Skip to content

Commit 3e21b21

Browse files
authored
Merge pull request #2400 from DebLanger/US544916_FIM
Us544916 FIM
2 parents f224ed2 + 105c5a7 commit 3e21b21

3 files changed

Lines changed: 34 additions & 9 deletions

File tree

articles/defender-for-cloud/file-integrity-monitoring-enable-defender-endpoint.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: Learn how to enable File Integrity Monitoring when you collect data
44
author: Elazark
55
ms.author: elkrieger
66
ms.topic: how-to
7-
ms.date: 06/25/2025
7+
ms.date: 03/22/2026
88
ms.custom: sfi-image-nochange
99
#customer intent: As a security administrator, I want to enable File Integrity Monitoring so that I can detect unauthorized changes to critical files.
1010
---
@@ -18,9 +18,9 @@ After you enable Defender for Servers Plan 2, follow the instructions in this ar
1818
> [!NOTE]
1919
>
2020
> - If you use a previous version of File Integrity Monitoring with the Log Analytics agent (Microsoft Monitoring agent (MMA)) or the Azure Monitor agent (AMA), you can [migrate to the new File Integrity Monitoring experience](migrate-file-integrity-monitoring.md).
21-
> - From June 2025 onwards, File Integrity Monitoring powered by Microsoft Defender for Endpoint requires a minimum version. [Update the agent](#verify-defender-for-endpoint-client-version) as needed.
22-
> - Windows: 10.8760 or later.
23-
> - Linux: 30.124082 or later.
21+
> - File Integrity Monitoring powered by Microsoft Defender for Endpoint requires a minimum agent version. [Update the agent](#verify-defender-for-endpoint-client-version) as needed.
22+
> - **Windows (legacy machines/downlevel clients)**: Defender for Servers Windows client (MDE agent) version 10.8799 or later.
23+
> - **Linux**: 30.124082 or later.
2424
2525
## Prerequisites
2626

articles/defender-for-cloud/file-integrity-monitoring-overview.md

Lines changed: 13 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: Learn about tracking file change with file integrity monitoring in
44
author: Elazark
55
ms.author: elkrieger
66
ms.topic: concept-article
7-
ms.date: 08/12/2025
7+
ms.date: 03/22/2026
88
---
99

1010
# File integrity monitoring
@@ -34,9 +34,19 @@ File integrity monitoring uses the Microsoft Defender for Endpoint agent and age
3434
- Collected file integrity monitoring data is part of the [500-MB benefit included in Defender for Servers Plan 2](data-ingestion-benefit.md).
3535
- File integrity monitoring gives information about file and resource changes. It includes the source of the change, account details, indication of who made the changes, and information about the initiating process.
3636

37-
### Migrate to the new version
37+
## Version requirements
3838

39-
File integrity monitoring previously used the Log Analytics agent (also known as the Microsoft Monitoring agent (MMA)) or the Azure Monitor agent (AMA) to collect data. If you're using file integrity monitoring with one of these legacy methods, you can [migrate file integrity monitoring](migrate-file-integrity-monitoring.md) to use Defender for Endpoint.
39+
To ensure proper file integrity monitoring functionality, machines must run the **Defender for Servers Windows client (Microsoft Defender for Endpoint agent) version 10.8799 or above**. This requirement is especially important for:
40+
41+
- Legacy Windows machines (downlevel clients)
42+
- Environments transitioning from MMA or AMA-based FIM
43+
44+
> [!IMPORTANT]
45+
> Due to a pipeline change in Microsoft Defender for Endpoint, users with existing FIM deployments on legacy Windows machines must update their MDE agent to version 10.8799 or above to continue receiving file integrity monitoring data.
46+
47+
### Migrate legacy AMA/MMA clients to MDE-based file integrity monitoring
48+
49+
If you're currently using file integrity monitoring with legacy agent-based methods (Log Analytics agent/Microsoft Monitoring Agent (MMA) or Azure Monitor Agent (AMA)), you need to migrate to the MDE-based (Microsoft Defender for Endpoint) approach. This migration ensures continued functionality and access to enhanced capabilities. Learn how to [migrate file integrity monitoring](migrate-file-integrity-monitoring.md) from legacy AMA/MMA clients to the MDE-based solution.
4050

4151
## Configure file integrity monitoring
4252

articles/defender-for-cloud/release-notes.md

Lines changed: 17 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: What's new in Microsoft Defender for Cloud features
33
description: What's new and updated in Microsoft Defender for Cloud features
44
ms.topic: overview
5-
ms.date: 03/11/2026
5+
ms.date: 03/22/2026
66
---
77

88
# What's new in Defender for Cloud features
@@ -31,13 +31,28 @@ This article summarizes what's new in Microsoft Defender for Cloud. It includes
3131

3232
| Date | Category | Update |
3333
| -------- | -------- | -------- |
34+
| March 22, 2026| Update | [File Integrity Monitoring requires MDE agent version 10.8799+ for legacy Windows machines](#file-integrity-monitoring-requires-mde-agent-version-108799-for-legacy-windows-machines) |
3435
| March 12, 2026 | GA | [Kubernetes gated deployment support for AKS Automatic (GA)](#kubernetes-gated-deployment-support-for-aks-automatic-ga) |
3536
| March 11, 2026 | GA| [Severity‑based risk assignment for "Not evaluated" recommendations](#severitybased-risk-assignment-for-not-evaluated-recommendations) |
3637
| March 10, 2026| Preview |[Code to runtime enrichment for recommendations](#code-to-runtime-enrichment-for-recommendations-preview)|
3738
| March 10, 2026 | Preview | [On-demand malware scanning of Azure Files in Microsoft Defender for Storage](#on-demand-malware-scanning-of-azure-files-in-microsoft-defender-for-storage-preview) |
3839
| March 04, 2026 | Deprecation | [Deprecation of preview of container and container images vulnerability recommendations](#deprecation-of-preview-of-container-and-container-images-vulnerability-recommendations) |
3940
| March 04, 2026 | Preview |[New individual recommendations format in Azure portal (Preview)](#new-individual-recommendations-format-in-azure-portal-preview)|
4041

42+
### File Integrity Monitoring requires MDE agent version 10.8799+ for legacy Windows machines
43+
44+
March 22, 2026
45+
46+
Due to a pipeline change in Microsoft Defender for Endpoint (MDE), File Integrity Monitoring now requires the **Defender for Servers Windows client (Microsoft Defender for Endpoint agent) version 10.8799 or above** for proper functionality on legacy Windows machines (downlevel clients).
47+
48+
**Key details:**
49+
50+
- **Affected systems**: Legacy Windows machines (Windows Server 2016, Windows Server 2012 R2, and other downlevel clients)
51+
- **Required version**: Defender for Servers Windows client (MDE agent) 10.8799 or later
52+
- **Impact**: FIM monitoring will not function properly on versions below the minimum requirement
53+
54+
Learn more about [File Integrity Monitoring](file-integrity-monitoring-overview.md) and how to [enable File Integrity Monitoring](file-integrity-monitoring-enable-defender-endpoint.md).
55+
4156
### Kubernetes gated deployment support for AKS Automatic (GA)
4257

4358
March 12, 2026
@@ -186,7 +201,7 @@ Learn more about [reviewing security recommendations](review-security-recommenda
186201

187202
| Date | Category | Update |
188203
| -------- | -------- | -------- |
189-
| February 22, 2026 | Preview | [Container runtime anti-malware detection and blocking (Preview)](#container-runtime-anti-malware-detection-and-blocking-preview) |
204+
| February 22, 2026 | Preview | [Container runtime anti-malware detection and blocking (Preview)](#container-runtime-anti-malware-detection-and-blocking-preview)
190205
| February 22, 2026 | Update - Preview | [Binary drift now supports blocking (Preview)](#binary-drift-now-supports-blocking-preview) |
191206
| February 10, 2026| Preview | [Database-level recommendations experience for SQL Vulnerability Assessment findings (Preview)](#database-level-recommendations-experience-for-sql-vulnerability-assessment-preview) |
192207
| February 10, 2026| GA | [Scanning support for Minimus and Photon OS container images](#scanning-support-for-minimus-and-photon-os-container-images) |

0 commit comments

Comments
 (0)