Skip to content

Commit 77070fa

Browse files
committed
Update FIM documentation with MDE agent version requirements
- Updated file-integrity-monitoring-overview.md with version requirements section - Removed version info from migrate-file-integrity-monitoring.md per feedback - Updated file-integrity-monitoring-enable-defender-endpoint.md with correct version (10.8799) for legacy Windows machines - Added release note entry for MDE agent version requirement due to pipeline change
1 parent 4a6a316 commit 77070fa

3 files changed

Lines changed: 25 additions & 19 deletions

File tree

articles/defender-for-cloud/file-integrity-monitoring-enable-defender-endpoint.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -18,9 +18,9 @@ After you enable Defender for Servers Plan 2, follow the instructions in this ar
1818
> [!NOTE]
1919
>
2020
> - If you use a previous version of File Integrity Monitoring with the Log Analytics agent (Microsoft Monitoring agent (MMA)) or the Azure Monitor agent (AMA), you can [migrate to the new File Integrity Monitoring experience](migrate-file-integrity-monitoring.md).
21-
> - From June 2025 onwards, File Integrity Monitoring powered by Microsoft Defender for Endpoint requires a minimum version. [Update the agent](#verify-defender-for-endpoint-client-version) as needed.
22-
> - Windows: 10.8760 or later.
23-
> - Linux: 30.124082 or later.
21+
> - File Integrity Monitoring powered by Microsoft Defender for Endpoint requires a minimum agent version. [Update the agent](#verify-defender-for-endpoint-client-version) as needed.
22+
> - **Windows (legacy machines/downlevel clients)**: 10.8799 or later.
23+
> - **Linux**: 30.124082 or later.
2424
2525
## Prerequisites
2626

articles/defender-for-cloud/migrate-file-integrity-monitoring.md

Lines changed: 1 addition & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -18,22 +18,7 @@ The previous version of file integrity monitoring used the Log Analytics agent (
1818

1919
- You must enable Defender for Servers Plan 2 to use file integrity monitoring.
2020
- Migration is relevant if file integrity monitoring is currently enabled using MMA or AMA.
21-
- Machines protected by Defender for Servers Plan 2 must run the Microsoft Defender for Endpoint agent version **10.8799 or above**. This is particularly critical for legacy Windows machines (downlevel clients).
22-
- To check agent status and version on machines in your environment, [use this workbook](https://aka.ms/DfServersDashboard).
23-
24-
## Important: Version requirements for legacy Windows machines
25-
26-
Due to a recent pipeline change in Microsoft Defender for Endpoint, users migrating from MMA or AMA-based file integrity monitoring must ensure their MDE agent meets the minimum version requirement:
27-
28-
- **Minimum required version**: 10.8799
29-
- **Affected systems**: Primarily legacy Windows machines (downlevel clients)
30-
- **Impact**: FIM monitoring will not function properly on versions below 10.8799
31-
32-
### Checking and updating MDE agent version
33-
34-
1. Use the [Defender for Servers dashboard workbook](https://aka.ms/DfServersDashboard) to verify agent versions across your environment
35-
2. For machines running older versions, update the MDE agent through your standard deployment method
36-
3. Verify FIM functionality resumes after the agent update
21+
- Machines protected by Defender for Servers Plan 2 must run the Microsoft Defender for Endpoint agent. To check agent status on machines in your environment, [use this workbook](https://aka.ms/DfServersDashboard) to do that.
3722

3823
## Migrate from MMA
3924

articles/defender-for-cloud/release-notes.md

Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -31,8 +31,29 @@ This article summarizes what's new in Microsoft Defender for Cloud. It includes
3131

3232
|Date | Category | Update|
3333
| -------- | -------- | -------- |
34+
|January 22, 2026| Update | [File Integrity Monitoring requires MDE agent version 10.8799+ for legacy Windows machines](#file-integrity-monitoring-requires-mde-agent-version-108799-for-legacy-windows-machines) |
3435
|January 8, 2026| Preview | [Microsoft Security Private Link (Preview)](#microsoft-security-private-link-preview) |
3536

37+
### File Integrity Monitoring requires MDE agent version 10.8799+ for legacy Windows machines
38+
39+
January 22, 2026
40+
41+
Due to a pipeline change in Microsoft Defender for Endpoint (MDE), File Integrity Monitoring now requires Microsoft Defender for Endpoint agent version 10.8799 or above for proper functionality on legacy Windows machines (downlevel clients).
42+
43+
**Key details:**
44+
45+
- **Affected systems**: Legacy Windows machines (Windows Server 2016, Windows Server 2012 R2, and other downlevel clients)
46+
- **Required version**: MDE agent 10.8799 or later
47+
- **Impact**: FIM monitoring will not function properly on versions below the minimum requirement
48+
49+
**Action required:**
50+
51+
Users with File Integrity Monitoring enabled on legacy Windows machines should update their MDE agent to version 10.8799 or above to continue receiving file integrity monitoring data. Use the [Defender for Servers dashboard workbook](https://aka.ms/DfServersDashboard) to verify agent versions across your environment.
52+
53+
For Windows Server 2016 and Windows Server 2012 R2, you must update machines manually to the latest agent version by installing [KB 5005292 from the Microsoft Update Catalog](https://www.catalog.update.microsoft.com/Search.aspx?q=KB5005292).
54+
55+
Learn more about [File Integrity Monitoring](file-integrity-monitoring-overview.md) and how to [enable File Integrity Monitoring](file-integrity-monitoring-enable-defender-endpoint.md).
56+
3657
## Microsoft Security Private Link (Preview)
3758

3859
January 8, 2026

0 commit comments

Comments
 (0)