Microsoft 365 Alert – Service Degradation – Microsoft Defender XDR – Users can’t access the Microsoft Defender for Endpoint on Linux service upon rebooting after a version upgrade – RESOLVED

01/07/2026 08:56:00 AM

NHS.net Connect Reference: INC46866425

Microsoft Reference: DZ1410811

Issue Status: RESOLVED

Issue Description: Users can’t access the Microsoft Defender for Endpoint on Linux service upon rebooting after a version upgrade.

More info: Specifically, rebooting after upgrading to version builds 101.26042.0009 and 101.26052.0007 is causing impact to active protection on devices across supported Linux platforms, leading to the Microsoft Defender for Endpoint on Linux service being disabled.

While we work to resolve this issue, we recommend users don’t upgrade to the latest version and wait until the next version is released or this impact is remediated.

If users have already upgraded, users can either downgrade to a previous version or manually start the Defender service (mdatp) to restore protection on affected devices.

For more information on the completed release note details, please see: https://review.learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-endpoint-releases?branch=main&branchFallbackFrom=pr-en-us-8536

Final Update: 09/07/2026 08:46:00 AM – : Microsoft is successfully completed deployment of the targeted fix across the affected environment and confirmed that normal service functionality has been restored. They have verified that impact has been fully remediated and affected users can now upgrade to the latest version without encountering the previously reported issue.

Scope of impact: Your organisation is affected by this event, and users expecting their endpoint agent to start automatically after rebooting following an upgrade to version builds 101.26042.0009 and 101.26052.0007 are impacted. This section may be updated as our investigation continues.

Root cause: Some version upgrades to builds 101.26042.0009 and 101.26052.0007, as well as certain reinstallation scenarios, resulted in the Microsoft Defender for Endpoint service not remaining configured to start automatically after a system reboot.

Next steps : Microsoft is analyzing our deployment procedures on the affected infrastructure to help prevent this problem from happening again.

back to top