Skip to content

Commit 5091cd9

Browse files
authored
Merge pull request #5327 from kurtsarens/docs-editor/microsoft-defender-antivirus-u-1761133225
archived older versions (n-2)
2 parents 7ad9e90 + ac2b792 commit 5091cd9

File tree

1 file changed

+0
-76
lines changed

1 file changed

+0
-76
lines changed

defender-endpoint/microsoft-defender-antivirus-updates.md

Lines changed: 0 additions & 76 deletions
Original file line numberDiff line numberDiff line change
@@ -101,82 +101,6 @@ Updates contain:
101101

102102
Improved Defender update reliability by allowing non-admin processes to trigger shared signature updates, reducing unnecessary privilege requirements.
103103

104-
### July-2025 (Platform: 4.18.25070.5 | Engine: 1.1.25070.4)
105-
106-
- Security intelligence update version: **1.435.11.0**
107-
- Release date: **August 5, 2025 (Engine) / August 6, 2025 (Platform)**
108-
- Platform: **4.18.25070.5**
109-
- Engine: **1.1.25070.4**
110-
- Support phase: **Security and Critical Updates**
111-
112-
#### What's new
113-
114-
- Enhanced Passive Mode Scanning Behavior
115-
When Microsoft Defender is in Passive mode, an Antivirus scan will not occur after a signature update , unless specifically set in the policy setting DisableScanOnUpdate.
116-
- Improved Tamper Protection Handling
117-
Optimized the configuration process for Tamper Protection in multi-threaded environments to ensure more reliable behavior.
118-
- Digital Signature Verification Performance Boost
119-
Enhanced the efficiency of digital signature verification to improve overall system performance.
120-
- Refined ASR Rule Exclusion Processing
121-
Refined exclusion processing and resolved false positives for the Attack Surface Reduction (ASR) rule: Block Office applications from injecting code into other processes.
122-
123-
124-
### June-2025 (Platform: 4.18.25060.7 | Engine: 1.1.25060.6)
125-
126-
- Security intelligence update version: **1.433.2.0**
127-
- Release date: **July 22, 2025 (Engine)** / **July 22, 2025 (Platform)**
128-
- Platform: **4.18.25060.7**
129-
- Engine: **1.1.25060.6**
130-
- Support phase: **Security and Critical Updates**
131-
132-
#### What's new
133-
134-
- Added filtering to improve scan stability and prevent engine crashes
135-
- Additional performance improvements to prevent concurrent scans. This change ensures that if a quick or full scan is already running, no additional quick or full scan scans are initiated from `MpCmdRun` or Powershell (`Start-Scan`).
136-
- Resolved the issue where subfolder exclusions were not being honored in Microsoft Defender Antivirus scans related to non-Microsoft SIEM solutions. This fix ensures that specified subfolders are now correctly excluded from scans, preventing unnecessary detections and improving overall system performance.
137-
138-
### May-2025 (Platform: 4.18.25050.5 | Engine: 1.1.25050.6)
139-
140-
- Security intelligence update version: **1.431.19.0**
141-
- Release date:  **June 13, 2025 (Engine)** / **June 13, 2025 (Platform)**
142-
- Platform: **4.18.25050.5**
143-
- Engine: **1.1.25050.6**
144-
- Support phase: **Security and Critical Updates**
145-
146-
#### What's new
147-
148-
- Windows multisession SKUs are now properly classified as client SKUs for signature versioning
149-
- `EnableDynamicSignatureDroppedEventReporting` configuration is now available in Intune (see [Event ID 2011](/defender-endpoint/troubleshoot-microsoft-defender-antivirus#event-id-2011))
150-
- The display name and description is now displayed correctly for the [device control](/defender-endpoint/device-control-overview) filter driver in Windows services
151-
- Improved performance for kernel driver
152-
- Improvements to [network protection](/defender-endpoint/network-protection#overview-of-network-protection) performance related to packet loss during high network utilization
153-
- Reliability improvements to network protection during service shutdown
154-
- Enriched [Event ID 1000](/defender-endpoint/troubleshoot-microsoft-defender-antivirus#event-id-1000) to include `ScanOnlyIfIdle` and scan priority
155-
- Improved device control Windows Portal Device (WPD) device discovery in File explorer. (For more information about device control, see [Device control policy samples and scenarios](/defender-endpoint/device-control-overview#device-control-policy-samples-and-scenarios).)
156-
- Resolved discrepancy in [device health reports](/defender-endpoint/device-health-reports) between signature publish and signature install date and time
157-
- Performance improvements when scanning files/folders with extended attributes
158-
- Reliability improvement in the Defender kernel driver to avoid crashing when there's excessive disk input/output
159-
- Added exponential backoff support to Core Service 1DS manager telemetry module to address memory consumption and DNS flooding issues
160-
161-
### April-2025 (Platform: 4.18.25040.2 | Engine: 1.1.25040.1)
162-
163-
- Security intelligence update version: **1.429.3.0**
164-
- Release date:  **May 14, 2025 (Engine)** / **May 22, 2025 (Platform)**
165-
- Platform: **4.18.25040.2**
166-
- Engine: **1.1.25040.1**
167-
- Support phase: **Security and Critical Updates**
168-
169-
#### What's new
170-
171-
- Fixed TVM Block where we failed to block a trusted file
172-
- Fixed Microsoft Defender platform update timestamp to reflect the actual update time.
173-
- The [1002 event](/defender-endpoint/troubleshoot-microsoft-defender-antivirus#event-id-1002) (An anti-malware scan was stopped before it finished) now includes details of the stop reason.
174-
- Added more details to the [1000 event](/defender-endpoint/troubleshoot-microsoft-defender-antivirus#event-id-1000) (Scan started), like scan trigger and scan on idle.
175-
- Improved attack surface reduction file processing to correctly handle ["allow" Indicators of Compromise](/defender-endpoint/indicators-overview) (IoCs).
176-
- Improvement in health reporting for machines that are rebooted or hibernated.
177-
- Improved performance for [Smart App Control](/windows/apps/develop/smart-app-control/overview) (SAC) trusted file handling.
178-
- Improved [device control](/defender-endpoint/device-control-overview) logic for offline printers.
179-
180104
### Previous version updates: Technical upgrade support only
181105

182106
After a new package version is released, support for the previous two versions is reduced to technical upgrade support only. For more information about previous versions, see [Microsoft Defender Antivirus updates: Previous versions for technical upgrade support](msda-updates-previous-versions-technical-upgrade-support.md).

0 commit comments

Comments
 (0)