Microsoft has just proven that you should never let your guard down with updates, even on Linux. A recent version of Defender for Endpoint has a serious problem with the service automatically disabling itself after a reboot. When a security solution fails like this, it undermines confidence in the entire infrastructure.
Microsoft Defender for Endpoint: an update that puts Linux at risk
Between versions 101.26042.0000 and 101.26042.0009, a critical flaw affects Defender for Endpoint on Linux. Following an update, the service may remain disabled after a reboot. Regardless of the distribution—Debian, Fedora, RHEL—no distribution is immune to the bug.
This problem primarily affects environments combining Defender for Servers Plan 1 or 2 with Defender for Cloud that includes MDE management enabled. In this case, the MDE.Linux extension updates automatically, and that’s where the trap is sprung.
Without manual intervention, your servers remain exposed with significantly reduced security. This is no small matter given today’s increasingly sophisticated cyber threats.
Concrete impacts on Linux production servers
Silent disabling is not without risk. For a Linux infrastructure, it’s like running barefoot through a bramble patch: sooner or later, it ends badly. These servers, which rely on Defender for Endpoint, lose their essential shield if no vigilance is exercised.
Systems teams must absolutely verify the deployed version; this is an essential step to avoid a security fiasco. The latest patched build, 101.26042.0011, is the key to getting things back on track.
Undertaking such a check also means gaining peace of mind, because one cannot blindly trust automatic updates in these kinds of conditions.
The added complication for RHEL 8 & 9 in FIPS mode
The second issue specifically affects Red Hat Enterprise Linux 8 and 9 systems configured in FIPS mode. As a reminder, this mode imposes strict restrictions on the encryption algorithms used, adhering to government or industry standards.
Microsoft has not yet provided a detailed explanation of the technical reasons behind this core issue. It’s the kind of invisible failure that is nonetheless extremely dangerous for the stability and compliance of critical servers.
Corrections are underway, but caution is still advised.
According to The RegisterThe fixes point to build 101.26042.0011 to revive the stopped service, and version 101.26052.0011 for the installation problem on FIPS.
However, administrators must not rest on their laurels. Ensuring that the correct version is deployed is now part of the manual for the perfect Linux administrator under Defender.
Beyond a simple bug, this touches on the crucial concept of a secure endpoint. In practice, a crashed or missing security service is an open invitation for ransomware and other attacks.
Between progress and setbacks: the paradox of Defender for Endpoint on Linux
In a world where trust in open source and free software is essential, these malfunctions are a major problem. How can we reconcile reliability and large-scale deployment on Linux when maintenance is inadequate?
The issue goes beyond mere technology. It is also a challenge of communication and honesty towards users, especially in environments requiring digital sovereignty.
To better understand the technical specifications and updates of the product, the official documentation remains an essential source to consult regularly.
Linux administrators will benefit from keeping up with developments on platforms like Microsoft Defender for Endpoint Linux documentation and to learn through in-depth feedback such as that available on .
Which Linux systems are affected by this Defender for Endpoint bug?
All distributions using versions 101.26042.0000 to 101.26042.0009 are affected. Whether it’s Debian, Fedora, RHEL, or another distribution, the service may remain disabled after a reboot.
Why doesn’t the Defender service reactivate automatically?
The bug prevents the service from restarting automatically after the update, leaving the system without active protection until manual intervention takes place.
What is FIPS mode on RHEL?
The FIPS (Federal Information Processing Standards) mode is a parameter that imposes strict cryptography rules on systems, often required by administrations and regulated sectors.
How do I fix this update problem?
The solution is to apply the corrective builds 101.26042.0011 for deactivation and 101.26052.0011 for installation problems under FIPS.
Yes, as long as the affected version remains in place and unpatched, critical vulnerabilities can remain open, exposing the system to attacks. Strong vigilance is recommended.
Source: www.clubic.com