Skip to content
Microsoft Defender for Endpoint EDR Updates are now Separate from Monthly Windows Security Updates for Faster Protection

Microsoft Defender for Endpoint EDR Updates are now Separate from Monthly Windows Security Updates for Faster Protection

Written By Anoop C Nair
Last Updated June 19, 2026
SHARE

Key Takeaways

  • Microsoft Defender for Endpoint EDR updates is moving from monthly Windows security updates to Microsoft Update.
  • The rollout started with Windows 10 in late May 2026.
  • Windows 11 and other supported Windows versions will receive the change by 2026.
  • EDR security improvements can now be delivered in Windows cumulative updates.

In this post, we are discussing how Microsoft Defender for Endpoint EDR Updates Will Be Delivered Through Microsoft Update. Microsoft has introduced a new update model for Microsoft Defender for Endpoint Detection and Response (EDR) security updates. Previously, these updates were included with the monthly Windows security updates. This change enables Microsoft to deliver security improvements more quickly and independently of the Windows update cycle.

Table of Contents

Microsoft Defender for Endpoint EDR Updates are now Separate from Monthly Windows Security Updates for Faster Protection

This change allows Microsoft to release EDR security improvements faster without waiting for the monthly Windows update cycle. It also provides a more flexible way to keep Microsoft Defender for Endpoint protected with the latest security enhancements. The rollout began with Windows 10 in late May 2026 and will gradually expand to Windows 11 and other supported Windows versions by fall 2026.

Organisations using Microsoft Update do not need to take any action, while those using manual update deployment should include the new Defender update package in their regular update process.

What’s changing in this Update

Microsoft Defender endpoint detection and response security updates will no longer be bundled with monthly Windows security updates. Instead, they will be delivered through Microsoft Update using KB5005292 after the required prerequisite updates are installed. This change EDR servicing with other Microsoft Defender components and enables Microsoft to release security improvements more quickly without waiting for monthly Windows updates.

Patch My PC

Rollout Schedule:

  • Rollout starts with Windows 10 in late May 2026.
  • Rollout will expand to Windows 11, followed by the remaining supported Windows versions.
  • We expect the rollout for Windows 10 and 11 to be completed by fall 2026.
Why is Microsoft Making This Change?
Faster delivery of security improvements
Reduced dependency on monthly Windows updates
Improved flexibility for Microsoft Defender servicing
More consistent update experience across Microsoft Defender components
Microsoft Defender for Endpoint EDR Updates are now Separate from Monthly Windows Security Updates for Faster Protection – Table 1

How the New Microsoft Defender for Endpoint Update Works

EDR security updates will no longer be included with the monthly Windows security updates. Instead, they will be delivered separately through Microsoft Update using KB5005292. To receive these updates, devices must be running Sense version 10.8798.25857.1000 or later and have the required cumulative update (or a later version) installed.

During the first EDR update, Windows installs a new Defender Update Service and creates the %ProgramData%\Microsoft\Microsoft Defender\Defender Update folder. Most EDR updates do not require a restart, but a reboot may be needed in rare cases if an update fails.

If needed, administrators can use the MpCmdRun.exe command-line tool to roll back an EDR update. You can revert to the inbox EDR version stored in %ProgramFiles%\Windows Defender Advanced Threat Protection or restore the previous (N-1) version if a backup is available in %ProgramData%\Microsoft\Windows Defender Advanced Threat Protection\Platform.

Check Microsoft Defender Version Information

Windows Security lists the installed Microsoft Defender versions, including the antimalware client, engine, antivirus, and antispyware. Administrators can use this information to confirm that Microsoft Defender is installed and updated on the device.

Microsoft Defender for Endpoint EDR Updates are now Separate from Monthly Windows Security Updates for Faster Protection - Fig.1
Microsoft Defender for Endpoint EDR Updates are now Separate from Monthly Windows Security Updates for Faster Protection – Fig.1

Configure Microsoft Defender Update Channels in Intune

Microsoft Intune lets administrators manage Microsoft Defender Antivirus update channels. You can configure the Engine Updates Channel, Platform Updates Channel, and Security Intelligence Updates Channel to control how Defender Antivirus updates are delivered. Microsoft Defender for Endpoint EDR updates is now delivered separately through Microsoft Update under the new update model.

Enable this policy to specify when devices receive Microsoft Defender engine updates during the monthly gradual rollout. Enable this policy to specify when devices receive Microsoft Defender platform updates during the monthly gradual rollout.

Microsoft Defender for Endpoint EDR Updates are now Separate from Monthly Windows Security Updates for Faster Protection - Fig.2
Microsoft Defender for Endpoint EDR Updates are now Separate from Monthly Windows Security Updates for Faster Protection – Fig.2

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, Join the WhatsApp Community  and WhatsApp Channel to get the latest news on Microsoft Technologies. We are there on Reddit as well.

Author

Anoop C Nair has been Microsoft MVP for 10 consecutive years from 2015 onwards. He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM,   Windows,  Cloud PC,  Windows, Entra, Microsoft Security, Career, etc.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Microsoft Defender for Endpoint

Microsoft Defender Custom Data Collection Lets You Collect Custom Endpoint Logs Without Extra Agents

Key Takeaways: Let’s discuss about Microsoft Defender Custom Data Collection to Streamlined Telemetry without Extra Agent. Microsoft announced the general availability of Microsoft Defender Custom Data Collection. This feature is simplified collection of logging through the Defender agent itself. Microsoft Defender Custom Data Collection to Streamlined Telemetry without Extra Agent Admins can define which events […]

AC Anoop C Nair 3 min read
Intune

Manage Offline Security Updates for Linux using Microsoft Defender and Intune

Key Takeaways Manage Offline Security Updates for Linux using Microsoft Defender and Intune! Microsoft now allows admins to manage offline security intelligence updates for Linux devices directly from the Defender and Intune portals. Admins can configure how Linux devices receive Defender security updates without using manual command-line configurations on each device. Configure Offline Security Intelligence […]

AC Anoop C Nair 3 min read
Microsoft Defender for Endpoint

New Selective Response Actions Improve Safer Device Onboarding in Microsoft Defender for Endpoint

Key Takeaways Selective Response Actions is a new Preview feature in Microsoft Defender for Endpoint that gives organizations better control over security response actions during device onboarding. It helps IT and security teams apply high-impact actions more carefully on Tier-0 systems and other important devices, improving protection while maintaining operational stability. New Selective Response Actions […]

AC Anoop C Nair 3 min read
Microsoft Defender for Endpoint

New Microsoft Security Recommendation to Block mshta.exe and Reduce Attack Risks

Key Takeaways Hey, let’s discuss about New Microsoft Security Recommendation to Block mshta.exe and Reduce Attack Risks. Microsoft introduces a new Microsoft Secure Score recommendation in Microsoft Defender for Endpoint (MDE) to help organizations strengthen endpoint security and reduce exposure to common attack techniques. This recommendation focuses on blocking outbound traffic from mshta.exe, a legitimate […]

AC Anoop C Nair 3 min read