业界动态
Microsoft Defender Antivirus security intelligence and product updates
2024-07-31 21:53

Applies to:

  • Microsoft Defender for Endpoint Plans 1 and 2
  • Microsoft Defender Antivirus

Platforms

  • Windows

Keeping Microsoft Defender Antivirus up to date is critical to assure your devices have the latest technology and features needed to protect against new malware and attack techniques. Update your antivirus protection, even if Microsoft Defender Antivirus is running in passive mode. This article includes information about the two types of updates for keeping Microsoft Defender Antivirus current:

  • Security intelligence updates
  • Product updates

This article also includes:

  • Microsoft Defender Antivirus platform support
  • How to roll back an update (if necessary)
  • Platform version included with Windows 10 releases
  • Updates for Deployment Image Servicing and Management (DISM)

To see the most current engine, platform, and signature date, see Security intelligence updates for Microsoft Defender Antivirus and other Microsoft antimalware.

Microsoft Defender Antivirus uses cloud-delivered protection (also called the Microsoft Advanced Protection Service, or MAPS) and periodically downloads dynamic security intelligence updates to provide more protection. These dynamic updates don't take the place of regular security intelligence updates via security intelligence update KB2267602.

Cloud-delivered protection is always on and requires an active connection to the Internet to function. Security intelligence updates occur on a scheduled cadence (configurable via policy). For more information, see Use Microsoft cloud-provided protection in Microsoft Defender Antivirus.

For a list of recent security intelligence updates, see Security intelligence updates for Microsoft Defender Antivirus and other Microsoft antimalware.

Engine updates are included with security intelligence updates and are released on a monthly cadence.

Microsoft Defender Antivirus requires monthly updates (KB4052623) known as platform updates.

You can manage the distribution of updates through one of the following methods:

  • Windows Server Update Service (WSUS)
  • Microsoft Configuration Manager
  • The usual methods you use to deploy Microsoft and Windows updates to endpoints in your network.

For more information, see Manage the sources for Microsoft Defender Antivirus protection updates.

  • Monthly updates are released in phases, resulting in multiple packages visible in your Window Server Update Services.

  • This article lists changes that are included in the broad release channel. See the latest broad channel release here.

  • To learn more about the gradual rollout process, and to see more information about the next release, see Manage the gradual rollout process for Microsoft Defender updates.

  • To learn more about security intelligence updates, see Security intelligence updates for Microsoft Defender Antivirus and other Microsoft antimalware.

  • If you're looking for a list of Microsoft Defender processes, see the spreadsheet provided at Enable access to Microsoft Defender for Endpoint service URLs in the proxy server. The sheet also lists the services and their associated URLs that your network must be able to connect to.

  • Platform updates can be temporarily postponed if other protection features, such as Endpoint DLP or Device Control are actively monitoring running processes. Platform updates are retried after a reboot or when all monitored services are stopped.

  • In the Microsoft Endpoint Configuration Manager / Windows Server Update Services (MECM/WSUS) catalog, the category Microsoft Defender for Endpoint includes updates for the MSSense service in KB5005292. KB5005292 includes updates and fixes to the Microsoft Defender for Endpoint endpoint detection and response (EDR) sensor. For more information, see Microsoft Defender for Endpoint update for EDR Sensor and What's new in Microsoft Defender for Endpoint on Windows.

All our updates contain:

  • Performance improvements
  • Serviceability improvements
  • Integration improvements (Cloud, Microsoft Defender XDR)
  • Security intelligence update version: 1.415.1.0
  • Release date: July 9, 2024 (Engine) / July 15, 2024 (Platform)
  • Platform: 4.18.24060.7
  • Engine: 1.1.24060.5
  • Support phase: Security and Critical Updates
  • Fixed issue where Microsoft Defender Antivirus was not properly changing state when non-Microsoft antivirus/antimalware software was installed and Windows Defender Application Control (WDAC) with Intelligent Security Graph were enabled.
  • Fixed deadlock issue on VDI that occurred when loading corrupted update files from UNC share.
  • Custom scans started with Start-MpScan are now reported in the event log.
  • Fixed potential deadlock that occurred on volume mount scanning.
  • Fixed issue where Microsoft Defender Antivirus did not allow applications to clean up temporary files.
  • Fixed potentially packet loss due to network protection shutdown that could lead to deadlock.
  • Implemented performance improvements for scenarios where WDAC is enabled with Intelligent Security Graph.
  • Fixed an issue where an Outlook exclusion for the ASR rule Block Office applications from injecting code into other processes was not honored.
  • Fixed a race condition during the startup of endpoint data loss prevention such that, in certain environments, some system files could be corrupted.
  • Security intelligence update version: 1.413.1.0
  • Release date: May 30, 2024 (Engine) / June 4, 2024 (Platform)
  • Engine: 1.1.24050.5
  • Platform: 4.18.24050.7
  • Support phase: Security and Critical Updates

What's new

  • Improved performance when running configuration queries.
  • Optimized how scans are prioritized.
  • Fixed a crash caused by a race condition with a device control driver.
  • Added Event Viewer Logging for scan start event where the scan originates from PowerShell.
  • Security intelligence update version: 1.411.7.0
  • Release date: May 07, 2024 (Engine) / May 16, 2024 (Platform)
  • Engine: 1.1.24040.1
  • Platform: 4.18.24040.4
  • Support phase: Security and Critical Updates

What's new

  • Added an opt-out feature for Experimental Configuration Services (ECS) and One collector in the Core Service.
  • Fixed an issue where occasionally exclusions deployed via Intune were not being honored when tamper protection was enabled.
  • After a new engine version is released, support for older versions (N-2) will now reduce to technical support only. Engine versions older than N-2 are no longer supported.
  • Improved health monitoring and telemetry for attack surface rules exclusions.
  • Updated inaccurate information in Configure exclusions for files opened by processes regarding wildcard usage with contextual exclusions.

After a new package version is released, support for the previous two versions is reduced to technical support only. For more information about previous versions, see Microsoft Defender Antivirus updates: Previous versions for technical upgrade support.

Platform and engine updates are provided on a monthly cadence. To be fully supported, keep current with the latest platform and engine updates. Our support structure is dynamic, evolving into two phases depending on the availability of the latest platform and engine version:

  • Security and Critical Updates servicing phase - When running the latest platform and engine version, you're eligible to receive both Security and Critical updates to the anti-malware platform.

  • Technical Support (Only) phase - After a new platform and engine version is released, support for older versions (N-2) reduce to technical support only. Platform and engine versions older than N-2 are no longer supported. Technical support continues to be provided for upgrades from the Windows 10 release version (see Platform version included with Windows 10 releases) to the latest platform version.

During the technical support (only) phase, commercially reasonable support incidents are provided through Microsoft Customer Service & Support and Microsoft's managed support offerings (such as Premier Support). If a support incident requires escalation to development for further guidance, requires a nonsecurity update, or requires a security update, customers are asked to upgrade to the latest platform version or an intermediate update (*).

In the unfortunate event that you encounter issues after a platform update, you can roll back to the previous or the inbox version of the Microsoft Defender platform.

  • To roll back to the previous version, run the following command:

  • To roll back this update to the version shipped with the Operating System ("%ProgramFiles%Windows Defender")

The below table provides the Microsoft Defender Antivirus platform and engine versions that are shipped with the latest Windows 10 releases:

Windows 10 release Platform version Engine version Support phase 2004 (20H1/20H2) Technical upgrade support (only) 1909 (19H2) Technical upgrade support (only) 1903 (19H1) Technical upgrade support (only) 1809 (RS5) Technical upgrade support (only) 1803 (RS4) Technical upgrade support (only) 1709 (RS3) Technical upgrade support (only) 1703 (RS2) Technical upgrade support (only) 1607 (RS1) Technical upgrade support (only)

For Windows 10 release information, see the Windows lifecycle fact sheet.

To avoid a gap in protection, keep your OS installation images up to date with the latest antivirus and antimalware updates. Updates are available for:

  • Windows 10 and 11 (Enterprise, Pro, and Home editions)
  • Windows Server 2022, Windows Server 2019, Windows Server 2016, and Windows Server 2012 R2
  • WIM and VHD(x) files

Updates are released for x86, x64, and ARM64 Windows architecture.

For more information, see Microsoft Defender update for Windows operating system installation images.

After a new package version is released, support for the previous two versions is reduced to technical support only.

  • Defender package version:
  • Security intelligence version:
  • Engine version:
  • Platform version:

Fixes

  • None

Additional information

  • None
  • Defender package version:
  • Security intelligence version:
  • Engine version:
  • Platform version:

Fixes

  • None

Additional information

  • None
  • Defender package version:
  • Security intelligence version:
  • Engine version:
  • Platform version:

Fixes

  • None

Additional information

  • None
Article Description Microsoft Defender update for Windows operating system installation images Review antimalware update packages for your OS installation images (WIM and VHD files). Get Microsoft Defender Antivirus updates for Windows 10 (Enterprise, Pro, and Home editions), Windows Server 2019, Windows Server 2022, Windows Server 2016, and Windows Server 2012 R2 installation images. Manage how protection updates are downloaded and applied Protection updates can be delivered through many sources. Manage when protection updates should be downloaded and applied You can schedule when protection updates should be downloaded. Manage updates for endpoints that are out of date If an endpoint misses an update or scheduled scan, you can force an update or scan the next time a user signs in. Manage event-based forced updates You can set protection updates to be downloaded at startup or after certain cloud-delivered protection events. Manage updates for mobile devices and virtual machines (VMs) You can specify settings, such as whether updates should occur on battery power that 's especially useful for mobile devices and virtual machines. Microsoft Defender for Endpoint update for EDR Sensor You can update the EDR sensor (MsSense.exe) that's included in the new Microsoft Defender for Endpoint unified solution package released in 2021.
    以上就是本篇文章【Microsoft Defender Antivirus security intelligence and product updates】的全部内容了,欢迎阅览 ! 文章地址:http://www78564.xrbh.cn/news/13969.html 
     文章      相关文章      动态      同类文章      热门文章      栏目首页      网站地图      返回首页 迅博思语移动站 http://www78564.xrbh.cn/mobile/ , 查看更多   
最新文章
OMEN暗影精灵MAX强势登场,解锁硬核玩家高能装备
2025年3月28日 ,惠普游戏家族2025重磅新品 —— OMEN暗影精灵 MAX于新品解密直播震撼发布,通过全方位实测展示,为玩家解锁新品
越传越离谱,张慧仪怒了要验DNA,邓兆尊隔空道歉:肯定不是她
最近的娱乐圈,真是风波不断,各种真真假假的传闻满天飞。这不,前段时间邓兆尊在网台节目里爆了个猛料,说某女星同时交往六位富
2024模拟二战的策略游戏有哪些 超受欢迎的二战题材手游二战游戏手机游戏「2024模拟二战的策略游戏有哪些 超受欢迎的二战题材手游」
本期要与小伙伴们一起分享的是模拟二战的策略游戏,这类手游不仅为各位玩家最大程度地还原了二战战场,还能让玩家在游戏中尽情发
苹果iwatch怎么连接android手机?苹果手表可以连接安卓手机吗「苹果iwatch怎么连接android手机?」
可以。点击手机里的设置选项。搜索蓝牙功能。再把蓝牙功能打开之后,用蓝牙搜索iwatch的蓝牙。搜索到它的型号之后。点击连接。这
小米手机宣布最新代言人,顺便曝光了小米9后置三摄和前置指纹小米9手机「小米手机宣布最新代言人,顺便曝光了小米9后置三摄和前置指纹」
今天一早,雷军发微博曝光了小米9的发布会日期,这一款小米手机的年度旗舰将在2月20日发布。对于这台新旗舰,小米官方的评价是“
百亿基金+百万落户奖+免费住房!珠海向全球海归发英雄帖
南都讯 4月1日,欧美同学会第四届“双创”大赛启动仪式暨媒体推介会在珠海高新区香山会议中心举行。此次大赛首次在粤港澳大湾区
关于2024年春节前后寄递服务的消费提示手机号查顺丰快递「关于2024年春节前后寄递服务的消费提示」
春节将至,为做好节日期间寄递服务保障工作,各邮政、快递企业依据业务实际情况,对网络运营进行了适当调整。企业将根据不同区域
面对“王羲之杜甫李时珍轮流骂我”的局面,就这样一笑而过?
AI正以前所未有的态势,“重塑”着我们的认知与生活。这不,最近各大短视频平台上AI复活历史文化名人的现象,再度引发人们的热议
So easy!电脑手机玩转DLNA Wifi音箱播放玩转手机「So easy!电脑手机玩转DLNA Wifi音箱播放」
本文来自网友广东第一恶霸分享在最数码论坛的文章://piebbs.pconline.com.cn/topic-85016.html  已经很难想象没有Wifi的世界
华为模拟器ensp怎么安装_华为模拟器怎么安装华为手机模拟器「华为模拟器ensp怎么安装_华为模拟器怎么安装」
大家好,又见面了,我是你们的朋友全栈君简单介绍一下 eNSP: eNSP是一款由提供的免费的图形化网络仿真工具平台,它将完美呈现真