<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title><![CDATA[Geeks for your information - Windows Defender (Microsoft)]]></title>
		<link>https://www.geeks.fyi/</link>
		<description><![CDATA[Geeks for your information - https://www.geeks.fyi]]></description>
		<pubDate>Thu, 30 Apr 2026 05:38:10 +0000</pubDate>
		<generator>MyBB</generator>
		<item>
			<title><![CDATA[Microsoft Defender Antivirus security intelligence]]></title>
			<link>https://www.geeks.fyi/showthread.php?tid=21707</link>
			<pubDate>Wed, 01 Apr 2026 07:25:30 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.geeks.fyi/member.php?action=profile&uid=1322">harlan4096</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.geeks.fyi/showthread.php?tid=21707</guid>
			<description><![CDATA[<blockquote class="mycode_quote"><cite>Quote:</cite>Stable channel updates:<ul class="mycode_list"><li>Antimalware Client Version: 4.18.26020.6<br />
</li>
<li>Engine Version: 1.1.26020.3<br />
</li>
</ul>
Enhancements and features​<ul class="mycode_list"><li>Improved the <span style="font-weight: bold;" class="mycode_b">network protection</span> feature to promptly release closed connections and reduce unnecessary memory usage.<br />
</li>
<li>Fixed an issue where the Get-MpComputerStatus PowerShell cmdlet could fail after updates due to a configuration mismatch.<br />
</li>
<li>Improved performance for <span style="font-weight: bold;" class="mycode_b">Network Response Intelligence (NRI)</span> by reducing CPU usage during high-volume asynchronous message processing.<br />
</li>
<li>Added support for <span style="font-weight: bold;" class="mycode_b">AMSI path exclusions for Exchange Server</span> so configured path exclusions are now correctly evaluated during AMSI scanning for Exchange workloads.<br />
</li>
<li>Improved policy refresh behavior for <span style="font-weight: bold;" class="mycode_b">device control</span> by updating default policy and Azure AD refresh intervals to reduce retry frequency.<br />
</li>
</ul>
<a href="https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-endpoint-releases#windows-antivirus--january-2026--platform-418260105--engine-11260101" target="_blank" rel="noopener" class="mycode_url">Microsoft Defender for Endpoint release notes - Microsoft Defender for Endpoint </a></blockquote>
]]></description>
			<content:encoded><![CDATA[<blockquote class="mycode_quote"><cite>Quote:</cite>Stable channel updates:<ul class="mycode_list"><li>Antimalware Client Version: 4.18.26020.6<br />
</li>
<li>Engine Version: 1.1.26020.3<br />
</li>
</ul>
Enhancements and features​<ul class="mycode_list"><li>Improved the <span style="font-weight: bold;" class="mycode_b">network protection</span> feature to promptly release closed connections and reduce unnecessary memory usage.<br />
</li>
<li>Fixed an issue where the Get-MpComputerStatus PowerShell cmdlet could fail after updates due to a configuration mismatch.<br />
</li>
<li>Improved performance for <span style="font-weight: bold;" class="mycode_b">Network Response Intelligence (NRI)</span> by reducing CPU usage during high-volume asynchronous message processing.<br />
</li>
<li>Added support for <span style="font-weight: bold;" class="mycode_b">AMSI path exclusions for Exchange Server</span> so configured path exclusions are now correctly evaluated during AMSI scanning for Exchange workloads.<br />
</li>
<li>Improved policy refresh behavior for <span style="font-weight: bold;" class="mycode_b">device control</span> by updating default policy and Azure AD refresh intervals to reduce retry frequency.<br />
</li>
</ul>
<a href="https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-endpoint-releases#windows-antivirus--january-2026--platform-418260105--engine-11260101" target="_blank" rel="noopener" class="mycode_url">Microsoft Defender for Endpoint release notes - Microsoft Defender for Endpoint </a></blockquote>
]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Microsoft Defender Antivirus security intelligence January 2026]]></title>
			<link>https://www.geeks.fyi/showthread.php?tid=21706</link>
			<pubDate>Wed, 01 Apr 2026 07:25:17 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.geeks.fyi/member.php?action=profile&uid=1322">harlan4096</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.geeks.fyi/showthread.php?tid=21706</guid>
			<description><![CDATA[<blockquote class="mycode_quote"><cite>Quote:</cite>Stable channel updates:<ul class="mycode_list"><li>Antimalware Client Version: 4.18.26020.6<br />
</li>
<li>Engine Version: 1.1.26020.3<br />
</li>
</ul>
Enhancements and features​<ul class="mycode_list"><li>Improved the <span style="font-weight: bold;" class="mycode_b">network protection</span> feature to promptly release closed connections and reduce unnecessary memory usage.<br />
</li>
<li>Fixed an issue where the Get-MpComputerStatus PowerShell cmdlet could fail after updates due to a configuration mismatch.<br />
</li>
<li>Improved performance for <span style="font-weight: bold;" class="mycode_b">Network Response Intelligence (NRI)</span> by reducing CPU usage during high-volume asynchronous message processing.<br />
</li>
<li>Added support for <span style="font-weight: bold;" class="mycode_b">AMSI path exclusions for Exchange Server</span> so configured path exclusions are now correctly evaluated during AMSI scanning for Exchange workloads.<br />
</li>
<li>Improved policy refresh behavior for <span style="font-weight: bold;" class="mycode_b">device control</span> by updating default policy and Azure AD refresh intervals to reduce retry frequency.<br />
</li>
</ul>
<a href="https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-endpoint-releases#windows-antivirus--january-2026--platform-418260105--engine-11260101" target="_blank" rel="noopener" class="mycode_url">Microsoft Defender for Endpoint release notes - Microsoft Defender for Endpoint </a></blockquote>
]]></description>
			<content:encoded><![CDATA[<blockquote class="mycode_quote"><cite>Quote:</cite>Stable channel updates:<ul class="mycode_list"><li>Antimalware Client Version: 4.18.26020.6<br />
</li>
<li>Engine Version: 1.1.26020.3<br />
</li>
</ul>
Enhancements and features​<ul class="mycode_list"><li>Improved the <span style="font-weight: bold;" class="mycode_b">network protection</span> feature to promptly release closed connections and reduce unnecessary memory usage.<br />
</li>
<li>Fixed an issue where the Get-MpComputerStatus PowerShell cmdlet could fail after updates due to a configuration mismatch.<br />
</li>
<li>Improved performance for <span style="font-weight: bold;" class="mycode_b">Network Response Intelligence (NRI)</span> by reducing CPU usage during high-volume asynchronous message processing.<br />
</li>
<li>Added support for <span style="font-weight: bold;" class="mycode_b">AMSI path exclusions for Exchange Server</span> so configured path exclusions are now correctly evaluated during AMSI scanning for Exchange workloads.<br />
</li>
<li>Improved policy refresh behavior for <span style="font-weight: bold;" class="mycode_b">device control</span> by updating default policy and Azure AD refresh intervals to reduce retry frequency.<br />
</li>
</ul>
<a href="https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-endpoint-releases#windows-antivirus--january-2026--platform-418260105--engine-11260101" target="_blank" rel="noopener" class="mycode_url">Microsoft Defender for Endpoint release notes - Microsoft Defender for Endpoint </a></blockquote>
]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Microsoft Defender Antivirus security intelligence November-2025]]></title>
			<link>https://www.geeks.fyi/showthread.php?tid=21425</link>
			<pubDate>Fri, 19 Dec 2025 07:28:08 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.geeks.fyi/member.php?action=profile&uid=1322">harlan4096</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.geeks.fyi/showthread.php?tid=21425</guid>
			<description><![CDATA[<blockquote class="mycode_quote"><cite>Quote:</cite><span style="font-weight: bold;" class="mycode_b">November-2025 (Platform: 4.18.25110.6 | Engine: 1.25110.1)</span><ul class="mycode_list"><li>Security intelligence update version: <span style="font-weight: bold;" class="mycode_b">1.443.6.0</span><br />
</li>
<li>Release date: <span style="font-weight: bold;" class="mycode_b">December 11, 2025 (Engine) / December 17, 2025 (Platform)</span><br />
</li>
<li>Platform: <span style="font-weight: bold;" class="mycode_b">4.18.25110.6</span><br />
</li>
<li>Engine: <span style="font-weight: bold;" class="mycode_b">1.1.25110.1</span><br />
</li>
<li>Support phase: <span style="font-weight: bold;" class="mycode_b">Security and Critical Updates</span><br />
</li>
</ul>
 What's new​<ul class="mycode_list"><li>Performance improvements when querying WMI due to Behavior Monitor detections.<br />
</li>
<li>Fixed potential hang in PowerShell on Server 2016 due to Defender Filter Driver.<br />
</li>
<li>Resolved an application compatibility issue due to a loopback with SMB1 enabled.<br />
</li>
<li>Fixed issue with ASR path exclusion requiring additional "" characters to function appropriately.<br />
</li>
<li>Resolved high I/O issue with NisSrv.exe due to high volume of network logging events.<br />
</li>
<li>Fixed error in threat enumeration causing repeated failure notifications every 15 minutes in SCCM.<br />
</li>
<li>Improved drive mapping enumeration for devices with many drives which resulted in false positive detections for ASR rules.<br />
</li>
<li>Fixed a crash with Defender related to long scan times causing the service to hang in Windows Server 2019<br />
</li>
</ul>
<a href="https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-updates" target="_blank" rel="noopener" class="mycode_url">Microsoft Defender Antivirus security intelligence and product updates - Microsoft Defender for Endpoint</a></blockquote>
]]></description>
			<content:encoded><![CDATA[<blockquote class="mycode_quote"><cite>Quote:</cite><span style="font-weight: bold;" class="mycode_b">November-2025 (Platform: 4.18.25110.6 | Engine: 1.25110.1)</span><ul class="mycode_list"><li>Security intelligence update version: <span style="font-weight: bold;" class="mycode_b">1.443.6.0</span><br />
</li>
<li>Release date: <span style="font-weight: bold;" class="mycode_b">December 11, 2025 (Engine) / December 17, 2025 (Platform)</span><br />
</li>
<li>Platform: <span style="font-weight: bold;" class="mycode_b">4.18.25110.6</span><br />
</li>
<li>Engine: <span style="font-weight: bold;" class="mycode_b">1.1.25110.1</span><br />
</li>
<li>Support phase: <span style="font-weight: bold;" class="mycode_b">Security and Critical Updates</span><br />
</li>
</ul>
 What's new​<ul class="mycode_list"><li>Performance improvements when querying WMI due to Behavior Monitor detections.<br />
</li>
<li>Fixed potential hang in PowerShell on Server 2016 due to Defender Filter Driver.<br />
</li>
<li>Resolved an application compatibility issue due to a loopback with SMB1 enabled.<br />
</li>
<li>Fixed issue with ASR path exclusion requiring additional "" characters to function appropriately.<br />
</li>
<li>Resolved high I/O issue with NisSrv.exe due to high volume of network logging events.<br />
</li>
<li>Fixed error in threat enumeration causing repeated failure notifications every 15 minutes in SCCM.<br />
</li>
<li>Improved drive mapping enumeration for devices with many drives which resulted in false positive detections for ASR rules.<br />
</li>
<li>Fixed a crash with Defender related to long scan times causing the service to hang in Windows Server 2019<br />
</li>
</ul>
<a href="https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-updates" target="_blank" rel="noopener" class="mycode_url">Microsoft Defender Antivirus security intelligence and product updates - Microsoft Defender for Endpoint</a></blockquote>
]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Microsoft Defender Antivirus security intelligence Sept. 2025]]></title>
			<link>https://www.geeks.fyi/showthread.php?tid=21265</link>
			<pubDate>Thu, 23 Oct 2025 09:38:10 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.geeks.fyi/member.php?action=profile&uid=1322">harlan4096</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.geeks.fyi/showthread.php?tid=21265</guid>
			<description><![CDATA[<blockquote class="mycode_quote"><cite>Quote:</cite><a href="https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-updates#september-2025-platform-418250903009--engine-11250903001" target="_blank" rel="noopener" class="mycode_url">September-2025 (Platform: 4.18.25090.3009 | Engine: 1.1.25090.3001)</a><ul class="mycode_list"><li>Security intelligence update version: <span style="font-weight: bold;" class="mycode_b">1.439.345.0</span><br />
</li>
<li>Release date: <span style="font-weight: bold;" class="mycode_b">September 8, 2025 (Engine) / September 21, 2025 (Platform)</span><br />
</li>
<li>Platform: <span style="font-weight: bold;" class="mycode_b">4.18.25090.3009</span><br />
</li>
<li>Engine: <span style="font-weight: bold;" class="mycode_b">1.1.25090.3001</span><br />
</li>
<li>Support phase: <span style="font-weight: bold;" class="mycode_b">Security and Critical Updates</span><br />
</li>
</ul>
 What's new​ <ul class="mycode_list"><li><span style="font-weight: bold;" class="mycode_b">Improved service startup behavior</span>: The core service now only restarts when necessary, for example, during a successful platform update. This change allows the organization to avoid unnecessary restarts when the service is already running correctly.<br />
</li>
<li><span style="font-weight: bold;" class="mycode_b">Improved stability for RPC services</span>: Added input validation across multiple RPC endpoints to prevent crashes caused by malformed data, which addresses a reported security vulnerability.<br />
</li>
<li><span style="font-weight: bold;" class="mycode_b">Fixed threat exclusion handling</span>: Resolved an issue where severity-based exclusions could cause the engine to misidentify threats, potentially skipping high severity detections.<br />
</li>
<li><span style="font-weight: bold;" class="mycode_b">Restored performance optimization for network file access</span>: Fixed a regression that caused slowdowns during file operations, like robocopy to network shares. The fix included reintroducing the logic to skip unnecessary checks on non-local files when Controlled Folder Access is enabled.<br />
</li>
</ul>
</blockquote>
]]></description>
			<content:encoded><![CDATA[<blockquote class="mycode_quote"><cite>Quote:</cite><a href="https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-updates#september-2025-platform-418250903009--engine-11250903001" target="_blank" rel="noopener" class="mycode_url">September-2025 (Platform: 4.18.25090.3009 | Engine: 1.1.25090.3001)</a><ul class="mycode_list"><li>Security intelligence update version: <span style="font-weight: bold;" class="mycode_b">1.439.345.0</span><br />
</li>
<li>Release date: <span style="font-weight: bold;" class="mycode_b">September 8, 2025 (Engine) / September 21, 2025 (Platform)</span><br />
</li>
<li>Platform: <span style="font-weight: bold;" class="mycode_b">4.18.25090.3009</span><br />
</li>
<li>Engine: <span style="font-weight: bold;" class="mycode_b">1.1.25090.3001</span><br />
</li>
<li>Support phase: <span style="font-weight: bold;" class="mycode_b">Security and Critical Updates</span><br />
</li>
</ul>
 What's new​ <ul class="mycode_list"><li><span style="font-weight: bold;" class="mycode_b">Improved service startup behavior</span>: The core service now only restarts when necessary, for example, during a successful platform update. This change allows the organization to avoid unnecessary restarts when the service is already running correctly.<br />
</li>
<li><span style="font-weight: bold;" class="mycode_b">Improved stability for RPC services</span>: Added input validation across multiple RPC endpoints to prevent crashes caused by malformed data, which addresses a reported security vulnerability.<br />
</li>
<li><span style="font-weight: bold;" class="mycode_b">Fixed threat exclusion handling</span>: Resolved an issue where severity-based exclusions could cause the engine to misidentify threats, potentially skipping high severity detections.<br />
</li>
<li><span style="font-weight: bold;" class="mycode_b">Restored performance optimization for network file access</span>: Fixed a regression that caused slowdowns during file operations, like robocopy to network shares. The fix included reintroducing the logic to skip unnecessary checks on non-local files when Controlled Folder Access is enabled.<br />
</li>
</ul>
</blockquote>
]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Microsoft Defender Antivirus security intelligence August-2025]]></title>
			<link>https://www.geeks.fyi/showthread.php?tid=21158</link>
			<pubDate>Fri, 19 Sep 2025 16:05:11 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.geeks.fyi/member.php?action=profile&uid=1322">harlan4096</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.geeks.fyi/showthread.php?tid=21158</guid>
			<description><![CDATA[<blockquote class="mycode_quote"><cite>Quote:</cite><a href="https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-updates#monthly-platform-and-engine-versions" target="_blank" rel="noopener" class="mycode_url">Microsoft Defender Antivirus security intelligence and product updates - Microsoft Defender for Endpoint</a><br />
<br />
August-2025 (Platform: 4.18.25080.5 | Engine: 1.1.25080.5)​<ul class="mycode_list"><li>Security intelligence update version: <span style="font-weight: bold;" class="mycode_b">1.437.1.0</span><br />
</li>
<li>Release date: <span style="font-weight: bold;" class="mycode_b">September 16, 2025 (Engine) / September 17, 2025 (Platform)</span><br />
</li>
<li>Platform: <span style="font-weight: bold;" class="mycode_b">4.18.25080.5</span><br />
</li>
<li>Engine: <span style="font-weight: bold;" class="mycode_b">1.1.25080.5</span><br />
</li>
<li>Support phase: <span style="font-weight: bold;" class="mycode_b">Security and Critical Updates </span><br />
</li>
</ul>
What's new​: Improved Defender update reliability by allowing non-admin processes to trigger shared signature updates, reducing unnecessary privilege requirements.</blockquote>
]]></description>
			<content:encoded><![CDATA[<blockquote class="mycode_quote"><cite>Quote:</cite><a href="https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-updates#monthly-platform-and-engine-versions" target="_blank" rel="noopener" class="mycode_url">Microsoft Defender Antivirus security intelligence and product updates - Microsoft Defender for Endpoint</a><br />
<br />
August-2025 (Platform: 4.18.25080.5 | Engine: 1.1.25080.5)​<ul class="mycode_list"><li>Security intelligence update version: <span style="font-weight: bold;" class="mycode_b">1.437.1.0</span><br />
</li>
<li>Release date: <span style="font-weight: bold;" class="mycode_b">September 16, 2025 (Engine) / September 17, 2025 (Platform)</span><br />
</li>
<li>Platform: <span style="font-weight: bold;" class="mycode_b">4.18.25080.5</span><br />
</li>
<li>Engine: <span style="font-weight: bold;" class="mycode_b">1.1.25080.5</span><br />
</li>
<li>Support phase: <span style="font-weight: bold;" class="mycode_b">Security and Critical Updates </span><br />
</li>
</ul>
What's new​: Improved Defender update reliability by allowing non-admin processes to trigger shared signature updates, reducing unnecessary privilege requirements.</blockquote>
]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Microsoft Defender Antivirus security intelligence June-2025]]></title>
			<link>https://www.geeks.fyi/showthread.php?tid=21076</link>
			<pubDate>Sat, 26 Jul 2025 05:44:08 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.geeks.fyi/member.php?action=profile&uid=1322">harlan4096</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.geeks.fyi/showthread.php?tid=21076</guid>
			<description><![CDATA[<blockquote class="mycode_quote"><cite>Quote:</cite><span style="font-weight: bold;" class="mycode_b">June-2025 (Platform: 4.18.25060.7 | Engine: 1.1.25060.6)</span><ul class="mycode_list"><li>Security intelligence update version: <span style="font-weight: bold;" class="mycode_b">1.433.2.0</span><br />
</li>
<li>Release date: <span style="font-weight: bold;" class="mycode_b">July 22, 2025 (Engine)</span> / <span style="font-weight: bold;" class="mycode_b">July 22, 2025 (Platform)</span><br />
</li>
<li>Platform: <span style="font-weight: bold;" class="mycode_b">4.18.25060.7</span><br />
</li>
<li>Engine: <span style="font-weight: bold;" class="mycode_b">1.1.25060.6</span><br />
</li>
<li>Support phase: <span style="font-weight: bold;" class="mycode_b">Security and Critical Updates</span><br />
</li>
</ul>
What's new​<ul class="mycode_list"><li>Added filtering to improve scan stability and prevent engine crashes<br />
</li>
<li>Additional performance improvements to prevent concurrent scans. This change ensures that if a quick or full scan is already running, no additional quick or full scan scans are initiated from MpCmdRun or Powershell (Start-Scan).<br />
</li>
<li>Resolved the issue where subfolder exclusions were not being honored in Microsoft Defender Antivirus scans related to non-Microsoft SIEM solutions. This fix ensures that specified subfolders are now correctly excluded from scans, preventing unnecessary detections and improving overall system performance.<br />
</li>
</ul>
<a href="https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-updates#monthly-platform-and-engine-versions" target="_blank" rel="noopener" class="mycode_url">Microsoft Defender Antivirus security intelligence and product updates - Microsoft Defender for Endpoint</a></blockquote>
]]></description>
			<content:encoded><![CDATA[<blockquote class="mycode_quote"><cite>Quote:</cite><span style="font-weight: bold;" class="mycode_b">June-2025 (Platform: 4.18.25060.7 | Engine: 1.1.25060.6)</span><ul class="mycode_list"><li>Security intelligence update version: <span style="font-weight: bold;" class="mycode_b">1.433.2.0</span><br />
</li>
<li>Release date: <span style="font-weight: bold;" class="mycode_b">July 22, 2025 (Engine)</span> / <span style="font-weight: bold;" class="mycode_b">July 22, 2025 (Platform)</span><br />
</li>
<li>Platform: <span style="font-weight: bold;" class="mycode_b">4.18.25060.7</span><br />
</li>
<li>Engine: <span style="font-weight: bold;" class="mycode_b">1.1.25060.6</span><br />
</li>
<li>Support phase: <span style="font-weight: bold;" class="mycode_b">Security and Critical Updates</span><br />
</li>
</ul>
What's new​<ul class="mycode_list"><li>Added filtering to improve scan stability and prevent engine crashes<br />
</li>
<li>Additional performance improvements to prevent concurrent scans. This change ensures that if a quick or full scan is already running, no additional quick or full scan scans are initiated from MpCmdRun or Powershell (Start-Scan).<br />
</li>
<li>Resolved the issue where subfolder exclusions were not being honored in Microsoft Defender Antivirus scans related to non-Microsoft SIEM solutions. This fix ensures that specified subfolders are now correctly excluded from scans, preventing unnecessary detections and improving overall system performance.<br />
</li>
</ul>
<a href="https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-updates#monthly-platform-and-engine-versions" target="_blank" rel="noopener" class="mycode_url">Microsoft Defender Antivirus security intelligence and product updates - Microsoft Defender for Endpoint</a></blockquote>
]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Microsoft Defender Antivirus security intelligence May-2025]]></title>
			<link>https://www.geeks.fyi/showthread.php?tid=20965</link>
			<pubDate>Sat, 14 Jun 2025 07:23:38 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.geeks.fyi/member.php?action=profile&uid=1322">harlan4096</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.geeks.fyi/showthread.php?tid=20965</guid>
			<description><![CDATA[<blockquote class="mycode_quote"><cite>Quote:</cite><span style="font-weight: bold;" class="mycode_b"><span style="font-size: small;" class="mycode_size">May-2025 (Platform: 4.18.25050.5 | Engine: 1.1.25050.6)</span>​:</span><ul class="mycode_list"><li>Security intelligence update version: <span style="font-weight: bold;" class="mycode_b">1.431.19.0</span><br />
</li>
<li>Release date: <span style="font-weight: bold;" class="mycode_b">June 13, 2025 (Engine)</span> / <span style="font-weight: bold;" class="mycode_b">June 13, 2025 (Platform)</span><br />
</li>
<li>Platform: <span style="font-weight: bold;" class="mycode_b">4.18.25050.5</span><br />
</li>
<li>Engine: <span style="font-weight: bold;" class="mycode_b">1.1.25050.6</span><br />
</li>
<li>Support phase: <span style="font-weight: bold;" class="mycode_b">Security and Critical Updates</span><br />
</li>
</ul>
What's new​<ul class="mycode_list"><li>Windows multisession SKUs are now properly classified as client SKUs for signature versioning<br />
</li>
<li>EnableDynamicSignatureDroppedEventReporting configuration is now available in Intune (see <a href="https://learn.microsoft.com/en-us/defender-endpoint/troubleshoot-microsoft-defender-antivirus#event-id-2011" target="_blank" rel="noopener" class="mycode_url">Event ID 2011</a>)<br />
</li>
<li>The display name and description is now displayed correctly for the <a href="https://learn.microsoft.com/en-us/defender-endpoint/device-control-overview" target="_blank" rel="noopener" class="mycode_url">device control</a> filter driver in Windows services<br />
</li>
<li>Improved performance for kernel driver<br />
</li>
<li>Improvements to <a href="https://learn.microsoft.com/en-us/defender-endpoint/network-protection#overview-of-network-protection" target="_blank" rel="noopener" class="mycode_url">network protection</a> performance related to packet loss during high network utilization<br />
</li>
<li>Reliability improvements to network protection during service shutdown<br />
</li>
<li>Enriched <a href="https://learn.microsoft.com/en-us/defender-endpoint/troubleshoot-microsoft-defender-antivirus#event-id-1000" target="_blank" rel="noopener" class="mycode_url">Event ID 1000</a> to include ScanOnlyIfIdle and scan priority<br />
</li>
<li>Improved device control Windows Portal Device (WPD) device discovery in File explorer. (For more information about device control, see <a href="https://learn.microsoft.com/en-us/defender-endpoint/device-control-overview#device-control-policy-samples-and-scenarios" target="_blank" rel="noopener" class="mycode_url">Device control policy samples and scenarios</a>.)<br />
</li>
<li>Resolved discrepancy in <a href="https://learn.microsoft.com/en-us/defender-endpoint/device-health-reports" target="_blank" rel="noopener" class="mycode_url">device health reports</a> between signature publish and signature install date and time<br />
</li>
<li>Performance improvements when scanning files/folders with extended attributes<br />
</li>
<li>Reliability improvement in the Defender kernel driver to avoid crashing when there's excessive disk input/output<br />
</li>
<li>Added exponential backoff support to Core Service 1DS manager telemetry module to address memory consumption and DNS flooding issues<br />
</li>
</ul>
<a href="https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-updates#may-2025-platform-418250505--engine-11250506" target="_blank" rel="noopener" class="mycode_url">Microsoft Defender Antivirus security intelligence and product updates - Microsoft Defender</a></blockquote>
]]></description>
			<content:encoded><![CDATA[<blockquote class="mycode_quote"><cite>Quote:</cite><span style="font-weight: bold;" class="mycode_b"><span style="font-size: small;" class="mycode_size">May-2025 (Platform: 4.18.25050.5 | Engine: 1.1.25050.6)</span>​:</span><ul class="mycode_list"><li>Security intelligence update version: <span style="font-weight: bold;" class="mycode_b">1.431.19.0</span><br />
</li>
<li>Release date: <span style="font-weight: bold;" class="mycode_b">June 13, 2025 (Engine)</span> / <span style="font-weight: bold;" class="mycode_b">June 13, 2025 (Platform)</span><br />
</li>
<li>Platform: <span style="font-weight: bold;" class="mycode_b">4.18.25050.5</span><br />
</li>
<li>Engine: <span style="font-weight: bold;" class="mycode_b">1.1.25050.6</span><br />
</li>
<li>Support phase: <span style="font-weight: bold;" class="mycode_b">Security and Critical Updates</span><br />
</li>
</ul>
What's new​<ul class="mycode_list"><li>Windows multisession SKUs are now properly classified as client SKUs for signature versioning<br />
</li>
<li>EnableDynamicSignatureDroppedEventReporting configuration is now available in Intune (see <a href="https://learn.microsoft.com/en-us/defender-endpoint/troubleshoot-microsoft-defender-antivirus#event-id-2011" target="_blank" rel="noopener" class="mycode_url">Event ID 2011</a>)<br />
</li>
<li>The display name and description is now displayed correctly for the <a href="https://learn.microsoft.com/en-us/defender-endpoint/device-control-overview" target="_blank" rel="noopener" class="mycode_url">device control</a> filter driver in Windows services<br />
</li>
<li>Improved performance for kernel driver<br />
</li>
<li>Improvements to <a href="https://learn.microsoft.com/en-us/defender-endpoint/network-protection#overview-of-network-protection" target="_blank" rel="noopener" class="mycode_url">network protection</a> performance related to packet loss during high network utilization<br />
</li>
<li>Reliability improvements to network protection during service shutdown<br />
</li>
<li>Enriched <a href="https://learn.microsoft.com/en-us/defender-endpoint/troubleshoot-microsoft-defender-antivirus#event-id-1000" target="_blank" rel="noopener" class="mycode_url">Event ID 1000</a> to include ScanOnlyIfIdle and scan priority<br />
</li>
<li>Improved device control Windows Portal Device (WPD) device discovery in File explorer. (For more information about device control, see <a href="https://learn.microsoft.com/en-us/defender-endpoint/device-control-overview#device-control-policy-samples-and-scenarios" target="_blank" rel="noopener" class="mycode_url">Device control policy samples and scenarios</a>.)<br />
</li>
<li>Resolved discrepancy in <a href="https://learn.microsoft.com/en-us/defender-endpoint/device-health-reports" target="_blank" rel="noopener" class="mycode_url">device health reports</a> between signature publish and signature install date and time<br />
</li>
<li>Performance improvements when scanning files/folders with extended attributes<br />
</li>
<li>Reliability improvement in the Defender kernel driver to avoid crashing when there's excessive disk input/output<br />
</li>
<li>Added exponential backoff support to Core Service 1DS manager telemetry module to address memory consumption and DNS flooding issues<br />
</li>
</ul>
<a href="https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-updates#may-2025-platform-418250505--engine-11250506" target="_blank" rel="noopener" class="mycode_url">Microsoft Defender Antivirus security intelligence and product updates - Microsoft Defender</a></blockquote>
]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Microsoft Defender Antivirus security intelligence April-2025]]></title>
			<link>https://www.geeks.fyi/showthread.php?tid=20878</link>
			<pubDate>Fri, 16 May 2025 06:42:54 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.geeks.fyi/member.php?action=profile&uid=1322">harlan4096</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.geeks.fyi/showthread.php?tid=20878</guid>
			<description><![CDATA[<blockquote class="mycode_quote"><cite>Quote:</cite><span style="font-weight: bold;" class="mycode_b">April-2025 (Platform: TBD | Engine: 1.1.25040.1)</span><ul class="mycode_list"><li>Security intelligence update version: <span style="font-weight: bold;" class="mycode_b">1.429.3.0</span><br />
</li>
<li>Release date: <span style="font-weight: bold;" class="mycode_b">May 14, 2025 (Engine)</span> / (Platform pending)<br />
</li>
<li>Platform: (<span style="font-style: italic;" class="mycode_i">coming soon</span>)<br />
</li>
<li>Engine: <span style="font-weight: bold;" class="mycode_b">1.1.25040.1</span><br />
</li>
<li>Support phase: <span style="font-weight: bold;" class="mycode_b">Security and Critical Updates</span><br />
</li>
</ul>
What's new​<ul class="mycode_list"><li>Fixed TVM Block where we failed to block a trusted file<br />
</li>
<li>Fixed Microsoft Defender platform update timestamp to reflect the actual update time.<br />
</li>
<li>The <a href="https://learn.microsoft.com/en-us/defender-endpoint/troubleshoot-microsoft-defender-antivirus#event-id-1002" target="_blank" rel="noopener" class="mycode_url">1002 event</a> (An anti-malware scan was stopped before it finished) now includes details of the stop reason.<br />
</li>
<li>Added more details to the <a href="https://learn.microsoft.com/en-us/defender-endpoint/troubleshoot-microsoft-defender-antivirus#event-id-1000" target="_blank" rel="noopener" class="mycode_url">1000 event</a> (Scan started), like scan trigger and scan on idle.<br />
</li>
<li>Improved ASR file processing to correctly handle <a href="https://learn.microsoft.com/en-us/defender-endpoint/indicators-overview" target="_blank" rel="noopener" class="mycode_url">"allow" Indicators of Compromise</a> (IoCs).<br />
</li>
<li>Improvement in health reporting for machines that are rebooted or hibernated.<br />
</li>
<li>Improved performance for <a href="https://learn.microsoft.com/en-us/windows/apps/develop/smart-app-control/overview" target="_blank" rel="noopener" class="mycode_url">Smart App Control</a> (SAC) trusted file handling.<br />
</li>
<li>Improved <a href="https://learn.microsoft.com/en-us/defender-endpoint/device-control-overview" target="_blank" rel="noopener" class="mycode_url">device control</a> logic for offline printers.<br />
</li>
</ul>
<a href="https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-updates#monthly-platform-and-engine-versions" target="_blank" rel="noopener" class="mycode_url">Microsoft Defender Antivirus security intelligence and product updates - Microsoft Defender for Endpoint</a></blockquote>
]]></description>
			<content:encoded><![CDATA[<blockquote class="mycode_quote"><cite>Quote:</cite><span style="font-weight: bold;" class="mycode_b">April-2025 (Platform: TBD | Engine: 1.1.25040.1)</span><ul class="mycode_list"><li>Security intelligence update version: <span style="font-weight: bold;" class="mycode_b">1.429.3.0</span><br />
</li>
<li>Release date: <span style="font-weight: bold;" class="mycode_b">May 14, 2025 (Engine)</span> / (Platform pending)<br />
</li>
<li>Platform: (<span style="font-style: italic;" class="mycode_i">coming soon</span>)<br />
</li>
<li>Engine: <span style="font-weight: bold;" class="mycode_b">1.1.25040.1</span><br />
</li>
<li>Support phase: <span style="font-weight: bold;" class="mycode_b">Security and Critical Updates</span><br />
</li>
</ul>
What's new​<ul class="mycode_list"><li>Fixed TVM Block where we failed to block a trusted file<br />
</li>
<li>Fixed Microsoft Defender platform update timestamp to reflect the actual update time.<br />
</li>
<li>The <a href="https://learn.microsoft.com/en-us/defender-endpoint/troubleshoot-microsoft-defender-antivirus#event-id-1002" target="_blank" rel="noopener" class="mycode_url">1002 event</a> (An anti-malware scan was stopped before it finished) now includes details of the stop reason.<br />
</li>
<li>Added more details to the <a href="https://learn.microsoft.com/en-us/defender-endpoint/troubleshoot-microsoft-defender-antivirus#event-id-1000" target="_blank" rel="noopener" class="mycode_url">1000 event</a> (Scan started), like scan trigger and scan on idle.<br />
</li>
<li>Improved ASR file processing to correctly handle <a href="https://learn.microsoft.com/en-us/defender-endpoint/indicators-overview" target="_blank" rel="noopener" class="mycode_url">"allow" Indicators of Compromise</a> (IoCs).<br />
</li>
<li>Improvement in health reporting for machines that are rebooted or hibernated.<br />
</li>
<li>Improved performance for <a href="https://learn.microsoft.com/en-us/windows/apps/develop/smart-app-control/overview" target="_blank" rel="noopener" class="mycode_url">Smart App Control</a> (SAC) trusted file handling.<br />
</li>
<li>Improved <a href="https://learn.microsoft.com/en-us/defender-endpoint/device-control-overview" target="_blank" rel="noopener" class="mycode_url">device control</a> logic for offline printers.<br />
</li>
</ul>
<a href="https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-updates#monthly-platform-and-engine-versions" target="_blank" rel="noopener" class="mycode_url">Microsoft Defender Antivirus security intelligence and product updates - Microsoft Defender for Endpoint</a></blockquote>
]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Microsoft Defender Antivirus security intelligence - March-2025 (Platform: 4.18.2503]]></title>
			<link>https://www.geeks.fyi/showthread.php?tid=20778</link>
			<pubDate>Fri, 11 Apr 2025 10:02:21 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.geeks.fyi/member.php?action=profile&uid=1322">harlan4096</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.geeks.fyi/showthread.php?tid=20778</guid>
			<description><![CDATA[<blockquote class="mycode_quote"><cite>Quote:</cite><a href="https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-updates#platform-and-engine-releases" target="_blank" rel="noopener" class="mycode_url">Microsoft Defender Antivirus security intelligence and product updates - Microsoft Defender for Endpoint</a><br />
<br />
Manage how Microsoft Defender Antivirus receives protection and product updates.learn.microsoft.com <br />
<br />
March-2025 (Platform: 4.18.25030.2 | Engine 1.1.25030.1)​<ul class="mycode_list"><li>Security intelligence update version: <span style="font-weight: bold;" class="mycode_b">1.427.3.0</span><br />
</li>
<li>Release date: <span style="font-weight: bold;" class="mycode_b">April 1, 2025</span> (Engine) / <span style="font-weight: bold;" class="mycode_b">April 9, 2025</span> (Platform)<br />
</li>
<li>Platform: <span style="font-weight: bold;" class="mycode_b">4.18.25030.2</span><br />
</li>
<li>Engine: <span style="font-weight: bold;" class="mycode_b">1.1.25030.1</span><br />
</li>
<li>Support phase: <span style="font-weight: bold;" class="mycode_b">Security and Critical Updates</span><br />
</li>
</ul>
What's new​<ul class="mycode_list"><li>Improved caching of <a href="https://learn.microsoft.com/en-us/defender-endpoint/device-control-policies" target="_blank" rel="noopener" class="mycode_url">device control settings</a> to improve reliability in occasionally connected environments.<br />
</li>
<li>Performance improvement in on-access scans of files in network locations.<br />
</li>
<li>Fixed the Defender service description to match the latest installed version.<br />
</li>
<li>Improved Defender engine update logic when the update is included in a custom image.<br />
</li>
<li>Fix in health reporting where signature update data might have been incorrect.<br />
</li>
<li>Fixed reporting issue with <a href="https://learn.microsoft.com/en-us/defender-endpoint/controlled-folders" target="_blank" rel="noopener" class="mycode_url">controlled folder access</a> (CFA) protected folders using the PowerShell cmdlet <a href="https://learn.microsoft.com/en-us/powershell/module/defender/get-mppreference" target="_blank" rel="noopener" class="mycode_url">Get-MpPreference</a> when CFA is disabled.<br />
</li>
<li>Improved performance when scanning UPX-packed files (Ultimate Packer for eXecutables) and updated the validation process to verify the integrity of the packed file itself.<br />
</li>
<li>Added support for distinguishing regular cloud allow signatures from clean <a href="https://learn.microsoft.com/en-us/defender-endpoint/indicators-overview" target="_blank" rel="noopener" class="mycode_url">Indicators of Compromise</a> (IoC) in <a href="https://learn.microsoft.com/en-us/defender-endpoint/attack-surface-reduction" target="_blank" rel="noopener" class="mycode_url">attack surface reduction</a> (ASR).<br />
</li>
</ul>
</blockquote>
]]></description>
			<content:encoded><![CDATA[<blockquote class="mycode_quote"><cite>Quote:</cite><a href="https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-updates#platform-and-engine-releases" target="_blank" rel="noopener" class="mycode_url">Microsoft Defender Antivirus security intelligence and product updates - Microsoft Defender for Endpoint</a><br />
<br />
Manage how Microsoft Defender Antivirus receives protection and product updates.learn.microsoft.com <br />
<br />
March-2025 (Platform: 4.18.25030.2 | Engine 1.1.25030.1)​<ul class="mycode_list"><li>Security intelligence update version: <span style="font-weight: bold;" class="mycode_b">1.427.3.0</span><br />
</li>
<li>Release date: <span style="font-weight: bold;" class="mycode_b">April 1, 2025</span> (Engine) / <span style="font-weight: bold;" class="mycode_b">April 9, 2025</span> (Platform)<br />
</li>
<li>Platform: <span style="font-weight: bold;" class="mycode_b">4.18.25030.2</span><br />
</li>
<li>Engine: <span style="font-weight: bold;" class="mycode_b">1.1.25030.1</span><br />
</li>
<li>Support phase: <span style="font-weight: bold;" class="mycode_b">Security and Critical Updates</span><br />
</li>
</ul>
What's new​<ul class="mycode_list"><li>Improved caching of <a href="https://learn.microsoft.com/en-us/defender-endpoint/device-control-policies" target="_blank" rel="noopener" class="mycode_url">device control settings</a> to improve reliability in occasionally connected environments.<br />
</li>
<li>Performance improvement in on-access scans of files in network locations.<br />
</li>
<li>Fixed the Defender service description to match the latest installed version.<br />
</li>
<li>Improved Defender engine update logic when the update is included in a custom image.<br />
</li>
<li>Fix in health reporting where signature update data might have been incorrect.<br />
</li>
<li>Fixed reporting issue with <a href="https://learn.microsoft.com/en-us/defender-endpoint/controlled-folders" target="_blank" rel="noopener" class="mycode_url">controlled folder access</a> (CFA) protected folders using the PowerShell cmdlet <a href="https://learn.microsoft.com/en-us/powershell/module/defender/get-mppreference" target="_blank" rel="noopener" class="mycode_url">Get-MpPreference</a> when CFA is disabled.<br />
</li>
<li>Improved performance when scanning UPX-packed files (Ultimate Packer for eXecutables) and updated the validation process to verify the integrity of the packed file itself.<br />
</li>
<li>Added support for distinguishing regular cloud allow signatures from clean <a href="https://learn.microsoft.com/en-us/defender-endpoint/indicators-overview" target="_blank" rel="noopener" class="mycode_url">Indicators of Compromise</a> (IoC) in <a href="https://learn.microsoft.com/en-us/defender-endpoint/attack-surface-reduction" target="_blank" rel="noopener" class="mycode_url">attack surface reduction</a> (ASR).<br />
</li>
</ul>
</blockquote>
]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Microsoft Defender Antivirus security intelligence and product updates]]></title>
			<link>https://www.geeks.fyi/showthread.php?tid=20752</link>
			<pubDate>Thu, 03 Apr 2025 13:44:20 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.geeks.fyi/member.php?action=profile&uid=1322">harlan4096</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.geeks.fyi/showthread.php?tid=20752</guid>
			<description><![CDATA[<blockquote class="mycode_quote"><cite>Quote:</cite><a href="https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-updates#monthly-platform-and-engine-versions" target="_blank" rel="noopener" class="mycode_url">Microsoft Defender Antivirus security intelligence and product updates - Microsoft Defender for Endpoint</a><br />
<br />
March-2025 (Engine 1.1.25030.1)<br />
<br />
Security intelligence update version: 1.427.3.0<br />
Release date: April 1, 2025 (Engine only)<br />
Platform: 4.18.25020.1009<br />
Engine: 1.1.25030.1<br />
Support phase: Security and Critical Updates<br />
<br />
<span style="font-weight: bold;" class="mycode_b">What's new</span><br />
<br />
Product improvements</blockquote>
]]></description>
			<content:encoded><![CDATA[<blockquote class="mycode_quote"><cite>Quote:</cite><a href="https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-updates#monthly-platform-and-engine-versions" target="_blank" rel="noopener" class="mycode_url">Microsoft Defender Antivirus security intelligence and product updates - Microsoft Defender for Endpoint</a><br />
<br />
March-2025 (Engine 1.1.25030.1)<br />
<br />
Security intelligence update version: 1.427.3.0<br />
Release date: April 1, 2025 (Engine only)<br />
Platform: 4.18.25020.1009<br />
Engine: 1.1.25030.1<br />
Support phase: Security and Critical Updates<br />
<br />
<span style="font-weight: bold;" class="mycode_b">What's new</span><br />
<br />
Product improvements</blockquote>
]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Microsoft Defender Antivirus security intelligence and product updates - Microsoft De]]></title>
			<link>https://www.geeks.fyi/showthread.php?tid=20625</link>
			<pubDate>Sat, 22 Feb 2025 08:41:42 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.geeks.fyi/member.php?action=profile&uid=1322">harlan4096</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.geeks.fyi/showthread.php?tid=20625</guid>
			<description><![CDATA[<blockquote class="mycode_quote"><cite>Quote:</cite><a href="https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-updates#monthly-platform-and-engine-versions" target="_blank" rel="noopener" class="mycode_url">Microsoft Defender Antivirus security intelligence and product updates - Microsoft Defender for Endpoint</a><br />
<br />
January-2025 (Platform: 4.18.25010.xxxx | Engine: 1.1.25010.7)<br />
<br />
Security intelligence update version: 1.423.21.0<br />
Release date: February 20, 2025 (Engine) / TBD (Platform)<br />
Platform: 4.18.225010.xxxx (Platform release is pending)<br />
Engine: 1.1.25010.7<br />
Support phase: Security and Critical Updates<br />
<br />
What's new<br />
<br />
Improved handling of attack surface reduction rule exclusions.<br />
Improved AMSI scan performance with changes to exclusion handling.<br />
Fixed Controlled Folder Access (CFA) protection for OneDrive when backup is enabled.<br />
Fixed performance issues with full scans when initiated from the Microsoft Defender portal.<br />
Fixed ASR warn mode processing for containerized objects (such as Office files) when the unblock option is selected.<br />
Fixed ASR warn mode processing when exclusions are applied.<br />
Fixed performance handling with file transfers having Mark of the Web (MoTW) set.<br />
Implemented AzureAd cache to handle offline environments with device control.<br />
Resolved an issue with TrustLabelProtectionStatus being reset after a Microsoft Defender platform update.<br />
Resolved an issue with tamper protection for exclusions where an exclusion policy was handled by System Center Configuration Manager.<br />
Fixed issue with device control auditing of removable media.<br />
Fixed issue with MDM policy management on Azure Virtual Desktop.<br />
Added support for wildcards in tamper protection trusted process.<br />
Improved device control policy enforcement in offline environments.</blockquote>
]]></description>
			<content:encoded><![CDATA[<blockquote class="mycode_quote"><cite>Quote:</cite><a href="https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-updates#monthly-platform-and-engine-versions" target="_blank" rel="noopener" class="mycode_url">Microsoft Defender Antivirus security intelligence and product updates - Microsoft Defender for Endpoint</a><br />
<br />
January-2025 (Platform: 4.18.25010.xxxx | Engine: 1.1.25010.7)<br />
<br />
Security intelligence update version: 1.423.21.0<br />
Release date: February 20, 2025 (Engine) / TBD (Platform)<br />
Platform: 4.18.225010.xxxx (Platform release is pending)<br />
Engine: 1.1.25010.7<br />
Support phase: Security and Critical Updates<br />
<br />
What's new<br />
<br />
Improved handling of attack surface reduction rule exclusions.<br />
Improved AMSI scan performance with changes to exclusion handling.<br />
Fixed Controlled Folder Access (CFA) protection for OneDrive when backup is enabled.<br />
Fixed performance issues with full scans when initiated from the Microsoft Defender portal.<br />
Fixed ASR warn mode processing for containerized objects (such as Office files) when the unblock option is selected.<br />
Fixed ASR warn mode processing when exclusions are applied.<br />
Fixed performance handling with file transfers having Mark of the Web (MoTW) set.<br />
Implemented AzureAd cache to handle offline environments with device control.<br />
Resolved an issue with TrustLabelProtectionStatus being reset after a Microsoft Defender platform update.<br />
Resolved an issue with tamper protection for exclusions where an exclusion policy was handled by System Center Configuration Manager.<br />
Fixed issue with device control auditing of removable media.<br />
Fixed issue with MDM policy management on Azure Virtual Desktop.<br />
Added support for wildcards in tamper protection trusted process.<br />
Improved device control policy enforcement in offline environments.</blockquote>
]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Microsoft Defender Antivirus security intelligence and product updates]]></title>
			<link>https://www.geeks.fyi/showthread.php?tid=20147</link>
			<pubDate>Fri, 12 Jul 2024 09:46:50 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.geeks.fyi/member.php?action=profile&uid=1322">harlan4096</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.geeks.fyi/showthread.php?tid=20147</guid>
			<description><![CDATA[<blockquote class="mycode_quote"><cite>Quote:</cite><a href="https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-updates#monthly-platform-and-engine-versions" target="_blank" rel="noopener" class="mycode_url">Microsoft Defender Antivirus security intelligence and product updates - Microsoft Defender for Endpoint</a><br />
<br />
June-2024 (Platform: 4.18.24060.xxxx | Engine: 1.1.24060.5)​<ul class="mycode_list"><li>Security intelligence update version: <span style="font-weight: bold;" class="mycode_b">1.415.1.0</span><br />
</li>
<li>Release date: <span style="font-weight: bold;" class="mycode_b">July 9, 2024</span> (Engine) / <span style="font-weight: bold;" class="mycode_b">TBD</span> (Platform)<br />
</li>
<li>Platform: <span style="font-weight: bold;" class="mycode_b">4.18.24060.xxxx</span><br />
</li>
<li>Engine: <span style="font-weight: bold;" class="mycode_b">1.1.24060.5</span><br />
</li>
<li>Support phase: <span style="font-weight: bold;" class="mycode_b">Security and Critical Updates</span><br />
</li>
</ul>
What's new​<ul class="mycode_list"><li>Fixed issue where Microsoft Defender Antivirus was not properly changing state when non-Microsoft antivirus/antimalware software was installed and <a href="https://learn.microsoft.com/en-us/windows/security/application-security/application-control/windows-defender-application-control/wdac" target="_blank" rel="noopener" class="mycode_url">Windows Defender Application Control</a> (WDAC) with <a href="https://learn.microsoft.com/en-us/windows/security/application-security/application-control/windows-defender-application-control/design/use-wdac-with-intelligent-security-graph" target="_blank" rel="noopener" class="mycode_url">Intelligent Security Graph</a> were enabled.<br />
</li>
<li>Fixed deadlock issue on <a href="https://learn.microsoft.com/en-us/defender-endpoint/deployment-vdi-microsoft-defender-antivirus" target="_blank" rel="noopener" class="mycode_url">VDI</a> that occurred when loading corrupted update files from UNC share.<br />
</li>
<li>Custom scans started with <a href="https://learn.microsoft.com/en-us/powershell/module/defender/start-mpscan" target="_blank" rel="noopener" class="mycode_url">Start-MpScan</a> are now reported in the event log.<br />
</li>
<li>Fixed potential deadlock that occurred on volume mount scanning.<br />
</li>
<li>Fixed issue where Microsoft Defender Antivirus did not allow applications to clean up temporary files.<br />
</li>
<li>Fixed potentially packet loss due to <a href="https://learn.microsoft.com/en-us/defender-endpoint/network-protection" target="_blank" rel="noopener" class="mycode_url">network protection</a> shutdown that could lead to deadlock.<br />
</li>
<li>Implemented performance improvements for scenarios where WDAC is enabled with Intelligent Security Graph.<br />
</li>
<li>Fixed an issue where an Outlook exclusion for the ASR rule <a href="https://learn.microsoft.com/en-us/defender-endpoint/attack-surface-reduction-rules-reference#block-office-applications-from-injecting-code-into-other-processes" target="_blank" rel="noopener" class="mycode_url">Block Office applications from injecting code into other processes</a> was not honored.<br />
</li>
</ul>
</blockquote>
]]></description>
			<content:encoded><![CDATA[<blockquote class="mycode_quote"><cite>Quote:</cite><a href="https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-updates#monthly-platform-and-engine-versions" target="_blank" rel="noopener" class="mycode_url">Microsoft Defender Antivirus security intelligence and product updates - Microsoft Defender for Endpoint</a><br />
<br />
June-2024 (Platform: 4.18.24060.xxxx | Engine: 1.1.24060.5)​<ul class="mycode_list"><li>Security intelligence update version: <span style="font-weight: bold;" class="mycode_b">1.415.1.0</span><br />
</li>
<li>Release date: <span style="font-weight: bold;" class="mycode_b">July 9, 2024</span> (Engine) / <span style="font-weight: bold;" class="mycode_b">TBD</span> (Platform)<br />
</li>
<li>Platform: <span style="font-weight: bold;" class="mycode_b">4.18.24060.xxxx</span><br />
</li>
<li>Engine: <span style="font-weight: bold;" class="mycode_b">1.1.24060.5</span><br />
</li>
<li>Support phase: <span style="font-weight: bold;" class="mycode_b">Security and Critical Updates</span><br />
</li>
</ul>
What's new​<ul class="mycode_list"><li>Fixed issue where Microsoft Defender Antivirus was not properly changing state when non-Microsoft antivirus/antimalware software was installed and <a href="https://learn.microsoft.com/en-us/windows/security/application-security/application-control/windows-defender-application-control/wdac" target="_blank" rel="noopener" class="mycode_url">Windows Defender Application Control</a> (WDAC) with <a href="https://learn.microsoft.com/en-us/windows/security/application-security/application-control/windows-defender-application-control/design/use-wdac-with-intelligent-security-graph" target="_blank" rel="noopener" class="mycode_url">Intelligent Security Graph</a> were enabled.<br />
</li>
<li>Fixed deadlock issue on <a href="https://learn.microsoft.com/en-us/defender-endpoint/deployment-vdi-microsoft-defender-antivirus" target="_blank" rel="noopener" class="mycode_url">VDI</a> that occurred when loading corrupted update files from UNC share.<br />
</li>
<li>Custom scans started with <a href="https://learn.microsoft.com/en-us/powershell/module/defender/start-mpscan" target="_blank" rel="noopener" class="mycode_url">Start-MpScan</a> are now reported in the event log.<br />
</li>
<li>Fixed potential deadlock that occurred on volume mount scanning.<br />
</li>
<li>Fixed issue where Microsoft Defender Antivirus did not allow applications to clean up temporary files.<br />
</li>
<li>Fixed potentially packet loss due to <a href="https://learn.microsoft.com/en-us/defender-endpoint/network-protection" target="_blank" rel="noopener" class="mycode_url">network protection</a> shutdown that could lead to deadlock.<br />
</li>
<li>Implemented performance improvements for scenarios where WDAC is enabled with Intelligent Security Graph.<br />
</li>
<li>Fixed an issue where an Outlook exclusion for the ASR rule <a href="https://learn.microsoft.com/en-us/defender-endpoint/attack-surface-reduction-rules-reference#block-office-applications-from-injecting-code-into-other-processes" target="_blank" rel="noopener" class="mycode_url">Block Office applications from injecting code into other processes</a> was not honored.<br />
</li>
</ul>
</blockquote>
]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Microsoft Defender Antivirus security intelligence and product updates]]></title>
			<link>https://www.geeks.fyi/showthread.php?tid=19899</link>
			<pubDate>Thu, 04 Apr 2024 07:36:35 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.geeks.fyi/member.php?action=profile&uid=1322">harlan4096</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.geeks.fyi/showthread.php?tid=19899</guid>
			<description><![CDATA[<blockquote class="mycode_quote"><cite>Quote:</cite><a href="https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/microsoft-defender-antivirus-updates?view=o365-worldwide#monthly-platform-and-engine-versions" target="_blank" rel="noopener" class="mycode_url"><span style="font-weight: bold;" class="mycode_b">March-2024 (Engine: 1.1.24030.4 | Platform: Coming soon)​</span></a><ul class="mycode_list"><li>Security intelligence update version: <span style="font-weight: bold;" class="mycode_b">1.409.1.0</span><br />
</li>
<li>Release date: <span style="font-weight: bold;" class="mycode_b">April 2, 2024</span> (Engine) / <span style="font-weight: bold;" class="mycode_b">Coming soon</span> (Platform)<br />
</li>
<li>Engine: <span style="font-weight: bold;" class="mycode_b">1.1.24030.4</span><br />
</li>
<li>Platform: <span style="font-weight: bold;" class="mycode_b">Coming soon</span><br />
</li>
<li>Support phase: <span style="font-weight: bold;" class="mycode_b">Security and Critical Updates</span><br />
</li>
</ul>
What's new​<ul class="mycode_list"><li>Added manageability settings to opt-out for One Collector telemetry channel and Experimentation and Configuration Service (ECS).<br />
</li>
<li>Microsoft Defender Core Service will be disabled when 3rd party Antivirus is installed (except when Defender for Endpoint is running in Passive mode).<br />
</li>
<li>The known issue in <a href="https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/microsoft-defender-antivirus-updates?view=o365-worldwide#february-2024-engine-11240209--platform-418240207" target="_blank" rel="noopener" class="mycode_url">4.18.24020.7</a> where enforcement of device level access policies wasn't working as expected no longer occurs.<br />
</li>
<li>Fixed high CPU issue caused by redetection done during Sense originating scans.<br />
</li>
<li>Fixed an issue with Security Intelligence Update disk cleanup.<br />
</li>
<li>Fixed an issue where the Signature date information on the Security Health report wasn't accurate.<br />
</li>
<li>Introducted performance improvements when processing paths for exclusions.<br />
</li>
<li>Added improvements to allow recovering from erroneously added <a href="https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/manage-indicators?view=o365-worldwide" target="_blank" rel="noopener" class="mycode_url">Indicators of compromise (IoC)</a>.<br />
</li>
<li>Improved resilience in processing <a href="https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/attack-surface-reduction?view=o365-worldwide" target="_blank" rel="noopener" class="mycode_url">attack surface reduction</a> exclusions for Anti Malware Scan Interface (AMSI) scans.<br />
</li>
<li>Fixed a high memory issue related to the <a href="https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/behavior-monitor?view=o365-worldwide" target="_blank" rel="noopener" class="mycode_url">Behavior Monitoring</a> queue that occured when MAPS is disabled.<br />
</li>
<li>A possible deadlock when receiving a <a href="https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/prevent-changes-to-security-settings-with-tamper-protection?view=o365-worldwide" target="_blank" rel="noopener" class="mycode_url">Tamper protection</a> configuration change from the <a href="https://security.microsoft.com/" target="_blank" rel="noopener" class="mycode_url">Microsoft Defender portal</a> no longer occurs.<br />
</li>
</ul>
</blockquote>
]]></description>
			<content:encoded><![CDATA[<blockquote class="mycode_quote"><cite>Quote:</cite><a href="https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/microsoft-defender-antivirus-updates?view=o365-worldwide#monthly-platform-and-engine-versions" target="_blank" rel="noopener" class="mycode_url"><span style="font-weight: bold;" class="mycode_b">March-2024 (Engine: 1.1.24030.4 | Platform: Coming soon)​</span></a><ul class="mycode_list"><li>Security intelligence update version: <span style="font-weight: bold;" class="mycode_b">1.409.1.0</span><br />
</li>
<li>Release date: <span style="font-weight: bold;" class="mycode_b">April 2, 2024</span> (Engine) / <span style="font-weight: bold;" class="mycode_b">Coming soon</span> (Platform)<br />
</li>
<li>Engine: <span style="font-weight: bold;" class="mycode_b">1.1.24030.4</span><br />
</li>
<li>Platform: <span style="font-weight: bold;" class="mycode_b">Coming soon</span><br />
</li>
<li>Support phase: <span style="font-weight: bold;" class="mycode_b">Security and Critical Updates</span><br />
</li>
</ul>
What's new​<ul class="mycode_list"><li>Added manageability settings to opt-out for One Collector telemetry channel and Experimentation and Configuration Service (ECS).<br />
</li>
<li>Microsoft Defender Core Service will be disabled when 3rd party Antivirus is installed (except when Defender for Endpoint is running in Passive mode).<br />
</li>
<li>The known issue in <a href="https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/microsoft-defender-antivirus-updates?view=o365-worldwide#february-2024-engine-11240209--platform-418240207" target="_blank" rel="noopener" class="mycode_url">4.18.24020.7</a> where enforcement of device level access policies wasn't working as expected no longer occurs.<br />
</li>
<li>Fixed high CPU issue caused by redetection done during Sense originating scans.<br />
</li>
<li>Fixed an issue with Security Intelligence Update disk cleanup.<br />
</li>
<li>Fixed an issue where the Signature date information on the Security Health report wasn't accurate.<br />
</li>
<li>Introducted performance improvements when processing paths for exclusions.<br />
</li>
<li>Added improvements to allow recovering from erroneously added <a href="https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/manage-indicators?view=o365-worldwide" target="_blank" rel="noopener" class="mycode_url">Indicators of compromise (IoC)</a>.<br />
</li>
<li>Improved resilience in processing <a href="https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/attack-surface-reduction?view=o365-worldwide" target="_blank" rel="noopener" class="mycode_url">attack surface reduction</a> exclusions for Anti Malware Scan Interface (AMSI) scans.<br />
</li>
<li>Fixed a high memory issue related to the <a href="https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/behavior-monitor?view=o365-worldwide" target="_blank" rel="noopener" class="mycode_url">Behavior Monitoring</a> queue that occured when MAPS is disabled.<br />
</li>
<li>A possible deadlock when receiving a <a href="https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/prevent-changes-to-security-settings-with-tamper-protection?view=o365-worldwide" target="_blank" rel="noopener" class="mycode_url">Tamper protection</a> configuration change from the <a href="https://security.microsoft.com/" target="_blank" rel="noopener" class="mycode_url">Microsoft Defender portal</a> no longer occurs.<br />
</li>
</ul>
</blockquote>
]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Microsoft Defender Application Guard for Office explained]]></title>
			<link>https://www.geeks.fyi/showthread.php?tid=12828</link>
			<pubDate>Tue, 15 Sep 2020 09:39:13 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.geeks.fyi/member.php?action=profile&uid=1322">harlan4096</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.geeks.fyi/showthread.php?tid=12828</guid>
			<description><![CDATA[<blockquote class="mycode_quote"><cite>Quote:</cite><div style="text-align: center;" class="mycode_align"><img src="https://www.ghacks.net/wp-content/uploads/2020/09/office-untrusted-document-application-guard.png" loading="lazy"  alt="[Image: office-untrusted-document-application-guard.png]" class="mycode_img" /></div>
<br />
Microsoft Defender Application Guard for Office is a new security feature designed to load untrusted Office documents, e.g. an Excel spreadsheet downloaded from the Internet, in an isolated environment to keep the underlying system and its data protected against potential attacks.<br />
<br />
The security feature is based on Microsoft Defender Application Guard, which is designed to load untrusted sites in an isolated container using automated and standalone modes. Automated mode, called Enterprise Management Mode, has an admin define trusted sites through GPO or other management interfaces.<br />
<br />
These sites are loaded normally on the system while all other sites are considered untrusted and therefore launched in the virtual environment.<br />
<br />
Standalone mode on the other hand has the user launch Microsoft Defender Application Guard manually to use it.<br />
<br />
Microsoft Defender Application Guard for Office attempts to address threats that exploit weaknesses in Microsoft Office that related to the supported documents or its features. The core idea is to launch untrusted files in a safe environment to avoid interactions with the host system, its data, and the network.<br />
<br />
Office users can still view, edit, print, and save documents in the Office application.<br />
 <br />
<blockquote class="mycode_quote"><cite>Quote:</cite>Microsoft Office will open files from potentially unsafe locations in  Microsoft Defender Application Guard, a secure container, that is isolated from the device through hardware-based virtualization. When Microsoft Office opens files in Microsoft Defender Application Guard, a user can then securely read, edit,  print, and save the files without having to re-open files outside of the container.</blockquote>
<br />
Microsoft Defender Application Guard for Office has the following hardware and software requirements:<ul class="mycode_list"><li>64-bit processor with at least 4 cores (physical or virtual), virtualization extensions (Intel VT-x or AMT-V), Core i5 or higher.<br />
</li>
<li>8 Gigabytes of memory.<br />
</li>
<li>10 Gigabytes of free hard disk space.<br />
</li>
<li>Windows 10 version 2004 build 19041 or later, Enterprise edition only<br />
</li>
<li>Licensing requirement: Microsoft 365 E5 or E5 Security.<br />
</li>
<li>Office Beta Channel build version 2008 or later.<br />
</li>
<li><a href="https://support.microsoft.com/en-us/help/4566782/windows-10-update-kb4566782" target="_blank" rel="noopener" class="mycode_url">Kb4566782</a> installed<br />
</li>
</ul>
Microsoft limits the feature to Enterprise versions of Windows 10 and customers who are subscribed to either Microsoft 365 E5 or E5 Security.<br />
<br />
Microsoft Defender Application Guard needs to be enabled on the system using the Windows Features interface or by executing the following PowerShell command: Enable-WindowsOptionalFeature -online -FeatureName Windows-Defender-ApplicationGuard<br />
<br />
Administrators need to open the Group Policy Editor and turn the Microsoft Defender Application Guard policy on. It is found @ Computer Configuration\Administrative Templates\Windows Components\Microsoft Defender Application Guard and needs to be set to 2 or 3.<ul class="mycode_list"><li>2 enables Microsoft Defender Application Guard for isolated Windows environments ONLY.<br />
</li>
<li>3 enables Microsoft Defender Application Guard for Microsoft Edge and isolated Windows environments.<br />
</li>
</ul>
Now launch an untrusted document, e.g. one downloaded from the Internet, to verify that Application Guard for Office has been set up correctly. You should get a "To keep you safe, we're opening this document in Application Guard" notice.<br />
<br />
The title bar of the interface should display the Application Guard icon which indicates that it is loaded in a virtual environment as well.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Closing Words</span><br />
<br />
Microsoft Defender Application Guard for Office eliminates many Office document related attack vectors when deployed on user systems. It would be great if Microsoft would make the feature available to all customers, and not just Enterprise customers, but the chance of this happening is not very high.<br />
<br />
Home users may use other virtualization software, e.g. <a href="https://www.ghacks.net/2019/10/29/how-to-use-sandboxie-for-browsing-downloading-and-installing-programs/" target="_blank" rel="noopener" class="mycode_url">Sandboxie</a> or virtual machines, to load untrusted files.<br />
<br />
Check out Microsoft's Docs website for <a href="https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/install-app-guard?view=o365-worldwide" target="_blank" rel="noopener" class="mycode_url">additional information</a>.<br />
...</blockquote>
<a href="https://www.ghacks.net/2020/09/15/microsoft-defender-application-guard-for-office-explained/?fbclid=IwAR0Nai3L2GzcPocTNe85E8cRwKloxG80k9-6dHlkZfrryTdPYXZfjM-am-U" target="_blank" rel="noopener" class="mycode_url">Continue Reading</a>]]></description>
			<content:encoded><![CDATA[<blockquote class="mycode_quote"><cite>Quote:</cite><div style="text-align: center;" class="mycode_align"><img src="https://www.ghacks.net/wp-content/uploads/2020/09/office-untrusted-document-application-guard.png" loading="lazy"  alt="[Image: office-untrusted-document-application-guard.png]" class="mycode_img" /></div>
<br />
Microsoft Defender Application Guard for Office is a new security feature designed to load untrusted Office documents, e.g. an Excel spreadsheet downloaded from the Internet, in an isolated environment to keep the underlying system and its data protected against potential attacks.<br />
<br />
The security feature is based on Microsoft Defender Application Guard, which is designed to load untrusted sites in an isolated container using automated and standalone modes. Automated mode, called Enterprise Management Mode, has an admin define trusted sites through GPO or other management interfaces.<br />
<br />
These sites are loaded normally on the system while all other sites are considered untrusted and therefore launched in the virtual environment.<br />
<br />
Standalone mode on the other hand has the user launch Microsoft Defender Application Guard manually to use it.<br />
<br />
Microsoft Defender Application Guard for Office attempts to address threats that exploit weaknesses in Microsoft Office that related to the supported documents or its features. The core idea is to launch untrusted files in a safe environment to avoid interactions with the host system, its data, and the network.<br />
<br />
Office users can still view, edit, print, and save documents in the Office application.<br />
 <br />
<blockquote class="mycode_quote"><cite>Quote:</cite>Microsoft Office will open files from potentially unsafe locations in  Microsoft Defender Application Guard, a secure container, that is isolated from the device through hardware-based virtualization. When Microsoft Office opens files in Microsoft Defender Application Guard, a user can then securely read, edit,  print, and save the files without having to re-open files outside of the container.</blockquote>
<br />
Microsoft Defender Application Guard for Office has the following hardware and software requirements:<ul class="mycode_list"><li>64-bit processor with at least 4 cores (physical or virtual), virtualization extensions (Intel VT-x or AMT-V), Core i5 or higher.<br />
</li>
<li>8 Gigabytes of memory.<br />
</li>
<li>10 Gigabytes of free hard disk space.<br />
</li>
<li>Windows 10 version 2004 build 19041 or later, Enterprise edition only<br />
</li>
<li>Licensing requirement: Microsoft 365 E5 or E5 Security.<br />
</li>
<li>Office Beta Channel build version 2008 or later.<br />
</li>
<li><a href="https://support.microsoft.com/en-us/help/4566782/windows-10-update-kb4566782" target="_blank" rel="noopener" class="mycode_url">Kb4566782</a> installed<br />
</li>
</ul>
Microsoft limits the feature to Enterprise versions of Windows 10 and customers who are subscribed to either Microsoft 365 E5 or E5 Security.<br />
<br />
Microsoft Defender Application Guard needs to be enabled on the system using the Windows Features interface or by executing the following PowerShell command: Enable-WindowsOptionalFeature -online -FeatureName Windows-Defender-ApplicationGuard<br />
<br />
Administrators need to open the Group Policy Editor and turn the Microsoft Defender Application Guard policy on. It is found @ Computer Configuration\Administrative Templates\Windows Components\Microsoft Defender Application Guard and needs to be set to 2 or 3.<ul class="mycode_list"><li>2 enables Microsoft Defender Application Guard for isolated Windows environments ONLY.<br />
</li>
<li>3 enables Microsoft Defender Application Guard for Microsoft Edge and isolated Windows environments.<br />
</li>
</ul>
Now launch an untrusted document, e.g. one downloaded from the Internet, to verify that Application Guard for Office has been set up correctly. You should get a "To keep you safe, we're opening this document in Application Guard" notice.<br />
<br />
The title bar of the interface should display the Application Guard icon which indicates that it is loaded in a virtual environment as well.<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Closing Words</span><br />
<br />
Microsoft Defender Application Guard for Office eliminates many Office document related attack vectors when deployed on user systems. It would be great if Microsoft would make the feature available to all customers, and not just Enterprise customers, but the chance of this happening is not very high.<br />
<br />
Home users may use other virtualization software, e.g. <a href="https://www.ghacks.net/2019/10/29/how-to-use-sandboxie-for-browsing-downloading-and-installing-programs/" target="_blank" rel="noopener" class="mycode_url">Sandboxie</a> or virtual machines, to load untrusted files.<br />
<br />
Check out Microsoft's Docs website for <a href="https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/install-app-guard?view=o365-worldwide" target="_blank" rel="noopener" class="mycode_url">additional information</a>.<br />
...</blockquote>
<a href="https://www.ghacks.net/2020/09/15/microsoft-defender-application-guard-for-office-explained/?fbclid=IwAR0Nai3L2GzcPocTNe85E8cRwKloxG80k9-6dHlkZfrryTdPYXZfjM-am-U" target="_blank" rel="noopener" class="mycode_url">Continue Reading</a>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Microsoft Safety Scanner 1.0.3001.0]]></title>
			<link>https://www.geeks.fyi/showthread.php?tid=12431</link>
			<pubDate>Sun, 09 Aug 2020 09:04:26 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.geeks.fyi/member.php?action=profile&uid=1474">Deep900</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.geeks.fyi/showthread.php?tid=12431</guid>
			<description><![CDATA[<blockquote class="mycode_quote"><cite>Quote:</cite>Microsoft Safety Scanner is a scan tool designed to find and remove malware from Windows computers. Simply download it and run a scan to find malware and try to reverse changes made by identified threats.</blockquote>
<br />
<a href="https://docs.microsoft.com/en-gb/windows/security/threat-protection/intelligence/safety-scanner-download" target="_blank" rel="noopener" class="mycode_url">https://docs.microsoft.com/en-gb/windows...r-download</a>]]></description>
			<content:encoded><![CDATA[<blockquote class="mycode_quote"><cite>Quote:</cite>Microsoft Safety Scanner is a scan tool designed to find and remove malware from Windows computers. Simply download it and run a scan to find malware and try to reverse changes made by identified threats.</blockquote>
<br />
<a href="https://docs.microsoft.com/en-gb/windows/security/threat-protection/intelligence/safety-scanner-download" target="_blank" rel="noopener" class="mycode_url">https://docs.microsoft.com/en-gb/windows...r-download</a>]]></content:encoded>
		</item>
	</channel>
</rss>