Skip to content

Commit 16b795c

Browse files
Merge pull request #5090 from MicrosoftDocs/main
[AutoPublish] main to live - 09/18 07:31 PDT | 09/18 20:01 IST
2 parents 5ade256 + 28f0478 commit 16b795c

File tree

1 file changed

+26
-40
lines changed

1 file changed

+26
-40
lines changed

defender-endpoint/microsoft-defender-antivirus-updates.md

Lines changed: 26 additions & 40 deletions
Original file line numberDiff line numberDiff line change
@@ -3,70 +3,45 @@ title: Microsoft Defender Antivirus security intelligence and product updates
33
description: Manage how Microsoft Defender Antivirus receives protection and product updates.
44
ms.service: defender-endpoint
55
ms.localizationpriority: high
6-
ms.date: 07/23/2025
6+
ms.date: 09/18/2025
77
audience: ITPro
88
ms.topic: reference
9-
author: batamig
10-
ms.author: bagol
11-
ms.custom: nextgen
12-
ms.reviewer: pahuijbr, tudobril, yongrhee
13-
manager: bagol
9+
author: KesemSharabi
10+
ms.author: kesharab
1411
ms.subservice: ngp
15-
ms.collection:
16-
- m365-security
17-
- tier2
18-
- mde-ngp
1912
search.appverid: met150
13+
appliesto:
14+
- Microsoft Defender for Endpoint Plan 1
15+
- Microsoft Defender for Endpoint Plan 2
2016
---
2117

2218
# Microsoft Defender Antivirus security intelligence and product updates
2319

24-
**Applies to:**
20+
Keeping Microsoft Defender Antivirus up to date is critical to assure your devices are protected against new malware and attack techniques. Update your antivirus protection, even if Microsoft Defender Antivirus is running in [passive mode](microsoft-defender-antivirus-compatibility.md). You can find the lates engine, platform, and signature date in [Security intelligence updates for Microsoft Defender Antivirus and other Microsoft anti-malware](https://www.microsoft.com/en-us/wdsi/defenderupdates)
2521

26-
- [Microsoft Defender for Endpoint Plans 1 and 2](microsoft-defender-endpoint.md)
27-
- Microsoft Defender Antivirus
28-
29-
**Platforms**
30-
31-
- Windows
32-
33-
Keeping Microsoft Defender Antivirus up to date is critical to assure your devices have the latest technology and features needed to protect against new malware and attack techniques. Update your antivirus protection, even if Microsoft Defender Antivirus is running in [passive mode](microsoft-defender-antivirus-compatibility.md). This article includes information about the two types of updates for keeping Microsoft Defender Antivirus current:
22+
This article is aimed at **Windows** devices, and includes information about the following two types of updates:
3423

3524
- [Security intelligence updates](#security-intelligence-updates)
36-
- [Product updates](#product-updates)
37-
38-
This article also includes:
39-
40-
- [Microsoft Defender Antivirus platform support](#microsoft-defender-antivirus-platform-and-engine-support)
41-
- [How to roll back an update](#how-to-roll-back-an-update) (if necessary)
42-
- [Platform version included with Windows 10 releases](#platform-version-included-with-windows-10-releases)
43-
- [Updates for Deployment Image Servicing and Management (DISM)](#updates-for-deployment-image-servicing-and-management-dism)
44-
45-
To see the most current engine, platform, and signature date, see [Security intelligence updates for Microsoft Defender Antivirus and other Microsoft anti-malware](https://www.microsoft.com/en-us/wdsi/defenderupdates).
4625

47-
[!INCLUDE [MDE automated setup guide](../includes/security-analyzer-setup-guide.md)]
26+
- [Product updates](#product-updates)
4827

4928
## Security intelligence updates
5029

51-
Microsoft Defender Antivirus uses [cloud-delivered protection](cloud-protection-microsoft-defender-antivirus.md) (also called the *Microsoft Advanced Protection Service*, or MAPS) and periodically downloads dynamic security intelligence updates to provide more protection. These dynamic updates don't take the place of regular security intelligence updates via security intelligence update KB2267602.
30+
Microsoft Defender Antivirus uses [cloud-delivered protection](cloud-protection-microsoft-defender-antivirus.md), also known as *Microsoft Advanced Protection Service*, or *MAPS*. Defender Antivirus periodically downloads dynamic security [intelligence updates](https://www.microsoft.com/en-us/wdsi/defenderupdates). These updates don't replace regular security intelligence updates. Engine updates are included with security intelligence updates and are released monthly.
5231

53-
> [!NOTE]
54-
> Updates are released under the following KBs:
55-
>
56-
> - Microsoft Defender Antivirus: KB2267602
57-
> - System Center Endpoint Protection: KB2461484
32+
Updates are released under the following KBs:
5833

59-
Cloud-delivered protection is always on and requires an active connection to the Internet to function. Security intelligence updates occur on a scheduled cadence (configurable via policy). For more information, see [Use Microsoft cloud-provided protection in Microsoft Defender Antivirus](cloud-protection-microsoft-defender-antivirus.md).
34+
- Microsoft Defender Antivirus: KB2267602
6035

61-
For a list of recent security intelligence updates, see [Security intelligence updates for Microsoft Defender Antivirus and other Microsoft anti-malware](https://www.microsoft.com/en-us/wdsi/defenderupdates).
36+
- System Center Endpoint Protection: KB2461484
6237

63-
Engine updates are included with security intelligence updates and are released on a monthly cadence.
38+
[Cloud-delivered protection](cloud-protection-microsoft-defender-antivirus.md) is always on and requires an active connection to the internet to function. Security intelligence updates occur on a scheduled cadence which you can configure using a policy.
6439

6540
## Product updates
6641

6742
Microsoft Defender Antivirus requires monthly updates (KB4052623) known as *platform updates*.
6843

69-
You can manage the distribution of updates through one of the following methods:
44+
You can manage the distribution of updates using one of the following methods:
7045

7146
- [Windows Server Update Service (WSUS)](/mem/configmgr/protect/deploy-use/endpoint-definitions-wsus#to-synchronize-endpoint-protection-definition-updates-in-standalone-wsus)
7247
- [Microsoft Configuration Manager](/configmgr/sum/understand/software-updates-introduction)
@@ -99,6 +74,17 @@ Updates contain:
9974
- Serviceability improvements
10075
- Integration improvements (Cloud, [Microsoft Defender XDR](/defender-xdr/microsoft-365-defender))
10176

77+
### August-2025 (Platform: 4.18.25080.5 | Engine: 1.1.25080.5)
78+
79+
- Security intelligence update version: **1.437.1.0**
80+
- Release date: **September 16, 2025 (Engine) / September 17, 2025 (Platform)**
81+
- Platform: **4.18.25080.5**
82+
- Engine: **1.1.25080.5**
83+
- Support phase: **Security and Critical Updates**
84+
85+
#### What's new
86+
87+
Improved Defender update reliability by allowing non-admin processes to trigger shared signature updates, reducing unnecessary privilege requirements.
10288

10389
### July-2025 (Platform: 4.18.25070.5 | Engine: 1.1.25070.4)
10490

0 commit comments

Comments
 (0)