Microsoft Defender for Endpoint Updates & Release Notes
21 updates curated from 1 source by the Releasebot Team. Last updated: Sep 3, 2026
- September 2026
- Date parsed from source:Sep 1, 2026
- First seen by Releasebot:Sep 3, 2026
Microsoft Defender for Endpoint by Microsoft
Feature - Memory scan for Linux
Microsoft Defender for Endpoint adds Memory Scan on Linux to inspect process memory for malicious behavior and memory-resident threats, improving visibility and protection against advanced in-memory attacks.
Memory Scan extends Microsoft Defender for Endpoint protection capabilities on Linux by enabling inspection of process memory for known malicious behaviours and memory-resident threats, providing an additional layer of protection against advanced attacks.
Memory-resident threats are increasingly challenging for security teams because they can execute directly in memory with little or no footprint on disk, making them more difficult to detect using traditional file-based scanning techniques.
Memory Scan helps improve visibility into these threats and strengthens protection against sophisticated attack methods such as in-memory malware and malicious code injection.
Available in Defender version 101.26071.0005 or later in Insiders-slow channel.
Original source - September 2026
- Date parsed from source:Sep 1, 2026
- First seen by Releasebot:Sep 2, 2026
Microsoft Defender for Endpoint by Microsoft
Feature - Microsoft Defender for Endpoint plug-in support for WSL containers (WSLc)
Microsoft Defender for Endpoint extends protection to WSL containers with visibility in inventory, alerts, incidents, timeline and hunting.
Extend Microsoft Defender for Endpoint protection to workloads running in WSL containers (WSLc). Gain visibility into WSL container activity through device inventory, alerts, incidents, device timeline, and Advanced Hunting, helping security teams investigate and respond to threats across both Windows and Linux workloads. Available in Public Preview. To enroll, complete the registration form.
Original source All of your release notes in one feed
Join Releasebot and get updates from Microsoft and hundreds of other software products.
- August 2026
- Date parsed from source:Aug 1, 2026
- First seen by Releasebot:Sep 2, 2026
- Modified by Releasebot:Sep 3, 2026
Microsoft Defender for Endpoint by Microsoft
Feature - Tamper protection in audit mode for Linux
Microsoft Defender for Endpoint adds tamper detection and alerts for unauthorized changes on Linux devices.
Detects and alerts on unauthorized modifications to Defender configurations, files, directories, processes, and services, including attempts by root users. Tampering activity is surfaced through alerts, the device timeline, and Advanced Hunting without blocking the activity. Available in Microsoft Defender for Endpoint on Linux version 101.26072.0004 or later in Insiders-slow channel.
Original source - August 2026
- Date parsed from source:Aug 1, 2026
- First seen by Releasebot:Aug 26, 2026
Microsoft Defender for Endpoint by Microsoft
Feature - Antivirus audit mode for Linux
Microsoft Defender for Endpoint adds real-time malware detection and alerting on Linux without automatic enforcement.
Provides real-time malware detection and alerting without automatically quarantining files or terminating processes. This enables organizations to evaluate Defender detection efficacy and performance on sensitive workloads before enabling enforcement. Available in Microsoft Defender for Endpoint on Linux version 101.26062.0007 or later.
Original source - August 2026
- Date parsed from source:Aug 1, 2026
- First seen by Releasebot:Aug 26, 2026
Microsoft Defender for Endpoint by Microsoft
Feature - Offboarding API support for Linux
Microsoft Defender for Endpoint adds Linux server offboarding automation through the Offboard machine API.
Enables organizations to automate the offboarding of Linux servers from Microsoft Defender for Endpoint through the Offboard machine API, simplifying device lifecycle management at scale.
Available in Microsoft Defender for Endpoint on Linux version 101.26062.0007 or later.
Original source Similar to Microsoft Defender for Endpoint with recent updates:
- Microsoft Copilot updates38 release notes · Latest Aug 25, 2026
- OpenAI updates197 release notes · Latest Sep 5, 2026
- Anthropic updates61 release notes · Latest Sep 1, 2026
- Agent Framework updates56 release notes · Latest Sep 3, 2026
- Microsoft 365 updates70 release notes · Latest Sep 1, 2026
- xAI updates126 release notes · Latest Sep 3, 2026
- August 2026
- Date parsed from source:Aug 1, 2026
- First seen by Releasebot:Aug 10, 2026
Microsoft Defender for Endpoint by Microsoft
Feature - Vulnerability assessment for Microsoft Store applications
Microsoft Defender for Endpoint now supports monitoring vulnerabilities in Microsoft Store apps with file paths and suggested queries.
You can now monitor vulnerabilities on devices running Microsoft Store applications, including Microsoft Teams, Mozilla Firefox, WhatsApp, Slack, Dropbox, DuckDuckGo, Dell Command, HP Smart, HP Support Assistant, Dell SupportAssist for Home PCs, and NVIDIA Control Panel (see Microsoft Store applications for the full list).
Use the Software evidence area in the software page to view the file path for the vulnerable application, along with a suggested query showing the vulnerable app, version, and file location.
Original source - August 2026
- Date parsed from source:Aug 1, 2026
- First seen by Releasebot:Jul 20, 2026
- Modified by Releasebot:Sep 3, 2026
Microsoft Defender for Endpoint by Microsoft
Release - macOS Build 101.26062.0011
Microsoft Defender for Endpoint releases 20.126062.11.0 with enhancements and new features.
Release version 20.126062.11.0 released: See enhancements and features for this release.
Original source - July 2026
- Date parsed from source:Jul 1, 2026
- First seen by Releasebot:Jul 25, 2026
Microsoft Defender for Endpoint by Microsoft
Defender Deployment Tool for Linux
Microsoft Defender for Endpoint adds the Defender Deployment Tool for Linux, streamlining installation, onboarding, upgrades, and uninstallation in one workflow. It also brings deployment progress visibility through Device Timeline, Advanced Hunting monitoring, and detailed error reporting for easier troubleshooting.
Available from Defender for Endpoint on Linux version 101.26042.0011 and later.
The Defender Deployment Tool for Linux simplifies deployment by combining installation, onboarding, upgrades, and uninstallation into a single workflow.
The tool automates prerequisite validation, supports custom installation paths, enables deployment of specific Defender versions from preferred update channels, and works seamlessly in environments that use local repositories.
In addition to a simplified deployment experience, customers can now gain complete visibility into deployment progress through Device Timeline integration, providing step-by-step installation, upgrade, and onboarding status, Advanced Hunting queries for fleet-wide deployment monitoring, and detailed error reporting, including deployment stage, status, exit code, and failure reason to simplify troubleshooting.
These capabilities help administrators quickly identify deployment issues, track onboarding progress, and understand deployment outcomes across their Linux estate.
Available from Defender version 101.26042.0011 onwards.
Original source - July 2026
- Date parsed from source:Jul 1, 2026
- First seen by Releasebot:Jul 20, 2026
Microsoft Defender for Endpoint by Microsoft
Release - iOS
Microsoft Defender for Endpoint releases version 1.1.78290102 with enhancements and new features.
Release version 1.1.78290102 released: See enhancements and features for this release.
Original source - July 2026
- Date parsed from source:Jul 1, 2026
- First seen by Releasebot:Jul 20, 2026
Microsoft Defender for Endpoint by Microsoft
AI agent runtime protection updates
Microsoft Defender for Endpoint expands AI agent runtime protection for Codex CLI, GitHub Copilot, and Node.js Claw agents.
AI agent runtime protection includes these enhancements:
- Vendor-supported agent event interfaces now work with standard platform and engine update channels, so no Beta channel configuration is required. Agent-native event inspection now supports Codex CLI and the GitHub Copilot app.
- Network inspection is now supported for agents that don't expose vendor-supported event interfaces, including OpenClaw and similar Node.js-based Claw agents. For more information, see AI agent runtime protection with Microsoft Defender for Endpoint.
- July 2026
- Date parsed from source:Jul 1, 2026
- First seen by Releasebot:Jul 20, 2026
- Modified by Releasebot:Aug 8, 2026
Microsoft Defender for Endpoint by Microsoft
Release - macOS
Microsoft Defender for Endpoint releases version 20.126052.16.0 with new enhancements and features.
Release version 20.126052.16.0 released: See enhancements and features for this release.
Original source - June 2026
- Date parsed from source:Jun 1, 2026
- First seen by Releasebot:Jul 20, 2026
Microsoft Defender for Endpoint by Microsoft
Release - Android
Microsoft Defender for Endpoint releases version 1.0.9029.0101 with new enhancements and features.
Release version 1.0.9029.0101 released: See enhancements and features for this release.
Original source - June 2026
- Date parsed from source:Jun 1, 2026
- First seen by Releasebot:Jul 20, 2026
Microsoft Defender for Endpoint by Microsoft
Local AI agent discovery — macOS support and new agents
Microsoft Defender for Endpoint expands Local AI agent discovery to macOS and adds support for new AI agents.
Local AI agent discovery now supports macOS endpoints in addition to Windows.
This update also adds discovery support for new agents including Junie CLI, Kiro CLI, Warp, Hermes Agent, Goose Desktop, Perplexity Desktop, Kiro IDE, Devin Desktop (formerly Windsurf), and QClaw.
For more information, see Local AI agent discovery.
Original source - June 2026
- Date parsed from source:Jun 1, 2026
- First seen by Releasebot:Jul 20, 2026
Microsoft Defender for Endpoint by Microsoft
Enhanced Defender deployment tool for Windows
Microsoft Defender for Endpoint adds streamlined onboarding and stronger package security, bundling the onboarding package into the executable, generating deployment keys, and supporting package expiry dates. It also lets users download .exe or .zip files and manage them from a new Deployment packages page.
The new version of the tool streamlines onboarding and enhances security by:
- Bundling the onboarding package directly into the tool's executable.
- Generating a key during deployment package creation that is required for running the tool.
- Enabling users to configure an expiry date for the package to reduce the risk of unauthorized use.
In addition:
- You have the option of downloading the package as either an .exe or a .zip file, whichever best suits your organization's needs.
- A new Deployment packages page in the Defender portal facilitates management of downloaded packages by providing centralized visibility into all the packages and their current status.
- June 2026
- Date parsed from source:Jun 1, 2026
- First seen by Releasebot:Jul 20, 2026
Microsoft Defender for Endpoint by Microsoft
Selective Response Actions
Microsoft Defender for Endpoint adds Selective Response Actions for tailored onboarding protection on Tier-0 and high-value devices.
Selective Response Actions enables organizations to tailor high-impact security operations on devices during onboarding. It provides precise control over how response actions are applied on Tier-0 systems and other high-value assets, helping maintain operational stability while delivering strong protection.
Original source
Curated by the Releasebot team
Releasebot is an aggregator of official product update announcements from hundreds of software vendors and thousands of sources.
Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.