"the Defender service might be disabled on some devices," according to Microsoft.
Affected versions and scope
Microsoft disclosed that a defect in Microsoft Defender for Endpoint on Linux affected versions 101.26042.0000 through 101.26042.0009 across all supported Linux operating systems. The vendor warned that an upgrade or reinstall followed by a reboot could result in the Defender service being disabled on some devices. The product at issue protects server workloads both on-premises and in the cloud and is integrated into the Microsoft Defender portal to provide unified visibility.
How the bug manifested and why it matters
The fault appears after an upgrade or reinstall: when the affected build was installed and the machine rebooted, "the Defender service might be disabled on some devices," Microsoft said. The company did not specify the technical cause of the service failure. Microsoft also cautioned that "if an affected version was installed, the issue might impact active protection on rebooted devices until remediation steps are taken," leaving administrators to identify and restore protection after the fact.
This is a notable failure mode because endpoint protection is expressly designed to run continuously; anything that can knock an agent out of service — even temporarily — undermines prevention, detection and response capabilities and complicates incident monitoring through the Defender portal.
FIPS-mode installation failure on RHEL 8 and 9
Microsoft described a separate problem specifically for Red Hat Enterprise Linux (RHEL) 8 and 9 systems running in FIPS mode: the same 101.26042.x update could fail to install, leaving devices on their previous version. The vendor explained that FIPS refers to US Federal Information Processing Standards, which "in this context impose requirements on the cryptography used by government and other regulated systems." In short, devices hardened to meet FIPS cryptographic requirements could be blocked from upgrading, while other devices might have received a version that disabled the Defender service on reboot.
Remediation: patched builds and update behavior
Microsoft's alert noted that where Defender for Servers (Plan 1 or 2) is used with Defender for Cloud and the Microsoft Defender Endpoint (MDE) integration is enabled, "automatic updates for the MDE.Linux extension are enabled by default, which means your machines could have received an affected version automatically." The vendor's release notes direct users affected by the disabled-service bug to build 101.26042.0011. The separate FIPS installation problem is fixed in version 101.26052.0011 and later.
Microsoft's advisory did not, in the alert text, list an available update for every scenario; rather, readers are pointed to the release notes for the specific builds that address the two problems. The combination of automatic extension updates and multiple fixes means administrators need to map their deployments to the appropriate replacement builds.
What this means for administrators, Defender for Servers customers, and security teams
- Administrators and security teams: verify whether affected builds were deployed and whether any systems have rebooted since the install; the company cautioned that active protection could be impacted on rebooted devices until remediation steps are taken. Where Defender for Servers Plans 1 or 2 are used with the Defender for Cloud MDE integration, check automatic-update settings for the MDE.Linux extension because default behavior could have pushed the affected builds.
- Defender for Servers customers: organizations that rely on the integrated update path should identify which machines received 101.26042.0000–0009 and apply the corresponding fixes — 101.26042.0011 for the disabled-service issue and 101.26052.0011 or later for the FIPS installation failure — as indicated in Microsoft's release notes.
- Security operations and procurement leaders: the episode underscores a tension in tightly unified platforms: the convenience of centralized management can accelerate delivery of a defective build to many servers, while the same centralization makes it imperative to track build numbers and remediation guidance closely.
Microsoft has "an unfortunate habit of shipping broken updates for its flagship operating system, Windows," the report observed, and an update that breaks software intended to protect devices compounds the stakes. In this case two intersecting issues — a build that can disable protection on reboot and an installation that refuses to apply on FIPS-hardened RHEL systems — left Linux servers either unprotected or unable to move forward until vendors' patched builds are applied and administrators verify status post-reboot.




