Manage Microsoft Defender Antivirus updates and apply baselines
Important
Customers who applied the March 2022 Microsoft Defender engine update (1.1.19100.5) might have encountered high resource utilization (CPU and/or memory). Microsoft has released an update (1.1.19200.5) that resolves the bugs introduced in the earlier version. Customers are recommended to update to at least this new engine build of Antivirus Engine (1.1.19200.5). To ensure any performance issues are fully fixed, it is recommended to reboot machines after applying update. See Monthly platform and engine versions (in this article).
Applies to:
- Microsoft Defender for Endpoint Plans 1 and 2
- Microsoft Defender Antivirus
Platforms
- Windows
Keeping Microsoft Defender Antivirus up to date is critical to assure your devices have the latest technology and features needed to protect against new malware and attack techniques. Make sure to update your antivirus protection, even if Microsoft Defender Antivirus is running in passive mode. There are two types of updates related to keeping Microsoft Defender Antivirus up to date:
Tip
To see the most current engine, platform, and signature date, visit the Security intelligence updates for Microsoft Defender Antivirus and other Microsoft antimalware
Security intelligence updates
Microsoft Defender Antivirus uses cloud-delivered protection (also called the Microsoft Advanced Protection Service or MAPS) and periodically downloads dynamic security intelligence updates to provide additional protection. These dynamic updates don't take the place of regular security intelligence updates via security intelligence update KB2267602.
Note
Updates are released under the following KBs:
- Microsoft Defender Antivirus: KB2267602
- System Center Endpoint Protection: KB2461484
Cloud-delivered protection is always on and requires an active connection to the Internet to function. Security intelligence updates occur on a scheduled cadence (configurable via policy). For more information, see Use Microsoft cloud-provided protection in Microsoft Defender Antivirus.
For a list of recent security intelligence updates, see Security intelligence updates for Microsoft Defender Antivirus and other Microsoft antimalware.
Engine updates are included with security intelligence updates and are released on a monthly cadence.
Product updates
Microsoft Defender Antivirus requires monthly updates (KB4052623) known as platform updates.
You can manage the distribution of updates through one of the following methods:
- Windows Server Update Service (WSUS)
- Microsoft Endpoint Configuration Manager
- The usual method you use to deploy Microsoft and Windows updates to endpoints in your network.
For more information, see Manage the sources for Microsoft Defender Antivirus protection updates.
Note
- Monthly updates are released in phases, resulting in multiple packages visible in your Window Server Update Services.
- This article lists changes that are included in the broad release channel. See the latest broad channel release here.
- To learn more about the gradual rollout process, and to see more information about the next release, see Manage the gradual rollout process for Microsoft Defender updates.
- To learn more about security intelligence updates, see Security intelligence updates for Microsoft Defender Antivirus and other Microsoft antimalware.
- If you're looking for a list of Microsoft Defender processes, download the mde-urls workbook, and then select the Microsoft Defender Processes worksheet. The mde-urls workbook also lists the services and their associated URLs that your network must be able to connect to, as described in Enable access to Microsoft Defender for Endpoint service URLs in the proxy server.
Monthly platform and engine versions
For information how to update or install the platform update, see Update for Windows Defender antimalware platform.
All our updates contain
- Performance improvements
- Serviceability improvements
- Integration improvements (Cloud, Microsoft 365 Defender)
May-2022 (Platform: 4.18.2205.7 | Engine: 1.1.19300.2)
Security intelligence update version: 1.369.88.0
Released: June 22, 2022
Platform: 4.18.2205.7
Engine: 1.1.19300.2
Support phase: Security and Critical Updates
Engine version: 1.1.19300.2
Security intelligence update version: 1.369.88.0
What's new
- Added fix for ETW channel configuration for updates
- Added support for contextual exclusions allowing more specific exclusion targeting
- Fixed context maximum size
- Added fix for ASR LSASS detection
- Added fix to SHSetKnownFolder for rule exclusion logic
- Added AMSI disk usage limits for The History Store
- Added fix for Defender service refusing to accept signature updates
Known Issues
No known issues
March-2022 *UPDATE* (Platform: 4.18.2203.5 | Engine: 1.1.19200.5)
Customers who applied the March 2022 Microsoft Defender engine update (1.1.19100.5) might have encountered high resource utilization (CPU and/or memory). Microsoft has released an update (1.1.19200.5) that resolves the bugs introduced in the earlier version. Customers are recommended to update to at least this new engine build of Antivirus Engine (1.1.19200.5). To ensure any performance issues are fully fixed, it is recommended to reboot machines after applying update.
Security intelligence update version: 1.363.817.0
Released: April 22, 2022
Platform: 4.18.2203.5
Engine: 1.1.19200.5
Support phase: Security and Critical Updates
Engine version: 1.1.19200.5
Security intelligence update version: 1.363.817.0
What's new
- Resolves issues with high resource utilization (CPU and/or memory) related to the earlier March 2022 Microsoft Defender engine update (1.1.19100.5)
Known Issues
No known issues
March-2022 (Platform: 4.18.2203.5 | Engine: 1.1.19100.5)
Security intelligence update version: 1.361.1449.0
Released: April 7, 2022
Platform: 4.18.2203.5
Engine: 1.1.19100.5
Support phase: Security and Critical Updates
Engine version: 1.1.19100.5
Security intelligence update version: 1.361.1449.0
What's new
- Added fix for an attack surface reduction rule that blocked an Outlook add-in
- Added fix for behavior monitoring performance issue related to short live processes
- Added fix for AMSI exclusion
- Improved tamper protection capabilities
- Added a fix for real-time protection getting disabled in some cases when using
SharedSignaturesPathconfig (For more details about theSharedSignaturesPathparameter, see Set-MpPreference)
Known Issues
- Potential for high resource utilization (CPU and/or memory). See the Platform 4.18.2203.5 and Engine 1.1.19200.5 update for March 2022.
February-2022 (Platform: 4.18.2202.4 | Engine: 1.1.19000.8)
Security intelligence update version: 1.361.14.0
Released: March 14, 2022
Platform: 4.18.2202.4
Engine: 1.1.19000.8
Support phase: Security and Critical Updates
Engine version: 1.1.19000.8
Security intelligence update version: 1.361.14.0
What's new
- Improvements to detection and behavior monitoring logic
- Fixed false positive triggering attack surface reduction detections
- Added fix resulting in better fidelity of EDR and Advanced Hunting detection alerts
- Defender no longer supports custom notifications on toast pop ups. Modified GPO/Intune/SCCM and docs to reflect this change.
- Improvements to capture both information and copy of files written to removable storage. To learn more, see Microsoft Defender for Endpoint Device Control Removable Storage Access Control, removable storage media.
- Improved traffic output when SmartScreen service is unreachable
- Connectivity improvements for customers using proxies with authentication requirements
- Fixed VDI device update bug for network FileShares
- EDR in block mode now supports granular device targeting with new CSPs. See Endpoint detection and response (EDR) in block mode.
Known Issues
No known issues
Previous version updates: Technical upgrade support only
After a new package version is released, support for the previous two versions is reduced to technical support only. Versions older than that are listed in this section, and are provided for technical upgrade support only.
January-2022 (Platform: 4.18.2201.10 | Engine: 1.1.18900.2)
Security intelligence update version: 1.357.8.0
Released: February 9, 2022
Platform: 4.18.2201.10
Engine: 1.1.18900.2
Support phase: Technical upgrade support (only)
Engine version: 1.1.18900.2
Security intelligence update version: 1.357.8.0
What's new
- Behavior monitoring improvements in filtering performance
- Hardening to TrustedInstaller
- Tamper protection improvements
- Replaced
ScanScheduleTimewith newScanScheduleOffestcmdlet in Set-MpPreference. This policy configures the number of minutes after midnight to perform a scheduled scan. - Added the
-ServiceHealthReportIntervalsetting to Set-MpPreference. This policy configures the time interval (in minutes) to perform a scheduled scan. - Added the
AllowSwitchToAsyncInspectionsetting to Set-MpPreference. This policy enables a performance optimization, that allows synchronously inspected network flows, to switch to async inspection once they've been checked and validated. - Performance Analyzer v2 updates: Remote PowerShell and PowerShell 7.x support added. See Performance analyzer for Microsoft Defender Antivirus.
- Fixed potential duplicate packet bug in Microsoft Defender Antivirus network inspection system driver.
Known Issues
No known issues
November-2021 (Platform: 4.18.2111.5 | Engine: 1.1.18800.4)
Security intelligence update version: 1.355.2.0
Released: December 9th, 2021
Platform: 4.18.2111.5
Engine: 1.1.18800.4
Support phase: Technical upgrade support (only)
Engine version: 1.1.18800.4 Security intelligence update version: 1.355.2.0
What's new
- Improved CPU usage efficiency of certain intensive scenarios on Exchange servers
- Added new device control status fields under Get-MpComputerStatus in Defender PowerShell module. For more information, see Microsoft Defender for Endpoint Device Control Removable Storage Access Control.
- Fixed bug in which
SharedSignatureRootvalue couldn't be removed when set with PowerShell - Fixed bug in which tamper protection failed to be enabled, even though Microsoft Defender for Endpoint indicated that tamper protection was turned on
- Added supportability and bug fixes to performance analyzer for Microsoft Defender Antivirus tool. For more information, see Performance analyzer for Microsoft Defender Antivirus.
- PowerShell ISE support added for
New-MpPerformanceRecording - Fixed bug errors for
Get-MpPerformanceReport -TopFilesPerProcess - Fixed performance recording session leak when using
New-MpPerformanceRecordingin PowerShell 7.x, remote sessions, and PowerShell ISE
- PowerShell ISE support added for
Known Issues
No known issues
October-2021 (Platform: 4.18.2110.6 | Engine: 1.1.18700.4)
Security intelligence update version: 1.353.3.0
Released: October 28th, 2021
Platform: 4.18.2110.6
Engine: 1.1.18700.4
Support phase: Technical upgrade support (only)
Engine version: 1.1.18700.4 Security intelligence update version: 1.353.3.0
What's new
- Improvements to file transfer protocol (FTP) network traffic coverage
- Fix to reduce Microsoft Defender CPU usage in Exchange Server running on Windows Server 2016
- Fix for scan interruptions
- Fix for alerts on blocked tampering attempts not appearing in Security Center
- Improvements to tamper resilience in Microsoft Defender service
Known Issues
No known issues
September-2021 (Platform: 4.18.2109.6 | Engine: 1.1.18600.4)
Security intelligence update version: 1.351.7.0
Released: October 7th, 2021
Platform: 4.18.2109.6
Engine: 1.1.18600.4
Support phase: Technical upgrade support (only)
Engine version: 1.1.18600.4 Security intelligence update version: 1.351.7.0
What's new
- New delay ring for Microsoft Defender Antivirus engine and platform updates. Devices that opt into this ring will receive updates with a 48-hour delay. The new delay ring is suggested for critical environments only. See Manage the gradual rollout process for Microsoft Defender updates.
- Improvements to Microsoft Defender update gradual rollout process
Known Issues
No known issues
August-2021 (Platform: 4.18.2108.7 | Engine: 1.1.18500.10)
Security intelligence update version: 1.349.22.0
Released: September 2, 2021
Platform: 4.18.2108.7
Engine: 1.1.18500.10
Support phase: Technical upgrade support (only)
What's new
- Improvements to the behavior monitoring engine
- Released new performance analyzer for Microsoft Defender Antivirus
- Microsoft Defender Antivirus hardened against loading malicious DLLs
- Microsoft Defender Antivirus hardened against the TrustedInstaller bypass
- Extending file change notifications to include more data for Human-Operated Ransomware (HumOR)
Known Issues
No known issues
July-2021 (Platform: 4.18.2107.4 | Engine: 1.1.18400.4)
Security intelligence update version: 1.345.13.0
Released: August 5, 2021
Platform: 4.18.2107.4
Engine: 1.1.18400.4
Support phase: Technical upgrade support (only)
What's new
- Device control support added for Windows Portable Devices
- Potentially unwanted applications (PUA) protection is turned on by default for consumers (See Block potentially unwanted applications with Microsoft Defender Antivirus.)
- Scheduled scans for Group Policy Object managed systems will adhere to user configured scan time
- Improvements to the behavior monitoring engine
Known Issues
No known issues
June-2021 (Platform: 4.18.2106.5 | Engine: 1.1.18300.4)
Security intelligence update version: 1.343.17.0
Released: June 28, 2021
Platform: 4.18.2106.5
Engine: 1.1.18300.4
Support phase: Technical upgrade support (only)
What's new
- New controls for managing the gradual rollout process of Microsoft Defender updates. See Manage the gradual rollout process for Microsoft Defender updates.
- Improvement to the behavior monitoring engine
- Improvements to the rollout of antimalware definitions
- Extended Edge network event inspections
Known Issues
No known issues
May-2021 (Platform: 4.18.2105.4 | Engine: 1.1.18200.4)
Security intelligence update version: 1.341.8.0
Released: June 3, 2021
Platform: 4.18.2105.4
Engine: 1.1.18200.4
Support phase: Technical upgrade support (only)
What's new
- Improvements to behavior monitoring
- Fixed network protection notification filtering feature
Known Issues
No known issues
April-2021 (Platform: 4.18.2104.14 | Engine: 1.1.18100.5)
Security intelligence update version: 1.337.2.0
Released: April 26, 2021 (Engine: 1.1.18100.6 released May 5, 2021)
Platform: 4.18.2104.14
Engine: 1.1.18100.5
Support phase: Technical upgrade support (only)
What's new
- More behavior monitoring logic
- Improved kernel mode key logger detection
- Added new controls to manage the gradual rollout process for Microsoft Defender updates
Known Issues
No known issues
March-2021 (Platform: 4.18.2103.7 | Engine: 1.1.18000.5)
Security intelligence update version: 1.335.36.0
Released: April 2, 2021
Platform: 4.18.2103.7
Engine: 1.1.18000.5
Support phase: Technical upgrade support (only)
What's new
- Improvement to the Behavior Monitoring engine
- Expanded network brute-force-attack mitigations
- More failed tampering attempt event generation when Tamper Protection is enabled
Known Issues
No known issues
February-2021 (Platform: 4.18.2102.3 | Engine: 1.1.17900.7)
Security intelligence update version: 1.333.7.0
Released: March 9, 2021
Platform: 4.18.2102.3
Engine: 1.1.17900.7
Support phase: Technical upgrade support (only)
What's new
- Improved service recovery through tamper protection
- Extend tamper protection scope
Known Issues
No known issues
January-2021 (Platform: 4.18.2101.9 | Engine: 1.1.17800.5)
Security intelligence update version: 1.327.1854.0
Released: February 2, 2021
Platform: 4.18.2101.9
Engine: 1.1.17800.5
Support phase: Technical upgrade support (only)
What's new
- Shellcode exploit detection improvements
- Increased visibility for credential stealing attempts
- Improvements in antitampering features in Microsoft Defender Antivirus services
- Improved support for ARM x64 emulation
- Fix: EDR Block notification remains in threat history after real-time protection performed initial detection
Known Issues
No known issues
November-2020 (Platform: 4.18.2011.6 | Engine: 1.1.17700.4)
Security intelligence update version: 1.327.1854.0
Released: December 03, 2020
Platform: 4.18.2011.6
Engine: 1.1.17700.4
Support phase: Technical upgrade support (only)
What's new
- Improved SmartScreen status support logging
Known Issues
No known issues
October-2020 (Platform: 4.18.2010.7 | Engine: 1.1.17600.5)
Security intelligence update version: 1.327.7.0
Released: October 29, 2020
Platform: 4.18.2010.7
Engine: 1.1.17600.5
Support phase: Technical upgrade support (only)
What's new
- New descriptions for special threat categories
- Improved emulation capabilities
- Improved host address allow/block capabilities
- New option in Defender CSP to Ignore merging of local user exclusions
Known Issues
No known issues
September-2020 (Platform: 4.18.2009.7 | Engine: 1.1.17500.4)
Security intelligence update version: 1.325.10.0
Released: October 01, 2020
Platform: 4.18.2009.7
Engine: 1.1.17500.4
Support phase: Technical upgrade support (only)
What's new
- Admin permissions are required to restore files in quarantine
- XML formatted events are now supported
- CSP support for ignoring exclusion merges
- New management interfaces for:
- UDP Inspection
- Network Protection on Server 2019
- IP Address exclusions for Network Protection
- Improved visibility into TPM measurements
- Improved Office VBA module scanning
Known Issues
No known issues
August-2020 (Platform: 4.18.2008.9 | Engine: 1.1.17400.5)
Security intelligence update version: 1.323.9.0
Released: August 27, 2020
Platform: 4.18.2008.9
Engine: 1.1.17400.5
Support phase: Technical upgrade support (only)
What's new
- Add more telemetry events
- Improved scan event telemetry
- Improved behavior monitoring for memory scans
- Improved macro streams scanning
- Added
AMRunningModeto Get-MpComputerStatus PowerShell cmdlet - DisableAntiSpyware is ignored. Microsoft Defender Antivirus automatically turns itself off when it detects another antivirus program.
Known Issues
No known issues
July-2020 (Platform: 4.18.2007.8 | Engine: 1.1.17300.4)
Security intelligence update version: 1.321.30.0
Released: July 28, 2020
Platform: 4.18.2007.8
Engine: 1.1.17300.4
Support phase: Technical upgrade support (only)
What's new
- Improved telemetry for BITS
- Improved Authenticode code signing certificate validation
Known Issues
No known issues
June-2020 (Platform: 4.18.2006.10 | Engine: 1.1.17200.2)
Security intelligence update version: 1.319.20.0
Released: June 22, 2020
Platform: 4.18.2006.10
Engine: 1.1.17200.2
Support phase: Technical upgrade support (only)
What's new
- Possibility to specify the location of the support logs
- Skipping aggressive catchup scan in Passive mode.
- Allow Defender to update on metered connections
- Fixed performance tuning when caching is disabled
- Fixed registry query
- Fixed scantime randomization in ADMX
Known Issues
No known issues
May-2020 (Platform: 4.18.2005.4 | Engine: 1.1.17100.2)
Security intelligence update version: 1.317.20.0
Released: May 26, 2020
Platform: 4.18.2005.4
Engine: 1.1.17100.2
Support phase: Technical upgrade support (only)
What's new
- Improved logging for scan events
- Improved user mode crash handling.
- Added event tracing for Tamper protection
- Fixed AMSI Sample submission
- Fixed AMSI Cloud blocking
- Fixed Security update install log
Known Issues
No known issues
April-2020 (Platform: 4.18.2004.6 | Engine: 1.1.17000.2)
Security intelligence update version: 1.315.12.0
Released: April 30, 2020
Platform: 4.18.2004.6
Engine: 1.1.17000.2
Support phase: Technical upgrade support (only)
What's new
- WDfilter improvements
- Add more actionable event data to attack surface reduction detection events
- Fixed version information in diagnostic data and WMI
- Fixed incorrect platform version in UI after platform update
- Dynamic URL intel for Fileless threat protection
- UEFI scan capability
- Extend logging for updates
Known Issues
No known issues
March-2020 (Platform: 4.18.2003.8 | Engine: 1.1.16900.2)
Security intelligence update version: 1.313.8.0
Released: March 24, 2020
Platform: 4.18.2003.8
Engine: 1.1.16900.4
Support phase: Technical upgrade support (only)
What's new
- CPU Throttling option added to MpCmdRun
- Improve diagnostic capability
- reduce Security intelligence timeout (5 min)
- Extend AMSI engine internal log capability
- Improve notification for process blocking
Known Issues
[Fixed] Microsoft Defender Antivirus is skipping files when running a scan.
February-2020 (Platform: - | Engine: 1.1.16800.2)
Security intelligence update version: 1.311.4.0
Released: February 25, 2020
Platform/Client: -
Engine: 1.1.16800.2
Support phase: Technical upgrade support (only)
What's new
Known Issues
No known issues
January-2020 (Platform: 4.18.2001.10 | Engine: 1.1.16700.2)
Security intelligence update version: 1.309.32.0
Released: January 30, 2020
Platform/Client: 4.18.2001.10
Engine: 1.1.16700.2
Support phase: Technical upgrade support (only)
What's new
- Fixed BSOD on WS2016 with Exchange
- Support platform updates when TMP is redirected to network path
- Platform and engine versions are added to WDSI
- extend Emergency signature update to passive mode
- Fix 4.18.1911.3 hang
Known Issues
[Fixed] devices utilizing modern standby mode may experience a hang with the Windows Defender filter driver that results in a gap of protection. Affected machines appear to the customer as having not updated to the latest antimalware platform.
Important
This update is:
- needed by RS1 devices running lower version of the platform to support SHA2;
- has a reboot flag for systems that have hanging issues;
- is re-released in April 2020 and will not be superseded by newer updates to keep future availability;
- is categorized as an update due to the reboot requirement; and
- is only be offered with Windows Update.
November-2019 (Platform: 4.18.1911.3 | Engine: 1.1.16600.7)
Security intelligence update version: 1.307.13.0
Released: December 7, 2019
Platform: 4.18.1911.3
Engine: 1.1.17000.7
Support phase: No support
What's new
- Fixed MpCmdRun tracing level
- Fixed WDFilter version info
- Improve notifications (PUA)
- add MRT logs to support files
Known Issues
When this update is installed, the device needs the jump package 4.18.2001.10 to be able to update to the latest platform version.
Microsoft Defender Antivirus platform support
Platform and engine updates are provided on a monthly cadence. To be fully supported, keep current with the latest platform updates. Our support structure is dynamic, evolving into two phases depending on the availability of the latest platform version:
Security and Critical Updates servicing phase - When running the latest platform version, you'll be eligible to receive both Security and Critical updates to the anti-malware platform.
Technical Support (Only) phase - After a new platform version is released, support for older versions (N-2) will reduce to technical support only. Platform versions older than N-2 will no longer be supported.*
* Technical support will continue to be provided for upgrades from the Windows 10 release version (see Platform version included with Windows 10 releases) to the latest platform version.
During the technical support (only) phase, commercially reasonable support incidents will be provided through Microsoft Customer Service & Support and Microsoft's managed support offerings (such as Premier Support). If a support incident requires escalation to development for further guidance, requires a non-security update, or requires a security update, customers will be asked to upgrade to the latest platform version or an intermediate update (*).
Note
If you are manually deploying Microsoft Defender Antivirus Platform Update, or if you are using a script or a non-Microsoft management product to deploy Microsoft Defender Antivirus Platform Update, make sure that version 4.18.2001.10 is installed from the Microsoft Update Catalog before the latest version of Platform Update (N-2) is installed.
Platform version included with Windows 10 releases
The below table provides the Microsoft Defender Antivirus platform and engine versions that are shipped with the latest Windows 10 releases:
| Windows 10 release | Platform version | Engine version | Support phase |
|---|---|---|---|
| 2004 (20H1/20H2) | 4.18.1909.6 | 1.1.17000.2 | Technical upgrade support (only) |
| 1909 (19H2) | 4.18.1902.5 | 1.1.16700.3 | Technical upgrade support (only) |
| 1903 (19H1) | 4.18.1902.5 | 1.1.15600.4 | Technical upgrade support (only) |
| 1809 (RS5) | 4.18.1807.18075 | 1.1.15000.2 | Technical upgrade support (only) |
| 1803 (RS4) | 4.13.17134.1 | 1.1.14600.4 | Technical upgrade support (only) |
| 1709 (RS3) | 4.12.16299.15 | 1.1.14104.0 | Technical upgrade support (only) |
| 1703 (RS2) | 4.11.15603.2 | 1.1.13504.0 | Technical upgrade support (only) |
| 1607 (RS1) | 4.10.14393.3683 | 1.1.12805.0 | Technical upgrade support (only) |
For Windows 10 release information, see the Windows lifecycle fact sheet.
Updates for Deployment Image Servicing and Management (DISM)
We recommend updating your Windows 10 (Enterprise, Pro, and Home editions), Windows Server 2019, Windows Server 2022, and Windows Server 2016 OS installation images with the latest antivirus and antimalware updates. Keeping your OS installation images up to date helps avoid a gap in protection.
For more information, see Microsoft Defender update for Windows operating system installation images.
20220629.5
Package version: 20220629.5
Platform version: 4.18.2205.7
Engine version: 1.1.19300.2
Signature version: 1.369.220.0
Fixes
- None
Additional information
- None
20220603.3
Package version: 20220603.3
Platform version: 4.18.2203.5
Engine version: 1.1.19200.6
Signature version: 1.367.1009.0
Fixes
- None
Additional information
- None
20220506.6
Package version: 20220506.6
Platform version: 4.18.2203.5
Engine version: 1.1.19200.5
Signature version: 1.363.1436.0
Fixes
- None
Additional information
- None
20220321.1
Package version: 20220321.1
Platform version: 4.18.2202.4
Engine version: 1.1.19000.8
Signature version: 1.351.337.0
Fixes
- None
Additional information
- None
20220305.1
Package version: 20220305.1
Platform version: 4.18.2201.10
Engine version: 1.1.18900.3
Signature version: 1.359.1405.0
Fixes
- None
Additional information
- None
20220203.1
Package version: 20220203.1
Platform version: 4.18.2111.5
Engine version: 1.1.18900.2
Signature version: 1.357.32.0
Fixes
- None
Additional information
- None
20220105.1
Package version: 20220105.1
Platform version: 4.18.2111.5
Engine version: 1.1.18800.4
Signature version: 1.355.1482.0
Fixes
- None
Additional information
- None
1.1.2112.01
Package version: 1.1.2112.01
Platform version: 4.18.2110.6
Engine version: 1.1.18700.4
Signature version: 1.353.2283.0
Fixes
- None
Additional information
- None
1.1.2111.02
Package version: 1.1.2111.02
Platform version: 4.18.2110.6
Engine version: 1.1.18700.4
Signature version: 1.353.613.0
Fixes
- Fixed an issue pertaining to localization files
Additional information
- None
1.1.2110.01
Package version: 1.1.2110.01
Platform version: 4.18.2109.6
Engine version: 1.1.18500.10
Signature version: 1.349.2103.0
Fixes
- None
Additional information
- None
1.1.2109.01
Package version: 1.1.2109.01
Platform version: 4.18.2107.4
Engine version: 1.1.18400.5
Signature version: 1.347.891.0
Fixes
- None
Additional information
- None
1.1.2108.01
Package version: 1.1.2108.01
Platform version: 4.18.2107.4
Engine version: 1.1.18300.4
Signature version: 1.343.2244.0
Fixes
- None
Additional information
- None
1.1.2107.02
Package version: 1.1.2107.02
Platform version: 4.18.2105.5
Engine version: 1.1.18300.4
Signature version: 1.343.658.0
Fixes
- None
Additional information
- None
1.1.2106.01
Package version: 1.1.2106.01
Platform version: 4.18.2104.14
Engine version: 1.1.18100.6
Signature version: 1.339.1923.0
Fixes
- None
Additional information
- None
1.1.2105.01
Package version: 1.1.2105.01
Platform version: 4.18.2103.7
Engine version: 1.1.18100.6
Signature version: 1.339.42.0
Fixes
- None
Additional information
- None
1.1.2104.01
Package version: 1.1.2104.01
Platform version: 4.18.2102.4
Engine version: 1.1.18000.5
Signature version: 1.335.232.0
Fixes
- None
Additional information
- None
1.1.2103.01
Package version: 1.1.2103.01
Platform version: 4.18.2101.9
Engine version: 1.1.17800.5
Signature version: 1.331.2302.0
Fixes
- None
Additional information
- None
1.1.2102.03
Package version: 1.1.2102.03
Platform version: 4.18.2011.6
Engine version: 1.1.17800.5
Signature version: 1.331.174.0
Fixes
- None
Additional information
- None
1.1.2101.02
Package version: 1.1.2101.02
Platform version: 4.18.2011.6
Engine version: 1.1.17700.4
Signature version: 1.329.1796.0
Fixes
- None
Additional information
- None
1.1.2012.01
Package version: 1.1.2012.01
Platform version: 4.18.2010.7
Engine version: 1.1.17600.5
Signature version: 1.327.1991.0
Fixes
- None
Additional information
- None
1.1.2011.02
Package version: 1.1.2011.02
Platform version: 4.18.2010.7
Engine version: 1.1.17600.5
Signature version: 1.327.658.0
Fixes
- None
Additional information
- Refreshed Microsoft Defender Antivirus signatures
1.1.2011.01
Package version: 1.1.2011.01
Platform version: 4.18.2009.7
Engine version: 1.1.17600.5
Signature version: 1.327.344.0
Fixes
- None
Additional information
- None
1.1.2009.10
Package version: 1.1.2011.01
Platform version: 4.18.2008.9
Engine version: 1.1.17400.5
Signature version: 1.327.2216.0
Fixes
- None
Additional information
- Added support for Windows 10 RS1 or later OS install images.
More resources
| Article | Description |
|---|---|
| Microsoft Defender update for Windows operating system installation images | Review antimalware update packages for your OS installation images (WIM and VHD files). Get Microsoft Defender Antivirus updates for Windows 10 (Enterprise, Pro, and Home editions), Windows Server 2019, Windows Server 2022, and Windows Server 2016 installation images. |
| Manage how protection updates are downloaded and applied | Protection updates can be delivered through many sources. |
| Manage when protection updates should be downloaded and applied | You can schedule when protection updates should be downloaded. |
| Manage updates for endpoints that are out of date | If an endpoint misses an update or scheduled scan, you can force an update or scan the next time a user signs in. |
| Manage event-based forced updates | You can set protection updates to be downloaded at startup or after certain cloud-delivered protection events. |
| Manage updates for mobile devices and virtual machines (VMs) | You can specify settings, such as whether updates should occur on battery power, that are especially useful for mobile devices and virtual machines. |
| Microsoft Defender for Endpoint update for EDR Sensor | You can update the EDR sensor (MsSense.exe) that is included in the new Microsoft Defender for Endpoint unified solution package released in 2021. |
Tip
If you're looking for Antivirus related information for other platforms, see:
- Set preferences for Microsoft Defender for Endpoint on macOS
- Microsoft Defender for Endpoint on Mac
- macOS Antivirus policy settings for Microsoft Defender Antivirus for Intune
- Set preferences for Microsoft Defender for Endpoint on Linux
- Microsoft Defender for Endpoint on Linux
- Configure Defender for Endpoint on Android features
- Configure Microsoft Defender for Endpoint on iOS features
Зворотний зв’язок
Надіслати й переглянути відгук про