Skip to content

Commit cfdf815

Browse files
authored
Merge branch 'main' into docs-editor/microsoft-defender-antivirus-u-1761133225
2 parents 9cb7ac6 + 7ad9e90 commit cfdf815

File tree

1 file changed

+88
-0
lines changed

1 file changed

+88
-0
lines changed

defender-endpoint/msda-updates-previous-versions-technical-upgrade-support.md

Lines changed: 88 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -28,6 +28,94 @@ Microsoft regularly releases [security intelligence updates and product updates
2828

2929
## Engine and platform updates
3030

31+
### July-2025 (Platform: 4.18.25070.5 | Engine: 1.1.25070.4)
32+
33+
- Security intelligence update version: **1.435.11.0**
34+
35+
- Release date: **August 5, 2025 (Engine) / August 6, 2025 (Platform)**
36+
37+
- Platform: **4.18.25070.5**
38+
39+
- Engine: **1.1.25070.4**
40+
41+
- Support phase: **Technical upgrade support (only)**
42+
43+
What's new
44+
45+
- Enhanced Passive Mode Scanning Behavior When Microsoft Defender is in Passive mode, an Antivirus scan will not occur after a signature update , unless specifically set in the policy setting DisableScanOnUpdate.
46+
- Improved Tamper Protection Handling Optimized the configuration process for Tamper Protection in multi-threaded environments to ensure more reliable behavior.
47+
- Digital Signature Verification Performance Boost Enhanced the efficiency of digital signature verification to improve overall system performance.
48+
- Refined ASR Rule Exclusion Processing Refined exclusion processing and resolved false positives for the Attack Surface Reduction (ASR) rule: Block Office applications from injecting code into other processes.
49+
50+
51+
### June-2025 (Platform: 4.18.25060.7 | Engine: 1.1.25060.6)
52+
53+
- Security intelligence update version: **1.433.2.0**
54+
55+
- Release date: **July 22, 2025 (Engine)** / **July 22, 2025 (Platform)**
56+
57+
- Platform: **4.18.25060.7**
58+
59+
- Engine: **1.1.25060.6**
60+
61+
- Support phase: **Technical upgrade support (only)**
62+
63+
What's new
64+
65+
- Added filtering to improve scan stability and prevent engine crashes
66+
- Additional performance improvements to prevent concurrent scans. This change ensures that if a quick or full scan is already running, no additional quick or full scan scans are initiated from `MpCmdRun` or Powershell (`Start-Scan`).
67+
- Resolved the issue where subfolder exclusions were not being honored in Microsoft Defender Antivirus scans related to non-Microsoft SIEM solutions. This fix ensures that specified subfolders are now correctly excluded from scans, preventing unnecessary detections and improving overall system performance.
68+
69+
### May-2025 (Platform: 4.18.25050.5 | Engine: 1.1.25050.6)
70+
71+
- Security intelligence update version: **1.431.19.0**
72+
73+
- Release date:  **June 13, 2025 (Engine)** / **June 13, 2025 (Platform)**
74+
75+
- Platform: **4.18.25050.5**
76+
77+
- Engine: **1.1.25050.6**
78+
79+
- Support phase: **Technical upgrade support (only)**
80+
81+
What's new
82+
83+
- Windows multisession SKUs are now properly classified as client SKUs for signature versioning
84+
- `EnableDynamicSignatureDroppedEventReporting` configuration is now available in Intune (see [Event ID 2011](/defender-endpoint/troubleshoot-microsoft-defender-antivirus#event-id-2011))
85+
- The display name and description is now displayed correctly for the [device control](/defender-endpoint/device-control-overview) filter driver in Windows services
86+
- Improved performance for kernel driver
87+
- Improvements to [network protection](/defender-endpoint/network-protection#overview-of-network-protection) performance related to packet loss during high network utilization
88+
- Reliability improvements to network protection during service shutdown
89+
- Enriched [Event ID 1000](/defender-endpoint/troubleshoot-microsoft-defender-antivirus#event-id-1000) to include `ScanOnlyIfIdle` and scan priority
90+
- Improved device control Windows Portal Device (WPD) device discovery in File explorer. (For more information about device control, see [Device control policy samples and scenarios](/defender-endpoint/device-control-overview#device-control-policy-samples-and-scenarios).)
91+
- Resolved discrepancy in [device health reports](/defender-endpoint/device-health-reports) between signature publish and signature install date and time
92+
- Performance improvements when scanning files/folders with extended attributes
93+
- Reliability improvement in the Defender kernel driver to avoid crashing when there's excessive disk input/output
94+
- Added exponential backoff support to Core Service 1DS manager telemetry module to address memory consumption and DNS flooding issues
95+
96+
### April-2025 (Platform: 4.18.25040.2 | Engine: 1.1.25040.1)
97+
98+
- Security intelligence update version: **1.429.3.0**
99+
100+
- Release date:  **May 14, 2025 (Engine)** / **May 22, 2025 (Platform)**
101+
102+
- Platform: **4.18.25040.2**
103+
104+
- Engine: **1.1.25040.1**
105+
106+
- Support phase: **Technical upgrade support (only)**
107+
108+
What's new
109+
110+
- Fixed TVM Block where we failed to block a trusted file
111+
- Fixed Microsoft Defender platform update timestamp to reflect the actual update time.
112+
- The [1002 event](/defender-endpoint/troubleshoot-microsoft-defender-antivirus#event-id-1002) (An anti-malware scan was stopped before it finished) now includes details of the stop reason.
113+
- Added more details to the [1000 event](/defender-endpoint/troubleshoot-microsoft-defender-antivirus#event-id-1000) (Scan started), like scan trigger and scan on idle.
114+
- Improved attack surface reduction file processing to correctly handle ["allow" Indicators of Compromise](/defender-endpoint/indicators-overview) (IoCs).
115+
- Improvement in health reporting for machines that are rebooted or hibernated.
116+
- Improved performance for [Smart App Control](/windows/apps/develop/smart-app-control/overview) (SAC) trusted file handling.
117+
- Improved [device control](/defender-endpoint/device-control-overview) logic for offline printers.
118+
31119
### March-2025 (Platform: 4.18.25030.2 | Engine 1.1.25030.1)
32120

33121
- Security intelligence update version: **1.427.3.0**

0 commit comments

Comments
 (0)