3 min Security

Update may disable Microsoft Defender on Linux after a restart

Update may disable Microsoft Defender on Linux after a restart

A recent update to Microsoft Defender for Endpoint contains two bugs that can affect Linux systems. A specific range of versions can cause the security service to be disabled after a reboot. Additionally, the same update causes installation issues on Red Hat Enterprise Linux systems running in FIPS mode.

Microsoft has confirmed the issues for Defender for Endpoint on Linux. The most serious issue affects versions 101.26042.0000 through 101.26042.0009, which have been released on all supported Linux distributions. According to The Register, after an upgrade or reinstallation, the Defender service may remain disabled on some systems following a reboot.

The risk is greater for organizations using Microsoft Defender for Servers in combination with Defender for Cloud. In that configuration, the Linux agent is automatically updated by default, which means affected versions may have been installed on systems without anyone noticing.

Endpoint protection is lost

Microsoft has not explained what causes the Defender service to be disabled. Precisely because endpoint protection serves as the first line of defense against malware and other attacks, such a flaw can have serious consequences. When the security service is not active after a reboot, systems lose their active protection until administrators intervene.

Microsoft has since released build 101.26042.0011 as a fix for this issue. This is indicated in the release notes for Defender for Endpoint.

Installation fails on FIPS systems

In addition to disabling the security service, the same update contains a second issue. On Red Hat Enterprise Linux 8 and 9 running in FIPS mode, version 101.26042.x cannot be installed. FIPS (Federal Information Processing Standards) specifies cryptographic standards that are widely used within government organizations and other highly regulated environments.

In these cases, the system will continue to run on the previously installed version of Defender. Microsoft states in the release notes that this issue has been resolved starting with version 101.26052.0011.

An important component of Microsoft security

Microsoft Defender for Endpoint protects Linux servers in both on-premises and cloud environments and, for many organizations, forms part of a single centralized security platform. Thanks to its integration with Microsoft Defender, administrators can manage endpoint security, detection, and incident response from a single management interface.

In recent years, Microsoft has faced frequent criticism for updates that caused unexpected issues in Windows. The fact that a security software update, of all things, can now cause endpoint protection to fail or prevent it from being installed significantly amplifies the impact. Administrators are therefore advised to check which version of Defender is running on Linux systems and, if necessary, update it to a release that resolves both issues.