top of page

Warning: Microsoft Defender on Linux may be disabled after an update

Microsoft has confirmed that Microsoft Defender for Endpoint on Linux versions 101.26042.0000 through 101.26042.0009 may become disabled after an upgrade or reinstallation followed by a system reboot.

The affected builds have been removed from the production channel, and version 101.26042.0011 has been released to resolve the issue. The incident is not associated with a CVE.

The primary concern is that Defender services may stop running on certain Linux systems after a reboot. Until administrators detect and remediate the issue, organizations may temporarily lose an important layer of malware detection, endpoint visibility, and behavioral monitoring.

Microsoft Defender on Linux may be disabled after an update
Microsoft Defender on Linux may be disabled after an update

What happened to Microsoft Defender for Endpoint on Linux?

Microsoft reported that the issue affects platform builds 101.26042.0000 through 101.26042.0009. On some Linux devices that were upgraded or reinstalled with these builds, Microsoft Defender for Endpoint may become disabled after the operating system restarts.

To prevent additional deployments, Microsoft has removed the affected builds from its production release channel for all supported Linux distributions. As a result, these versions are no longer distributed through standard update channels.

The issue should not be confused with a separate problem affecting Red Hat Enterprise Linux (RHEL) 8 and 9 running in FIPS mode. In that case, version 101.26042.x may fail to install, leaving systems on the previous release. Microsoft states that this installation issue is resolved in version 101.26052.0011 and later.

Scenario

Affected Systems

Impact

Fixed Version

Defender service becomes disabled

Linux running 101.26042.0000–101.26042.0009

Defender may stop after upgrade/reinstallation and reboot

101.26042.0011

Update installation failure

RHEL 8/9 with FIPS enabled

System remains on previous version

101.26052.0011 or later

Microsoft has not yet disclosed the technical root cause of the issue. Therefore, there is currently no evidence that the problem originates from the antivirus engine, the EDR sensor, service initialization, or the packaging process.

Which organizations should take immediate action?

Any organization running Microsoft Defender for Endpoint on Linux should verify the installed version across its environment. Priority should be given to servers that were recently upgraded, reinstalled, or rebooted while the affected builds were available.

Organizations using Microsoft Defender for Servers Plan 1 or Plan 2 with Microsoft Defender for Cloud should pay particular attention. Since automatic updates for the MDE.Linux extension are enabled in many deployments, some systems may have received the affected version without manual intervention.

High-priority systems include:

  • Internet-facing Linux servers.

  • Application and database servers.

  • Linux workloads hosted in Microsoft Azure or hybrid environments.

  • Systems with privileged administrative access.

  • Servers recently rebooted following maintenance or kernel updates.

  • RHEL 8 or RHEL 9 systems operating in FIPS mode.

Why does a disabled EDR create a security blind spot?

Endpoint Detection and Response (EDR) continuously collects endpoint telemetry, detects suspicious behavior, and supports incident investigations. When an EDR sensor or antivirus component stops functioning, security teams may lose critical visibility into endpoint activity.

Why does a disabled EDR create a security blind spot?
Why does a disabled EDR create a security blind spot?

However, organizations relying primarily on Microsoft Defender for Endpoint for Linux visibility could temporarily lose detection capabilities during the affected period. Suspicious processes, privilege escalation attempts, malicious file execution, or command-and-control communications may not be fully monitored.

This incident also reinforces an important operational lesson: the absence of security alerts does not necessarily indicate that systems are safe. It may simply mean the security sensor has stopped reporting.

What should organizations do immediately?

Microsoft recommends upgrading directly to version 101.26042.0011 to resolve the service disablement issue. Organizations affected by the RHEL FIPS installation problem should instead deploy version 101.26052.0011 or later.

Immediate Response Checklist

  • Verify all Linux systems running Microsoft Defender for Endpoint.

  • Identify devices using versions 101.26042.0000–101.26042.0009.

  • Run mdatp health to confirm service status.

  • Check the service using systemctl status mdatp.

  • Confirm antivirus and EDR protection are healthy.

  • Upgrade to version 101.26042.0011 or a newer supported release.

  • Reboot systems within a controlled maintenance window if required.

  • Verify Defender status after reboot.

  • Review any telemetry gaps during the affected period.

  • Investigate suspicious activity that may have occurred while protection was unavailable.

Installing the updated package alone should not be considered sufficient. Organizations should also verify service health, endpoint connectivity, and telemetry restoration after the upgrade.

IPSIP Vietnam's expert perspective

This is not a confirmed cyberattack. The security risk arises because endpoint protection may become unavailable after an update, potentially reducing detection capabilities if malicious activity occurs during that window.

Linux servers often support business-critical applications, databases, cloud workloads, and production infrastructure. Losing EDR visibility may delay threat detection, incident response, and forensic investigations.

Giải pháp nào của IPSIP Việt Nam phù hợp cho doanh nghiệp?

Trung tâm Điều hành An ninh mạng - SOC 24/7: Phù hợp khi doanh nghiệp thiếu khả năng giám sát liên tục trạng thái EDR, log và các dấu hiệu xâm nhập. SOC có thể hỗ trợ tương quan dữ liệu từ nhiều nguồn và ưu tiên điều tra những thiết bị đã mất telemetry.

Trung tâm Vận hành Mạng - NOC 24/7: Phù hợp khi vấn đề cần giải quyết bao gồm tính sẵn sàng của dịch vụ, trạng thái máy chủ và các thay đổi sau bảo trì. Kết hợp NOC và SOC giúp doanh nghiệp phân biệt sự cố vận hành với dấu hiệu an ninh mạng.

IPSIP Vietnam cybersecurity solutions
IPSIP Vietnam cybersecurity solutions

This Microsoft Defender for Endpoint incident serves as a reminder that security software itself requires operational validation after deployment. Installing updates alone is not enough, organizations should confirm that endpoint protection remains active, telemetry continues to flow, and security monitoring is fully operational.

For enterprises operating Linux workloads, verifying Defender health, deploying the fixed release, and incorporating post-update validation into standard patch management processes should become routine operational practice.

References


Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
whatsapp-mobile-software-icon-png-image_6315991.png
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page