Microsoft Defender for Endpoint on Linux could leave some upgraded servers without active protection after their next reboot, affecting platform builds 101.26042.0000 through 101.26042.0009. Microsoft has pulled those builds from the production channel and says administrators should update affected systems to build 101.26042.0011 or later.
The Register first reported the issue on July 27, while Microsoft’s Defender for Endpoint release notes confirm that the Defender service “might be disabled” on some devices after an upgrade or reinstall followed by a restart. The important operational detail is that an apparently successful package update was not necessarily the end of the change window: the protection gap could emerge only when the server rebooted.
Microsoft says the problem applies across supported Linux operating systems, not solely one distribution. It is particularly significant for organizations using Defender for Servers Plan 1 or Plan 2 through Defender for Cloud with Microsoft Defender for Endpoint integration enabled, because the MDE.Linux extension is automatically updated by default.
That means a fleet may have received an affected package without a separately scheduled endpoint-agent rollout. A reboot undertaken later for kernel maintenance, application work, or routine patching could then turn a latent package issue into an active endpoint-protection failure.
This is not a Windows Defender Antivirus issue on PCs. It concerns the Linux version of the enterprise Defender for Endpoint agent, including its antivirus and endpoint detection and response functions.
Administrators should treat package version checks alone as insufficient. For servers that may have installed an affected build, the sensible order is:
For security teams, the overlap matters: a server can be compliant with a strict cryptographic configuration and still need its endpoint agent monitored as closely as the operating system itself. The post-reboot health check is the key safeguard here—particularly for automated cloud-managed deployments where an agent update may arrive before an administrator has scheduled a restart.
The Register first reported the issue on July 27, while Microsoft’s Defender for Endpoint release notes confirm that the Defender service “might be disabled” on some devices after an upgrade or reinstall followed by a restart. The important operational detail is that an apparently successful package update was not necessarily the end of the change window: the protection gap could emerge only when the server rebooted.
The risk is highest where agent updates are automatic
Microsoft says the problem applies across supported Linux operating systems, not solely one distribution. It is particularly significant for organizations using Defender for Servers Plan 1 or Plan 2 through Defender for Cloud with Microsoft Defender for Endpoint integration enabled, because the MDE.Linux extension is automatically updated by default.That means a fleet may have received an affected package without a separately scheduled endpoint-agent rollout. A reboot undertaken later for kernel maintenance, application work, or routine patching could then turn a latent package issue into an active endpoint-protection failure.
This is not a Windows Defender Antivirus issue on PCs. It concerns the Linux version of the enterprise Defender for Endpoint agent, including its antivirus and endpoint detection and response functions.
Upgrade first, then verify protection
Microsoft’s immediate remediation is to install 101.26042.0011, which contains the fix for the reboot-related service failure. The newer July build, 101.26052.0011, also includes the fix and adds anantivirus_enforcement_level value to mdatp health, intended to show whether antivirus is operating in real-time, passive, on-demand, or audit mode.Administrators should treat package version checks alone as insufficient. For servers that may have installed an affected build, the sensible order is:
- Update the
mdatppackage to build 101.26042.0011 or a later supported release. - Confirm that the Defender service starts successfully after a controlled reboot.
- Run
mdatp healthand verify that the endpoint reports a healthy state and the intended antivirus enforcement mode. - Review Defender portal telemetry for Linux devices that went offline, stopped reporting, or changed protection status following recent maintenance windows.
yum update mdatp for RHEL-family systems, zypper update mdatp for SUSE systems, and apt-get install --only-upgrade mdatp for Ubuntu and Debian.A separate FIPS problem has also been addressed
The same release notes identify a different installation failure affecting some FIPS-enabled Red Hat Enterprise Linux 8 and RHEL 9 systems on the 101.26042.x platform branch. Microsoft says that issue is fixed in 101.26052.0011 and later.For security teams, the overlap matters: a server can be compliant with a strict cryptographic configuration and still need its endpoint agent monitored as closely as the operating system itself. The post-reboot health check is the key safeguard here—particularly for automated cloud-managed deployments where an agent update may arrive before an administrator has scheduled a restart.
References
- Primary source: LinkedIn
Published: 2026-07-28T09:00:21+00:00
WARNING: Microsoft Defender Update Could Disable Protection On Linux Servers After Reboot
Microsoft has fixed two defects in Defender for Endpoint on Linux after an update caused the security service to become disabled on some machines following a reboot and prevented installation on certain Red Hat Enterprise Linux systems configured to meet federal cryptographic requirements. The morewww.linkedin.com
- Independent coverage: Techzine Global
Published: 2026-07-28T07:38:05+00:00
- Independent coverage: The Register
Published: 2026-07-27T13:45:00+00:00
Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update
One bug disabled the security service on restart, another blocked installation on hardened RHEL systemswww.theregister.com - Related coverage: learn.microsoft.com
Microsoft Defender for Endpoint release notes - Microsoft Defender for Endpoint | Microsoft Learn
This article describes releases of Microsoft Defender for Endpoint on Windows, macOS, Linux, Android, and iOS.learn.microsoft.com - Related coverage: techcommunity.microsoft.com
- Related coverage: techradar.com
Microsoft confirms two major Defender security issues — so update now or face possible attack | TechRadar
CISA confirms two bugs being actively exploited in the wildwww.techradar.com