for-endpoint/) ### Feb-2022 (Build: 101.59.50 | Release version: 20.122021.15950.0)- Released: **Feb 28, 2022**<br/>- Published: **Feb 28, 2022**<br/>- Build: **101.59.50**<br/>- Release version: **20.122021.15950.0**<br/>+|Build:|**101.59.50**|+|---|---|+|Released:|**Feb 28, 2022**|+|Published:|**Feb 28, 2022**|+|Release version:|**20.122021.15950.0**|-**What's new**+#### What's new - This version adds support for macOS 12.3. Starting with macOS 12.3, [Apple is removing Python 2.7](https://developer.apple.com/documentation/macos-release-notes/macos-12_3-release-notes). There's no Python version preinstalled on macOS by default. **ACTION NEEDED**: - Users must update Microsoft Defender for Endpoint for Mac to version 101.59.50 (or newer) before updating their devices to macOS Monterey 12.3 (or newer). This minimal version 101.59.50 is a prerequisite to eliminating Python-related issues with Microsoft Defender for Endpoint for macOS devices on macOS Monterey.@@ -766,12 +779,13 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### Feb-2022 (Build: 101.59.10 | Release version: 20.122012.15910.0)- Released: **Feb 22, 2022**<br/>- Published: **Feb 22, 2022**<br/>- Build: **101.59.10**<br/>- Release version: **20.122012.15910.0**<br/>+|Build:|**101.59.10**|+|---|---|+|Released:|**Feb 22, 2022**|+|Published:|**Feb 22, 2022**|+|Release version:|**20.122012.15910.0**|-**What's new**+#### What's new - The command-line tool now supports restoring quarantined files to a location other than the one where the file was originally detected. Restoration can be done through `mdatp threat quarantine restore --id [threat-id] --path [destination-folder]`. - Extended device control to handle devices connected over Thunderbolt 3@@ -780,27 +794,29 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### Feb-2022 (Build: 101.56.62 | Release version: 20.121122.15662.0)- Released: **Feb 7, 2022**<br/>- Published: **Feb 7, 2022**<br/>- Build: **101.56.62**<br/>- Release version: **20.121122.15662.0**<br/>+|Build:|**101.56.62**|+|---|---|+|Released:|**Feb 7, 2022**|+|Published:|**Feb 7, 2022**|+|Release version:|**20.121122.15662.0**|-**What's new**+#### What's new - Product improvements ### Jan-2022 (Build: 101.56.35 | Release version: 20.121121.15635.0)- Released: **Jan 30, 2022**<br/>- Published: **Jan 30, 2022**<br/>- Build: **101.56.35**<br/>- Release version: **20.121121.15635.0**<br/>+|Build:|**101.56.35**|+|---|---|+|Released:|**Jan 30, 2022**|+|Published:|**Jan 30, 2022**|+|Release version:|**20.121121.15635.0**|-**What's new**+#### What's new - The application is renamed from *Microsoft Defender ATP* to *Microsoft Defender*. End users observe the following changes:- - The application installation path changed from `/Application/Microsoft Defender ATP.app` to `/Applications/Microsoft Defender.app`.- - Within the user experience, occurrences of *Microsoft Defender ATP* are replaced by *Microsoft Defender*+ - The application installation path changed from `/Application/Microsoft Defender ATP.app` to `/Applications/Microsoft Defender.app`.+ - Within the user experience, occurrences of *Microsoft Defender ATP* are replaced by *Microsoft Defender* - Resolved an issue where some VPN applications couldn't connect due to the network content filter that is distributed with Microsoft Defender for Endpoint for macOS. - Addressed an issue discovered in macOS 12.2 preview 2 where the installation package couldn't be opened due to a change in the operating system (OS) that prevents installation of packages with certain characteristics. While it appears that this OS change isn't included in the final release of macOS 12.2, it's likely that it will be reintroduced in a future macOS version. As such, we encourage all enterprise administrators to refresh the Microsoft Defender for Endpoint package in their management console to this product version (or a newer version). - Addressed an issue seen on some M1 devices where the product was stuck with invalid anti-malware definitions and couldn't successfully update to a working set of definitions.@@ -809,12 +825,13 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### Jan-2022 (Build: 101.54.16 | Release version: 20.121111.15416.0)- Released: **Jan 12, 2022**<br/>- Published: **Jan 12, 2022**<br/>- Build: **101.54.16**<br/>- Release version: **20.121111.15416.0**<br/>+|Build:|**101.54.16**|+|---|---|+|Released:|**Jan 12, 2022**|+|Published:|**Jan 12, 2022**|+|Release version:|**20.121111.15416.0**|-**What's new**+#### What's new - macOS 10.14 (Mojave) is no longer supported - After a product setting stops being managed by the administrator through MDM, it now reverts to the value it had before it was managed (the value configured locally by the end user or, if no such local value was explicitly provided, the default value used by the product). Prior to this change, after a setting stopped being managed, its managed value persisted and was still used by the product.@@ -822,39 +839,43 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### Nov-2021 (Build: 101.49.25)- Build: **101.49.25**<br/>- Release version: **20.121092.14925.0** <br/>+|Build:|**101.49.25**|+|---|---|+|Release version:|**20.121092.14925.0**|-**What's new**+#### What's new - Added a new switch to the command-line tool to control whether archives are scanned during on-demand scans. This can be configured through `mdatp config scan-archives --value [enabled/disabled]`. By default, this is set to enabled. - Product improvements ### Oct-2021 (Build: 101.47.27)- Build: **101.47.27**<br/>- Release version: **20.121082.14727.0** <br/>+|Build:|**101.47.27**|+|---|---|+|Release version:|**20.121082.14727.0**|-**What's new**+#### What's new-- Fix for a system freeze occurring on shutdown on macOS Mojave and macOS Catalina. +- Fix for a system freeze occurring on shutdown on macOS Mojave and macOS Catalina. ### Oct-2021 (Build: 101.43.84)- Build: **101.43.84**<br/>- Release version: **20.121082.14384.0** <br/>+|Build:|**101.43.84**|+|---|---|+|Release version:|**20.121082.14384.0**|-**What's new**+#### What's new - Candidate build for macOS 12 (Monterey) - Product improvements ### Sep-2021 (Build: 101.41.10)- Build: **101.41.10**<br/>- Release version: **20.121072.14110.0** <br/>+|Build:|**101.41.10**|+|---|---|+|Release version:|**20.121072.14110.0**|-**What's new**+#### What's new - Added new switches to the command-line tool: - Control degree of parallelism for on-demand scans. This can be configured through `mdatp config maximum-on-demand-scan-threads --value [number-between-1-and-64]`. By default, a degree of parallelism of 2 is used.@@ -864,47 +885,52 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### Aug-2021 (Build: 101.40.84)- Build: **101.40.84**<br/>- Release version: **20.121071.14084.0** <br/>+|Build:|**101.40.84**|+|---|---|+|Release version:|**20.121071.14084.0**|-**What's new**+#### What's new - M1 chip native support - Performance improvements & Product improvements ### Jul-2021 (Build: 101.37.97)- Build: **101.37.97**<br/>- Release version: **20.121062.13797.0** <br/>+|Build:|**101.37.97**|+|---|---|+|Release version:|**20.121062.13797.0**|-**What's new**+#### What's new - Performance improvements & Product improvements ### Jun-2021 (Build: 101.34.28)- Build: **101.34.28**<br/>- Release version: **20.121061.13428.0** <br/>+|Build:|**101.34.28**|+|---|---|+|Release version:|**20.121061.13428.0**|-**What's new**+#### What's new - Product improvements ### Jun-2021 (Build: 101.34.27)- Build: **101.34.27**<br/>- Release version: **20.121052.13427.0** <br/>+|Build:|**101.34.27**|+|---|---|+|Release version:|**20.121052.13427.0**|-**What's new**+#### What's new - Product improvements ### May-2021 (Build: 101.34.20)- Build: **101.34.20**<br/>- Release version: **20.121051.13420.0** <br/>+|Build:|**101.34.20**|+|---|---|+|Release version:|**20.121051.13420.0**|-**What's new**+#### What's new - [Device control for macOS](mac-device-control-overview.md) is now in general availability. - Addressed an issue where a quick scan couldn't be started from the status menu on macOS 11 (Big Sur).@@ -912,19 +938,21 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### Apr-2021 (Build: 101.32.69)- Build: **101.32.69**<br/>- Release version: **20.121042.13269.0** <br/>+|Build:|**101.32.69**|+|---|---|+|Release version:|**20.121042.13269.0**|-**What's new**+#### What's new - Addressed an issue where concurrent access to the keychain from Microsoft Defender for Endpoint and other applications can lead to keychain corruption. ### Mar-2021 (Build: 101.29.64)- Build: **101.29.64**<br/>- Release version: **20.121042.12964.0** <br/>+|Build:|**101.29.64**|+|---|---|+|Release version:|**20.121042.12964.0**|-**What's new**+#### What's new - Starting with this version, threats detected during on-demand antivirus scans triggered through the command-line client are automatically remediated. Threats detected during scans triggered through the user interface still require manual action. - `mdatp diagnostic real-time-protection-statistics` now supports two other switches:@@ -934,78 +962,87 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### Feb-2021 (Build: 101.27.50)- Build: **101.27.50**<br/>- Release version: **20.121022.12750.0** <br/>+|Build:|**101.27.50**|+|---|---|+|Release version:|**20.121022.12750.0**|-**What's new**+#### What's new-- Fix to accommodate for Apple certificate expiration for macOS Catalina and earlier. This fix restores Microsoft Defender Vulnerability Management (MDVM) functionality. +- Fix to accommodate for Apple certificate expiration for macOS Catalina and earlier. This fix restores Microsoft Defender Vulnerability Management (MDVM) functionality. ### Feb-2021 (Build: 101.25.69)- Build: **101.25.69**<br/>- Release version: **20.121022.12569.0** <br/>+|Build:|**101.25.69**|+|---|---|+|Release version:|**20.121022.12569.0**|-**What's new**+#### What's new - Microsoft Defender for Endpoint on macOS is now available in preview for US Government customers. For more information, see [Microsoft Defender for Endpoint for US Government customers](gov.md). - Performance improvements (specifically for the situation when the XCode Simulator app is used) & Product improvements. ### Jan-2021 (Build: 101.23.64)- Build: **101.23.64**<br/>- Release version: **20.121021.12364.0** <br/>+|Build:|**101.23.64**|+|---|---|+|Release version:|**20.121021.12364.0**|-**What's new**+#### What's new - Added a new option to the command-line tool to view information about the last on-demand scan. To view information about the last on-demand scan, run `mdatp health --details antivirus`. - Performance improvements & Product improvements ### Dec-2020 (Build: 101.22.79)- Build: **101.22.79**<br>- Release version: **20.121012.12279.0**<br>+|Build:|**101.22.79**|+|---|---|+|Release version:|**20.121012.12279.0**|-**What's new**+#### What's new - Performance improvements & Product improvements ### Nov-2020 (Build: 101.19.88)- Build: **101.19.88**<br>- Release version: **20.121011.11988.0**<br>+|Build:|**101.19.88**|+|---|---|+|Release version:|**20.121011.11988.0**|-**What's new**+#### What's new - Performance improvements & Product improvements ### Nov-2020 (Build: 101.19.48)- Build: **101.19.48**<br>- Release version: **20.120121.11948.0**<br>+|Build:|**101.19.48**|+|---|---|+|Release version:|**20.120121.11948.0**|-**What's new**+#### What's new > [!NOTE]-> The old command-line tool syntax has been deprecated with this release. For information on the new syntax, see [Resources](mac-resources.md#configuring-from-the-command-line).-- Added a new command-line switch to disable the network extension: `mdatp system-extension network-filter disable`. This command can be useful to troubleshoot networking issues that could be related to Microsoft Defender for Endpoint on Mac.-- Performance improvements & Product improvements+>+> - The old command-line tool syntax has been deprecated with this release. For information on the new syntax, see [Resources](mac-resources.md#configuring-from-the-command-line).+> - Added a new command-line switch to disable the network extension: `mdatp system-extension network-filter disable`. This command can be useful to troubleshoot networking issues that could be related to Microsoft Defender for Endpoint on Mac.+> - Performance improvements & Product improvements ### Oct-2020 (Build: 101.19.21)- Build: **101.19.21**<br>- Release version: **20.120101.11921.0** <br>+|Build:|**101.19.21**|+|---|---|+|Release version:|**20.120101.11921.0**|-**What's new**+#### What's new - Product improvements ### Oct-2020 (Build: 101.15.26)- Build: **101.15.26**<br>- Release version: **20.120102.11526.0**<br>+|Build:|**101.15.26**|+|---|---|+|Release version:|**20.120102.11526.0**|-**What's new**+#### What's new - Improved the reliability of the agent when running on macOS 11 Big Sur. - Added a new command-line switch (`--ignore-exclusions`) to ignore AV exclusions during custom scans (`mdatp scan custom`).@@ -1013,28 +1050,31 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### Sep-2020 (Build: 101.13.75)- Build: **101.13.75**<br>- Release version: **20.120101.11375.0**<br>+|Build:|**101.13.75**|+|---|---|+|Release version:|**20.120101.11375.0**|-**What's new**+#### What's new - Removed conditions when Microsoft Defender for Endpoint was triggering a macOS 11 (Big Sur) issue that manifests into a kernel panic. - Fixed a memory leak in the Endpoint Security system extension when running on macOS 11 (Big Sur). - Product improvements-### Aug-2020 (Build: 101.10.72) +### Aug-2020 (Build: 101.10.72)- Build: **101.10.72** <br>+|Build:|**101.10.72**|+|---|---|-**What's new**+#### What's new - Product improvements ### Jul-2020 (Build: 101.09.61)- Build: **101.09.61**<br>+|Build:|**101.09.61**|+|---|---|-**What's new**+#### What's new - Added a new managed preference for [disabling the option to send feedback](mac-preferences.md#show--hide-option-to-send-feedback). - Status menu icon now shows a healthy state when the product settings are managed. Previously, the status menu icon was displaying a warning or error state, even though the product settings were managed by the administrator.@@ -1042,22 +1082,26 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### Jul-2020 (Build: 101.09.50)- Build: **101.09.50**<br>+|Build:|**101.09.50**|+|---|---|-**What's new**+#### What's new - This product version is validated on macOS Big Sur 11 preview 9. - The new syntax for the mdatp command-line tool is now the default one. For more information on the new syntax, see [Resources for Microsoft Defender for Endpoint on macOS](mac-resources.md#configuring-from-the-command-line).-> [!NOTE]-> The old command-line tool syntax will be removed from the product on **January 1st, 2021**.++ > [!NOTE]+ > The old command-line tool syntax will be removed from the product on **January 1st, 2021**.+ - Extended `mdatp diagnostic create` with a new parameter (`--path [directory]`) that allows the diagnostic logs to be saved to a different directory. - Performance improvements & Product improvements ### Jul-2020 (Build: 101.09.49)- Build: **101.09.49**<br>+|Build:|**101.09.49**|+|---|---|-**What's new**+#### What's new - User interface improvements to differentiate exclusions that are managed by the IT administrator versus exclusions defined by the local user. - Improved CPU utilization during on-demand scans.@@ -1065,9 +1109,10 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### Jun-2020 (Build: 101.07.23)- Build: **101.07.23**<br>+|Build:|**101.07.23**|+|---|---|-**What's new**+#### What's new - Added new fields to the output of `mdatp --health` for checking the status of passive mode and the EDR group ID.@@ -1080,29 +1125,34 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### May-2020 (Build: 101.06.63)- Build: **101.06.63**<br>+|Build:|**101.06.63**|+|---|---|-**What's new**+#### What's new - Addressed a performance regression introduced in version `101.05.17`. The regression was introduced with the fix to eliminate the kernel panics some customers observed when accessing SMB shares. We reverted this code change and are investigating alternative ways to eliminate the kernel panics. ### May-2020 (Build: 101.05.17)- Build: **101.05.17**<br>+|Build:|**101.05.17**|+|---|---|-**What's new**+#### What's new > [!IMPORTANT] > We're working on a new and enhanced syntax for the `mdatp` command-line tool. The new syntax is currently the default in the Insider Fast and Insider Slow update channels. We encourage you to familiarize yourself with this new syntax.+> > We continue supporting the old syntax in parallel with the new syntax and provide more communications around the deprecation plan for the old syntax in the upcoming months.+ - Addressed a kernel panic that occurred sometimes when accessing SMB file shares. - Performance improvements & Product improvements ### Apr-2020 (Build: 101.05.16)- Build: **101.05.16**<br>+|Build:|**101.05.16**|+|---|---|-**What's new**+#### What's new - Improvements to quick scan logic to significantly reduce the number of scanned files. - Added [autocompletion support](mac-resources.md#how-to-enable-autocompletion) for the command-line tool.@@ -1110,17 +1160,19 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### Mar-2020 (Build: 101.03.12)- Build: **101.03.12**<br>+|Build:|**101.03.12**|+|---|---|-**What's new**+#### What's new - Performance improvements & Product improvements ### Feb-2020 (Build: 101.01.54)- Build: **101.01.54**<br>+|Build:|**101.01.54**|+|---|---|-**What's new**+#### What's new - Improvements around compatibility with Time Machine - Accessibility improvements@@ -1128,9 +1180,10 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### Jan-2020 (Build: 101.00.31)- Build: **101.00.31**<br>+|Build:|**101.00.31**|+|---|---|-**What's new**+#### What's new - Improved [product onboarding experience for Intune users](/intune/intune-service/apps/apps-advanced-threat-protection-macos) - Antivirus [exclusions now support wildcards](mac-exclusions.md#supported-exclusion-types)@@ -1140,9 +1193,10 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### 2019 releases (Build: 100.90.27)- Build: **100.90.27**<br>+|Build:|**100.90.27**|+|---|---|-**What's new**+#### What's new - You can now [set an update channel](mac-updates.md#set-the-channel-name) for Microsoft Defender for Endpoint on macOS that is different from the system-wide update channel. - New product icon@@ -1151,9 +1205,10 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### 2019 releases (Build: 100.86.92)- Build: **100.86.92**<br>+|Build:|**100.86.92**|+|---|---|-**What's new**+#### What's new - Improvements around compatibility with Time Machine - Addressed an issue where the product was sometimes not cleaning all files under `/Library/Application Support/Microsoft/Defender` during uninstallation.@@ -1162,9 +1217,10 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### 2019 releases (Build: 100.86.91)- Build: **100.86.91**<br>+|Build:|**100.86.91**|+|---|---|-**What's new**+#### What's new > [!CAUTION] > To ensure the most complete protection for your macOS devices and in alignment with Apple stopping delivery of macOS native security updates to OS versions older than [current - 2], MDATP for macOS deployment and updates will no longer be supported on macOS Sierra [10.12]. MDATP for macOS updates and enhancements are delivered to devices running versions Catalina [10.15], Mojave [10.14], and High Sierra [10.13].@@ -1175,9 +1231,10 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### 2019 releases (Build: 100.83.73)- Build: **100.83.73**<br>+|Build:|**100.83.73**|+|---|---|-**What's new**+#### What's new - Added more controls for IT administrators around [management of exclusions](mac-preferences.md#exclusion-merge-policy), [management of threat type settings](mac-preferences.md#threat-type-settings-merge-policy), and [disallowed threat actions](mac-preferences.md#disallowed-threat-actions). - When Full Disk Access isn't enabled on the device, a warning is now displayed in the status menu.@@ -1185,25 +1242,28 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### 2019 releases (Build: 100.82.60)- Build: **100.82.60**<br>+|Build:|**100.82.60**|+|---|---|-**What's new**+#### What's new - Addressed an issue where the product fails to start following a definition update. ### 2019 releases (Build: 100.80.42)- Build: **100.80.42**<br>+|Build:|**100.80.42**|+|---|---|-**What's new**+#### What's new - Product improvements ### 2019 releases (Build: 100.79.42)- Build: **100.79.42**<br>+|Build:|**100.79.42**|+|---|---|-**What's new**+#### What's new - Fixed an issue where Microsoft Defender for Endpoint on macOS was sometimes interfering with Time Machine. - Added a new switch to the command-line utility for testing the connectivity with the backend service@@ -1217,40 +1277,46 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### 2019 releases (Build: 100.72.15)- Build: **100.72.15**<br>+|Build:|**100.72.15**|+|---|---|-**What's new**+#### What's new - Product improvements ### 2019 releases (Build: 100.70.99)- Build: **100.70.99**<br>+|Build:|**100.70.99**|+|---|---|-**What's new**+#### What's new - Addressed an issue that impacts the ability of some users to upgrade to macOS Catalina when real-time protection is enabled. This sporadic issue was caused by Microsoft Defender for Endpoint locking files within Catalina upgrade package while scanning them for threats, which led to failures in the upgrade sequence. ### 2019 releases (Build: 100.68.99)- Build: **100.68.99**<br>+|Build:|**100.68.99**|+|---|---|-**What's new**+#### What's new - Added the ability to configure the antivirus functionality to run in [passive mode](mac-preferences.md#enforcement-level-for-antivirus-engine). - Performance improvements & Product improvements ### 2019 releases (Build: 100.65.28)- Build: **100.65.28**<br>+|Build:|**100.65.28**|+|---|---|-**What's new**+#### What's new - Added support for macOS Catalina. > [!CAUTION] > macOS 10.15 (Catalina) contains new security and privacy enhancements. Beginning with this version, by default, applications aren't able to access certain locations on disk (such as Documents, Downloads, Desktop, etc.) without explicit consent. In the absence of this consent, Microsoft Defender for Endpoint isn't able to fully protect your device.+> > The mechanism for granting this consent depends on how you deployed Microsoft Defender for Endpoint:+> > - For manual deployments, see the updated instructions in the [Manual deployment article](mac-install-manually.md#allow-full-disk-access). > - For managed deployments, see the updated instructions in the [JAMF-based deployment](mac-install-with-jamf.md) and [Microsoft Intune-based deployment](mac-install-with-intune.md#create-system-configuration-profiles) articles.@@ -1260,120 +1326,113 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### July-2025 Build: 101.25052.0007 | Release version: 30.125052.0007.0-|Build: |**101.25052.0007** |-|-------------------|----------------------|-|Released: |**July 22, 2025** |-|Published: |**July 22, 2025** |-|Release version: |**30.125052.0007.0** |-|Engine version: |**1.1.25020.4000** |-|Signature version: |**1.427.370.0** |+|Build:|**101.25052.0007**|+|---|---|+|Released:|**July 22, 2025**|+|Published:|**July 22, 2025**|+|Release version:|**30.125052.0007.0**|+|Engine version:|**1.1.25020.4000**|+|Signature version:|**1.427.370.0**| #### What's new+ - Fixed issue to generate unique Machine identifiers to ensure each onboarded device is uniquely identified. - Other stability improvements and bug fixes. ### June-2025 Build: 101.25042.0003 | Release version: 30.125042.0003.0-|Build: |**101.25042.0003** |-|-------------------|----------------------|-|Released: |**June 30, 2025** |-|Published: |**June 30, 2025** |-|Release version: |**30.125042.0003.0** |-|Engine version: |**1.1.25020.4000** |-|Signature version: |**1.427.370.0** |+|Build:|**101.25042.0003**|+|---|---|+|Released:|**June 30, 2025**|+|Published:|**June 30, 2025**|+|Release version:|**30.125042.0003.0**|+|Engine version:|**1.1.25020.4000**|+|Signature version:|**1.427.370.0**| #### What's new+ - The Defender for Endpoint package rollout into production happens gradually. From the time the release notes are published, it might take up to a week for the package to be pushed to all production machines. - Removed external dependency of uuid-runtime from the Defender for Endpoint package - Other stability improvements and bug fixes ### May-2025 Build: 101.25032.0010 | Release version: 30.125032.0010.0-|Build: |**101.25032.0010** |-|-------------------|----------------------|-|Released: |**May 23, 2025** |-|Published: |**May 23, 2025** |-|Release version: |**30.125032.0010.0** |-|Engine version: |**1.1.25020.4000** |-|Signature version: |**1.427.370.0** |+|Build:|**101.25032.0010**|+|---|---|+|Released:|**May 23, 2025**|+|Published:|**May 23, 2025**|+|Release version:|**30.125032.0010.0**|+|Engine version:|**1.1.25020.4000**|+|Signature version:|**1.427.370.0**| #### What's new - Removed external dependency of MDE Netfilter and libpcre from MDE package- - Fix for Python script executing unverified binaries with root-level privileges to identify Java processes using outdated versions of log4j (CVE-2025-26684) has been addressed.- - Added detection mechanism for CVE-2025-31324 affecting the "Visual Composer" component of the SAP NetWeaver application server. ### April-2025 Build: 101.25022.0002 | Release version: 30.125022.0001.0-|Build: |**101.25022.0002** |-|-------------------|----------------------|-|Released: |**April 07, 2025** |-|Published: |**April 07, 2025** |-|Release version: |**30.125022.0001.0** |-|Engine version: |**1.1.24090.13** |-|Signature version: |**1.421.226.0** |+|Build:|**101.25022.0002**|+|---|---|+|Released:|**April 07, 2025**|+|Published:|**April 07, 2025**|+|Release version:|**30.125022.0001.0**|+|Engine version:|**1.1.24090.13**|+|Signature version:|**1.421.226.0**| #### What's new - mdatp diagnostic ebpf-statistics command requires sudo privilege now- - Manage dynamic signature file share source by setting URL and update interval- - Other stability improvements and bug fixes--- Support for ARM64 Linux servers +- Support for ARM64 Linux servers ### Mar-2025 Build: 101.25012.0000 | Release version: 30.125012.0000.0-| Build: | **101.25012.0000** |-|-------------------|----------------------|-|Released: | **March 11, 2025** |-|Published: | **March 11, 2025** |-|Release version: | **30.125012.0000.0** |-|Engine version: | **1.1.24090.13** |-|Signature version: | **1.421.226.0** |+|Build:|**101.25012.0000**|+|---|---|+|Released:|**March 11, 2025**|+|Published:|**March 11, 2025**|+|Release version:|**30.125012.0000.0**|+|Engine version:|**1.1.24090.13**|+|Signature version:|**1.421.226.0**| #### What's new - The MDATP package rollout into production will be done gradually. From the time the release notes are published, it might take up to a week for the package to be pushed to all production machines.- - The vulnerability in curl, CVE-2024-7264, has been addressed.- - Other stability improvements and bug fixes.-##### Known Issues+#### Known Issues - There's a known issue where MDE is deleting the configuration file located at /etc/systemd/system/mdatp.service.d on each service start. As a workaround, customers can use the Immutable attribute that prevents the files from being modified or deleted. To set the file to be unmodifiable, execute the following command:- -```bash+ ```bash sudo chattr +i /etc/systemd/system/mdatp.service.d/[file name] ```- + This command makes the file unchangeable. If you need to restore modification permissions, use the following command: ```bash- sudo chattr -i /etc/systemd/system/mdatp.service.d/[file name] ```- - Note that the chattr command can only be used on supported file systems, such as ext4.- - If you need further assistance, you can reach out to our support team with your organization ID, and we can implement a temporary mitigation to prevent deletion. A permanent fix for this issue is available in MDE version 101.25032.0000.++ Note that the `chattr` command can only be used on supported file systems, such as ext4.++If you need further assistance, you can reach out to our support team with your organization ID, and we can implement a temporary mitigation to prevent deletion. A permanent fix for this issue is available in MDE version 101.25032.0000. ### Feb-2025 Build: 101.24122.0008 | Release version: 30.124112.0008.0-| Build: | **101.24122.0008** |-|--------------------|-----------------------|-| Released: | **February 20, 2025** |-| Published: | **February 20, 2025** |-| Release version: | **30.124122.0008.0** |-| Engine version: | **1.1.24090.13** |-| Signature version: | **1.421.226.0** |+|Build:|**101.24122.0008**|+|---|---|+|Released:|**February 20, 2025**|+|Published:|**February 20, 2025**|+|Release version:|**30.124122.0008.0**|+|Engine version:|**1.1.24090.13**|+|Signature version:|**1.421.226.0**| #### What's new@@ -1382,13 +1441,13 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### Feb-2025 Build: 101.24112.0003 | Release version: 30.124112.0003.0-| Build: | **101.24112.0003** |-|--------------------|-----------------------|-| Released: | **February 04, 2025** |-| Published: | **February 04, 2025** |-| Release version: | **30.124112.0003.0** |-| Engine version: | **1.1.24090.13** |-| Signature version: | **1.421.1681.0** |+|Build:|**101.24112.0003**|+|---|---|+|Released:|**February 04, 2025**|+|Published:|**February 04, 2025**|+|Release version:|**30.124112.0003.0**|+|Engine version:|**1.1.24090.13**|+|Signature version:|**1.421.1681.0**| #### What's new@@ -1397,20 +1456,20 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### Jan-2025 Build: 101.24112.0001 | Release version: 30.124112.0001.0-| Build: | **101.24112.0001** |-|--------------------|-----------------------|-| Released: | **January 13, 2025** |-| Published: | **January 13, 2025** |-| Release version: | **30.124112.0001.0** |-| Engine version: | **1.1.24090.13** |-| Signature version: | **1.421.226.0** |+|Build:|**101.24112.0001**|+|---|---|+|Released:|**January 13, 2025**|+|Published:|**January 13, 2025**|+|Release version:|**30.124112.0001.0**|+|Engine version:|**1.1.24090.13**|+|Signature version:|**1.421.226.0**| #### What's new - Upgraded the Bond version to 13.0.1 to address security vulnerabilities in versions 12 or lower. - Mdatp package no longer has a dependency on SELinux packages.- + - Users can now query the status of supplementary event provider eBPF using the threat hunting query in `DeviceTvmInfoGathering`. To learn more about this query check: [Use eBPF-based sensor for Microsoft Defender for Endpoint on Linux](linux-support-ebpf.md). The result of this query can return the following two values as eBPF status: - Enabled: When eBPF is enabled as working as expected. - Disabled: When eBPF is disabled due to one of the following reasons:@@ -1426,13 +1485,13 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### Jan-2025 Build: 101.24102.0000 | Release version: 30.124102.0000.0-| Build: | **101.24102.0000** |-|--------------------|-----------------------|-| Released: | **January 8, 2025** |-| Published: | **January 8, 2025** |-| Release version: | **30.124102.0000.0** |-| Engine version: | **1.1.24080.11** |-| Signature version: | **1.419.351.0** |+|Build:|**101.24102.0000**|+|---|---|+|Released:|**January 8, 2025**|+|Published:|**January 8, 2025**|+|Release version:|**30.124102.0000.0**|+|Engine version:|**1.1.24080.11**|+|Signature version:|**1.419.351.0**| #### What's new@@ -1442,13 +1501,13 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### Nov-2024 Build: 101.24092.0002 | Release version: 30.124092.0002.0-| Build: | **101.24092.0002** |-|--------------------|-----------------------|-| Released: | **November 14, 2024** |-| Published: | **November 14, 2024** |-| Release version: | **30.124092.0002.0** |-| Engine version: | **1.1.24080.9** |-| Signature version: | **1.417.659.0** |+|Build:|**101.24092.0002**|+|---|---|+|Released:|**November 14, 2024**|+|Published:|**November 14, 2024**|+|Release version:|**30.124092.0002.0**|+|Engine version:|**1.1.24080.9**|+|Signature version:|**1.417.659.0**| #### What's new@@ -1458,31 +1517,30 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### Oct-2024 Build: 101.24082.0004 | Release version: 30.124082.0004.0-| Build: | **101.24082.0004** |-|--------------------|-----------------------|-| Released: | **October 15, 2024** |-| Published: | **October 15, 2024** |-| Release version: | **30.124082.0004** |-| Engine version: | **1.1.24080.9** |-| Signature version: | **1.417.659.0** |+|Build:|**101.24082.0004**|+|---|---|+|Released:|**October 15, 2024**|+|Published:|**October 15, 2024**|+|Release version:|**30.124082.0004**|+|Engine version:|**1.1.24080.9**|+|Signature version:|**1.417.659.0**| #### What's new - Starting with this version, Defender for Endpoint on Linux no longer supports `AuditD` as a supplementary event provider. For improved stability and performance, we have transitioned to eBPF. If you disable eBPF, or in the event eBPF isn't supported on any specific kernel, Defender for Endpoint on Linux automatically switches back to Net link as a fallback supplementary event provider. Net link provides reduced functionality and tracks only process-related events. In this case, all process operations continue to flow seamlessly, but you could miss specific file and socket-related events that eBPF would otherwise capture. For more information, see [Use eBPF-based sensor for Microsoft Defender for Endpoint on Linux](linux-support-ebpf.md). If you have any concerns or need assistance during this transition, contact support. - Stability and performance improvements- - Other bug fixes ### Sept-2024 Build: 101.24072.0001 | Release version: 30.124072.0001.0-| Build: | **101.24072.0001** |-|--------------------|-----------------------|-| Released: | **September 23, 2024** |-| Published: | **September 23, 2024** |-| Release version: | **30.124072.0001.0** |-| Engine version: | **1.1.24060.6** |-| Signature version: | **1.415.228.0** |+|Build:|**101.24072.0001**|+|---|---|+|Released:|**September 23, 2024**|+|Published:|**September 23, 2024**|+|Release version:|**30.124072.0001.0**|+|Engine version:|**1.1.24060.6**|+|Signature version:|**1.415.228.0**| #### What's new@@ -1492,39 +1550,34 @@ Live Response for macOS is now available for all Mac devices onboarded to Defend ### July-2024 Build: 101.24062.0001 | Release version: 30.124062.0001.0-| Build: | **101.24072.0001** |-|--------------------|-----------------------|-| Released: | **July 31, 2024** |-| Published: | **July 31, 2024** |-| Release version: | **30.124062.0001.0** |-| Engine version: | **1.1.24050.7** |-| Signature version: | **1.411.410.0** |+|Build:|**101.24072.0001**|+|---|---|+|Released:|**July 31, 2024**|+|Published:|**July 31, 2024**|+|Release version:|**30.124062.0001.0**|+|Engine version:|**1.1.24050.7**|+|Signature version:|**1.411.410.0**| #### What's new There are multiple fixes and new changes in this release. - Fixes bug in which infected command-line threat information wasn't showing correctly in security portal.- - Fixes a bug where disabling a preview feature required a Defender of Endpoint to disable it.- - Global Exclusions feature using managed JSON is now in Public Preview. available in insiders slow from 101.23092.0012. For more information, see [linux-exclusions](linux-exclusions.md).- - Updated the Linux default engine version to 1.1.24050.7 and default signature version to 1.411.410.0.- - Stability and performance improvements.- - Other bug fixes. ### June-2024 Build: 101.24052.0002 | Release version: 30.124052.0002.0-| Build: | **101.24052.0002** |-|--------------------|-----------------------|-| Released: | **June 24, 2024** |-| Published: | **June 24, 2024** |-| Release version: | **30.124052.0002.0** |-| Engine version: | **1.1.24040.2** |-| Signature version: | **1.411.153.0** |+|Build:|**101.24052.0002**|+|---|---|+|Released:|**June 24, 2024**|+|Published:|**June 24, 2024**|+|Release version:|**30.124052.0002.0**|+|Engine version:|**1.1.24040.2**|+|Signature version:|**1.411.153.0**| #### What's new@@ -1533,62 +1586,57 @@ There are multiple fixes and new changes in this release. - This release fixes a bug related to high memory usage eventually leading to high CPU due to eBPF memory leak in kernel space resulting in servers going into unusable states. This only affected the kernel versions 3.10x and <= 4.16x, majorly on RHEL/CentOS distros. Update to the latest MDE version to avoid any impact. - We have now simplified the output of `mdatp health --detail features`- - Stability and performance improvements.- - Other bug fixes. ### May-2024 Build: 101.24042.0002 | Release version: 30.124042.0002.0-| Build: | **101.24042.0002** |-|--------------------|-----------------------|-| Released: | **May 29, 2024** |-| Published: | **May 29, 2024** |-| Release version: | **30.124042.0002.0** |-| Engine version: | **1.1.24030.4** |-| Signature version: | **1.407.521.0** |+|Build:|**101.24042.0002**|+|---|---|+|Released:|**May 29, 2024**|+|Published:|**May 29, 2024**|+|Release version:|**30.124042.0002.0**|+|Engine version:|**1.1.24030.4**|+|Signature version:|**1.407.521.0**| #### What's new There are multiple fixes and new changes in this release: - In version 24032.0007, there was a known issue where the enrollment of devices to MDE Security Management failed when using the "Device Tagging" mechanism via the mdatp_managed.json file. This issue has been resolved in the current release.- - Stability and performance improvements.- - Other bug fixes. ### May-2024 Build: 101.24032.0007 | Release version: 30.124032.0007.0-| Build: | **101.24032.0007** |-|--------------------|-----------------------|-| Released: | **May 15, 2024** |-| Published: | **May 15, 2024** |-| Release version: | **30.124032.0007.0** |-| Engine version: | **1.1.24020.3** |-| Signature version: | **1.403.3500.0** |+|Build:|**101.24032.0007**|+|---|---|+|Released:|**May 15, 2024**|+|Published:|**May 15, 2024**|+|Release version:|**30.124032.0007.0**|+|Engine version:|**1.1.24020.3**|+|Signature version:|**1.403.3500.0**| #### What's new There are multiple fixes and new changes in this release: - In passive and on-demand modes, antivirus engine remains in idle state and is used only during scheduled custom scans. Thus as part of performance improvements, we have made changes to keep the AV engine down in passive and on-demand mode except during scheduled custom scans. If the real time protection is enabled, antivirus engine will always be up and running. This has no impact on your server protection in any mode.- + To keep users informed of the state of antivirus engine, we have introduced a new field called "engine_load_status" as part of MDATP health. It indicates whether antivirus engine is currently running or not.- | `Field name` | `engine_load_status` | + |`Field name`|`engine_load_status`| |---|---|- | Possible values | Engine not loaded (AV engine process is down), Engine load succeeded (AV engine process up and running) | + |Possible values|Engine not loaded (AV engine process is down), Engine load succeeded (AV engine process up and running)| Healthy scenarios:- - If RTP is enabled, engine_load_status should be "Engine load succeeded"- - If MDE is in on-demand or passive mode, and custom scan isn't running then "engine_load_status" should be "Engine not loaded"- - If MDE is in on-demand or passive mode, and custom scan is running then "engine_load_status" should be "Engine load succeeded" -- Bug fix to enhance behavioral detections.+ - If RTP is enabled, engine_load_status should be "Engine load succeeded"+ - If MDE is in on-demand or passive mode, and custom scan isn't running then "engine_load_status" should be "Engine not loaded"+ - If MDE is in on-demand or passive mode, and custom scan is running then "engine_load_status" should be "Engine load succeeded"+- Bug fix to enhance behavioral detections. - Stability and performance improvements.- - Other bug fixes. #### Known Issues@@ -1598,96 +1646,90 @@ There are multiple fixes and new changes in this release: ```bash sudo mdatp edr tag set --name GROUP --value MDE-Management ```- **The issue has been fixed in Build: 101.24042.0002**++ **The issue has been fixed in Build: 101.24042.0002** ### March-2024 Build: 101.24022.0001 | Release version: 30.124022.0001.0-| Build: | **101.24022.0001** |-|--------------------|-----------------------|-| Released: | **March 22,2024** |-| Published: | **March 22,2024** |-| Release version: | **30.124022.0001.0** |-| Engine version: | **1.1.23110.4** |-| Signature version: | **1.403.87.0** |+|Build:|**101.24022.0001**|+|---|---|+|Released:|**March 22,2024**|+|Published:|**March 22,2024**|+|Release version:|**30.124022.0001.0**|+|Engine version:|**1.1.23110.4**|+|Signature version:|**1.403.87.0**| #### What's new There are multiple fixes and new changes in this release: - The addition of a new log file - `microsoft_defender_scan_skip.log`. This logs the filenames that were skipped from various antivirus scans by Microsoft Defender for Endpoint due to any reason.- - Stability and performance improvements.- - Bug fixes. ### March-2024 Build: 101.24012.0001 | Release version: 30.124012.0001.0-| Build: | **101.24012.0001** |-|--------------------|-----------------------|-| Released: | **March 12,2024** |-| Published: | **March 12,2024** |-| Release version: | **30.124012.0001.0** |-| Engine version: | **1.1.23110.4** |-| Signature version: | **1.403.87.0** |+|Build:|**101.24012.0001**|+|---|---|+|Released:|**March 12,2024**|+|Published:|**March 12,2024**|+|Release version:|**30.124012.0001.0**|+|Engine version:|**1.1.23110.4**|+|Signature version:|**1.403.87.0**| #### What's new There are multiple fixes and new changes in this release: - Updated default engine version to `1.1.23110.4`, and default signatures version to `1.403.87.0`.- - Stability and performance improvements.- - Bug fixes. ### February-2024 Build: 101.23122.0002 | Release version: 30.123122.0002.0-| Build: | **101.23122.0002** |-|--------------------|-----------------------|-| Released: | **February 5,2024** |-| Published: | **February 5,2024** |-| Release version: | **30.123122.0002.0** |-| Engine version: | **1.1.23100.2010** |-| Signature version: | **1.399.1389.0** |+|Build:|**101.23122.0002**|+|---|---|+|Released:|**February 5,2024**|+|Published:|**February 5,2024**|+|Release version:|**30.123122.0002.0**|+|Engine version:|**1.1.23100.2010**|+|Signature version:|**1.399.1389.0**| #### What's new There are multiple fixes and new changes in this release: - Updated default engine version to `1.1.23100.2010`, and default signatures version to `1.399.1389.0`.- - General stability and performance improvements.- - Bug fixes.- - Microsoft Defender for Endpoint on Linux now officially supports the following distros and versions:- | Distro & version | Ring | Package |- |---|---|---|- | Mariner 2 | Production | https://packages.microsoft.com/cbl-mariner/2.0/prod/extras/x86_64/config.repo |- | Rocky 8.7 and higher | Insiders Slow | https://packages.microsoft.com/config/rocky/8/insiders-slow.repo |- | Rocky 9.2 and higher | Insiders Slow | https://packages.microsoft.com/config/rocky/9/insiders-slow.repo |- | Alma 8.4 and higher | Insiders Slow | https://packages.microsoft.com/config/alma/8/insiders-slow.repo |- | Alma 9.2 and higher | Insiders Slow | https://packages.microsoft.com/config/alma/9/insiders-slow.repo |+ |Distro & version|Ring|Package|+ |---|---|---|+ |Mariner 2|Production|https://packages.microsoft.com/cbl-mariner/2.0/prod/extras/x86_64/config.repo|+ |Rocky 8.7 and higher|Insiders Slow|https://packages.microsoft.com/config/rocky/8/insiders-slow.repo|+ |Rocky 9.2 and higher|Insiders Slow|https://packages.microsoft.com/config/rocky/9/insiders-slow.repo|+ |Alma 8.4 and higher|Insiders Slow|https://packages.microsoft.com/config/alma/8/insiders-slow.repo|+ |Alma 9.2 and higher|Insiders Slow|https://packages.microsoft.com/config/alma/9/insiders-slow.repo|-If you already have Defender for Endpoint running on any of these distros and facing any issues in the older versions, upgrade to the latest Defender for Endpoint version from the corresponding ring mentioned above. +If you already have Defender for Endpoint running on any of these distros and facing any issues in the older versions, upgrade to the latest Defender for Endpoint version from the corresponding ring mentioned above.-> [!NOTE]-> Known issues: -> -> Microsoft Defender for Endpoint for Linux on Rocky and Alma currently has the following known issues:-> - Live Response and Threat Vulnerability Management are currently not supported (work in progress).-> - Operating system info for devices isn't visible in the Microsoft Defender portal+#### Known issues:++Microsoft Defender for Endpoint for Linux on Rocky and Alma currently has the following known issues:++- Live Response and Threat Vulnerability Management are currently not supported (work in progress).+- Operating system info for devices isn't visible in the Microsoft Defender portal ### January-2024 Build: 101.23112.0009 | Release version: 30.123112.0009.0-| Build: | **101.23112.0009** |-|--------------------|-----------------------|-| Released: | **January 29,2024** |-| Published: | **January 29,2024** |-| Release version: | **30.123112.0009.0** |-| Engine version: | **1.1.23100.2010** |-| Signature version: | **1.399.1389.0** |+|Build:|**101.23112.0009**|+|---|---|+|Released:|**January 29,2024**|+|Published:|**January 29,2024**|+|Release version:|**30.123112.0009.0**|+|Engine version:|**1.1.23100.2010**|+|Signature version:|**1.399.1389.0**| #### What's new@@ -1701,13 +1743,13 @@ If you already have Defender for Endpoint running on any of these distros and fa ### November-2023 Build: 101.23102.0003 | Release version: 30.123102.0003.0-| Build: | **101.23102.0003** |-|--------------------|-----------------------|-| Released: | **November 28,2023** |-| Published: | **November 28,2023** |-| Release version: | **30.123102.0003.0** |-| Engine version: | **1.1.23090.2008** |-| Signature version: | **1.399.690.0** |+|Build:|**101.23102.0003**|+|---|---|+|Released:|**November 28,2023**|+|Published:|**November 28,2023**|+|Release version:|**30.123102.0003.0**|+|Engine version:|**1.1.23090.2008**|+|Signature version:|**1.399.690.0**| #### What's new@@ -1723,29 +1765,31 @@ If you already have Defender for Endpoint running on any of these distros and fa ### November-2023 Build: 101.23092.0012 | Release version: 30.123092.0012.0-| Build: | **101.23092.0012** |-|--------------------|-----------------------|-| Released: | **November 14,2023** |-| Published: | **November 14,2023** |-| Release version: | **30.123092.0012.0** |-| Engine version: | **1.1.23080.2007** |-| Signature version: | **1.395.1560.0** |+|Build:|**101.23092.0012**|+|---|---|+|Released:|**November 14,2023**|+|Published:|**November 14,2023**|+|Release version:|**30.123092.0012.0**|+|Engine version:|**1.1.23080.2007**|+|Signature version:|**1.395.1560.0**| #### What's new-There are multiple fixes and new changes in this release: +There are multiple fixes and new changes in this release: - Support added to restore threat based on original path using the following command:- + ```bash sudo mdatp threat quarantine restore threat-path --path [threat-original-path] --destination-path [destination-folder] ```+ - From this release, Microsoft Defender for Endpoint on Linux will no longer be shipping a solution for RHEL 6.- + RHEL 6 'Extended end of life support' is poised to end by June 30, 2024 and customers are advised to plan their RHEL upgrades accordingly aligned with guidance from Red Hat. Customers who need to run Defender for Endpoint on RHEL 6 servers can continue to use version 101.23082.0011 (doesn't expire before June 30, 2024) supported on kernel versions 2.6.32-754.49.1.el6.x86_64 or prior.- - Engine Update to `1.1.23080.2007` and Signatures Ver: `1.395.1560.0`.- - Streamlined device connectivity experience is now in public preview mode. [public blog](https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/announcing-a-streamlined-device-connectivity-experience-for/ba-p/3956236)- - Performance improvements & bug fixes.++- Engine Update to `1.1.23080.2007` and Signatures Ver: `1.395.1560.0`.+- Streamlined device connectivity experience is now in public preview mode. [public blog](https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/announcing-a-streamlined-device-connectivity-experience-for/ba-p/3956236)+- Performance improvements & bug fixes. #### Known issues@@ -1753,20 +1797,18 @@ There are multiple fixes and new changes in this release: ### November-2023 Build: 101.23082.0011 | Release version: 30.123082.0011.0-| Build: | **101.23082.0011** |-|--------------------|-----------------------|-| Released: | **November 1,2023** |-| Published: | **November 1,2023** |-| Release version: | **30.123082.0011.0** |-| Engine version: | **1.1.23070.1002** |-| Signature version: | **1.393.1305.0** |+|Build:|**101.23082.0011**|+|---|---|+|Released:|**November 1,2023**|+|Published:|**November 1,2023**|+|Release version:|**30.123082.0011.0**|+|Engine version:|**1.1.23070.1002**|+|Signature version:|**1.393.1305.0**| #### What's new - This new release is built over October 2023 release (101.23082.0009) with addition of following changes. There's no change for other customers and upgrading is optional.- - Fix for immutable mode of auditd when supplementary subsystem is ebpf: In ebpf mode all mdatp audit rules should be cleaned after switching to ebpf and rebooting. After the reboot, mdatp audit rules weren't cleaned due to which it was resulting in hang of the server. The fix cleans these rules, user shouldn't see any mdatp rules loaded on reboot- - Fix for MDE not starting up on RHEL 6. #### Known issues@@ -1781,32 +1823,33 @@ There are two ways to mitigate this upgrade issue: ```bash sudo apt purge mdatp+ sudo apt-get install mdatp ``` 2. As an alternative you can follow the instructions to [uninstall](./linux-off-board-endpoints.md#uninstall-the-defender-application-from-a-linux-server), then [install](linux-install-manually.md#application-installation) the latest version of the package.-If you don't want to uninstall mdatp, you can disable rtp and mdatp in sequence before upgrading.-Some customers (<1%) experience issues with this method.+If you don't want to uninstall mdatp, you can disable rtp and mdatp in sequence before upgrading. Some customers (<1%) experience issues with this method. ```bash sudo mdatp config real-time-protection --value=disabled+ sudo systemctl disable mdatp ``` ### October-2023 Build: 101.23082.0009 | Release version: 30.123082.0009.0-| Build: | **101.23082.0009** |-|--------------------|-----------------------|-| Released: | **October 9,2023** |-| Published: | **October 9,2023** |-| Release version: | **30.123082.0009.0** |-| Engine version: | **1.1.23070.1002** |-| Signature version: | **1.393.1305.0** |+|Build:|**101.23082.0009**|+|---|---|+|Released:|**October 9,2023**|+|Published:|**October 9,2023**|+|Release version:|**30.123082.0009.0**|+|Engine version:|**1.1.23070.1002**|+|Signature version:|**1.393.1305.0**| #### What's new-- This new release is built over October 2023 release (`101.23082.0009`) with addition of new CA Certificates. There's no change for other customers and upgrading is optional. +- This new release is built over October 2023 release (`101.23082.0009`) with addition of new CA Certificates. There's no change for other customers and upgrading is optional. #### Known issues@@ -1835,55 +1878,58 @@ sudo systemctl disable mdatp ### October-2023 Build: 101.23082.0006 | Release version: 30.123082.0006.0-| Build: | **101.23082.0006** |-|--------------------|-----------------------|-| Released: | **October 9,2023** |-| Published: | **October 9,2023** |-| Release version: | **30.123082.0006.0** |-| Engine version: | **1.1.23070.1002** |-| Signature version: | **1.393.1305.0** |+|Build:|**101.23082.0006**|+|---|---|+|Released:|**October 9,2023**|+|Published:|**October 9,2023**|+|Release version:|**30.123082.0006.0**|+|Engine version:|**1.1.23070.1002**|+|Signature version:|**1.393.1305.0**| #### What's new - Feature updates and new changes- - eBPF sensor is now the default supplementary event provider for endpoints- - Microsoft Intune tenant attach feature is in public preview (as of mid July) - You must add "*.dm.microsoft.com" to firewall exclusions for the feature to work correctly- + - Defender for Endpoint is now available for Debian 12 and Amazon Linux 2023- + - Support to enable Signature verification of updates downloaded - You must update the manajed.json as shown:- ```++ ```json "features":{ "OfflineDefinitionUpdateVerifySig":"enabled" } ```- + - Prerequisite to enable feature - Engine version on the device must be "1.1.23080.007" or above. Check your engine version by using the following command.- ``` mdatp health --field engine_version ```- ++ ```bash+ mdatp health --field engine_version+ ```+ - Option to support monitoring of NFS and FUSE mount points. These are ignored by default. The following example shows how to monitor all filesystem while ignoring only NFS:- ```- "antivirusEngine": {- "unmonitoredFilesystems": ["nfs"]- }- ```- + ```json+ "antivirusEngine": {+ "unmonitoredFilesystems": ["nfs"]+ }+ ```+ Example to monitor all filesystems including NFS and FUSE:- ```++ ```json "antivirusEngine": { "unmonitoredFilesystems": [] } ``` - Other performance improvements- + - Bug Fixes #### Known issues@@ -1897,6 +1943,7 @@ There are two ways to mitigate this upgrade issue: ```bash sudo apt purge mdatp+ sudo apt-get install mdatp ```@@ -1912,24 +1959,21 @@ sudo systemctl disable mdatp ### September-2023 Build: 101.23072.0021 | Release version: 30.123072.0021.0-| Build: | **101.23072.0021** |-|--------------------|-----------------------|-| Released: | **September 11,2023** |-| Published: | **September 11,2023** |-| Release version: | **30.123072.0021.0** |-| Engine version: | **1.1.20100.7** |-| Signature version: | **1.385.1648.0** |+|Build:|**101.23072.0021**|+|---|---|+|Released:|**September 11,2023**|+|Published:|**September 11,2023**|+|Release version:|**30.123072.0021.0**|+|Engine version:|**1.1.20100.7**|+|Signature version:|**1.385.1648.0**| #### What's new There are multiple fixes and new changes in this release: - In `mde_installer.sh` v0.6.3, users can use the `--channel` argument to provide the channel of the configured repository during cleanup. For example, `sudo ./mde_installer --clean --channel prod`- - The Network Extension can now be reset by administrators using `mdatp network-protection reset`.- - Other performance improvements- - Bug Fixes #### Known issues@@ -1944,6 +1988,7 @@ There are two ways to mitigate this upgrade issue: ```bash sudo apt purge mdatp+ sudo apt-get install mdatp ```@@ -1954,39 +1999,33 @@ Some customers (<1%) experience issues with this method. ```bash sudo mdatp config real-time-protection --value=disabled+ sudo systemctl disable mdatp ``` ### July-2023 Build: 101.23062.0010 | Release version: 30.123062.0010.0-| Build: | **101.23062.0010** |-|--------------------|-----------------------|-| Released: | **July 26,2023** |-| Published: | **July 26,2023** |-| Release version: | **30.123062.0010.0** |-| Engine version: | **1.1.20100.7** |-| Signature version: | **1.385.1648.0** |+|Build:|**101.23062.0010**|+|---|---|+|Released:|**July 26,2023**|+|Published:|**July 26,2023**|+|Release version:|**30.123062.0010.0**|+|Engine version:|**1.1.20100.7**|+|Signature version:|**1.385.1648.0**| #### What's new-There are multiple fixes and new changes in this release+There are multiple fixes and new changes in this release: - If a proxy is set for Defender for Endpoint, then it's visible in the `mdatp health` command output. With this release we provided two options in mdatp diagnostic hot-event-sources:-- - Files- - Executables- + - Files+ - Executables - Network Protection: Connections that are blocked by Network Protection and have the block overridden by users is now correctly reported to Microsoft Defender XDR- - Improved logging in Network Protection block and audit events for debugging- - Other fixes and improvements-- - From this version, enforcementLevel are in passive mode by default giving admins more control over where they want 'RTP on' within their estate- - This change only applies to fresh MDE deployments, for example, servers where Defender for Endpoint is being deployed for the first time. In update scenarios, servers that have Defender for Endpoint deployed with RTP ON, continue operating with RTP ON even post update to version 101.23062.0010-+ - From this version, enforcementLevel are in passive mode by default giving admins more control over where they want 'RTP on' within their estate+ - This change only applies to fresh MDE deployments, for example, servers where Defender for Endpoint is being deployed for the first time. In update scenarios, servers that have Defender for Endpoint deployed with RTP ON, continue operating with RTP ON even post update to version 101.23062.0010 - Bug fix: RPM database corruption issue in Defender Vulnerability Management baseline is fixed.- - Other performance improvements #### Known issues@@ -2001,6 +2040,7 @@ There are two ways to mitigate this upgrade issue: ```bash sudo apt purge mdatp+ sudo apt-get install mdatp ```@@ -2011,26 +2051,28 @@ Some customers (<1%) experience issues with this method. ```bash sudo mdatp config real-time-protection --value=disabled+ sudo systemctl disable mdatp ``` ### July-2023 Build: 101.23052.0009 | Release version: 30.123052.0009.0-| Build: | **101.23052.0009** |-|--------------------|-----------------------|-| Released: | **July 10,2023** |-| Published: | **July 10,2023** |-| Release version: | **30.123052.0009.0** |-| Engine version: | **1.1.20100.7** |-| Signature version: | **1.385.1648.0** |+|Build:|**101.23052.0009**|+|---|---|+|Released:|**July 10,2023**|+|Published:|**July 10,2023**|+|Release version:|**30.123052.0009.0**|+|Engine version:|**1.1.20100.7**|+|Signature version:|**1.385.1648.0**| #### What's new-- There are multiple fixes and new changes in this release- - The build version schema is updated from this release. While the major version number remains same as 101, the minor version number now has five digits followed by four digit patch number that is, `101.xxxxx.yyy`- - Improved Network Protection memory consumption under stress- - Updated the engine version to `1.1.20300.5` and signature version to `1.391.2837.0`.- - Bug fixes.+There are multiple fixes and new changes in this release:++- The build version schema is updated from this release. While the major version number remains same as 101, the minor version number now has five digits followed by four digit patch number that is, `101.xxxxx.yyy`+- Improved Network Protection memory consumption under stress+- Updated the engine version to `1.1.20300.5` and signature version to `1.391.2837.0`.+- Bug fixes. #### Known issues@@ -2044,6 +2086,7 @@ There are two ways to mitigate this upgrade issue: ```bash sudo apt purge mdatp+ sudo apt-get install mdatp ```@@ -2054,33 +2097,29 @@ Some customers (<1%) experience issues with this method. ```bash sudo mdatp config real-time-protection --value=disabled+ sudo systemctl disable mdatp ``` ### June-2023 Build: 101.98.89 | Release version: 30.123042.19889.0-| Build: | **101.98.89** |-|--------------------|-----------------------|-| Released: | **June 12,2023** |-| Published: | **June 12,2023** |-| Release version: | **30.123042.19889.0** |-| Engine version: | **1.1.20100.7** |-| Signature version: | **1.385.1648.0** |+|Build:|**101.98.89**|+|---|---|+|Released:|**June 12,2023**|+|Published:|**June 12,2023**|+|Release version:|**30.123042.19889.0**|+|Engine version:|**1.1.20100.7**|+|Signature version:|**1.385.1648.0**| #### What's new-There are multiple fixes and new changes in this release +There are multiple fixes and new changes in this release: - Improved Network Protection Proxy handling.- - In Passive mode, Defender for Endpoint no longer scans when Definition update happens.- - Devices continue to be protected even after Defender for Endpoint agent is expired. We recommend upgrading the Defender for Endpoint Linux agent to the latest available version to receive bug fixes, features, and performance improvements.- - Removed semanage package dependency.- - Engine Update to `1.1.20100.7` and Signatures Ver: `1.385.1648.0`.- - Bug fixes. #### Known issues@@ -2100,8 +2139,8 @@ There are two ways to mitigate this upgrade issue: 2. As an alternative you can follow the instructions to [uninstall](./linux-off-board-endpoints.md#uninstall-the-defender-application-from-a-linux-server), then [install](linux-install-manually.md#application-installation) the latest version of the package.-If you don't want to uninstall mdatp, you can disable rtp and mdatp in sequence before upgrading. -Some customers (<1%) experience issues with this method. +If you don't want to uninstall mdatp, you can disable rtp and mdatp in sequence before upgrading.+Some customers (<1%) experience issues with this method. ```bash sudo mdatp config real-time-protection --value=disabled@@ -2110,34 +2149,26 @@ sudo systemctl disable mdatp ### May-2023 Build: 101.98.64 | Release version: 30.123032.19864.0-| Build: | **101.98.64** |-|--------------------|-----------------------|-| Released: | **May 3,2023** |-| Published: | **May 3,2023** |-| Release version: | **30.123032.19864.0** |-| Engine version: | **1.1.20100.6** |-| Signature version: | **1.385.68.0** |+|Build:|**101.98.64**|+|---|---|+|Released:|**May 3,2023**|+|Published:|**May 3,2023**|+|Release version:|**30.123032.19864.0**|+|Engine version:|**1.1.20100.6**|+|Signature version:|**1.385.68.0**| #### What's new-There are multiple fixes and new changes in this release +There are multiple fixes and new changes in this release: - Health message improvements to capture details about auditd failures.- - Improvements to handle augenrules, which was causing installation failure.- - Periodic memory cleanup in engine process.- - Fix for memory issue in mdatp audisp plugin.- - Handled missing plugin directory path during installation.- - When conflicting application is using blocking fanotify, with default configuration mdatp health shows unhealthy. This is now fixed.- - Support for ICMP traffic inspection in BM.- - Engine Update to `1.1.20100.6` and Signatures Ver: `1.385.68.0`.- - Bug fixes. #### Known issues@@ -2157,8 +2188,8 @@ There are two ways to mitigate this upgrade issue: 2. As an alternative you can follow the instructions to [uninstall](./linux-off-board-endpoints.md#uninstall-the-defender-application-from-a-linux-server), then [install](linux-install-manually.md#application-installation) the latest version of the package.-If you don't want to uninstall mdatp, you can disable rtp and mdatp in sequence before upgrading. -Caution: Some customers (<1%) experience issues with this method. +If you don't want to uninstall mdatp, you can disable rtp and mdatp in sequence before upgrading.+Caution: Some customers (<1%) experience issues with this method. ```bash sudo mdatp config real-time-protection --value=disabled@@ -2167,28 +2198,23 @@ sudo systemctl disable mdatp ### April-2023 Build: 101.98.58 | Release version: 30.123022.19858.0-| Build: | **101.98.58** |-|--------------------|-----------------------|-| Released: | **April 20,2023** |-| Published: | **April 20,2023** |-| Release version: | **30.123022.19858.0** |-| Engine version: | **1.1.20000.2** |-| Signature version: | **1.381.3067.0** |+|Build:|**101.98.58**|+|---|---|+|Released:|**April 20,2023**|+|Published:|**April 20,2023**|+|Release version:|**30.123022.19858.0**|+|Engine version:|**1.1.20000.2**|+|Signature version:|**1.381.3067.0**| #### What's new-There are multiple fixes and new changes in this release +There are multiple fixes and new changes in this release: - Logging and error reporting improvements for auditd.- - Handle failure in reload of auditd configuration.- - Handling for empty auditd rule files during MDE install.- - Engine Update to `1.1.20000.2` and Signatures Ver: `1.381.3067.0`.- - Addressed a health issue in mdatp that occurs due to selinux denials.- - Bug fixes. #### Known issues@@ -2197,6 +2223,7 @@ There are multiple fixes and new changes in this release ```bash echo -c >> /etc/audit/rules.d/audit.rules+ augenrules --load ```@@ -2205,38 +2232,40 @@ There are multiple fixes and new changes in this release There are two ways to mitigate this upgrade issue: 1. Use your package manager to uninstall the `101.75.43` or `101.78.13` mdatp version.- + Example: ```bash sudo apt purge mdatp+ sudo apt-get install mdatp ``` 2. As an alternative you can follow the instructions to [uninstall](./linux-off-board-endpoints.md#uninstall-the-defender-application-from-a-linux-server), then [install](linux-install-manually.md#application-installation) the latest version of the package.-If you don't want to uninstall mdatp, you can disable rtp and mdatp in sequence before upgrading. -Caution: Some customers (<1%) experience issues with this method. +If you don't want to uninstall mdatp, you can disable rtp and mdatp in sequence before upgrading.+Caution: Some customers (<1%) experience issues with this method. ```bash sudo mdatp config real-time-protection --value=disabled+ sudo systemctl disable mdatp ``` ### March-2023 Build: 101.98.30 | Release version: 30.123012.19830.0-| Build: | **101.98.30** |-|--------------------|-----------------------|-| Released: | **March 20, 2023** |-| Published: | **March 20, 2023** |-| Release version: | **30.123012.19830.0** |-| Engine version: | **1.1.19900.2** |-| Signature version: | **1.379.1299.0** |+|Build:|**101.98.30**|+|---|---|+|Released:|**March 20, 2023**|+|Published:|**March 20, 2023**|+|Release version:|**30.123012.19830.0**|+|Engine version:|**1.1.19900.2**|+|Signature version:|**1.379.1299.0**| #### What's new-- This new release is built over March 2023 release (`101.98.05`) with a fix for Live response commands failing for one of our customers. There's no change for other customers and upgrade is optional. - +- This new release is built over March 2023 release (`101.98.05`) with a fix for Live response commands failing for one of our customers. There's no change for other customers and upgrade is optional.+ #### Known issues - With mdatp version 101.98.30 you might see a health false issue in some of the cases, because SELinux rules aren't defined for certain scenarios. The health warning could look something like this:@@ -2247,6 +2276,7 @@ The issue could be mitigated by running the following commands. ```bash sudo ausearch -c 'mdatp_audisp_pl' --raw | sudo audit2allow -M my-mdatpaudisppl_v1+ sudo semodule -i my-mdatpaudisppl_v1.pp ```@@ -2254,11 +2284,17 @@ Here, my-mdatpaudisppl_v1 represents the policy module name. After you run the c ```bash sudo service auditd stop+ sudo systemctl stop mdatp+ cd /var/log/audit+ sudo gzip audit.*+ sudo service auditd start+ sudo systemctl start mdatp+ mdatp health ```@@ -2266,49 +2302,38 @@ In case the issue reappears with some different denials. We need to run the miti ### March-2023 Build: 101.98.05 | Release version: 30.123012.19805.0-| Build: | **101.98.05** |-|--------------------|-----------------------|-| Released: | **March 08, 2023** |-| Published: | **March 08, 2023** |-| Release version: | **30.123012.19805.0** |-| Engine version: | **1.1.19900.2** |-| Signature version: | **1.379.1299.0** |+|Build:|**101.98.05**|+|---|---|+|Released:|**March 08, 2023**|+|Published:|**March 08, 2023**|+|Release version:|**30.123012.19805.0**|+|Engine version:|**1.1.19900.2**|+|Signature version:|**1.379.1299.0**| #### What's new - Improved Data Completeness for Network Connection events- - Improved Data Collection capabilities for file ownership/permissions changes- - seManage in part of the package, to that seLinux policies can be configured in different distro (fixed).- - Improved enterprise daemon stability- - AuditD stop path clean-up- - Improved the stability of mdatp stop flow.- - Added new field to wdavstate to keep track of platform update time.- - Stability improvements to parsing Defender for Endpoint onboarding blob.- - Scan doesn't proceed if a valid license isn't present (fixed)- - Added performance tracing option to xPlatClientAnalyzer, with tracing enabled mdatp process dumps the flow in all_process.zip file that can be used for analysis of performance issues.- - Added support in Defender for Endpoint for the following RHEL-6 kernel versions:-- - `2.6.32-754.43.1.el6.x86_64`- - `2.6.32-754.49.1.el6.x86_64`-+ - `2.6.32-754.43.1.el6.x86_64`+ - `2.6.32-754.49.1.el6.x86_64` - Other fixes- + #### Known issues While upgrading mdatp to version 101.94.13, you might notice that health is false, with health_issues as "no active supplementary event provider". This can happen due to misconfigured/conflicting auditd rules on existing machines. To mitigate the issue, the auditd rules on the existing machines need to be fixed. The following steps can help you to identify such auditd rules (these commands need to be run as super user). Make sure to back up following file: `/etc/audit/rules.d/audit.rules` as these steps are only to identify failures. ```bash echo -c >> /etc/audit/rules.d/audit.rules+ augenrules --load ```@@ -2322,13 +2347,14 @@ Example: ```bash sudo apt purge mdatp+ sudo apt-get install mdatp ``` As an alternative, you can follow the instructions to [uninstall](./linux-off-board-endpoints.md#uninstall-the-defender-application-from-a-linux-server), then [install](linux-install-manually.md#application-installation) the latest version of the package.-In case you don't want to uninstall mdatp you can disable rtp and mdatp in sequence before upgrade. -Caution: Some customers(<1%) are experiencing issues with this method. +In case you don't want to uninstall mdatp you can disable rtp and mdatp in sequence before upgrade.+Caution: Some customers(<1%) are experiencing issues with this method. ```bash sudo mdatp config real-time-protection --value=disabled@@ -2337,27 +2363,28 @@ sudo systemctl disable mdatp ### Jan-2023 Build: 101.94.13 | Release version: 30.122112.19413.0-| Build: | **101.94.13** |-|--------------------|-----------------------|-| Released: | **January 10, 2023** |-| Published: | **January 10, 2023** |-| Release version: | **30.122112.19413.0** |-| Engine version: | **1.1.19700.3** |-| Signature version: | **1.377.550.0** |+|Build:|**101.94.13**|+|---|---|+|Released:|**January 10, 2023**|+|Published:|**January 10, 2023**|+|Release version:|**30.122112.19413.0**|+|Engine version:|**1.1.19700.3**|+|Signature version:|**1.377.550.0**| #### What's new-- There are multiple fixes and new changes in this release- - Skip quarantine of threats in passive mode by default.- - New config, nonExecMountPolicy, can now be used to specify behavior of RTP on mount point marked as noexec.- - New config, unmonitoredFilesystems, can be used to unmonitor certain filesystems.- - Improved performance under high load and in speed test scenarios.- - Fixes an issue with accessing SMB shares behind Cisco AnyConnect VPN connections.- - Fixes an issue with Network Protection and SMB.- - lttng performance tracing support.- - TVM, eBPF, auditd, telemetry, and mdatp cli improvements.- - mdatp health now reports behavior_monitoring- - Other fixes.+There are multiple fixes and new changes in this release:++- Skip quarantine of threats in passive mode by default.+- New config, nonExecMountPolicy, can now be used to specify behavior of RTP on mount point marked as noexec.+- New config, unmonitoredFilesystems, can be used to unmonitor certain filesystems.+- Improved performance under high load and in speed test scenarios.+- Fixes an issue with accessing SMB shares behind Cisco AnyConnect VPN connections.+- Fixes an issue with Network Protection and SMB.+- lttng performance tracing support.+- TVM, eBPF, auditd, telemetry, and mdatp cli improvements.+- mdatp health now reports behavior_monitoring+- Other fixes. #### Known issues@@ -2378,6 +2405,7 @@ Example: ```bash sudo apt purge mdatp+ sudo apt-get install mdatp ```@@ -2388,29 +2416,31 @@ Caution: Some customers(<1%) are experiencing issues with this method. ```bash sudo mdatp config real-time-protection --value=disabled+ sudo systemctl disable mdatp ``` ### Nov-2022 Build: 101.85.27 | Release version: 30.122092.18527.0-| Build: | **101.85.27** |-|--------------------|-----------------------|-| Released: | **November 02, 2022** |-| Published: | **November 02, 2022** |-| Release version: | **30.122092.18527.0** |-| Engine version: | **1.1.19500.2** |-| Signature version: | **1.371.1369.0** |+|Build:|**101.85.27**|+|---|---|+|Released:|**November 02, 2022**|+|Published:|**November 02, 2022**|+|Release version:|**30.122092.18527.0**|+|Engine version:|**1.1.19500.2**|+|Signature version:|**1.371.1369.0**| #### What's new-- There are multiple fixes and new changes in this release- - V2 engine is default with this release and V1 engine bits are removed for enhanced security.- - V2 engine support configuration path for AV definitions. (mdatp definition set path)- - Removed external packages dependencies from MDE package. Removed dependencies are libatomic1, libselinux, libseccomp, libfuse, and libuuid- - In case crash collection is disabled by configuration, crash monitoring process isn't launched.- - Performance fixes to optimally use system events for AV capabilities.- - Stability improvement when restarting mdatp and load epsext issues.- - Other fixes+There are multiple fixes and new changes in this release:++- V2 engine is default with this release and V1 engine bits are removed for enhanced security.+- V2 engine support configuration path for AV definitions. (mdatp definition set path)+- Removed external packages dependencies from MDE package. Removed dependencies are libatomic1, libselinux, libseccomp, libfuse, and libuuid+- In case crash collection is disabled by configuration, crash monitoring process isn't launched.+- Performance fixes to optimally use system events for AV capabilities.+- Stability improvement when restarting mdatp and load epsext issues.+- Other fixes #### Known issues@@ -2424,6 +2454,7 @@ Example: ```bash sudo apt purge mdatp+ sudo apt-get install mdatp ```@@ -2434,18 +2465,19 @@ Caution: Some customers(<1%) are experiencing issues with this method. ```bash sudo mdatp config real-time-protection --value=disabled+ sudo systemctl disable mdatp ``` ### Sep-2022 Build: 101.80.97 | Release version: 30.122072.18097.0-| Build: | **101.80.97** |-|--------------------|-----------------------|-| Released: | **September 14, 2022** |-| Published: | **September 14, 2022** |-| Release version: | **30.122072.18097.0** |-| Engine version: | **1.1.19300.3** |-| Signature version: | **1.369.395.0** |+|Build:|**101.80.97**|+|---|---|+|Released:|**September 14, 2022**|+|Published:|**September 14, 2022**|+|Release version:|**30.122072.18097.0**|+|Engine version:|**1.1.19300.3**|+|Signature version:|**1.369.395.0**| #### What's new@@ -2457,6 +2489,7 @@ sudo systemctl disable mdatp ```bash sudo mdatp config real-time-protection --value=disabled+ sudo systemctl disable mdatp ```@@ -2466,27 +2499,27 @@ As an alternative approach, follow the instructions to [uninstall](./linux-off-b ### Aug-2022 Build: 101.78.13 | Release version: 30.122072.17813.0-| Build: | **101.78.13** |-|--------------------|-----------------------|-| Released: | **August 24, 2022** |-| Published: | **August 24, 2022** |-| Release version: | **30.122072.17813.0** |-| Engine version: | **1.1.19300.3** |-| Signature version: | **1.369.395.0** |- +|Build:|**101.78.13**|+|---|---|+|Released:|**August 24, 2022**|+|Published:|**August 24, 2022**|+|Release version:|**30.122072.17813.0**|+|Engine version:|**1.1.19300.3**|+|Signature version:|**1.369.395.0**|+ #### What's new - Rolled back due to reliability issues ### Aug-2022 (Build: 101.75.43 | Release version: 30.122071.17543.0)-| Build: | **101.75.43** |-|--------------------|-----------------------|-| Released: | **August 2, 2022** |-| Published: | **August 2, 2022** |-| Release version: | **30.122071.17543.0** |-| Engine version: | **1.1.19300.3** |-| Signature version: | **1.369.395.0** |+|Build:|**101.75.43**|+|---|---|+|Released:|**August 2, 2022**|+|Published:|**August 2, 2022**|+|Release version:|**30.122071.17543.0**|+|Engine version:|**1.1.19300.3**|+|Signature version:|**1.369.395.0**| #### What's new@@ -2498,13 +2531,13 @@ As an alternative approach, follow the instructions to [uninstall](./linux-off-b ### Jul-2022 Build: 101.73.77 | Release version: 30.122062.17377.0-| Build: | **101.73.77** |-|--------------------|-----------------------|-| Released: | **July 21, 2022** |-| Published: | **July 21, 2022** |-| Release version: | **30.122062.17377.0** |-| Engine version: | **1.1.19200.3** |-| Signature version: | **1.367.1011.0** |+|Build:|**101.73.77**|+|---|---|+|Released:|**July 21, 2022**|+|Published:|**July 21, 2022**|+|Release version:|**30.122062.17377.0**|+|Engine version:|**1.1.19200.3**|+|Signature version:|**1.367.1011.0**| #### What's new@@ -2515,11 +2548,11 @@ As an alternative approach, follow the instructions to [uninstall](./linux-off-b ### Jun-2022 Build: 101.71.18 | Release version: 30.122052.17118.0-| Build: | **101.71.18** |-|--------------------|-----------------------|-| Released: | **June 24, 2022** |-| Published: | **June 24, 2022** |-| Release version: | **30.122052.17118.0** |+|Build:|**101.71.18**|+|---|---|+|Released:|**June 24, 2022**|+|Published:|**June 24, 2022**|+|Release version:|**30.122052.17118.0**| #### What's new@@ -2533,11 +2566,11 @@ As an alternative approach, follow the instructions to [uninstall](./linux-off-b ### May-2022 Build: 101.68.80 | Release version: 30.122042.16880.0-| Build: | **101.68.80** |-|--------------------|-----------------------|-| Released: | **May 23, 2022** |-| Published: | **May 23, 2022** |-| Release version: | **30.122042.16880.0** |+|Build:|**101.68.80**|+|---|---|+|Released:|**May 23, 2022**|+|Published:|**May 23, 2022**|+|Release version:|**30.122042.16880.0**| #### What's new@@ -2550,11 +2583,11 @@ As an alternative approach, follow the instructions to [uninstall](./linux-off-b ### May-2022 Build: 101.65.77 | Release version: 30.122032.16577.0-| Build: | **101.65.77** |-|--------------------|-----------------------|-| Released: | **May 2, 2022** |-| Published: | **May 2, 2022** |-| Release version: | **30.122032.16577.0** |+|Build:|**101.65.77**|+|---|---|+|Released:|**May 2, 2022**|+|Published:|**May 2, 2022**|+|Release version:|**30.122032.16577.0**| #### What's new@@ -2563,11 +2596,11 @@ As an alternative approach, follow the instructions to [uninstall](./linux-off-b ### Mar-2022 (Build: 101.62.74 | Release version: 30.122022.16274.0)-| Build: | **101.62.74** |-|--------------------|-----------------------|-| Released: | **Mar 24, 2022** |-| Published: | **Mar 24, 2022** |-| Release version: | **30.122022.16274.0** |+|Build:|**101.62.74**|+|---|---|+|Released:|**Mar 24, 2022**|+|Published:|**Mar 24, 2022**|+|Release version:|**30.122022.16274.0**| #### What's new@@ -2576,11 +2609,11 @@ As an alternative approach, follow the instructions to [uninstall](./linux-off-b ### Mar-2022 Build: 101.60.93 | Release version: 30.122012.16093.0-| Build: | **101.60.93** |-|--------------------|-----------------------|-| Released: | **Mar 9, 2022** |-| Published: | **Mar 9, 2022** |-| Release version: | **30.122012.16093.0** |+|Build:|**101.60.93**|+|---|---|+|Released:|**Mar 9, 2022**|+|Published:|**Mar 9, 2022**|+|Release version:|**30.122012.16093.0**| #### What's new@@ -2588,11 +2621,11 @@ As an alternative approach, follow the instructions to [uninstall](./linux-off-b ### Mar-2022 Build: 101.60.05 | Release version: 30.122012.16005.0-| Build: | **101.60.05** |-|--------------------|-----------------------|-| Released: | **Mar 3, 2022** |-| Published: | **Mar 3, 2022** |-| Release version: | **30.122012.16005.0** |+|Build:|**101.60.05**|+|---|---|+|Released:|**Mar 3, 2022**|+|Published:|**Mar 3, 2022**|+|Release version:|**30.122012.16005.0**| #### What's new@@ -2601,11 +2634,11 @@ As an alternative approach, follow the instructions to [uninstall](./linux-off-b ### Feb-2022 Build: 101.58.80 | Release version: 30.122012.15880.0-| Build: | **101.58.80** |-|--------------------|-----------------------|-| Released: | **Feb 20, 2022** |-| Published: | **Feb 20, 2022** |-| Release version: | **30.122012.15880.0** |+|Build:|**101.58.80**|+|---|---|+|Released:|**Feb 20, 2022**|+|Published:|**Feb 20, 2022**|+|Release version:|**30.122012.15880.0**| #### What's new@@ -2615,11 +2648,11 @@ As an alternative approach, follow the instructions to [uninstall](./linux-off-b ### Jan-2022 Build: 101.56.62 | Release version: 30.121122.15662.0-| Build: | **101.56.62** |-|--------------------|-----------------------|-| Released: | **Jan 26, 2022** |-| Published: | **Jan 26, 2022** |-| Release version: | **30.121122.15662.0** |+|Build:|**101.56.62**|+|---|---|+|Released:|**Jan 26, 2022**|+|Published:|**Jan 26, 2022**|+|Release version:|**30.121122.15662.0**| #### What's new@@ -2627,11 +2660,11 @@ As an alternative approach, follow the instructions to [uninstall](./linux-off-b ### Jan-2022 Build: 101.53.02 | Release version: 30.121112.15302.0-| Build: | **101.53.02** |-|--------------------|-----------------------|-| Released: | **Jan 8, 2022** |-| Published: | **Jan 8, 2022** |-| Release version: | **30.121112.15302.0** |+|Build:|**101.53.02**|+|---|---|+|Released:|**Jan 8, 2022**|+|Published:|**Jan 8, 2022**|+|Release version:|**30.121112.15302.0**| #### What's new@@ -2641,47 +2674,44 @@ As an alternative approach, follow the instructions to [uninstall](./linux-off-b #### Build: 101.52.57 | Release version: 30.121092.15257.0-| Build: | **101.52.57** |-|--------------------|-----------------------|-| Release version: | **30.121092.15257.0** |+|Build:|**101.52.57**|+|---|---|+|Release version:|**30.121092.15257.0**|-##### What's new +##### What's new - Added a capability to detect vulnerable Log4j jars in use by Java applications. The machine is periodically inspected for running Java processes with loaded Log4j jars. The information is reported to the Microsoft Defender for Endpoint backend and is exposed in the Vulnerability Management area of the portal.-#### Build: 101.47.76 | Release version: 30.121092.14776.0+#### Build: 101.47.76 | Release version: 30.121092.14776.0++|Build:|**101.47.76**|+|---|---|+|Release version:|**30.121092.14776.0**|-| Build: | **101.47.76** |-|--------------------|-----------------------|-| Release version: | **30.121092.14776.0** |- ##### What's new - Added a new switch to the command-line tool to control whether archives are scanned during on-demand scans. This can be configured through mdatp config scan-archives--value [enabled/disabled]. By default, this setting is set to enabled.- - Bug fixes #### Build: 101.45.13 | Release version: 30.121082.14513.0-| Build: | **101.45.13** |-|--------------------|-----------------------|-| Release version: | **30.121082.14513.0** |+|Build:|**101.45.13**|+|---|---|+|Release version:|**30.121082.14513.0**| ##### What's new - Beginning with this version, we're bringing Microsoft Defender for Endpoint support to the following distros:- - RHEL6.7-6.10 and CentOS6.7-6.10 versions. - Amazon Linux 2 - Fedora 33 or higher- - Bug fixes #### Build: 101.45.00 | Release version: 30.121072.14500.0-| Build: | **101.45.00** |-|--------------------|-----------------------|-| Release version: | **30.121072.14500.0** |+|Build:|**101.45.00**|+|---|---|+|Release version:|**30.121072.14500.0**| ##### What's new@@ -2693,9 +2723,9 @@ As an alternative approach, follow the instructions to [uninstall](./linux-off-b #### Build: 101.39.98 | Release version: 30.121062.13998.0-| Build: | **101.39.98** |-|--------------------|-----------------------|-| Release version: | **30.121062.13998.0** |+|Build:|**101.39.98**|+|---|---|+|Release version:|**30.121062.13998.0**| ##### What's new@@ -2703,9 +2733,9 @@ As an alternative approach, follow the instructions to [uninstall](./linux-off-b #### Build: 101.34.27 | Release version: 30.121052.13427.0-| Build: | **101.34.27** |-|--------------------|-----------------------|-| Release version: | **30.121052.13427.0** |+|Build:|**101.34.27**|+|---|---|+|Release version:|**30.121052.13427.0**| ##### What's new@@ -2713,9 +2743,9 @@ As an alternative approach, follow the instructions to [uninstall](./linux-off-b #### Build: 101.29.64 | Release version: 30.121042.12964.0-| Build: | **101.29.64** |-|--------------------|-----------------------|-| Release version: | **30.121042.12964.0** |+|Build:|**101.29.64**|+|---|---|+|Release version:|**30.121042.12964.0**| ##### What's new@@ -2727,21 +2757,21 @@ As an alternative approach, follow the instructions to [uninstall](./linux-off-b #### Build: 101.25.72 | Release version: 30.121022.12563.0-| Build: | **101.25.72** |-|--------------------|-----------------------|-| Release version: | **30.121022.12563.0** |+|Build:|**101.25.72**|+|---|---|+|Release version:|**30.121022.12563.0**| ##### What's new - Microsoft Defender for Endpoint on Linux is now available in preview for US Government customers. For more information, see [Microsoft Defender for Endpoint for US Government customers](gov.md). - Fixed an issue where usage of Microsoft Defender for Endpoint on Linux on systems with FUSE filesystems was leading to OS hang - Performance improvements & other bug fixes- + #### Build: 101.25.63 | Release version: 30.121022.12563.0-| Build: | **101.25.63** |-|--------------------|-----------------------|-| Release version: | **30.121022.12563.0** |+|Build:|**101.25.63**|+|---|---|+|Release version:|**30.121022.12563.0**| ##### What's new@@ -2749,9 +2779,9 @@ As an alternative approach, follow the instructions to [uninstall](./linux-off-b #### Build: 101.23.64 | Release version: 30.121021.12364.0-| Build: | **101.23.64** |-|--------------------|-----------------------|-| Release version: | **30.121021.12364.0** |+|Build:|**101.23.64**|+|---|---|+|Release version:|**30.121021.12364.0**| ##### What's new@@ -2764,7 +2794,6 @@ As an alternative approach, follow the instructions to [uninstall](./linux-off-b ##### What's new - EDR for Linux is now [generally available](https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/edr-for-linux-is-now-is-generally-available/ba-p/2048539)- - Added a new command-line switch (`--ignore-exclusions`) to ignore AV exclusions during custom scans (`mdatp scan custom`) - Extended `mdatp diagnostic create` with a new parameter (`--path [directory]`) that allows the diagnostic logs to be saved to a different directory - Performance improvements & bug fixes@@ -2822,4 +2851,4 @@ As an alternative approach, follow the instructions to [uninstall](./linux-off-b ### 1.1.15010101 - With this version, we're announcing support for iPadOS/iPad devices.-- Bug fixes.\ No newline at end of file+- Bug fixes.