Affected versions may stop providing endpoint protection until administrators apply Microsoft's recommended remediation.
Key Takeaways:
Microsoft is investigating two issues affecting Microsoft Defender for Endpoint on Linux, including a newly confirmed bug that could leave some systems without active threat protection after a reboot. The issue may expose affected Linux devices to potential security risks.
According to Microsoft, Defender for Endpoint on Linux may stop working after an upgrade or reinstallation followed by a reboot. When this happens, the endpoint may lose active threat protection until administrators apply a fix. This problem affects versions 101.26042.0000 through 101.26042.0009 across all supported Linux operating systems.
“If you use Defender for Servers (Plan 1 or 2) with Defender for Cloud and have the MDE integration enabled, automatic updates for the MDE.Linux extension are enabled by default, which means your machines could have received an affected version automatically. If an affected version was installed, the issue might impact active protection on rebooted devices until remediation steps are taken,” Microsoft explained.
Microsoft has also fixed an issue that was previously preventing certain Defender for Endpoint on Linux updates from installing on Red Hat Enterprise Linux (RHEL) 8 and 9 systems running in FIPS mode. The company recommends that customers upgrade to 101.26052.0011 or later to fix the FIPS-related installation problem.
FIPS (Federal Information Processing Standards) mode is a security setting used in regulated environments that restricts systems to approved cryptographic algorithms and security controls defined by U.S. government standards. Systems running in FIPS mode enforce stricter encryption requirements, which can sometimes trigger compatibility issues when software updates are not fully validated for those security constraints.
Organizations should immediately audit their Linux endpoints to determine whether any systems received the affected Microsoft Defender for Endpoint versions and verify that the Defender service is still running after recent reboots. Moreover, administrators should upgrade impacted devices to the latest releases as well as confirm protection status through local health checks and centralized monitoring tools. They must also prioritize remediation for internet-facing or business-critical servers where a lapse in endpoint protection could create higher security risk.
Security teams should continuously monitor endpoint health, review patch and reboot logs for anomalies, and validate that security agents remain active after updates. They should also create alerts for disabled or non-responsive protection services so that similar issues can be detected and addressed quickly in the future.