Skip to content

Commit 912aa92

Browse files
committed
Update windows-whatsnew.md
1 parent 787298a commit 912aa92

File tree

1 file changed

+50
-22
lines changed

1 file changed

+50
-22
lines changed

defender-endpoint/windows-whatsnew.md

Lines changed: 50 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -54,7 +54,29 @@ All updates contain:
5454
| Windows 11 23H2 | [KB5058502](https://support.microsoft.com/en-us/topic/may-27-2025-kb5058502-os-22621-5413-and-22631-5413-preview-6291789c-1eea-4227-9740-a701af6de688) |
5555
| Windows 10 22/H2 | [KB5058481](https://support.microsoft.com/en-us/topic/may-28-2025-kb5058481-os-build-19045-5917-preview-7698d6e7-dd65-494d-b523-aa4c6aa913a2) |
5656

57+
### What's new
58+
59+
#### Data Loss Prevention (DLP)
60+
61+
- On-Demand Scan: Improved the functionality, performance, and reliability of the Cold Data Scan feature. This enhancement enables deeper, more consistent scanning of archived or infrequently accessed data, helping organizations uncover potential data risks hidden in long-term storage.
62+
- General Stability and Performance Improvements: Additional under-the-hood optimizations to improve overall system performance, reliability, and stability.
63+
64+
#### Identity
65+
66+
- Entity sync enrichment: Expanded the capabilities of the SenseIdentity client to enhance Active Directory (AD) entity synchronization. This update introduces support for syncing new entity types including Group Policy Objects, Authentication Silos, and Domain Controller computer accounts for all Domain Controllers within trusted domains. Additionally, the update enriches existing synced entities (Domain, Account, and Group) with a broader set of attributes, enabling more comprehensive visibility and detection capabilities.
67+
68+
#### Threat protection
69+
70+
- User contaminant improvements
5771

72+
#### Network Detection and Response (NDR)
73+
74+
- Improved data telemetry providing better visibility and insights
75+
76+
#### SOC experience
77+
78+
- Improved Data Completeness and Detection: Enhancements have been made to improve the completeness of data collected and reduce the time it takes to detect potential data loss incidents. These improvements enable faster and more accurate identification of data exfiltration attempts across monitored endpoints.
79+
- Improved Handling for Offline Network Environments: Refined the handling of scenarios where devices operate in offline or restricted network environments. Specifically addresses cases where result uploads to blob storage fail due to offline Certificate Revocation List (CRL) checks, ensuring better reliability and continuity in data collection.
5880

5981
## July-2024 (Release version: 10.8760)
6082

@@ -70,7 +92,7 @@ All updates contain:
7092

7193
### What's new
7294

73-
**Data Loss Prevention (DLP)**
95+
#### Data Loss Prevention (DLP)
7496

7597
- Scoped classification (Know Your Data policy): Scope classification and activity events across workloads.
7698
- Device group discovery and scoping: Scope [Endpoint DLP](/purview/endpoint-dlp-learn-about) custom policy based on the device or device group.
@@ -84,7 +106,7 @@ All updates contain:
84106

85107
### What's new
86108

87-
**Configuration Management**
109+
#### Configuration Management
88110

89111
- Fixed an issue that caused empty policies to appear in the UI.
90112
- Configured Windows Defender Application Control(WDAC) policies to block undesired applications from running on the device.
@@ -97,31 +119,36 @@ All updates contain:
97119

98120
### What's new
99121

100-
- **Endpoint Detection and Response**
101-
- Enabled support for IPV6 connections in Live Response connection commands.
102-
- Fixed an issue in Downlevel Unified Agent that caused ServerRoles not to be populated.
122+
#### Endpoint Detection and Response
123+
124+
- Enabled support for IPV6 connections in Live Response connection commands.
125+
- Fixed an issue in Downlevel Unified Agent that caused ServerRoles not to be populated.
103126

104-
- **Threat Vulnerability Management**
105-
- An issue related to the agent's monitoring of deleted registry keys no longer occurs.
106-
- Added a new capability to enable/disable registry monitoring through configuration settings.
107-
108-
- **Network Detection and Response (NDR) Performance Enhancements**
109-
- Introduced performance enhancements to minimize the CPU and memory footprint of the agent.
110-
- Enhanced the accuracy of network detections.
127+
#### Threat Vulnerability Management
128+
129+
- An issue related to the agent's monitoring of deleted registry keys no longer occurs.
130+
- Added a new capability to enable/disable registry monitoring through configuration settings.
131+
132+
#### Network Detection and Response (NDR) Performance Enhancements
133+
134+
- Introduced performance enhancements to minimize the CPU and memory footprint of the agent.
135+
- Enhanced the accuracy of network detections.
111136

112-
- **Data Loss Prevention (DLP)**
113-
- Introduced multiple performance and stability fixes.
137+
#### Data Loss Prevention (DLP)
138+
139+
- Introduced multiple performance and stability fixes.
114140

115-
- **Security Configuration Management**
116-
- Policies that include special characters are now supported.
141+
#### Security Configuration Management
142+
143+
- Policies that include special characters are now supported.
117144

118145
## Dec-2023 (Release version: 10.8672.25926.1019)
119146

120147
|OS |KB |Release version |
121148
|---------|---------|---------|
122149
|Windows Server 2012 R2, 2016 |[KB5005292](https://support.microsoft.com/topic/microsoft-defender-for-endpoint-update-for-edr-sensor-f8f69773-f17f-420f-91f4-a8e5167284ac)|10.8672.25926.1019|
123150

124-
**What's new**
151+
### What's new
125152

126153
- Supports Expanded User Contain capabilities
127154

@@ -131,7 +158,7 @@ All updates contain:
131158
|---------|---------|---------|
132159
|Windows Server 2012 R2, 2016 |[KB5005292](https://support.microsoft.com/topic/microsoft-defender-for-endpoint-update-for-edr-sensor-f8f69773-f17f-420f-91f4-a8e5167284ac)|10.8560.25364.1036|
133160

134-
**What's new**
161+
### What's new
135162

136163
- Supports User Contain availability
137164

@@ -141,7 +168,7 @@ All updates contain:
141168
|---------|---------|---------|
142169
|Windows Server 2012 R2, 2016 |[KB5005292](https://support.microsoft.com/topic/microsoft-defender-for-endpoint-update-for-edr-sensor-f8f69773-f17f-420f-91f4-a8e5167284ac)|10.8295.22621.1023|
143170

144-
**What's new**
171+
### What's new
145172

146173
- Supports new security settings management capabilities
147174

@@ -151,7 +178,7 @@ All updates contain:
151178
|---------|---------|---------|
152179
|Windows Server 2012 R2, 2016 |[KB5005292](https://support.microsoft.com/topic/microsoft-defender-for-endpoint-update-for-edr-sensor-f8f69773-f17f-420f-91f4-a8e5167284ac)|10.8295.22621.1019|
153180

154-
**What's new**
181+
### What's new
155182

156183
- Improved command and control security, quality fixes
157184

@@ -175,7 +202,7 @@ All updates contain:
175202
|Windows 10 20H2/21H1/21H2<br> Windows Server 20H2 (Vibranium) | [KB5016688](https://support.microsoft.com/topic/august-26-2022-kb5016688-os-builds-19042-1949-19043-1949-and-19044-1949-preview-ec31ebdc-067d-44dd-beb0-eabcc984d843) | 10.8210.19041.1949 |
176203
|Windows Server 2019 (RS5) |[KB5016690](https://support.microsoft.com/topic/august-23-2022-kb5016690-os-build-17763-3346-preview-b81d1ac5-75c7-42c1-b638-f13aa4242f42) |10.8210.17763.3346 |
177204

178-
**What's new**
205+
### What's new
179206

180207
- Added a fix to resolve a missing intermediate certificate issue with the use of "TelemetryProxyServer" on Windows Server 2012 R2 running the unified agent.
181208
- Enhanced [Endpoint DLP](/purview/endpoint-dlp-learn-about) with ability to protect password protected and encrypted files and not label files.
@@ -191,7 +218,8 @@ All updates contain:
191218
> Update package KB5005292 is on a gradual rollout schedule through Windows Update. Towards the end of this schedule, the package will be published completely, including to the update catalog for manual download. For the current release, this will be in the second half of October. If you want to test the package sooner, you can use [gradual rollout controls for platform updates](configure-updates.md) to select the Preview channel.
192219
193220

194-
See also:
221+
## See also
222+
195223
- [What's new in Microsoft Defender for Endpoint](whats-new-in-microsoft-defender-endpoint.md)
196224
- [What's new in Defender for Endpoint on macOS](mac-whatsnew.md)
197225
- [What's new in Defender for Endpoint on iOS](ios-whatsnew.md)

0 commit comments

Comments
 (0)