Microsoft Defender for Endpoint
Endpoint protection

Release Notes Mde Archive

In brief

The archive metadata date was updated to August 25, 2026. Release tables were reformatted, KB5005292 links were updated, and the “What’s new” heading was adjusted.

What Defender admins need to know

Administrators consulting the archive will find updated KB links and presentation; no action is specified.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

ms.author: lwainstein author: limwainstein ms.localizationpriority: medium ms.date: 02/18/08/25/2026 ai-usage: ai-assisted ms.collection:

  • m365-security

May-2024 (Release version: 10.8750.27558.1004)

OS KB Release version
Windows Server 2012 R2, 2016 KB5005292KB5005292 10.8750.27558.1004

What's new

Configuration Management
  • Fixed an issue that caused empty policies to appear in the UI.
  • Configured Windows Defender Application Control (WDAC) policies to block undesired applications from running on the device.

Feb-2024 (Release version: 10.8735.26020.1009)

OS KB Release version
Windows Server 2012 R2, 2016 KB5005292KB5005292 10.8735.26020.1009

What's new

  • Enabled support for IPV6 connections in Live Response connection commands.
  • Fixed an issue in Downlevel Unified Agent that caused ServerRoles not to be populated.
Threat Vulnerability Management
  • An issue related to the agent's monitoring of deleted registry keys no longer occurs.

  • Introduced performance enhancements to minimize the CPU and memory footprint of the agent.

  • Enhanced the accuracy of network detections.

Data Loss Prevention (DLP)
  • Introduced multiple performance and stability fixes.
Security Configuration Management
  • Policies that include special characters are now supported.

Dec-2023 (Release version: 10.8672.25926.1019)

OS KB Release version
Windows Server 2012 R2, 2016 KB5005292KB5005292 10.8672.25926.1019

What's new

Sept-2023 (Release version: 10.8560.25364.1036)

OS KB Release version
Windows Server 2012 R2, 2016 KB5005292KB5005292 10.8560.25364.1036

What's new

May-2023 (Release version: 10.8295.22621.1023)

OS KB Release version
Windows Server 2012 R2, 2016 KB5005292KB5005292 10.8295.22621.1023

What's new

Jan/Feb-2023 (Release version: 10.8295.22621.1019)

OS KB Release version
Windows Server 2012 R2, 2016 KB5005292KB5005292 10.8295.22621.1019

What's new

Dec-2022 (Release version: 10.8210.22621.1016)

OS KB Release version
Windows Server 2012 R2, 2016 KB5005292KB5005292 10.8210.22621.1016

What's new

  • Bug fixes and stability improvements

Aug-2022 (Release version: 10.8210.*)

OS KB Release version
Windows Server 2012 R2, 2016 KB5005292KB5005292 10.8210.22621.1011
Windows 11 21H2 (Cobalt)
(Windows 11 SV 21H2)
KB5016691KB5016691 10.8210.22000.918
Server 2022 (Iron) KB5016693KB5016693 10.8210.20348.946
Windows 10 20H2/21H1/21H2
Windows Server 20H2 (Vibranium)
KB5016688KB5016688 10.8210.19041.1949
Windows Server 2019 (RS5) KB5016690KB5016690 10.8210.17763.3346

What's new

  • Live Response improvements include reduced session creation latency when using proxies, an undo remediation manual command, support for OneDrive shares in FindFile action, and improved isolation and stability.
  • Security Management for Microsoft Defender for Endpoint now provides the ability to sync the device configuration on demand instead of waiting for a specific cadence.

macOS releases

Release details

Release version Engine version Signature version
20.125062.6.0 1.1.25070.3000 1.435.357.0

Enhancements and features

Feature area Update summary
General Bug and performance fixes.

Jul-2025 (Build: 101.25062.0005 | Release version: 20.125062.5.0)

Build: 101.25062.0005
Release version: 20.125062.5.0
Engine version: 1.1.25040.3000
Signature version: 1.427.248.0

What's new

  • Bug and performance fixes

Jun-2025 (Build: 101.25052.0012 | Release version: 20.125052.12.0)

Build: 101.25052.0012
Release version: 20.125052.12.0
Engine version: 1.1.25060.3000
Signature version: 1.431.226.0

What's new

  • Bug and performance fixes

May-2025 (Build: 101.25042.0009 | Release version: 20.125042.9.0)

Build: 101.25042.0009
Release version: 20.125042.9.0
Engine version: 1.1.25040.3000
Signature version: 1.429.521.0

What's new

  • mdatp health --details edr now includes Azure Active Directory information
  • Bug and performance fixes

Apr-2025 (Build: 101.25032.0006 | Release version: 20.125032.6.0)

Build: 101.25032.0006
Release version: 20.125032.6.0
Engine version: 1.1.25020.3000
Signature version: 1.427.158.0

What's new

Mar-2025 (Build: 101.25022.0003 | Release version: 20.125022.3.0)

Build: 101.25022.0003
Release version: 20.125022.3.0
Engine version: 1.1.24090.12
Signature version: 1.423.249.0

What's new

  • Bug and performance fixes

Mar-2025 (Build: 101.25012.0008 | Release version: 20.125012.7.0)

Build: 101.25012.0008
Release version: 20.125012.7.0
Engine version: 1.1.25020.3000
Signature version: 1.423.211.0

What's new

  • Bug fixes and performance improvements

Feb-2025 (Build: 101.24122.0011 | Release version: 20.124122.11.0)

Build: 101.24122.0011
Release version: 20.124122.11.0
Engine version: 1.1.24080.11
Signature version: 1.419.351.0

What's new

  • Fixed an issue with the auth prompt during new installation on macOS with multiple active users
  • Improved stability when using the antivirus engine in passive mode

Jan-2025 (Build: 101.24122.0005 | Release version: 20.124122.5.0)

Build: 101.24122.0005
Release version: 20.124122.4.0
Engine version: 1.1.24080.11
Signature version: 1.419.351.0

What's new

  • Removed support of macOS 12, the minimal requirement is now macOS 13.0 or later
  • Fix: Defender quarantines a file even if it's marked as immutable
  • mdatp health can return out_of_date status for definitions_status
  • Bug and performance fixes

Dec-2024 (Build: 101.24102.0018 | Release version: 20.124102.18.0)

Build: 101.24102.0018
Release version: 20.124102.18.0
Engine version: 1.1.24080.10
Signature version: 1.419.298.0

What's new

  • Improved User/Group Permission Handling - Added reporting in mdatp-health for user/group permission issues for Defender files. On restart Defender attempts to cure these issues.
  • Bug and performance fixes.

Oct-2024 (Build: 101.24092.0004 | Release version: 20.124092.4.0)

Build: 101.24092.0004
Release version: 20.124092.4.0
Engine version: 1.1.24080.11
Signature version: 1.421.14.0

What's new

  • Bug and performance fixes

Oct-2024 (Build: 101.24082.0009 | Release version: 20.124082.9.0)

Build: 101.24082.0009
Release version: 20.124082.9.0
Engine version: 1.1.24080.9
Signature version: 1.411.410.0

What's new

  • Product improvements and performance fixes

Sep-2024 (Build: 101.24072.0007 | Release version: 20.124072.7)

Build: 101.24072.0007
Release version: 20.124072.7
Engine version: 1.1.24080.9
Signature version: 1.411.410.0

What's new

  • Resolved the issue causing outdated vulnerability assessments impacting some macOS devices

Aug-2024 (Build: 101.24072.0006 | Release version: 20.124072.6.0)

Build: 101.24072.0006
Release version: 20.124072.6.0
Engine version: 1.1.24060.7
Signature version: 1.417.325.0

What's new

  • Product improvements and performance fixes

Jul-2024 (Build: 101.24062.0009 | Release version: 20.124062.9.0)

Build: 101.24062.0009
Release version: 20.124062.9.0
Engine version: 1.1.24050.7
Signature version: 1.411.410.0

What's new

  • Product improvements and performance fixes

Jun-2024 (Build: 101.24052.0013 | Release version: 20.124052.13.0)

Build: 101.24052.0013
Release version: 20.124052.13.0
Engine version: 1.1.24040.2
Signature version: 1.411.153.0

What's new

  • [device control] Secure Digital cards aren't recognized on newer macOS
  • Product improvements and performance fixes

May-2024 (Build: 101.24042.0008 | Release version: 20.124042.8.0)

Build: 101.24042.0008
Release version: 20.124042.8.0
Engine version: 1.1.24040.1
Signature version: 1.413.13.0

What's new

  • Product improvements and performance fixes

Apr-2024 (Build: 101.24032.0006 | Release version: 20.124032.06.0)

Build: 101.24032.0006
Release version: 20.124012.10.0
Engine version: 1.1.24030.4
Signature version: 1.407.521.0

What's new

  • Remove Big Sur from supported versions of macOS
  • [device control] Fix Bluetooth support on Sonoma (see the note later in this section)
  • Product improvements and performance fixes
  • (GA) Troubleshooting mode for macOS. Troubleshooting mode helps you identify instances where antivirus might be causing issues with your applications or system resources. To learn more, see Troubleshooting mode in Microsoft Defender for Endpoint on macOS.

Mar-2024 (Build: 101.24012.0010 | Release version: 20.124012.10.0)

Build: 101.24012.0010
Release version: 20.124012.10.0
Engine version: 1.1.24020.3
Signature version: 1.405.788.0

What's new

Jan-2024 (Build: 101.23122.0005 | Release version: 20.123122.5.0)

Build: 101.23122.0005
Release version: 20.123122.5.0
Engine version: 1.1.23100.2010
Signature version: 1.403.3022.0

What's new

Dec-2023 (Build: 101.23102.0020 | Release version: 20.123102.20.0)

Build: 101.23102.0020
Release version: 20.123102.20.0
Engine version: 1.1.23090.2005
Signature version: 1.401.1729.0

What's new

Nov-2023 (Build: 101.23092.0007 | Release version: 20.123092.7.0)

Build: 101.23092.0007
Release version: 20.123092.7.0
Engine version: 1.1.23090.2005
Signature version: 1.399.1196.0

What's new

Device Control v1 will be considered deprecated in the nearest future. To check, run the [mdatp health --details device_control](mac-device-control-overview.md#status) command, and inspect the active property. It shouldn't contain "v1".

Oct-2023 (Build: 101.23082.0018 | Release version: 20.123082.18.0)

Build: 101.23082.0018
Release version: 20.123082.18.0
Engine version: 1.1.23070.1002
Signature version: 1.399.384.0

What's new

Sep-2023 (Build: 101.23072.0025 | Release version: 20.123072.25.0)

Build: 101.23072.0025
Release version: 20.123072.25.0
Engine version: 1.1.23050.3
Signature version: 1.397.911.0

What's new

  • Fix: Major performance issues on macOS when Network Protection is set to Audit mode
  • (GA) macOS devices receive built-in protection. Tamper protection is turned on in block mode by default. This setting helps secure your Mac against threats. To learn more, see Protect macOS security settings with tamper protection.

Aug-2023 (Build: 101.23062.0016 | Release version: 20.123062.16.0)

Build: 101.23062.0016
Release version: 20.123062.16.0
Engine version: 1.1.23050.3
Signature version: 1.395.436.0

What's new

  • Product improvements and performance fixes
  • Fix: macOS complains that uninstall background task is from unidentified developer

Jul-2023 (Build: 101.23052.0004 | Release version: 20.123052.4.0)

Build: 101.23052.0004
Release version: 20.123052.4.0
Engine version: 1.1.20100.7
Signature version: 1.391.2163.0

What's new

  • Fix: Defender doesn't start on a machine with certain versions of Microsoft Edge due to directory permission issue
  • Product improvements and performance fixes

Jun-2023 (Build: 101.98.84 | Release version: 20.123042.19884.0)

Build: 101.98.84
Release version: 20.123042.19884.0
Engine version: 1.1.20300.4
Signature version: 1.391.221.0

What's new

Network protection for macOS is now available for all Mac devices onboarded to Defender for Endpoint. Devices must meet the minimum requirements. To learn more, see Use network protection to help prevent macOS connections to bad sites.

May-2023 (Build: 101.98.71 | Release version: 20.123032.19871.0)

Build: 101.98.71
Release version: 20.123032.19871.0
Engine version: 1.1.20300.4
Signature version: 1.389.1872.0

What's new

  • Fix: Remove Codesigned Artifact from App Bundle
  • Product improvements and performance fixes

May-2023 (Build: 101.98.70 | Release version: 20.123022.19870.0)

Build: 101.98.70
Release version: 20.123022.19870.0
Engine version: 1.1.20300.4
Signature version: 1.389.1396.0

What's new

  • Product improvements and performance fixes

Mar-2023 (Build: 101.98.30 | Release version: 20.123012.19830.0)

Build: 101.98.30
Release version: 20.123012.19830.0
Engine version: 1.1.20100.6
Signature version: 1.385.924.0

What's new

  • Product improvements and performance fixes

Feb-2023 (Build: 101.97.94 | Release version: 20.123011.19794.0)

Build: 101.97.94
Release version: 20.123011.19794.0
Engine version: 1.1.20000.2
Signature version: 1.383.104.0

What's new

  • (GA) Live Response available for macOS

Live Response for macOS is now available for all Mac devices onboarded to Defender for Endpoint. Devices must meet the minimum requirements. To learn more, see Investigate entities on devices using live response

Nov-2022 (Build: 101.87.30 | Release version: 20.122082.18681.0)

Build:101.87.30
Released:Nov 5, 2022
Published:Nov 5, 2022
 Build:
101.87.30
Release version:20.122082.18681.0
Engine version:1.1.19700.3
Signature version:1.379.17.0

What's new

  • Fix for some users experiencing performance issues and temporary system hangs
  • Product improvements and performance fixes

Oct-2022 (Build: 101.86.81 | Release version: 20.122082.18681.0)

Build:101.86.81
Released:Oct 25, 2022
Published:Oct 25, 2022
 Build:
101.86.81
Release version:20.122082.18681.0
Engine version:1.1.19700.3
Signature version:1.377.636.0

What's new

  • Issue resolution: Upgrade fails if \_mdatp user is a member of \_lpadmin group

Oct-2022 (Build: 101.82.21 | Release version: 20.122082.18221.0)

Build: 101.82.21
Release version: 20.122082.18221.0
Engine version: 1.1.19400.3
Signature version: 1.369.962.0

What's new

  • Fix - macOS TP in Block mode causing device hang on shutdown/crashes on reboot
  • Add a mdatp command-line switch to view the on-demand scan history

Sep-2022 (Build: 101.78.13)

Build: 101.78.13
Release version: 20.122072.17813.0
Engine version: 1.1.19500.2
Signature version: 1.373.556.0

What's new

  • Fix for uninstaller to properly delete Application Support folder
  • Fix for Network Protection not filtering Safari when Firewall or iCloud Private Relay is on

Aug-2022 (Build: 101.75.90 | Release version: 20.122071.17590.0)

Build: 101.75.90
Released: Aug 3, 2022
Published: Aug 3, 2022
Release version: 20.122071.17590.0
Engine version: 1.1.19300.3
Signature version: 1.369.395.0

What's new

  • Added a new field in the output of mdatp health that can be used to query the enforcement level of the network protection feature. The new field is called network_protection_enforcement_level and can take one of the following values: audit, block, or disabled.
  • Addressed a product issue where multiple detections of the same content could lead to duplicate entries in the threat history.

Jul-2022 (Build: 101.73.77 | Release version: 20.122062.17377.0)

Build: 101.73.77
Released: Jul 21, 2022
Published: Jul 21, 2022
Release version: 20.122062.17377.0
Engine version: 1.1.19200.3
Signature version: 1.367.1011.0

What's new

Jul-2022 (Build: 101.71.18 | Release version: 20.122052.17118.0)

Build:101.71.18
Released:Jul 7, 2022
Published:Jul 7, 2022
 Build:
101.71.18
Release version:20.122052.17118.0

What's new

  • mdatp connectivity test added an extra URL. The new URL is https://go.microsoft.com/fwlink/?linkid=2144709.
  • Up until now, the product log level didn't persist between product restarts. Beginning in this version, there's a new command-line tool switch that persists the log level. The new command is mdatp log level persist --level <level>.

Jun-2022 (Build: 101.70.19 | Release version: 20.122051.17019.0)

Build:101.70.19
Released:Jun 14, 2022
Published:Jun 14, 2022
 Build:
101.70.19
Release version:20.122051.17019.0

What's new

  • Resolved an issue where threat-related notifications weren't always presented to the end user.
  • Performance improvements & other updates.

Jun-2022 (Build: 101.70.18 | Release version: 20.122042.17018.0)

Build:101.70.18
Released:Jun 2, 2022
Published:Jun 2, 2022
 Build:
101.70.18
Release version:20.122042.17018.0

What's new

  • Resolved an issue where the installation package was sometimes hanging indefinitely during product updates
  • Resolved an issue where the product sometimes was incorrectly detecting files inside the quarantine folder

May-2022 (Build: 101.66.54 | Release version: 20.122041.16654.0)

Build:101.66.54
Released:May 11, 2022
Published:May 11, 2022
 Build:
101.66.54
Release version:20.122041.16654.0

What's new

  • Addressed an issue where mdatp diagnostic real-time-protection-statistics wasn't printing the correct process path in some cases.
  • Product improvements

Apr-2022 (Build: 101.64.15 | Release version: 20.122032.16415.0)

Build:101.64.15
Released:Apr 26, 2022
Published:Apr 26, 2022
 Build:
101.64.15
Release version:20.122032.16415.0

What's new

  • Fixed a regression introduced in version 101.61.69 where the status menu icon was sometimes showing an error icon, even though no action was required from the end user
  • Improved the conflicting_applications field in mdatp health to show only the most recent 10 processes and also to include the process names. This improvement makes it easier to identify which processes are potentially conflicting with Microsoft Defender for Endpoint for macOS.

Mar-2022 (Build: 101.61.69 | Release version: 20.122022.16169.0)

Build:101.61.69
Released:Mar 25, 2022
Published:Mar 25, 2022
 Build:
101.61.69
Release version:20.122022.16169.0

What's new

  • Product improvements

Mar-2022 (Build: 101.60.91 | Release version: 20.122021.16091.0)

Build:101.60.91
Released:Mar 8, 2022
Published:Mar 8, 2022
 Build:
101.60.91
Release version:20.122021.16091.0

What's new

Feb-2022 (Build: 101.59.50 | Release version: 20.122021.15950.0)

Build:101.59.50
Released:Feb 28, 2022
Published:Feb 28, 2022
 Build:
101.59.50
Release version:20.122021.15950.0

What's new

  • This version adds support for macOS 12.3. Starting with macOS 12.3, Apple is removing Python 2.7. There's no Python version preinstalled on macOS by default. ACTION NEEDED:
    • Users must update Microsoft Defender for Endpoint for Mac to version 101.59.50 (or newer) before updating their devices to macOS Monterey 12.3 (or newer). This minimal version 101.59.50 is a prerequisite to eliminating Python-related issues with Microsoft Defender for Endpoint for macOS devices on macOS Monterey.

Feb-2022 (Build: 101.59.10 | Release version: 20.122012.15910.0)

Build:101.59.10
Released:Feb 22, 2022
Published:Feb 22, 2022
 Build:
101.59.10
Release version:20.122012.15910.0

What's new

  • The command-line tool now supports restoring quarantined files to a location other than the one where the file was originally detected. Restoration can be done through mdatp threat quarantine restore --id [threat-id] --path [destination-folder].
  • Extended device control to handle devices connected over Thunderbolt 3

Feb-2022 (Build: 101.56.62 | Release version: 20.121122.15662.0)

Build:101.56.62
Released:Feb 7, 2022
Published:Feb 7, 2022
 Build:
101.56.62
Release version:20.121122.15662.0

What's new

  • Product improvements

Jan-2022 (Build: 101.56.35 | Release version: 20.121121.15635.0)

Build:101.56.35
Released:Jan 30, 2022
Published:Jan 30, 2022
 Build:
101.56.35
Release version:20.121121.15635.0

What's new

  • The application is renamed from Microsoft Defender ATP to Microsoft Defender. End users observe the following changes:
    • The application installation path changed from /Application/Microsoft Defender ATP.app to /Applications/Microsoft Defender.app.
    • Within the user experience, occurrences of Microsoft Defender ATP are replaced by Microsoft Defender
  • Resolved an issue where some VPN applications couldn't connect due to the network content filter that is distributed with Microsoft Defender for Endpoint for macOS.
  • Addressed an issue discovered in macOS 12.2 preview 2 where the installation package couldn't be opened due to a change in the operating system (OS) that prevents installation of packages with certain characteristics. While it appears that this OS change isn't included in the final release of macOS 12.2, it's likely that it will be reintroduced in a future macOS version. As such, we encourage all enterprise administrators to refresh the Microsoft Defender for Endpoint package in their management console to this product version (or a newer version).
  • Addressed an issue seen on some M1 devices where the product was stuck with invalid anti-malware definitions and couldn't successfully update to a working set of definitions.

Jan-2022 (Build: 101.54.16 | Release version: 20.121111.15416.0)

Build:101.54.16
Released:Jan 12, 2022
Published:Jan 12, 2022
 Build:
101.54.16
Release version:20.121111.15416.0

What's new

  • macOS 10.14 (Mojave) is no longer supported
  • After a product setting stops being managed by the administrator through MDM, it now reverts to the value it had before it was managed (the value configured locally by the end user or, if no such local value was explicitly provided, the default value used by the product). Prior to this change, after a setting stopped being managed, its managed value persisted and was still used by the product.

Nov-2021 (Build: 101.49.25)

Build:101.49.25
Release version:20.121092.14925.0

What's new

  • Added a new switch to the command-line tool to control whether archives are scanned during on-demand scans. This can be configured through mdatp config scan-archives --value [enabled/disabled]. By default, this is set to enabled.
  • Product improvements

Oct-2021 (Build: 101.47.27)

Build:101.47.27
Release version:20.121082.14727.0

What's new

  • Fix for a system freeze occurring on shutdown on macOS Mojave and macOS Catalina.

Oct-2021 (Build: 101.43.84)

Build:101.43.84
Release version:20.121082.14384.0

What's new

  • Candidate build for macOS 12 (Monterey)
  • Product improvements

Sep-2021 (Build: 101.41.10)

Build:101.41.10
Release version:20.121072.14110.0

What's new

  • Added new switches to the command-line tool:
    • Control degree of parallelism for on-demand scans. This can be configured through mdatp config maximum-on-demand-scan-threads --value [number-between-1-and-64]. By default, a degree of parallelism of 2 is used.

Aug-2021 (Build: 101.40.84)

Build:101.40.84
Release version:20.121071.14084.0

What's new

  • M1 chip native support
  • Performance improvements & Product improvements

Jul-2021 (Build: 101.37.97)

Build:101.37.97
Release version:20.121062.13797.0

What's new

  • Performance improvements & Product improvements

Jun-2021 (Build: 101.34.28)

Build:101.34.28
Release version:20.121061.13428.0

What's new

  • Product improvements

Jun-2021 (Build: 101.34.27)

Build:101.34.27
Release version:20.121052.13427.0

What's new

  • Product improvements

May-2021 (Build: 101.34.20)

Build:101.34.20
Release version:20.121051.13420.0

What's new

  • Device control for macOS is now in general availability.
  • Addressed an issue where a quick scan couldn't be started from the status menu on macOS 11 (Big Sur).

Apr-2021 (Build: 101.32.69)

Build:101.32.69
Release version:20.121042.13269.0

What's new

  • Addressed an issue where concurrent access to the keychain from Microsoft Defender for Endpoint and other applications can lead to keychain corruption.

Mar-2021 (Build: 101.29.64)

Build:101.29.64
Release version:20.121042.12964.0

What's new

  • Starting with this version, threats detected during on-demand antivirus scans triggered through the command-line client are automatically remediated. Threats detected during scans triggered through the user interface still require manual action.
  • mdatp diagnostic real-time-protection-statistics now supports two other switches:

Feb-2021 (Build: 101.27.50)

Build:101.27.50
Release version:20.121022.12750.0

What's new

  • Fix to accommodate for Apple certificate expiration for macOS Catalina and earlier. This fix restores Microsoft Defender Vulnerability Management (MDVM) functionality.

Feb-2021 (Build: 101.25.69)

Build:101.25.69
Release version:20.121022.12569.0

What's new

  • Microsoft Defender for Endpoint on macOS is now available in preview for US Government customers. For more information, see Microsoft Defender for Endpoint for US Government customers.
  • Performance improvements (specifically for the situation when the XCode Simulator app is used) & Product improvements.

Jan-2021 (Build: 101.23.64)

Build:101.23.64
Release version:20.121021.12364.0

What's new

  • Added a new option to the command-line tool to view information about the last on-demand scan. To view information about the last on-demand scan, run mdatp health --details antivirus.
  • Performance improvements & Product improvements

Dec-2020 (Build: 101.22.79)

Build:101.22.79
Release version:20.121012.12279.0

What's new

  • Performance improvements & Product improvements

Nov-2020 (Build: 101.19.88)

Build:101.19.88
Release version:20.121011.11988.0

What's new

  • Performance improvements & Product improvements

Nov-2020 (Build: 101.19.48)

Build:101.19.48
Release version:20.120121.11948.0

What's new

  • Added a new command-line switch to disable the network extension: mdatp system-extension network-filter disable. This command can be useful to troubleshoot networking issues that could be related to Microsoft Defender for Endpoint on Mac.
  • Performance improvements & Product improvements

Oct-2020 (Build: 101.19.21)

Build:101.19.21
Release version:20.120101.11921.0

What's new

  • Product improvements

Oct-2020 (Build: 101.15.26)

Build:101.15.26
Release version:20.120102.11526.0

What's new

  • Improved the reliability of the agent when running on macOS 11 Big Sur.
  • Added a new command-line switch (--ignore-exclusions) to ignore AV exclusions during custom scans (mdatp scan custom).

Sep-2020 (Build: 101.13.75)

Build:101.13.75
Release version:20.120101.11375.0

What's new

  • Removed conditions when Microsoft Defender for Endpoint was triggering a macOS 11 (Big Sur) issue that manifests into a kernel panic.
  • Fixed a memory leak in the Endpoint Security system extension when running on macOS 11 (Big Sur).
  • Product improvements

Aug-2020 (Build: 101.10.72)

Build:101.10.72

What's new

  • Product improvements

Jul-2020 (Build: 101.09.61)

Build:101.09.61

What's new

  • Added a new managed preference for disabling the option to send feedback.
  • Status menu icon now shows a healthy state when the product settings are managed. Previously, the status menu icon was displaying a warning or error state, even though the product settings were managed by the administrator.

Jul-2020 (Build: 101.09.50)

Build:101.09.50

What's new

  • Extended mdatp diagnostic create with a new parameter (--path [directory]) that allows the diagnostic logs to be saved to a different directory.
  • Performance improvements & Product improvements

Jul-2020 (Build: 101.09.49)

Build: 101.09.49

What's new

  • User interface improvements to differentiate exclusions that are managed by the IT administrator versus exclusions defined by the local user.
  • Improved CPU utilization during on-demand scans.

Jun-2020 (Build: 101.07.23)

Build: 101.07.23

What's new

  • Added new fields to the output of mdatp --health for checking the status of passive mode and the EDR group ID.

May-2020 (Build: 101.06.63)

Build: 101.06.63

What's new

  • Addressed a performance regression introduced in version 101.05.17. The regression was introduced with the fix to eliminate the kernel panics some customers observed when accessing SMB shares. We reverted this code change and are investigating alternative ways to eliminate the kernel panics.

May-2020 (Build: 101.05.17)

Build: 101.05.17

What's new

  • Addressed a kernel panic that occurred sometimes when accessing SMB file shares.
  • Performance improvements & Product improvements

Apr-2020 (Build: 101.05.16)

Build: 101.05.16

What's new

  • Improvements to quick scan logic to significantly reduce the number of scanned files.
  • Added autocompletion support for the command-line tool.

Mar-2020 (Build: 101.03.12)

Build:101.03.12

What's new

  • Performance improvements & Product improvements

Feb-2020 (Build: 101.01.54)

Build:101.01.54

What's new

  • Improvements around compatibility with Time Machine
  • Accessibility improvements

Jan-2020 (Build: 101.00.31)

Build:101.00.31

What's new

2019 releases (Build: 100.90.27)

Build:100.90.27

What's new

  • You can now set an update channel for Microsoft Defender for Endpoint on macOS that is different from the system-wide update channel.
  • New product icon

2019 releases (Build: 100.86.92)

Build:100.86.92

What's new

  • Improvements around compatibility with Time Machine
  • Addressed an issue where the product was sometimes not cleaning all files under /Library/Application Support/Microsoft/Defender during uninstallation.

2019 releases (Build: 100.86.91)

Build:100.86.91

What's new

2019 releases (Build: 100.83.73)

Build: 100.83.73

What's new

2019 releases (Build: 100.82.60)

Build:100.82.60

What's new

  • Addressed an issue where the product fails to start following a definition update.

2019 releases (Build: 100.80.42)

Build:100.80.42

What's new

  • Product improvements

2019 releases (Build: 100.79.42)

Build:100.79.42

What's new

  • Fixed an issue where Microsoft Defender for Endpoint on macOS was sometimes interfering with Time Machine.
  • Added a new switch to the command-line utility for testing the connectivity with the backend service

2019 releases (Build: 100.72.15)

Build:100.72.15

What's new

  • Product improvements

2019 releases (Build: 100.70.99)

Build:100.70.99

What's new

  • Addressed an issue that impacts the ability of some users to upgrade to macOS Catalina when real-time protection is enabled. This sporadic issue was caused by Microsoft Defender for Endpoint locking files within Catalina upgrade package while scanning them for threats, which led to failures in the upgrade sequence.

2019 releases (Build: 100.68.99)

Build:100.68.99

What's new

  • Added the ability to configure the antivirus functionality to run in passive mode.
  • Performance improvements & Product improvements

2019 releases (Build: 100.65.28)

Build:100.65.28

What's new

  • Added support for macOS Catalina.

July-2025 Build: 101.25052.0007 | Release version: 30.125052.0007.0

Build: 101.25052.0007
Released: July 22, 2025
Published: July 22, 2025
Release version: 30.125052.0007.0
Engine version: 1.1.25020.4000
Signature version: 1.427.370.0

What's new

  • Fixed issue to generate unique Machine identifiers to ensure each onboarded device is uniquely identified.
  • Other stability improvements and bug fixes.

June-2025 Build: 101.25042.0003 | Release version: 30.125042.0003.0

Build: 101.25042.0003
Released: June 30, 2025
Published: June 30, 2025
Release version: 30.125042.0003.0
Engine version: 1.1.25020.4000
Signature version: 1.427.370.0

What's new

  • The Defender for Endpoint package rollout into production happens gradually. From the time the release notes are published, it might take up to a week for the package to be pushed to all production machines.
  • Removed external dependency of uuid-runtime from the Defender for Endpoint package
  • Other stability improvements and bug fixes

May-2025 Build: 101.25032.0010 | Release version: 30.125032.0010.0

Build: 101.25032.0010
Released: May 23, 2025
Published: May 23, 2025
Release version: 30.125032.0010.0
Engine version: 1.1.25020.4000
Signature version: 1.427.370.0

What's new

  • Removed external dependency of MDE Netfilter and libpcre from MDE package

  • Fix for Python script executing unverified binaries with root-level privileges to identify Java processes using outdated versions of log4j (CVE-2025-26684) has been addressed.

  • Added detection mechanism for CVE-2025-31324 affecting the "Visual Composer" component of the SAP NetWeaver application server.

April-2025 Build: 101.25022.0002 | Release version: 30.125022.0001.0

Build: 101.25022.0002
Released: April 07, 2025
Published: April 07, 2025
Release version: 30.125022.0001.0
Engine version: 1.1.24090.13
Signature version: 1.421.226.0

What's new

  • mdatp diagnostic ebpf-statistics command requires sudo privilege now

  • Manage dynamic signature file share source by setting URL and update interval

  • Other stability improvements and bug fixes

  • Support for ARM64 Linux servers

Mar-2025 Build: 101.25012.0000 | Release version: 30.125012.0000.0

Build: 101.25012.0000
Released: March 11, 2025
Published: March 11, 2025
Release version: 30.125012.0000.0
Engine version: 1.1.24090.13
Signature version: 1.421.226.0

What's new

  • The MDATP package rollout into production will be done gradually. From the time the release notes are published, it might take up to a week for the package to be pushed to all production machines.

  • The vulnerability in curl, CVE-2024-7264, has been addressed.

  • Other stability improvements and bug fixes.

Known Issues

  • There's a known issue where MDE is deleting the configuration file located at /etc/systemd/system/mdatp.service.d on each service start. As a workaround, customers can use the Immutable attribute that prevents the files from being modified or deleted.

    To set the file to be unmodifiable, execute the following command:

sudo chattr +i /etc/systemd/system/mdatp.service.d/[file name]

This command makes the file unchangeable. If you need to restore modification permissions, use the following command:

sudo chattr -i /etc/systemd/system/mdatp.service.d/[file name]

Note that the chattr command can only be used on supported file systems, such as ext4.

If you need further assistance, you can reach out to our support team with your organization ID, and we can implement a temporary mitigation to prevent deletion. A permanent fix for this issue is available in MDE version 101.25032.0000.

Feb-2025 Build: 101.24122.0008 | Release version: 30.124112.0008.0

Build: 101.24122.0008
Released: February 20, 2025
Published: February 20, 2025
Release version: 30.124122.0008.0
Engine version: 1.1.24090.13
Signature version: 1.421.226.0

What's new

Feb-2025 Build: 101.24112.0003 | Release version: 30.124112.0003.0

Build: 101.24112.0003
Released: February 04, 2025
Published: February 04, 2025
Release version: 30.124112.0003.0
Engine version: 1.1.24090.13
Signature version: 1.421.1681.0

What's new

Jan-2025 Build: 101.24112.0001 | Release version: 30.124112.0001.0

Build: 101.24112.0001
Released: January 13, 2025
Published: January 13, 2025
Release version: 30.124112.0001.0
Engine version: 1.1.24090.13
Signature version: 1.421.226.0

What's new

  • Upgraded the Bond version to 13.0.1 to address security vulnerabilities in versions 12 or lower.

  • Mdatp package no longer has a dependency on SELinux packages.

  • Users can now query the status of supplementary event provider eBPF using the threat hunting query in DeviceTvmInfoGathering. To learn more about this query check: Use eBPF-based sensor for Microsoft Defender for Endpoint on Linux. The result of this query can return the following two values as eBPF status:

    • Enabled: When eBPF is enabled as working as expected.
    • Disabled: When eBPF is disabled due to one of the following reasons:

Jan-2025 Build: 101.24102.0000 | Release version: 30.124102.0000.0

Build: 101.24102.0000
Released: January 8, 2025
Published: January 8, 2025
Release version: 30.124102.0000.0
Engine version: 1.1.24080.11
Signature version: 1.419.351.0

What's new

Nov-2024 Build: 101.24092.0002 | Release version: 30.124092.0002.0

Build: 101.24092.0002
Released: November 14, 2024
Published: November 14, 2024
Release version: 30.124092.0002.0
Engine version: 1.1.24080.9
Signature version: 1.417.659.0

What's new

Oct-2024 Build: 101.24082.0004 | Release version: 30.124082.0004.0

Build: 101.24082.0004
Released: October 15, 2024
Published: October 15, 2024
Release version: 30.124082.0004
Engine version: 1.1.24080.9
Signature version: 1.417.659.0

What's new

  • Starting with this version, Defender for Endpoint on Linux no longer supports AuditD as a supplementary event provider. For improved stability and performance, we have transitioned to eBPF. If you disable eBPF, or in the event eBPF isn't supported on any specific kernel, Defender for Endpoint on Linux automatically switches back to Net link as a fallback supplementary event provider. Net link provides reduced functionality and tracks only process-related events. In this case, all process operations continue to flow seamlessly, but you could miss specific file and socket-related events that eBPF would otherwise capture. For more information, see Use eBPF-based sensor for Microsoft Defender for Endpoint on Linux. If you have any concerns or need assistance during this transition, contact support.

  • Stability and performance improvements

  • Other bug fixes

Sept-2024 Build: 101.24072.0001 | Release version: 30.124072.0001.0

Build: 101.24072.0001
Released: September 23, 2024
Published: September 23, 2024
Release version: 30.124072.0001.0
Engine version: 1.1.24060.6
Signature version: 1.415.228.0

What's new

July-2024 Build: 101.24062.0001 | Release version: 30.124062.0001.0

Build: 101.24072.0001
Released: July 31, 2024
Published: July 31, 2024
Release version: 30.124062.0001.0
Engine version: 1.1.24050.7
Signature version: 1.411.410.0

What's new

There are multiple fixes and new changes in this release.

  • Fixes bug in which infected command-line threat information wasn't showing correctly in security portal.

  • Fixes a bug where disabling a preview feature required a Defender of Endpoint to disable it.

  • Global Exclusions feature using managed JSON is now in Public Preview. available in insiders slow from 101.23092.0012. For more information, see linux-exclusions.

  • Updated the Linux default engine version to 1.1.24050.7 and default signature version to 1.411.410.0.

  • Stability and performance improvements.

  • Other bug fixes.

June-2024 Build: 101.24052.0002 | Release version: 30.124052.0002.0

Build: 101.24052.0002
Released: June 24, 2024
Published: June 24, 2024
Release version: 30.124052.0002.0
Engine version: 1.1.24040.2
Signature version: 1.411.153.0

What's new

  • This release fixes a bug related to high memory usage eventually leading to high CPU due to eBPF memory leak in kernel space resulting in servers going into unusable states. This only affected the kernel versions 3.10x and <= 4.16x, majorly on RHEL/CentOS distros. Update to the latest MDE version to avoid any impact.

  • We have now simplified the output of mdatp health --detail features

  • Stability and performance improvements.

  • Other bug fixes.

May-2024 Build: 101.24042.0002 | Release version: 30.124042.0002.0

Build: 101.24042.0002
Released: May 29, 2024
Published: May 29, 2024
Release version: 30.124042.0002.0
Engine version: 1.1.24030.4
Signature version: 1.407.521.0

What's new

There are multiple fixes and new changes in this release:

  • In version 24032.0007, there was a known issue where the enrollment of devices to MDE Security Management failed when using the "Device Tagging" mechanism via the mdatp_managed.json file. This issue has been resolved in the current release.

  • Stability and performance improvements.

  • Other bug fixes.

May-2024 Build: 101.24032.0007 | Release version: 30.124032.0007.0

Build: 101.24032.0007
Released: May 15, 2024
Published: May 15, 2024
Release version: 30.124032.0007.0
Engine version: 1.1.24020.3
Signature version: 1.403.3500.0

What's new

There are multiple fixes and new changes in this release:

  • In passive and on-demand modes, antivirus engine remains in idle state and is used only during scheduled custom scans. Thus as part of performance improvements, we have made changes to keep the AV engine down in passive and on-demand mode except during scheduled custom scans. If the real time protection is enabled, antivirus engine will always be up and running. This has no impact on your server protection in any mode.

    To keep users informed of the state of antivirus engine, we have introduced a new field called "engine_load_status" as part of MDATP health. It indicates whether antivirus engine is currently running or not.

    Field name engine_load_status
    Possible values Engine not loaded (AV engine process is down), Engine load succeeded (AV engine process up and running)

    Healthy scenarios:

    • If RTP is enabled, engine_load_status should be "Engine load succeeded"
    • If MDE is in on-demand or passive mode, and custom scan isn't running then "engine_load_status" should be "Engine not loaded"
    • If MDE is in on-demand or passive mode, and custom scan is running then "engine_load_status" should be "Engine load succeeded"
  • Bug fix to enhance behavioral detections.

  • Stability and performance improvements.

  • Other bug fixes.

Known Issues

sudo mdatp edr tag set --name GROUP --value MDE-Management
**

The issue has been fixed in Build: 101.24042.0002**

0002

March-2024 Build: 101.24022.0001 | Release version: 30.124022.0001.0

Build: 101.24022.0001
Released: March 22,2024
Published: March 22,2024
Release version: 30.124022.0001.0
Engine version: 1.1.23110.4
Signature version: 1.403.87.0

What's new

There are multiple fixes and new changes in this release:

  • The addition of a new log file - microsoft_defender_scan_skip.log. This logs the filenames that were skipped from various antivirus scans by Microsoft Defender for Endpoint due to any reason.

  • Stability and performance improvements.

  • Bug fixes.

March-2024 Build: 101.24012.0001 | Release version: 30.124012.0001.0

Build: 101.24012.0001
Released: March 12,2024
Published: March 12,2024
Release version: 30.124012.0001.0
Engine version: 1.1.23110.4
Signature version: 1.403.87.0

What's new

There are multiple fixes and new changes in this release:

  • Updated default engine version to 1.1.23110.4, and default signatures version to 1.403.87.0.

  • Stability and performance improvements.

  • Bug fixes.

February-2024 Build: 101.23122.0002 | Release version: 30.123122.0002.0

Build: 101.23122.0002
Released: February 5,2024
Published: February 5,2024
Release version: 30.123122.0002.0
Engine version: 1.1.23100.2010
Signature version: 1.399.1389.0

What's new

There are multiple fixes and new changes in this release:

If you already have Defender for Endpoint running on any of these distros and facing any issues in the older versions, upgrade to the latest Defender for Endpoint version from the corresponding ring mentioned above.

January-2024 Build: 101.23112.0009 | Release version: 30.123112.0009.0

Build: 101.23112.0009
Released: January 29,2024
Published: January 29,2024
Release version: 30.123112.0009.0
Engine version: 1.1.23100.2010
Signature version: 1.399.1389.0

What's new

November-2023 Build: 101.23102.0003 | Release version: 30.123102.0003.0

Build: 101.23102.0003
Released: November 28,2023
Published: November 28,2023
Release version: 30.123102.0003.0
Engine version: 1.1.23090.2008
Signature version: 1.399.690.0

What's new

November-2023 Build: 101.23092.0012 | Release version: 30.123092.0012.0

Build: 101.23092.0012
Released: November 14,2023
Published: November 14,2023
Release version: 30.123092.0012.0
Engine version: 1.1.23080.2007
Signature version: 1.395.1560.0

What's new

There are multiple fixes and new changes in this release:

  • Support added to restore threat based on original path using the following command:

    sudo mdatp threat quarantine restore threat-path --path [threat-original-path] --destination-path [destination-folder]
    
  • From this release, Microsoft Defender for Endpoint on Linux will no longer be shipping a solution for RHEL 6.

    RHEL 6 'Extended end of life support' is poised to end by June 30, 2024 and customers are advised to plan their RHEL upgrades accordingly aligned with guidance from Red Hat. Customers who need to run Defender for Endpoint on RHEL 6 servers can continue to use version 101.23082.0011 (doesn't expire before June 30, 2024) supported on kernel versions 2.6.32-754.49.1.el6.x86_64 or prior.

    • Engine Update to 1.1.23080.2007 and Signatures Ver: 1.395.1560.0.
    • Streamlined device connectivity experience is now in public preview mode. public blog

      Known issues:

      Microsoft Defender for Endpoint for Linux on Rocky and Alma currently has the following known issues:

      • Live Response and Threat Vulnerability Management are currently not supported (work in progress).
      • Operating system info for devices isn't visible in the Microsoft Defender portal

      January-2024 Build: 101.23112.0009 | Release version: 30.123112.0009.0

      Build:101.23112.0009
      Released:January 29,2024
      Published:January 29,2024
      Release version:30.123112.0009.0
      Engine version:1.1.23100.2010
      Signature version:1.399.1389.0

      What's new

      November-2023 Build: 101.23102.0003 | Release version: 30.123102.0003.0

      Build:101.23102.0003
      Released:November 28,2023
      Published:November 28,2023
      Release version:30.123102.0003.0
      Engine version:1.1.23090.2008
      Signature version:1.399.690.0

      What's new

      November-2023 Build: 101.23092.0012 | Release version: 30.123092.0012.0

      Build:101.23092.0012
      Released:November 14,2023
      Published:November 14,2023
      Release version:30.123092.0012.0
      Engine version:1.1.23080.2007
      Signature version:1.395.1560.0

      What's new

      There are multiple fixes and new changes in this release:

      • Support added to restore threat based on original path using the following command:

        sudo mdatp threat quarantine restore threat-path --path [threat-original-path] --destination-path [destination-folder]
        
      • From this release, Microsoft Defender for Endpoint on Linux will no longer be shipping a solution for RHEL 6.

        RHEL 6 'Extended end of life support' is poised to end by June 30, 2024 and customers are advised to plan their RHEL upgrades accordingly aligned with guidance from Red Hat. Customers who need to run Defender for Endpoint on RHEL 6 servers can continue to use version 101.23082.0011 (doesn't expire before June 30, 2024) supported on kernel versions 2.6.32-754.49.1.el6.x86_64 or prior.

      • Engine Update to 1.1.23080.2007 and Signatures Ver: 1.395.1560.0.

      • Streamlined device connectivity experience is now in public preview mode. public blog

      • Performance improvements & bug fixes.

    Known issues

    November-2023 Build: 101.23082.0011 | Release version: 30.123082.0011.0

    Build: 101.23082.0011
    Released: November 1,2023
    Published: November 1,2023
    Release version: 30.123082.0011.0
    Engine version: 1.1.23070.1002
    Signature version: 1.393.1305.0

    What's new

    • This new release is built over October 2023 release (101.23082.0009) with addition of following changes. There's no change for other customers and upgrading is optional.

    • Fix for immutable mode of auditd when supplementary subsystem is ebpf: In ebpf mode all mdatp audit rules should be cleaned after switching to ebpf and rebooting. After the reboot, mdatp audit rules weren't cleaned due to which it was resulting in hang of the server. The fix cleans these rules, user shouldn't see any mdatp rules loaded on reboot

    • Fix for MDE not starting up on RHEL 6.

    Known issues

    sudo apt purge mdatp
    
    sudo apt-get install mdatp
    
    1. As an alternative you can follow the instructions to uninstall, then install the latest version of the package.

    If you don't want to uninstall mdatp, you can disable rtp and mdatp in sequence before upgrading. Some customers (<1%) experience issues with this method.

    sudo mdatp config real-time-protection --value=disabled
    
    sudo systemctl disable mdatp
    

    October-2023 Build: 101.23082.0009 | Release version: 30.123082.0009.0

    Build: 101.23082.0009
    Released: October 9,2023
    Published: October 9,2023
    Release version: 30.123082.0009.0
    Engine version: 1.1.23070.1002
    Signature version: 1.393.1305.0

    What's new

    • This new release is built over October 2023 release (101.23082.0009) with addition of new CA Certificates. There's no change for other customers and upgrading is optional.

    Known issues

    October-2023 Build: 101.23082.0006 | Release version: 30.123082.0006.0

    Build: 101.23082.0006
    Released: October 9,2023
    Published: October 9,2023
    Release version: 30.123082.0006.0
    Engine version: 1.1.23070.1002
    Signature version: 1.393.1305.0

    What's new

    • Feature updates and new changes

      • eBPF sensor is now the default supplementary event provider for endpoints

      • Microsoft Intune tenant attach feature is in public preview (as of mid July)

        • You must add "*.dm.microsoft.com" to firewall exclusions for the feature to work correctly
      • Defender for Endpoint is now available for Debian 12 and Amazon Linux 2023

      • Support to enable Signature verification of updates downloaded

        • You must update the manajed.json as shown:

            "features":{
              "OfflineDefinitionUpdateVerifySig":"enabled"
            }
          
        • Prerequisite to enable feature

          • Engine version on the device must be "1.1.23080.007" or above. Check your engine version by using the following command.

            mdatp health --field engine_version
      • Option to support monitoring of NFS and FUSE mount points. These are ignored by default. The following example shows how to monitor all filesystem while ignoring only NFS:

        "antivirusEngine": {
            "unmonitoredFilesystems": ["nfs"]
        }
      

      Example to monitor all filesystems including NFS and FUSE:

      "antivirusEngine": {
         "unmonitoredFilesystems": []
      }
      
      • Other performance improvements

      • Bug Fixes

    Known issues

    sudo apt purge mdatp
    
    sudo apt-get install mdatp
    

    September-2023 Build: 101.23072.0021 | Release version: 30.123072.0021.0

    Build: 101.23072.0021
    Released: September 11,2023
    Published: September 11,2023
    Release version: 30.123072.0021.0
    Engine version: 1.1.20100.7
    Signature version: 1.385.1648.0

    What's new

    There are multiple fixes and new changes in this release:

    • In mde_installer.sh v0.6.3, users can use the --channel argument to provide the channel of the configured repository during cleanup. For example, sudo ./mde_installer --clean --channel prod

    • The Network Extension can now be reset by administrators using mdatp network-protection reset.

    • Other performance improvements

    • Bug Fixes

    Known issues

    sudo apt purge mdatp
    
    sudo apt-get install mdatp
    
    sudo mdatp config real-time-protection --value=disabled
    
    sudo systemctl disable mdatp
    

    July-2023 Build: 101.23062.0010 | Release version: 30.123062.0010.0

    Build: 101.23062.0010
    Released: July 26,2023
    Published: July 26,2023
    Release version: 30.123062.0010.0
    Engine version: 1.1.20100.7
    Signature version: 1.385.1648.0

    What's new

    There are multiple fixes and new changes in this releaserelease:

    • If a proxy is set for Defender for Endpoint, then it's visible in the mdatp health command output. With this release we provided two options in mdatp diagnostic hot-event-sources:

      • Files
      • Executables
    • Network Protection: Connections that are blocked by Network Protection and have the block overridden by users is now correctly reported to Microsoft Defender XDR

    • Improved logging in Network Protection block and audit events for debugging

    • Other fixes and improvements

      • From this version, enforcementLevel are in passive mode by default giving admins more control over where they want 'RTP on' within their estate
      • This change only applies to fresh MDE deployments, for example, servers where Defender for Endpoint is being deployed for the first time. In update scenarios, servers that have Defender for Endpoint deployed with RTP ON, continue operating with RTP ON even post update to version 101.23062.0010
    • Bug fix: RPM database corruption issue in Defender Vulnerability Management baseline is fixed.

    • Other performance improvements

    Known issues

    sudo apt purge mdatp
    
    sudo apt-get install mdatp
    
    sudo mdatp config real-time-protection --value=disabled
    
    sudo systemctl disable mdatp
    

    July-2023 Build: 101.23052.0009 | Release version: 30.123052.0009.0

    Build: 101.23052.0009
    Released: July 10,2023
    Published: July 10,2023
    Release version: 30.123052.0009.0
    Engine version: 1.1.20100.7
    Signature version: 1.385.1648.0

    What's new

    • There are multiple fixes and new changes in this release - release:

      • The build version schema is updated from this release. While the major version number remains same as 101, the minor version number now has five digits followed by four digit patch number that is, 101.xxxxx.yyy -
      • Improved Network Protection memory consumption under stress
        • Updated the engine version to 1.1.20300.5 and signature version to 1.391.2837.0.
        • Bug fixes.

      Known issues

      sudo apt purge mdatp
      
      sudo apt-get install mdatp
      
      sudo mdatp config real-time-protection --value=disabled
      
      sudo systemctl disable mdatp
      

      June-2023 Build: 101.98.89 | Release version: 30.123042.19889.0

      Build: 101.98.89
      Released: June 12,2023
      Published: June 12,2023
      Release version: 30.123042.19889.0
      Engine version: 1.1.20100.7
      Signature version: 1.385.1648.0

      What's new

      There are multiple fixes and new changes in this release release:

      • Improved Network Protection Proxy handling.

      • In Passive mode, Defender for Endpoint no longer scans when Definition update happens.

      • Devices continue to be protected even after Defender for Endpoint agent is expired. We recommend upgrading the Defender for Endpoint Linux agent to the latest available version to receive bug fixes, features, and performance improvements.

      • Removed semanage package dependency.

      • Engine Update to 1.1.20100.7 and Signatures Ver: 1.385.1648.0.

      • Bug fixes.

      Known issues

      1. As an alternative you can follow the instructions to uninstall, then install the latest version of the package.

      If you don't want to uninstall mdatp, you can disable rtp and mdatp in sequence before upgrading. Some customers (<1%) experience issues with this method.

      sudo mdatp config real-time-protection --value=disabled
      
      ### May-2023 Build: 101.98.64 | Release version: 30.123032.19864.0
      
      |Build:| Build:             | ****101.98.64**|
      |--------------------|-----------------------|
      |Released:| Released:          | ****May 3,2023**|
      |Published:| Published:         | ****May 3,2023**|
      |Release version:| Release version:   | ****30.123032.19864.0**|
      |Engine version:| Engine version:    | ****1.1.20100.6**|
      |Signature version:| Signature version: | ****1.385.68.0**|
      
      #### What's new
      
      There are multiple fixes and new changes in this releaserelease:
      
      - Health message improvements to capture details about auditd failures.
      - Improvements to handle augenrules, which was causing installation failure.
      - Periodic memory cleanup in engine process.
      - Fix for memory issue in mdatp audisp plugin.
      - Handled missing plugin directory path during installation.
      - When conflicting application is using blocking fanotify, with default configuration mdatp health shows unhealthy. This is now fixed.
      - Support for ICMP traffic inspection in BM.
      - Engine Update to `1.1.20100.6` and Signatures Ver: `1.385.68.0`.
      - Bug fixes.
      
      #### Known issues
      
      2. As an alternative you can follow the instructions to [uninstall](./linux-off-board-endpoints.md#uninstall-the-defender-application-from-a-linux-server), then [install](linux-install-manually.md#application-installation) the latest version of the package.
      
      If you don't want to uninstall mdatp, you can disable rtp and mdatp in sequence before upgrading.
      Caution: Some customers (<1%) experience issues with this method.
      
      ```bash
      sudo mdatp config real-time-protection --value=disabled
      
      ### April-2023 Build: 101.98.58 | Release version: 30.123022.19858.0
      
      |Build:| Build:             | ****101.98.58**|
      |--------------------|-----------------------|
      |Released:| Released:          | ****April 20,2023**|
      |Published:| Published:         | ****April 20,2023**|
      |Release version:| Release version:   | ****30.123022.19858.0**|
      |Engine version:| Engine version:    | ****1.1.20000.2**|
      |Signature version:| Signature version: | ****1.381.3067.0**|
      
      #### What's new
      
      There are multiple fixes and new changes in this releaserelease:
      
      - Logging and error reporting improvements for auditd.
      - Handle failure in reload of auditd configuration.
      - Handling for empty auditd rule files during MDE install.
      - Engine Update to `1.1.20000.2` and Signatures Ver: `1.381.3067.0`.
      - Addressed a health issue in mdatp that occurs due to selinux denials.
      - Bug fixes.
      
      #### Known issues
      
        ```bash
        echo -c >> /etc/audit/rules.d/audit.rules
      
        augenrules --load
      

      There are two ways to mitigate this upgrade issue:

      1. Use your package manager to uninstall the 101.75.43 or 101.78.13 mdatp version.

        Example:

        sudo apt purge mdatp
        
        sudo apt-get install mdatp
        
      2. As an alternative you can follow the instructions to uninstall, then install the latest version of the package.

      If you don't want to uninstall mdatp, you can disable rtp and mdatp in sequence before upgrading. Caution: Some customers (<1%) experience issues with this method.

      sudo mdatp config real-time-protection --value=disabled
      
      sudo systemctl disable mdatp
      

      March-2023 Build: 101.98.30 | Release version: 30.123012.19830.0

      Build: 101.98.30
      Released: March 20, 2023
      Published: March 20, 2023
      Release version: 30.123012.19830.0
      Engine version: 1.1.19900.2
      Signature version: 1.379.1299.0

      What's new

      • This new release is built over March 2023 release (101.98.05) with a fix for Live response commands failing for one of our customers. There's no change for other customers and upgrade is optional.

      Known issues

      • With mdatp version 101.98.30 you might see a health false issue in some of the cases, because SELinux rules aren't defined for certain scenarios. The health warning could look something like this:
      sudo ausearch -c 'mdatp_audisp_pl' --raw | sudo audit2allow -M my-mdatpaudisppl_v1
      
      sudo semodule -i my-mdatpaudisppl_v1.pp
      
      sudo service auditd stop
      
      sudo systemctl stop mdatp
      
      cd /var/log/audit
      
      sudo gzip audit.*
      
      sudo service auditd start
      
      sudo systemctl start mdatp
      
      mdatp health
      

      March-2023 Build: 101.98.05 | Release version: 30.123012.19805.0

      Build: 101.98.05
      Released: March 08, 2023
      Published: March 08, 2023
      Release version: 30.123012.19805.0
      Engine version: 1.1.19900.2
      Signature version: 1.379.1299.0

      What's new

      • Improved Data Completeness for Network Connection events

      • Improved Data Collection capabilities for file ownership/permissions changes

      • seManage in part of the package, to that seLinux policies can be configured in different distro (fixed).

      • Improved enterprise daemon stability

      • AuditD stop path clean-up

      • Improved the stability of mdatp stop flow.

      • Added new field to wdavstate to keep track of platform update time.

      • Stability improvements to parsing Defender for Endpoint onboarding blob.

      • Scan doesn't proceed if a valid license isn't present (fixed)

      • Added performance tracing option to xPlatClientAnalyzer, with tracing enabled mdatp process dumps the flow in all_process.zip file that can be used for analysis of performance issues.

      • Added support in Defender for Endpoint for the following RHEL-6 kernel versions:

        • 2.6.32-754.43.1.el6.x86_64
        • 2.6.32-754.49.1.el6.x86_64
      • Other fixes

      Known issues

      While upgrading mdatp to version 101.94.13, you might notice that health is false, with health_issues as "no active supplementary event provider". This can happen due to misconfigured/conflicting auditd rules on existing machines. To mitigate the issue, the auditd rules on the existing machines need to be fixed. The following steps can help you to identify such auditd rules (these commands need to be run as super user). Make sure to back up following file: /etc/audit/rules.d/audit.rules as these steps are only to identify failures.

      echo -c >> /etc/audit/rules.d/audit.rules
      
      augenrules --load
      
      sudo apt purge mdatp
      
      sudo apt-get install mdatp
      

      As an alternative, you can follow the instructions to uninstall, then install the latest version of the package.

      In case you don't want to uninstall mdatp you can disable rtp and mdatp in sequence before upgrade. Caution: Some customers(<1%) are experiencing issues with this method.

      sudo mdatp config real-time-protection --value=disabled
      
      ### Jan-2023 Build: 101.94.13 | Release version: 30.122112.19413.0
      
      |Build:| Build:             | ****101.94.13**|
      |--------------------|-----------------------|
      |Released:| Released:          | ****January 10, 2023**|
      |Published:| Published:         | ****January 10, 2023**|
      |Release version:| Release version:   | ****30.122112.19413.0**|
      |Engine version:| Engine version:    | ****1.1.19700.3**|
      |Signature version:| Signature version: | ****1.377.550.0**|
      
      #### What's new
      
      -
      
      There are multiple fixes and new changes in this releaserelease:
      
      - Skip quarantine of threats in passive mode by default.
      - New config, nonExecMountPolicy, can now be used to specify behavior of RTP on mount point marked as noexec.
      - New config, unmonitoredFilesystems, can be used to unmonitor certain filesystems.
      - Improved performance under high load and in speed test scenarios.
      - Fixes an issue with accessing SMB shares behind Cisco AnyConnect VPN connections.
      - Fixes an issue with Network Protection and SMB.
      - lttng performance tracing support.
      - TVM, eBPF, auditd, telemetry, and mdatp cli improvements.
      - mdatp health now reports behavior_monitoring
      - Other fixes.
      
      #### Known issues
      
      
      ```bash
      sudo apt purge mdatp
      
      sudo apt-get install mdatp
      
      sudo mdatp config real-time-protection --value=disabled
      
      sudo systemctl disable mdatp
      

      Nov-2022 Build: 101.85.27 | Release version: 30.122092.18527.0

      Build: 101.85.27
      Released: November 02, 2022
      Published: November 02, 2022
      Release version: 30.122092.18527.0
      Engine version: 1.1.19500.2
      Signature version: 1.371.1369.0

      What's new

      • There are multiple fixes and new changes in this releaserelease:

        • V2 engine is default with this release and V1 engine bits are removed for enhanced security.
        • V2 engine support configuration path for AV definitions. (mdatp definition set path)
        • Removed external packages dependencies from MDE package. Removed dependencies are libatomic1, libselinux, libseccomp, libfuse, and libuuid
        • In case crash collection is disabled by configuration, crash monitoring process isn't launched.
        • Performance fixes to optimally use system events for AV capabilities.
        • Stability improvement when restarting mdatp and load epsext issues.
        • Other fixes

      Known issues

      sudo apt purge mdatp
      
      sudo apt-get install mdatp
      
      sudo mdatp config real-time-protection --value=disabled
      
      sudo systemctl disable mdatp
      

      Sep-2022 Build: 101.80.97 | Release version: 30.122072.18097.0

      Build: 101.80.97
      Released: September 14, 2022
      Published: September 14, 2022
      Release version: 30.122072.18097.0
      Engine version: 1.1.19300.3
      Signature version: 1.369.395.0

      What's new

      sudo mdatp config real-time-protection --value=disabled
      
      sudo systemctl disable mdatp
      

      Aug-2022 Build: 101.78.13 | Release version: 30.122072.17813.0

      Build: 101.78.13
      Released: August 24, 2022
      Published: August 24, 2022
      Release version: 30.122072.17813.0
      Engine version: 1.1.19300.3
      Signature version: 1.369.395.0

      What's new

      • Rolled back due to reliability issues

      Aug-2022 (Build: 101.75.43 | Release version: 30.122071.17543.0)

      Build: 101.75.43
      Released: August 2, 2022
      Published: August 2, 2022
      Release version: 30.122071.17543.0
      Engine version: 1.1.19300.3
      Signature version: 1.369.395.0

      What's new

      Jul-2022 Build: 101.73.77 | Release version: 30.122062.17377.0

      Build: 101.73.77
      Released: July 21, 2022
      Published: July 21, 2022
      Release version: 30.122062.17377.0
      Engine version: 1.1.19200.3
      Signature version: 1.367.1011.0

      What's new

      Jun-2022 Build: 101.71.18 | Release version: 30.122052.17118.0

      Build: 101.71.18
      Released: June 24, 2022
      Published: June 24, 2022
      Release version: 30.122052.17118.0

      What's new

      May-2022 Build: 101.68.80 | Release version: 30.122042.16880.0

      Build: 101.68.80
      Released: May 23, 2022
      Published: May 23, 2022
      Release version: 30.122042.16880.0

      What's new

      May-2022 Build: 101.65.77 | Release version: 30.122032.16577.0

      Build: 101.65.77
      Released: May 2, 2022
      Published: May 2, 2022
      Release version: 30.122032.16577.0

      What's new

      Mar-2022 (Build: 101.62.74 | Release version: 30.122022.16274.0)

      Build: 101.62.74
      Released: Mar 24, 2022
      Published: Mar 24, 2022
      Release version: 30.122022.16274.0

      What's new

      Mar-2022 Build: 101.60.93 | Release version: 30.122012.16093.0

      Build: 101.60.93
      Released: Mar 9, 2022
      Published: Mar 9, 2022
      Release version: 30.122012.16093.0

      What's new

      Mar-2022 Build: 101.60.05 | Release version: 30.122012.16005.0

      Build: 101.60.05
      Released: Mar 3, 2022
      Published: Mar 3, 2022
      Release version: 30.122012.16005.0

      What's new

      Feb-2022 Build: 101.58.80 | Release version: 30.122012.15880.0

      Build: 101.58.80
      Released: Feb 20, 2022
      Published: Feb 20, 2022
      Release version: 30.122012.15880.0

      What's new

      Jan-2022 Build: 101.56.62 | Release version: 30.121122.15662.0

      Build: 101.56.62
      Released: Jan 26, 2022
      Published: Jan 26, 2022
      Release version: 30.121122.15662.0

      What's new

      Jan-2022 Build: 101.53.02 | Release version: 30.121112.15302.0

      Build: 101.53.02
      Released: Jan 8, 2022
      Published: Jan 8, 2022
      Release version: 30.121112.15302.0

      What's new

      Build: 101.52.57 | Release version: 30.121092.15257.0

      Build: 101.52.57
      Release version: 30.121092.15257.0
      What's new
      • Added a capability to detect vulnerable Log4j jars in use by Java applications. The machine is periodically inspected for running Java processes with loaded Log4j jars. The information is reported to the Microsoft Defender for Endpoint backend and is exposed in the Vulnerability Management area of the portal.

      Build: 101.47.76 | Release version: 30.121092.14776.0

      Build: 101.47.76
      Release version: 30.121092.14776.0
      What's new
      • Added a new switch to the command-line tool to control whether archives are scanned during on-demand scans. This can be configured through mdatp config scan-archives--value [enabled/disabled]. By default, this setting is set to enabled.

      • Bug fixes

      Build: 101.45.13 | Release version: 30.121082.14513.0

      Build: 101.45.13
      Release version: 30.121082.14513.0
      What's new
      • Beginning with this version, we're bringing Microsoft Defender for Endpoint support to the following distros:

        • RHEL6.7-6.10 and CentOS6.7-6.10 versions.
        • Amazon Linux 2
        • Fedora 33 or higher
      • Bug fixes

      Build: 101.45.00 | Release version: 30.121072.14500.0

      Build: 101.45.00
      Release version: 30.121072.14500.0
      What's new

      Build: 101.39.98 | Release version: 30.121062.13998.0

      Build: 101.39.98
      Release version: 30.121062.13998.0
      What's new

      Build: 101.34.27 | Release version: 30.121052.13427.0

      Build: 101.34.27
      Release version: 30.121052.13427.0
      What's new

      Build: 101.29.64 | Release version: 30.121042.12964.0

      Build: 101.29.64
      Release version: 30.121042.12964.0
      What's new

      Build: 101.25.72 | Release version: 30.121022.12563.0

      Build: 101.25.72
      Release version: 30.121022.12563.0
      What's new
      • Microsoft Defender for Endpoint on Linux is now available in preview for US Government customers. For more information, see Microsoft Defender for Endpoint for US Government customers.
      • Fixed an issue where usage of Microsoft Defender for Endpoint on Linux on systems with FUSE filesystems was leading to OS hang
      • Performance improvements & other bug fixes

      Build: 101.25.63 | Release version: 30.121022.12563.0

      Build: 101.25.63
      Release version: 30.121022.12563.0
      What's new

      Build: 101.23.64 | Release version: 30.121021.12364.0

      Build: 101.23.64
      Release version: 30.121021.12364.0
      What's new
      What's new
      • EDR for Linux is now generally available

      • Added a new command-line switch (--ignore-exclusions) to ignore AV exclusions during custom scans (mdatp scan custom)

      • Extended mdatp diagnostic create with a new parameter (--path [directory]) that allows the diagnostic logs to be saved to a different directory

      • Performance improvements & bug fixes

      1.1.15010101

      • With this version, we're announcing support for iPadOS/iPad devices.
      • Bug fixes. \ No newline at end of file
      • Bug fixes.