You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-endpoint/windows-whatsnew.md
+50-22Lines changed: 50 additions & 22 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -54,7 +54,29 @@ All updates contain:
54
54
| Windows 11 23H2 |[KB5058502](https://support.microsoft.com/en-us/topic/may-27-2025-kb5058502-os-22621-5413-and-22631-5413-preview-6291789c-1eea-4227-9740-a701af6de688)|
55
55
| Windows 10 22/H2 |[KB5058481](https://support.microsoft.com/en-us/topic/may-28-2025-kb5058481-os-build-19045-5917-preview-7698d6e7-dd65-494d-b523-aa4c6aa913a2)|
56
56
57
+
### What's new
58
+
59
+
#### Data Loss Prevention (DLP)
60
+
61
+
- On-Demand Scan: Improved the functionality, performance, and reliability of the Cold Data Scan feature. This enhancement enables deeper, more consistent scanning of archived or infrequently accessed data, helping organizations uncover potential data risks hidden in long-term storage.
62
+
- General Stability and Performance Improvements: Additional under-the-hood optimizations to improve overall system performance, reliability, and stability.
63
+
64
+
#### Identity
65
+
66
+
- Entity sync enrichment: Expanded the capabilities of the SenseIdentity client to enhance Active Directory (AD) entity synchronization. This update introduces support for syncing new entity types including Group Policy Objects, Authentication Silos, and Domain Controller computer accounts for all Domain Controllers within trusted domains. Additionally, the update enriches existing synced entities (Domain, Account, and Group) with a broader set of attributes, enabling more comprehensive visibility and detection capabilities.
67
+
68
+
#### Threat protection
69
+
70
+
- User contaminant improvements
57
71
72
+
#### Network Detection and Response (NDR)
73
+
74
+
- Improved data telemetry providing better visibility and insights
75
+
76
+
#### SOC experience
77
+
78
+
- Improved Data Completeness and Detection: Enhancements have been made to improve the completeness of data collected and reduce the time it takes to detect potential data loss incidents. These improvements enable faster and more accurate identification of data exfiltration attempts across monitored endpoints.
79
+
- Improved Handling for Offline Network Environments: Refined the handling of scenarios where devices operate in offline or restricted network environments. Specifically addresses cases where result uploads to blob storage fail due to offline Certificate Revocation List (CRL) checks, ensuring better reliability and continuity in data collection.
58
80
59
81
## July-2024 (Release version: 10.8760)
60
82
@@ -70,7 +92,7 @@ All updates contain:
70
92
71
93
### What's new
72
94
73
-
**Data Loss Prevention (DLP)**
95
+
#### Data Loss Prevention (DLP)
74
96
75
97
- Scoped classification (Know Your Data policy): Scope classification and activity events across workloads.
76
98
- Device group discovery and scoping: Scope [Endpoint DLP](/purview/endpoint-dlp-learn-about) custom policy based on the device or device group.
@@ -84,7 +106,7 @@ All updates contain:
84
106
85
107
### What's new
86
108
87
-
**Configuration Management**
109
+
#### Configuration Management
88
110
89
111
- Fixed an issue that caused empty policies to appear in the UI.
90
112
- Configured Windows Defender Application Control(WDAC) policies to block undesired applications from running on the device.
@@ -97,31 +119,36 @@ All updates contain:
97
119
98
120
### What's new
99
121
100
-
-**Endpoint Detection and Response**
101
-
- Enabled support for IPV6 connections in Live Response connection commands.
102
-
- Fixed an issue in Downlevel Unified Agent that caused ServerRoles not to be populated.
122
+
#### Endpoint Detection and Response
123
+
124
+
- Enabled support for IPV6 connections in Live Response connection commands.
125
+
- Fixed an issue in Downlevel Unified Agent that caused ServerRoles not to be populated.
103
126
104
-
-**Threat Vulnerability Management**
105
-
- An issue related to the agent's monitoring of deleted registry keys no longer occurs.
106
-
- Added a new capability to enable/disable registry monitoring through configuration settings.
107
-
108
-
-**Network Detection and Response (NDR) Performance Enhancements**
109
-
- Introduced performance enhancements to minimize the CPU and memory footprint of the agent.
110
-
- Enhanced the accuracy of network detections.
127
+
#### Threat Vulnerability Management
128
+
129
+
- An issue related to the agent's monitoring of deleted registry keys no longer occurs.
130
+
- Added a new capability to enable/disable registry monitoring through configuration settings.
131
+
132
+
#### Network Detection and Response (NDR) Performance Enhancements
133
+
134
+
- Introduced performance enhancements to minimize the CPU and memory footprint of the agent.
135
+
- Enhanced the accuracy of network detections.
111
136
112
-
-**Data Loss Prevention (DLP)**
113
-
- Introduced multiple performance and stability fixes.
137
+
#### Data Loss Prevention (DLP)
138
+
139
+
- Introduced multiple performance and stability fixes.
114
140
115
-
-**Security Configuration Management**
116
-
- Policies that include special characters are now supported.
141
+
#### Security Configuration Management
142
+
143
+
- Policies that include special characters are now supported.
117
144
118
145
## Dec-2023 (Release version: 10.8672.25926.1019)
119
146
120
147
|OS |KB |Release version |
121
148
|---------|---------|---------|
122
149
|Windows Server 2012 R2, 2016 |[KB5005292](https://support.microsoft.com/topic/microsoft-defender-for-endpoint-update-for-edr-sensor-f8f69773-f17f-420f-91f4-a8e5167284ac)|10.8672.25926.1019|
123
150
124
-
**What's new**
151
+
### What's new
125
152
126
153
- Supports Expanded User Contain capabilities
127
154
@@ -131,7 +158,7 @@ All updates contain:
131
158
|---------|---------|---------|
132
159
|Windows Server 2012 R2, 2016 |[KB5005292](https://support.microsoft.com/topic/microsoft-defender-for-endpoint-update-for-edr-sensor-f8f69773-f17f-420f-91f4-a8e5167284ac)|10.8560.25364.1036|
133
160
134
-
**What's new**
161
+
### What's new
135
162
136
163
- Supports User Contain availability
137
164
@@ -141,7 +168,7 @@ All updates contain:
141
168
|---------|---------|---------|
142
169
|Windows Server 2012 R2, 2016 |[KB5005292](https://support.microsoft.com/topic/microsoft-defender-for-endpoint-update-for-edr-sensor-f8f69773-f17f-420f-91f4-a8e5167284ac)|10.8295.22621.1023|
143
170
144
-
**What's new**
171
+
### What's new
145
172
146
173
- Supports new security settings management capabilities
147
174
@@ -151,7 +178,7 @@ All updates contain:
151
178
|---------|---------|---------|
152
179
|Windows Server 2012 R2, 2016 |[KB5005292](https://support.microsoft.com/topic/microsoft-defender-for-endpoint-update-for-edr-sensor-f8f69773-f17f-420f-91f4-a8e5167284ac)|10.8295.22621.1019|
153
180
154
-
**What's new**
181
+
### What's new
155
182
156
183
- Improved command and control security, quality fixes
157
184
@@ -175,7 +202,7 @@ All updates contain:
175
202
|Windows 10 20H2/21H1/21H2<br> Windows Server 20H2 (Vibranium) |[KB5016688](https://support.microsoft.com/topic/august-26-2022-kb5016688-os-builds-19042-1949-19043-1949-and-19044-1949-preview-ec31ebdc-067d-44dd-beb0-eabcc984d843)| 10.8210.19041.1949 |
176
203
|Windows Server 2019 (RS5) |[KB5016690](https://support.microsoft.com/topic/august-23-2022-kb5016690-os-build-17763-3346-preview-b81d1ac5-75c7-42c1-b638-f13aa4242f42)|10.8210.17763.3346 |
177
204
178
-
**What's new**
205
+
### What's new
179
206
180
207
- Added a fix to resolve a missing intermediate certificate issue with the use of "TelemetryProxyServer" on Windows Server 2012 R2 running the unified agent.
181
208
- Enhanced [Endpoint DLP](/purview/endpoint-dlp-learn-about) with ability to protect password protected and encrypted files and not label files.
@@ -191,7 +218,8 @@ All updates contain:
191
218
> Update package KB5005292 is on a gradual rollout schedule through Windows Update. Towards the end of this schedule, the package will be published completely, including to the update catalog for manual download. For the current release, this will be in the second half of October. If you want to test the package sooner, you can use [gradual rollout controls for platform updates](configure-updates.md) to select the Preview channel.
192
219
193
220
194
-
See also:
221
+
## See also
222
+
195
223
-[What's new in Microsoft Defender for Endpoint](whats-new-in-microsoft-defender-endpoint.md)
196
224
-[What's new in Defender for Endpoint on macOS](mac-whatsnew.md)
197
225
-[What's new in Defender for Endpoint on iOS](ios-whatsnew.md)
0 commit comments