Package fails to install for Windows 2016 endpoints in Microsoft Defender for Identity

Arran 0 Reputation points
2024-01-11T17:29:36.0466667+00:00

Problem with enroling Windows 2016 devices in Microsoft Defender for Identity

As part of moving from a third party AV to defender (2019 and 2022 work fine).

PowerShell Running the installation package fails on 2016 for multiple servers

All available updates have been installed Initially when running Stops with the message ""Please Update Windows Defender Antivirus to the latest version KB4052623" • Update is downloaded and installed from the update Catalog • Next time it stops with the message the package has been updated, please download a new version (we are using the latest!)

Is there a newer (or different) version of the md4ws.msi we should be using?

Amongst others we have tried Running the package manually, with and without swicthes Installing using the github.com/microsoft/mdefordownlevelserver/blob/main Installer Removing and re-adding components All without success.

MDE is showing enabled but key features like ASR, PUA and EDR in block mode are missing.

Customer is not able to update to 2019 or later at this time.

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
155 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Chris 0 Reputation points
    2024-03-03T05:22:12.1433333+00:00

    I have this same problem. I'm am required to update from update and security and then have to run files to download from MDE to onboard. Is there an easier way to download the KB that is not N-2 and run application to onboard from Defender?

    0 comments No comments

  2. Catherine Kyalo 570 Reputation points Microsoft Employee
    2024-04-04T14:33:14.5333333+00:00

    The error message you're seeing ("Please Update Windows Defender Antivirus to the latest version KB4052623") is related to a Windows Defender update that's required for the installation package to work. Since you mentioned that you've already installed all available updates, it's possible that this particular update is missing or failed to install on the Windows 2016 endpoints.

    You can try downloading and installing the update manually from the Microsoft Update Catalog: https://www.catalog.update.microsoft.com/Search.aspx?q=KB4052623

    As for the version of the md4ws.msi package, it's possible that the latest version is not compatible with Windows 2016. You can try contacting Microsoft Support to confirm the compatibility and obtain the appropriate version of the package.

    In terms of missing key features in MDE, it's possible that these features require a newer version of MDE. If updating to 2019 or later is not an option, you can try contacting Microsoft Support for assistance with resolving the missing features issue.

    Here's a relevant GitHub repository that may be helpful: https://github.com/microsoft/mdefordownlevelserver. This repository contains a PowerShell script that installs Microsoft Defender for Endpoint (formerly known as Microsoft Defender Advanced Threat Protection) on down-level Windows Server and Windows 10 endpoints.

    0 comments No comments