Jul 27, 2026
Policy

Microsoft Defender Linux update can disable protection after reboot

Microsoft says some Defender for Endpoint Linux builds can disable the service after reboot, while a separate RHEL FIPS issue blocks updates.

Dominic Okoye

By Dominic Okoye · Staff Writer

· 3 min read

Microsoft Defender Linux update can disable protection after reboot
Photo: The Register

Microsoft has disclosed two problems tied to a Microsoft Defender Linux update, including one that can leave Defender for Endpoint disabled after an upgrade or reinstall followed by a reboot. The higher-risk issue affects versions 101.26042.0000 through 101.26042.0009 across all supported Linux operating systems, according to Microsoft.

Microsoft said the Defender service “might be disabled on some devices” after the affected builds are installed and the machine is restarted. For operators running Defender for Servers Plan 1 or Plan 2 with Defender for Cloud and Microsoft Defender Endpoint integration enabled, Microsoft said automatic updates for the MDE.Linux extension are turned on by default, so some machines could have received an affected version without manual action.

The company said active protection on rebooted devices could be affected until administrators apply remediation steps. Microsoft did not explain what caused the service to become disabled.

Which Microsoft Defender for Endpoint Linux versions are affected?

The disabled-service issue covers Defender for Endpoint on Linux versions 101.26042.0000 through 101.26042.0009. Microsoft’s release notes direct customers affected by that bug to build 101.26042.0011.

A separate installation problem affects Red Hat Enterprise Linux 8 and 9 systems running in FIPS mode. On those systems, the 101.26042.x update can fail to install, which leaves the device on its prior Defender version rather than moving it forward.

FIPS, short for Federal Information Processing Standards, refers here to US government requirements governing cryptographic implementations. In practice, FIPS mode is common on government and regulated systems, which makes a failed security-agent update more than a routine package-management nuisance for teams responsible for compliance-bound Linux fleets.

Microsoft says the RHEL FIPS installation issue is fixed in version 101.26052.0011 and later. The two issues are separate: one can disable the Defender service after reboot on supported Linux systems, while the other blocks installation on FIPS-enabled RHEL 8 and 9 machines.

Why does this matter for security teams?

Defender for Endpoint on Linux is used to protect server workloads in cloud and on-premises environments. Microsoft describes the product as a way to prevent, detect, investigate and respond to advanced threats through the Microsoft Defender portal.

That unified console is the draw for organizations already standardized on Microsoft security tooling. It also raises the operational risk when an agent update affects availability of protection, because administrators may assume coverage is intact unless they verify service status after reboot.

The practical task for security and infrastructure teams is to identify Linux systems that received versions 101.26042.0000 through 101.26042.0009, check whether the Defender service remains enabled after reboot, and move affected systems to Microsoft’s referenced fixed builds. RHEL 8 and 9 machines in FIPS mode need separate attention because the failed install condition can leave them running an older Defender version rather than the intended update.

This story draws on original reporting from The Register.

More from Policy

All Policy →