Microsoft Defender Upgrade Exposes Linux Vulnerabilities – GadgetLad

Microsoft Defender Fiasco: Ignoring Linux Users

Not satisfied with the chaos on Windows, Microsoft has created problems with Defender for Endpoint on Linux. Several issues have arisen, including one that might disable the security service after a reboot, and another that disrupts updates on FIPS-enabled Red Hat Enterprise Linux 8 and 9. Truly a double blow!

Defender Vanishes After Reboot

The more significant issue affected versions 101.26042.0000 to 101.26042.0009 across all supported Linux systems. Following an upgrade or reinstallation and a reboot, the Defender service may opt to go offline on certain devices, according to Microsoft. It’s quite a hassle, particularly if you’re using Defender for Servers (Plan 1 or 2) with the Defender for Cloud integration enabled by default. Your systems might have unknowingly installed an affected version, leaving you unprotected after a reboot. Microsoft remains tight-lipped about the cause of this behavior, but it’s causing IT professionals some anxiety.

FIPS Mode Challenges on RHEL 8 and 9

There’s more! Another issue plagues RHEL 8 and 9 systems operating in FIPS mode: the 101.26042.x update may struggle to install, causing devices to remain outdated. FIPS refers to the US Federal Information Processing Standards, which impose strict requirements on cryptography for government and other tightly regulated environments. While Microsoft hasn’t announced a fix, the release notes direct users facing the disabled-service issue to upgrade to build 101.26042.0011. For the FIPS mode concern, you’ll need version 101.26052.0011 or later to resolve it.

Defender’s Purpose in Server Protection

Microsoft Defender for Endpoint on Linux is designed to protect server workloads both on-premises and in the cloud. Microsoft claims it assists users in preventing, detecting, investigating, and responding to various threats while providing a unified view through the Microsoft Defender portal. While other endpoint security solutions are available, for organizations deeply integrated with Microsoft, the comprehensive management offered by Defender for Endpoint on Linux can be appealing.

Microsoft’s Update Issues: An Ongoing Problem

Microsoft has a tendency to release problematic updates for its flagship product, Windows. Yet, when an update disrupts software intended to safeguard a device, it escalates the situation, especially with increasing cyber threats and the necessity to counter them while maintaining oversight. This is where the unified visibility from the Microsoft Defender portal becomes essential. However, encountering Defender disabled after a reboot – along with an update that fails to cooperate with certain security-focused systems – is far from what you expected.

Conclusion: Microsoft, Get It Together!

Microsoft has truly created a mess with Defender for Endpoint on Linux. With updates that may leave your security inactive or unresponsive, it’s enough to make you wonder what they’re up to. Get it together, Microsoft – tech professionals are relying on you!