What's new in Microsoft Defender for Endpoint - Microsoft Defender for Endpoint (2024)

Edit

Share via

  • Article

Applies to:

  • Microsoft Defender for Endpoint Plan 1
  • Microsoft Defender for Endpoint Plan 2
  • Microsoft Defender XDR

Want to experience Defender for Endpoint? Sign up for a free trial.

The following features are in preview or generally available (GA) in the latest release of Microsoft Defender for Endpoint.

For more information on preview features, see Preview features.

For more information on what's new with Microsoft Defender for Endpoint on Windows, see:What's new in Microsoft Defender for Endpoint on Windows

For more information on what's new with other Microsoft Defender security products, see:

  • What's new in Microsoft Defender XDR
  • What's new in Microsoft Defender for Office 365
  • What's new in Microsoft Defender for Identity
  • What's new in Microsoft Defender for Cloud Apps
  • What's new in Microsoft Defender Vulnerability Management

For more information on Microsoft Defender for Endpoint on specific operating systems:

  • What's new in Defender for Endpoint on Windows
  • What's new in Defender for Endpoint on macOS
  • What's new in Defender for Endpoint on Linux
  • What's new in Defender for Endpoint on Android
  • What's new in Defender for Endpoint on iOS

July 2024

  • (GA) Learning hub resources have moved from the Microsoft Defender portal to learn.microsoft.com. Access Microsoft Defender XDR Ninja training, learning paths, training modules and more. Browse the list of learning paths, and filter by product, role, level, and subject.

June 2024

  • (Preview) BitLocker support for Device control: Allows device control to apply policy based on the BitLocker encrypted state of a device.

May 2024

  • (GA) Microsoft Defender for Endpoint plug-in for Windows Subsystem for Linux (WSL) is now generally available (GA version - 1.24.522.2). The plug-in enables Defender for Endpoint to provide more visibility into all running WSL containers by plugging into the isolated subsystem.

  • (Preview) Turn preview options on in the main Microsoft 365 Defender settings together with other Microsoft 365 Defender preview features. Customers who aren't using preview features yet continue to see the legacy settings under Settings > Endpoints > Advanced features > Preview features. For more information, see Microsoft 365 Defender preview features.

  • (GA) Streamlined device connectivity for Defender for Endpoint is now generally available for Windows, macOS, and Linux. This experience makes it easier to configure and manage Defender for Endpoint services by reducing the number of URLs required for connectivity, providing IP & Azure service tag support, and simplifying post-deployment network management.

  • (GA) Microsoft Defender Core service is now generally available on Windows clients. Helps with the stability and performance of Microsoft Defender Antivirus.

April 2024

Microsoft Defender for Endpoint on macOS feature now in GA:

  • Troubleshooting mode for macOS : Troubleshooting mode helps you identify instances where antivirus might be causing issues with your applications or system resources. To learn more, see Troubleshooting mode in Microsoft Defender for Endpoint on macOS.

March 2024

  • (GA) Built-in Scheduled scan for macOS: For information on Scheduled Scan built-in for Microsoft Defender for Endpoint on macOS, see How to schedule scans with Microsoft Defender for Endpoint on macOS

February 2024

Attack Surface Reduction (ASR) Rules

Two new ASR rules are now in public preview:

  • Block rebooting machine in Safe Mode (preview): This rule prevents the execution of commands to restart machines in Safe Mode.
  • Block use of copied or impersonated system tools (preview): This rule blocks the use of executable files that are identified as copies of Windows system tools. These files are either duplicates or impostors of the original system tools.

Microsoft Defender for Endpoint on macOS features are in public preview:

  • Built-in Scheduled Scan for macOS (preview): Scheduled Scan built-in for Microsoft Defender for Endpoint on macOS is now available in public preview. To learn more, see How to schedule scans with Microsoft Defender for Endpoint on macOS.

  • Troubleshooting mode for macOS (preview): Troubleshooting mode for macOS is now available in public preview. Troubleshooting mode helps you identify instances where antivirus might be causing issues with your applications or system resources. To learn more, see Troubleshooting mode in Microsoft Defender for Endpoint on macOS.

January 2024

  • Defender Boxed is available for a limited period of time. Defender Boxed highlights your organization's security successes, improvements, and response actions during 2023. Take a moment to celebrate your organization's improvements in security posture, overall response to detected threats (manual and automatic), blocked emails, and more.

    • Defender Boxed opens automatically when you go to the Incidents page in the Microsoft Defender portal.
    • If you close Defender Boxed and you want to reopen it, in the Microsoft Defender portal, go to Incidents, and then select Your Defender Boxed.
    • Act quickly! Defender Boxed is available only for a short period of time.
  • (GA) User Contain can now contain compromised users automatically stopping Human Operated Ransomware in its track using Automatic Attack Disruption.

November 2023

  • Microsoft Defender Core service overview is now available for consumers and is planned to begin rolling out to enterprise customers in early 2024.
  • The Microsoft Defender for Endpoint plug-in for Windows Subsystem for Linux (WSL) is now available in public preview.
  • Support for mixed-license scenarios is now generally available in Defender for Endpoint.

October 2023

  • (GA) The device isolation and run antivirus scan responses in macOS and Linux are now generally available. You can now remotely run an AV scan or isolate devices when responding to attacks.
  • (Public Preview) Streamlined device connectivity for Defender for Endpoint is available in public preview for Windows, macOS, and Linux. This experience makes it easier to configure and manage Defender for Endpoint services by reducing the number of URLs required for connectivity, providing IP & Azure service tag support, and simplifying post-deployment network management.
  • (Public Preview) User Contain can now contain compromised users automatically stopping Human Operated Ransomware in its track using Automatic Attack Disruption.

September 2023

(GA) Protecting Dev Drive using performance mode is now generally available. The goal of Performance mode is to improve functional performance for developers who use Windows 11. Performance mode reduces the performance impact of Microsoft Defender Antivirus scans for files stored on designated Dev Drive.

August 2023

  • (GA) The Monthly security summary report is now generally available. The report helps organizations get a visual summary of key findings and overall preventative actions taken to enhance the organization's overall security posture completed in the last month.

July 2023

  • The eBPF-based sensor for Microsoft Defender for Endpoint on Linux is available for public preview on all supported Linux devices. For more information, see Use eBPF-based sensor for Microsoft Defender for Endpoint on Linux.
  • Manage endpoint security policies in Defender for Endpoint is now in public preview
    You can now configure security settings directly in Microsoft Defender XDR.
  • A new file page is now available in Defender for Endpoint. The file page now includes information like file details and file content and capabilities. For more information, see Investigate files.

June 2023

  • Microsoft Defender Antivirus scan response action is supported for macOS and Linux for client version 101.98.84 and above. It is in preview. See Run Microsoft Defender Antivirus scan on devices.
  • Isolating devices from the network is supported for macOS for client version 101.98.84 and above. It is in preview. See Isolate devices from the network.
  • Forcibly releasing devices from isolation is now available for public preview. This new capability allows you to forcibly release devices from isolation, when isolated devices become unresponsive. For more information, see Forcibly release device from isolation.

May 2023

  • Performance mode for Microsoft Defender Antivirus is now available for public preview. This new capability provides asynchronous scanning on a Dev Drive, and doesn't change the security posture of your system drive or other drives. For more information, see Protecting Dev Drive using performance mode.

March 2023

  • Support for mixed-licensing scenarios is now in preview! With these capabilities, you can Manage Microsoft Defender for Endpoint subscription settings across client devices (preview!).

February 2023

  • The Microsoft Defender for Identity integration toggle is now removed from the Microsoft Defender for Endpoint Settings > Advanced features page. Because Defender for Identity is now integrated with Microsoft Defender XDR, this toggle is no longer required. You don't need to manually configure integration between services. See What's new - Microsoft Defender for Identity.

January 2023

  • Tamper protection can now protect exclusions when deployed with Microsoft Intune. See Protect Microsoft Defender Antivirus exclusions from tampering

  • Live Response is now generally available for macOS and Linux. For more information, see Investigate entities on devices using live response.

  • Live response API and library API for Linux and macOS is now generally available
    You can now run live response API commands on Linux and macOS.

Prior to 2023

For information about features released prior to 2023, see Archive - What's new in Defender for Endpoint, December 2022 and earlier.

Feedback

Was this page helpful?

Provide product feedback

Feedback

Coming soon: Throughout 2024 we will be phasing out GitHub Issues as the feedback mechanism for content and replacing it with a new feedback system. For more information see: https://aka.ms/ContentUserFeedback.

Submit and view feedback for

This product This page

What's new in Microsoft Defender for Endpoint - Microsoft Defender for Endpoint (2024)

FAQs

What is the new Defender for Endpoint? ›

Microsoft Defender for Endpoint (MDE) is a massive stack of endpoint protection and endpoint detection and response (EDR) capabilities. It integrates with the broader Microsoft Defender XDR and is available for almost any OS you'll find in an enterprise.

What is the difference between Microsoft Defender and Microsoft Defender for Endpoint? ›

Microsoft Defender for Office 365 is a cloud-based product offering protection against email threats and safeguarding files stored in the cloud. Microsoft Defender for Endpoint provides cybersecurity against malware, spyware and other malicious software.

What's new in Windows Defender? ›

(Preview) The application governance add-on feature to Defender for Cloud Apps is now available in Microsoft Defender XDR. App governance provides a security and policy management capability designed for OAuth-enabled apps that access Microsoft 365 data through Microsoft Graph APIs.

What are the components of Microsoft Defender for Endpoint? ›

Microsoft Defender for Endpoint
  • Core Defender Vulnerability Management. ...
  • Attack surface reduction. ...
  • Next-generation protection. ...
  • Endpoint detection and response. ...
  • Automated investigation and remediation. ...
  • Microsoft Secure Score for Devices. ...
  • Microsoft Threat Experts. ...
  • Centralized configuration and administration, APIs.
May 31, 2024

What is the new name for Microsoft Defender for Endpoint? ›

Product Name Changes
Previous nameNew name
Microsoft Defender Advanced Threat ProtectionMicrosoft Defender for Endpoint
Microsoft Threat ProtectionMicrosoft 365 Defender
Office 365 Advanced Threat ProtectionMicrosoft Defender for Office 365
Microsoft 365 BusinessMicrosoft 365 Business Premium
56 more rows

What is the difference between defender for endpoint and EDR? ›

Endpoint Detection and Response

Microsoft Defender for Endpoint is an EDR because it lets your team detect, investigate and respond to threats all across your endpoints.

Is Windows Defender good enough now? ›

Windows Defender shines with solid protection. A four-week review of over 19,000 malware files showed 100% coverage protection. You can configure your Windows security center settings for maximum privacy.

What is Windows Defender update? ›

Windows Defender updates (or Microsoft Defender updates) are the regular updates released by Microsoft to keep the software up to date with the latest features and to keep bugs at bay.

What is Windows Defender called now? ›

Microsoft Defender Antivirus (formerly Windows Defender) is an antivirus software component of Microsoft Windows.

Is Microsoft Defender for Endpoint good enough? ›

Microsoft Defender for Endpoint is an excellent security solution for our computer. Also it is already integrated into windows, so we don't need extra software to protect against things like viruses and cyber attacks. It's a handy tool to keep an eye on the security of our computer.

What are the two capabilities of Microsoft Defender for Endpoint? ›

Microsoft Defender Antivirus includes:
  • Real-time antivirus protection with always-on scanning that uses file and process-behavior monitoring and other heuristics. ...
  • Cloud-delivered protection with near-instant detection and blocking of new and emerging cyberthreats.

What is the benefit of Microsoft Defender for Endpoint? ›

Defender for Endpoint is a comprehensive, cloud-native endpoint security solution that delivers visibility and AI-powered cyberthreat protection to help stop cyberattacks across Windows, macOS, Linux, Android, iOS, and IoT devices.

What is Microsoft ATP called now? ›

Defender for Endpoint was previously known as Microsoft Defender Advanced Threat Protection but was rebranded in 2019 along with other products under the Defender brand.

What is the difference between Plan 1 and Plan 2 defender for Endpoint? ›

P2 offers advanced features on top of the core P1 features. They include device discovery, automated investigation, advanced hunting, threat analytics, and sandboxing. P2 provides enterprises a more complete endpoint security with more complete capabilities. Compare plans further.

What is the difference between EDR and ASR? ›

Attack Surface Reduction (ASR)—analyzes attack surfaces and enforces rules that can reduce the attack surface on endpoints. Endpoint Detection and Response (EDR)—helps you detect attacks happening in real time and respond to them directly on endpoint devices.

References

Top Articles
NEET-UG 2024 row: SC to hear over 30 petitions today on re-exam; updates
Find a Resale | Franchise Resales.com
Spasa Parish
Rentals for rent in Maastricht
159R Bus Schedule Pdf
Sallisaw Bin Store
Black Adam Showtimes Near Maya Cinemas Delano
Espn Transfer Portal Basketball
Pollen Levels Richmond
11 Best Sites Like The Chive For Funny Pictures and Memes
Things to do in Wichita Falls on weekends 12-15 September
Craigslist Pets Huntsville Alabama
Paulette Goddard | American Actress, Modern Times, Charlie Chaplin
Red Dead Redemption 2 Legendary Fish Locations Guide (“A Fisher of Fish”)
What's the Difference Between Halal and Haram Meat & Food?
R/Skinwalker
Rugged Gentleman Barber Shop Martinsburg Wv
Jennifer Lenzini Leaving Ktiv
Justified - Streams, Episodenguide und News zur Serie
Epay. Medstarhealth.org
Olde Kegg Bar & Grill Portage Menu
Cubilabras
Half Inning In Which The Home Team Bats Crossword
Amazing Lash Bay Colony
Juego Friv Poki
Dirt Devil Ud70181 Parts Diagram
Truist Bank Open Saturday
Water Leaks in Your Car When It Rains? Common Causes & Fixes
What’s Closing at Disney World? A Complete Guide
New from Simply So Good - Cherry Apricot Slab Pie
Drys Pharmacy
modelo julia - PLAYBOARD
Poker News Views Gossip
Abby's Caribbean Cafe
Joanna Gaines Reveals Who Bought the 'Fixer Upper' Lake House and Her Favorite Features of the Milestone Project
Tri-State Dog Racing Results
Navy Qrs Supervisor Answers
Trade Chart Dave Richard
Lincoln Financial Field Section 110
Free Stuff Craigslist Roanoke Va
Wi Dept Of Regulation & Licensing
Pick N Pull Near Me [Locator Map + Guide + FAQ]
Crystal Westbrooks Nipple
Ice Hockey Dboard
Über 60 Prozent Rabatt auf E-Bikes: Aldi reduziert sämtliche Pedelecs stark im Preis - nur noch für kurze Zeit
Wie blocke ich einen Bot aus Boardman/USA - sellerforum.de
Infinity Pool Showtimes Near Maya Cinemas Bakersfield
Dermpathdiagnostics Com Pay Invoice
How To Use Price Chopper Points At Quiktrip
Maria Butina Bikini
Busted Newspaper Zapata Tx
Latest Posts
Article information

Author: Aracelis Kilback

Last Updated:

Views: 5458

Rating: 4.3 / 5 (44 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Aracelis Kilback

Birthday: 1994-11-22

Address: Apt. 895 30151 Green Plain, Lake Mariela, RI 98141

Phone: +5992291857476

Job: Legal Officer

Hobby: LARPing, role-playing games, Slacklining, Reading, Inline skating, Brazilian jiu-jitsu, Dance

Introduction: My name is Aracelis Kilback, I am a nice, gentle, agreeable, joyous, attractive, combative, gifted person who loves writing and wants to share my knowledge and understanding with you.