You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
-[Windows Server 2022 updates](https://support.microsoft.com/topic/windows-server-2022-update-history-e1caa597-00c5-4ab9-9f3e-8212fe80b2ee)
37
36
-[Windows Server 2019 updates](https://support.microsoft.com/topic/windows-10-and-windows-server-2019-update-history-725fc2e1-4443-6831-a5ca-51ff5cbcb059)
37
+
-[Windows Server 2025 updates](https://support.microsoft.com/en-us/topic/windows-server-2025-update-history-10f58da7-e57b-4a9d-9c16-9f1dcd72d7d7)
38
38
39
39
For the latest updates to Microsoft Defender for Endpoint all up, see [What's new in Defender for Endpoint](whats-new-in-microsoft-defender-endpoint.md).
| Windows 11 24H2 |[KB5058499](https://support.microsoft.com/en-us/topic/may-28-2025-kb5058499-os-build-26100-4202-preview-d4c2f1ee-8138-4038-b705-546945076f92)|
54
+
| Windows 11 23H2 |[KB5058502](https://support.microsoft.com/en-us/topic/may-27-2025-kb5058502-os-22621-5413-and-22631-5413-preview-6291789c-1eea-4227-9740-a701af6de688)|
55
+
| Windows 10 22/H2 |[KB5058481](https://support.microsoft.com/en-us/topic/may-28-2025-kb5058481-os-build-19045-5917-preview-7698d6e7-dd65-494d-b523-aa4c6aa913a2)|
56
+
57
+
### What's new
58
+
59
+
#### Data Loss Prevention (DLP)
60
+
61
+
- On-Demand Scan: Improved the functionality, performance, and reliability of the Cold Data Scan feature. This enhancement enables deeper, more consistent scanning of archived or infrequently accessed data, helping organizations uncover potential data risks hidden in long-term storage.
62
+
- General Stability and Performance Improvements: Additional under-the-hood optimizations to improve overall system performance, reliability, and stability.
63
+
64
+
#### Identity
65
+
66
+
- Entity sync enrichment: Expanded the capabilities of the SenseIdentity client to enhance Active Directory (AD) entity synchronization. This update introduces support for syncing new entity types including Group Policy Objects, Authentication Silos, and Domain Controller computer accounts for all Domain Controllers within trusted domains. Additionally, the update enriches existing synced entities (Domain, Account, and Group) with a broader set of attributes, enabling more comprehensive visibility and detection capabilities.
67
+
68
+
#### Threat protection
69
+
70
+
- User contaminant improvements
71
+
72
+
#### Network Detection and Response (NDR)
73
+
74
+
- Improved data telemetry providing better visibility and insights
75
+
76
+
#### SOC experience
77
+
78
+
- Improved Data Completeness and Detection: Enhancements have been made to improve the completeness of data collected and reduce the time it takes to detect potential data loss incidents. These improvements enable faster and more accurate identification of data exfiltration attempts across monitored endpoints.
79
+
- Improved Handling for Offline Network Environments: Refined the handling of scenarios where devices operate in offline or restricted network environments. Specifically addresses cases where result uploads to blob storage fail due to offline Certificate Revocation List (CRL) checks, ensuring better reliability and continuity in data collection.
80
+
49
81
## July-2024 (Release version: 10.8760)
50
82
51
83
|OS |KB |
@@ -60,7 +92,7 @@ All updates contain:
60
92
61
93
### What's new
62
94
63
-
**Data Loss Prevention (DLP)**
95
+
#### Data Loss Prevention (DLP)
64
96
65
97
- Scoped classification (Know Your Data policy): Scope classification and activity events across workloads.
66
98
- Device group discovery and scoping: Scope [Endpoint DLP](/purview/endpoint-dlp-learn-about) custom policy based on the device or device group.
@@ -74,10 +106,10 @@ All updates contain:
74
106
75
107
### What's new
76
108
77
-
**Configuration Management**
109
+
#### Configuration Management
78
110
79
111
- Fixed an issue that caused empty policies to appear in the UI.
80
-
- Configured Windows Defender Application Control(WDAC) policies to block undesired applications from running on the device.
112
+
- Configured Windows Defender Application Control(WDAC) policies to block undesired applications from running on the device.
81
113
82
114
## Feb-2024 (Release version: 10.8735.26020.1009)
83
115
@@ -87,31 +119,36 @@ All updates contain:
87
119
88
120
### What's new
89
121
90
-
-**Endpoint Detection and Response**
91
-
- Enabled support for IPV6 connections in Live Response connection commands.
92
-
- Fixed an issue in Downlevel Unified Agent that caused ServerRoles not to be populated.
122
+
#### Endpoint Detection and Response
123
+
124
+
- Enabled support for IPV6 connections in Live Response connection commands.
125
+
- Fixed an issue in Downlevel Unified Agent that caused ServerRoles not to be populated.
93
126
94
-
-**Threat Vulnerability Management**
95
-
- An issue related to the agent's monitoring of deleted registry keys no longer occurs.
96
-
- Added a new capability to enable/disable registry monitoring through configuration settings.
97
-
98
-
-**Network Detection and Response (NDR) Performance Enhancements**
99
-
- Introduced performance enhancements to minimize the CPU and memory footprint of the agent.
100
-
- Enhanced the accuracy of network detections.
127
+
#### Threat Vulnerability Management
128
+
129
+
- An issue related to the agent's monitoring of deleted registry keys no longer occurs.
130
+
- Added a new capability to enable/disable registry monitoring through configuration settings.
131
+
132
+
#### Network Detection and Response (NDR) Performance Enhancements
133
+
134
+
- Introduced performance enhancements to minimize the CPU and memory footprint of the agent.
135
+
- Enhanced the accuracy of network detections.
101
136
102
-
-**Data Loss Prevention (DLP)**
103
-
- Introduced multiple performance and stability fixes.
137
+
#### Data Loss Prevention (DLP)
138
+
139
+
- Introduced multiple performance and stability fixes.
104
140
105
-
-**Security Configuration Management**
106
-
- Policies that include special characters are now supported.
141
+
#### Security Configuration Management
142
+
143
+
- Policies that include special characters are now supported.
107
144
108
145
## Dec-2023 (Release version: 10.8672.25926.1019)
109
146
110
147
|OS |KB |Release version |
111
148
|---------|---------|---------|
112
149
|Windows Server 2012 R2, 2016 |[KB5005292](https://support.microsoft.com/topic/microsoft-defender-for-endpoint-update-for-edr-sensor-f8f69773-f17f-420f-91f4-a8e5167284ac)|10.8672.25926.1019|
113
150
114
-
**What's new**
151
+
### What's new
115
152
116
153
- Supports Expanded User Contain capabilities
117
154
@@ -121,7 +158,7 @@ All updates contain:
121
158
|---------|---------|---------|
122
159
|Windows Server 2012 R2, 2016 |[KB5005292](https://support.microsoft.com/topic/microsoft-defender-for-endpoint-update-for-edr-sensor-f8f69773-f17f-420f-91f4-a8e5167284ac)|10.8560.25364.1036|
123
160
124
-
**What's new**
161
+
### What's new
125
162
126
163
- Supports User Contain availability
127
164
@@ -131,7 +168,7 @@ All updates contain:
131
168
|---------|---------|---------|
132
169
|Windows Server 2012 R2, 2016 |[KB5005292](https://support.microsoft.com/topic/microsoft-defender-for-endpoint-update-for-edr-sensor-f8f69773-f17f-420f-91f4-a8e5167284ac)|10.8295.22621.1023|
133
170
134
-
**What's new**
171
+
### What's new
135
172
136
173
- Supports new security settings management capabilities
137
174
@@ -141,7 +178,7 @@ All updates contain:
141
178
|---------|---------|---------|
142
179
|Windows Server 2012 R2, 2016 |[KB5005292](https://support.microsoft.com/topic/microsoft-defender-for-endpoint-update-for-edr-sensor-f8f69773-f17f-420f-91f4-a8e5167284ac)|10.8295.22621.1019|
143
180
144
-
**What's new**
181
+
### What's new
145
182
146
183
- Improved command and control security, quality fixes
147
184
@@ -165,7 +202,7 @@ All updates contain:
165
202
|Windows 10 20H2/21H1/21H2<br> Windows Server 20H2 (Vibranium) |[KB5016688](https://support.microsoft.com/topic/august-26-2022-kb5016688-os-builds-19042-1949-19043-1949-and-19044-1949-preview-ec31ebdc-067d-44dd-beb0-eabcc984d843)| 10.8210.19041.1949 |
166
203
|Windows Server 2019 (RS5) |[KB5016690](https://support.microsoft.com/topic/august-23-2022-kb5016690-os-build-17763-3346-preview-b81d1ac5-75c7-42c1-b638-f13aa4242f42)|10.8210.17763.3346 |
167
204
168
-
**What's new**
205
+
### What's new
169
206
170
207
- Added a fix to resolve a missing intermediate certificate issue with the use of "TelemetryProxyServer" on Windows Server 2012 R2 running the unified agent.
171
208
- Enhanced [Endpoint DLP](/purview/endpoint-dlp-learn-about) with ability to protect password protected and encrypted files and not label files.
@@ -181,7 +218,8 @@ All updates contain:
181
218
> Update package KB5005292 is on a gradual rollout schedule through Windows Update. Towards the end of this schedule, the package will be published completely, including to the update catalog for manual download. For the current release, this will be in the second half of October. If you want to test the package sooner, you can use [gradual rollout controls for platform updates](configure-updates.md) to select the Preview channel.
182
219
183
220
184
-
See also:
221
+
## See also
222
+
185
223
-[What's new in Microsoft Defender for Endpoint](whats-new-in-microsoft-defender-endpoint.md)
186
224
-[What's new in Defender for Endpoint on macOS](mac-whatsnew.md)
187
225
-[What's new in Defender for Endpoint on iOS](ios-whatsnew.md)
0 commit comments