Skip to content

Commit 4a6a316

Browse files
committed
Add MDE agent version requirements for FIM on legacy Windows machines
- Added version requirement section to file-integrity-monitoring-overview.md - Updated prerequisites in migrate-file-integrity-monitoring.md - Users with FIM and legacy Windows machines must update to MDE agent version 10.8799+ due to pipeline change
1 parent ec28a05 commit 4a6a316

2 files changed

Lines changed: 26 additions & 1 deletion

File tree

articles/defender-for-cloud/file-integrity-monitoring-overview.md

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -34,6 +34,16 @@ File integrity monitoring uses the Microsoft Defender for Endpoint agent and age
3434
- Collected file integrity monitoring data is part of the [500-MB benefit included in Defender for Servers Plan 2](data-ingestion-benefit.md).
3535
- File integrity monitoring gives information about file and resource changes. It includes the source of the change, account details, indication of who made the changes, and information about the initiating process.
3636

37+
## Version requirements
38+
39+
To ensure proper file integrity monitoring functionality, machines must run Microsoft Defender for Endpoint agent version **10.8799 or above**. This requirement is especially important for:
40+
41+
- Legacy Windows machines (downlevel clients)
42+
- Environments transitioning from MMA or AMA-based FIM
43+
44+
> [!IMPORTANT]
45+
> Due to a pipeline change in Microsoft Defender for Endpoint, users with existing FIM deployments on legacy Windows machines must update their MDE agent to version 10.8799 or above to continue receiving file integrity monitoring data.
46+
3747
### Migrate to the new version
3848

3949
File integrity monitoring previously used the Log Analytics agent (also known as the Microsoft Monitoring agent (MMA)) or the Azure Monitor agent (AMA) to collect data. If you're using file integrity monitoring with one of these legacy methods, you can [migrate file integrity monitoring](migrate-file-integrity-monitoring.md) to use Defender for Endpoint.

articles/defender-for-cloud/migrate-file-integrity-monitoring.md

Lines changed: 16 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,22 @@ The previous version of file integrity monitoring used the Log Analytics agent (
1818

1919
- You must enable Defender for Servers Plan 2 to use file integrity monitoring.
2020
- Migration is relevant if file integrity monitoring is currently enabled using MMA or AMA.
21-
- Machines protected by Defender for Servers Plan 2 must run the Microsoft Defender for Endpoint agent. To check agent status on machines in your environment, [use this workbook](https://aka.ms/DfServersDashboard) to do that.
21+
- Machines protected by Defender for Servers Plan 2 must run the Microsoft Defender for Endpoint agent version **10.8799 or above**. This is particularly critical for legacy Windows machines (downlevel clients).
22+
- To check agent status and version on machines in your environment, [use this workbook](https://aka.ms/DfServersDashboard).
23+
24+
## Important: Version requirements for legacy Windows machines
25+
26+
Due to a recent pipeline change in Microsoft Defender for Endpoint, users migrating from MMA or AMA-based file integrity monitoring must ensure their MDE agent meets the minimum version requirement:
27+
28+
- **Minimum required version**: 10.8799
29+
- **Affected systems**: Primarily legacy Windows machines (downlevel clients)
30+
- **Impact**: FIM monitoring will not function properly on versions below 10.8799
31+
32+
### Checking and updating MDE agent version
33+
34+
1. Use the [Defender for Servers dashboard workbook](https://aka.ms/DfServersDashboard) to verify agent versions across your environment
35+
2. For machines running older versions, update the MDE agent through your standard deployment method
36+
3. Verify FIM functionality resumes after the agent update
2237

2338
## Migrate from MMA
2439

0 commit comments

Comments
 (0)