DefenderHow-to

Defender Antivirus platform and engine updates: channels, gradual rollout and rollback

What the monthly KB4052623 platform and engine updates are, how to assign Intune update channels in rings, how to read versions with Get-MpComputerStatus, and how to roll back with MpCmdRun.

Microsoft Defender Antivirus updates itself three ways, and only one of them is the signature file most admins think about. The platform and engine also change every month, they arrive through Windows Update on their own gradual schedule, and when a release misbehaves it is the platform you need to roll back. In this post I'll explain what each update is, how to put devices into update channels with Intune so your pilot machines take the hit first, how to read the versions on a device and in reports, and what the supported rollback looks like.

How this guide is organised: How it works → Step-by-step → Verify → Tips and gotchasFlow diagram of the article's sections in reading order: 1. How it works. 2. Step-by-step (5 steps: Design the rings; Build one Entra group per ring; Create the Intune policy; Check a device; Watch the fleet). 3. Verify. 4. Tips and gotchas. Toolbox: Set-MpPreference, Get-MpPreference, MpCmdRun.exe, Endpoint security › Antivirus, AMProductVersion.1How it works2Step-by-step3Verify4Tips and gotchas1Design the rings2Build one Entragroup per ring3Create the Intunepolicy4Check a device5Watch the fleetTOOLBOXSet-MpPreferenceGet-MpPreferenceMpCmdRun.exeEndpoint security › AntivirusAMProductVersionHow this guide is organised: How it works → Step-by-step → Verify → Tips and gotchasFlow diagram of the article's sections in reading order: 1. How it works. 2. Step-by-step (5 steps: Design the rings; Build one Entra group per ring; Create the Intune policy; Check a device; Watch the fleet). 3. Verify. 4. Tips and gotchas. Toolbox: Set-MpPreference, Get-MpPreference, MpCmdRun.exe, Endpoint security › Antivirus, AMProductVersion.1How it works2Step-by-step1Design the rings2Build one Entra group per ring3Create the Intune policy4Check a device5Watch the fleet3Verify4Tips and gotchasTOOLBOXSet-MpPreferenceGet-MpPreferenceMpCmdRun.exeEndpoint security › AntivirusAMProductVersion
At a glance: how this guide is organised · 5 steps · 5 key settings and tools

How it works#

ComponentDelivered asCadenceVersion format and example
Antimalware platform (the service and client binaries)KB4052623, a product update through Windows Update, WSUS, Configuration Manager or a UNC shareMonthly4.18.YYMM0.X, for example 4.18.26080.4 (August 2026)
Scanning engineBundled with security intelligence updates (KB2267602)Monthly1.1.YYMM0.X, for example 1.1.26080.3
Security intelligence (signatures)KB2267602, plus dynamic updates from cloud protectionSeveral times a day1.NNN.NNN.0, for example 1.459.287.0

Monthly updates go out gradually: first to Beta channel subscribers, then throttled to Preview subscribers, then to everyone else scaling from 10 to 100 percent while Microsoft watches for problems. In WSUS that shows up as several packages for the same month. Support follows the same rhythm: the latest platform and engine get security and critical fixes, the two previous versions (N-2) are in technical upgrade support only, and anything older is unsupported. The platform versions that shipped inside Windows 10 and Windows Server 2016 and 2019 are all in the upgrade-only phase, so a freshly built server is out of support until KB4052623 lands. One more behaviour worth knowing: a platform update can be postponed while features such as Endpoint DLP or device control are monitoring running processes, and is retried after a reboot.

Step-by-step#

1. Design the rings#

Channel control needs platform 4.18.2106.6 or later. The monthly channels and Microsoft's suggested use:

Channel (as Microsoft lists them)What it doesSuggested population
Beta Channel - PrereleaseFirst to get new monthly updates; Windows Insider devices are here by defaultTest environments only
Current Channel (Preview)Earliest in the gradual releasePre-production and validation
Current Channel (Staged)Later in the gradual releaseA representative ~10% of production
Current Channel (Broad)Only after the gradual release completesThe bulk of production (~10-100%)
Critical: Time Delay48-hour delayCritical systems and datacenter machines only
Not configuredMicrosoft picks the channel, which may be an early oneFine for most devices, not for critical ones

Security intelligence has its own channel setting with only Current Channel (Staged), Current Channel (Broad) and Not configured; the Defender CSP currently documents Staged as equivalent to Broad, so do not design around a timing gap between them. A fourth setting, Disable gradual rollout of Microsoft Defender updates (Disable Gradual Release in the settings catalog), overrides the channel settings and opts the device out of the gradual rollout for both monthly and security intelligence updates. Microsoft's advice is to keep some devices on Preview and Staged so both you and Microsoft catch environment-specific problems before Broad.

2. Build one Entra group per ring#

Dynamic device groups work well here: a Windows Insider or lab group for Beta, a validation group for Preview, a representative slice (mixed hardware, mixed roles) for Staged, and the rest on Broad or Not configured. Put domain controllers, hypervisors and other machines you cannot afford to touch on Critical: Time Delay.

3. Create the Intune policy#

In the Microsoft Intune admin center create a Settings catalog policy for Windows, open the Defender category and configure Platform Updates Channel, Engine Updates Channel, Security Intelligence Updates Channel and, if needed, Disable Gradual Release. The same settings are available in the Defender Update controls profile of an endpoint security Antivirus policy, which also reaches devices managed through security settings management. If you must use a custom OMA-URI, the values are:

OMA-URIValues
./Device/Vendor/MSFT/Defender/Configuration/PlatformUpdatesChannel0 Not configured, 2 Beta, 3 Preview, 4 Staged, 5 Broad, 6 Critical: Time Delay
./Device/Vendor/MSFT/Defender/Configuration/EngineUpdatesChannel0 Not configured, 2 Beta, 3 Preview, 4 Staged, 5 Broad, 6 Critical: Time Delay
./Device/Vendor/MSFT/Defender/Configuration/SecurityIntelligenceUpdatesChannel0 Not configured, 4 Staged, 5 Broad
./Device/Vendor/MSFT/Defender/Configuration/DisableGradualRelease0 False, 1 True

Watch out: use one management authority. The MDMWinsOverGP behaviour does not apply to the Defender CSP, so a Group Policy under Windows Components › Microsoft Defender Antivirus that sets a different channel will fight your Intune policy. Remove the GPO settings when you move to Intune.

4. Check a device#

PowerShell
# Versions actually running
Get-MpComputerStatus | Select-Object AMProductVersion, AMEngineVersion, AMServiceVersion,
    AntivirusSignatureVersion, AntivirusSignatureLastUpdated, AMRunningMode

# Channel configuration the device has applied
Get-MpPreference | Select-Object PlatformUpdatesChannel, EngineUpdatesChannel,
    DefinitionUpdatesChannel, DisableGradualRelease

# Policy-backed values written by Intune or Group Policy
Get-ItemProperty 'HKLM:\SOFTWARE\Policies\Microsoft\Windows Defender' |
    Select-Object PlatformRing, EngineRing, SignaturesRing

AMProductVersion is the platform, AMEngineVersion the engine and AntivirusSignatureVersion the security intelligence version. The same cmdlet, Set-MpPreference, accepts -PlatformUpdatesChannel, -EngineUpdatesChannel and -DefinitionUpdatesChannel with the values Beta, Preview, Staged, Broad, Delayed or NotConfigured if you need to move a single machine quickly.

5. Watch the fleet#

In Intune, Reports › Microsoft Defender Antivirus opens the Summary page; the Reports tab holds the Antivirus agent status report, where Columns exposes the full set of fields reported through the Defender CSP so you can sort by version. Endpoint security › Antivirus adds the Unhealthy endpoints and Active malware tabs. In the Microsoft Defender portal, Reports › Endpoints › Device health › Microsoft Defender Antivirus health summarises platform versions across onboarded devices and lets you export the full inventory.

Verify#

  • Within a release cycle, Preview devices report the new AMProductVersion first, Staged later, and Broad only after the gradual release completes; compare what you see against the versions listed in the Microsoft Defender for Endpoint release notes.
  • Get-MpPreference on a device in each ring returns the channel you assigned, and the Intune policy report shows Succeeded for the three channel settings.
  • The Antivirus health report shows no supported device more than two platform versions behind the current one.

Tips and gotchas#

Rolling back a bad platform#

Microsoft documents the rollback through MpCmdRun.exe, which lives in the current platform folder:

Command Prompt
cd /d "%ProgramData%\Microsoft\Windows Defender\Platform\<current platform version>"
MpCmdRun.exe -RevertPlatform
MpCmdRun.exe -ResetPlatform
MpCmdRun.exe -RemoveDefinitions -Engine
MpCmdRun.exe -RemoveDefinitions -All
MpCmdRun.exe -RemoveDefinitions -DynamicSignatures

-RevertPlatform returns to the previous platform version, -ResetPlatform goes all the way back to the version shipped with the operating system in %ProgramFiles%\Windows Defender, -RemoveDefinitions -Engine reverts the engine, and the other two roll back security intelligence. Rollback is a pause, not a fix: the device will take the same update again on its next cycle unless you move the ring to Critical: Time Delay, decline the package in WSUS or Configuration Manager, or wait for Microsoft to publish a corrected release. Do it on a handful of devices while you investigate; a fleet sitting on an old platform is a bigger risk than most update bugs.

Devices stuck on an old platform#

  • Check how the device gets updates. If it uses WSUS or Configuration Manager, confirm KB4052623 is approved; because of phased release there are several packages per month, and declining the wrong one leaves devices behind.
  • A platform update waiting on Endpoint DLP or device control is retried after a reboot, so a device that never restarts never updates.
  • If you deploy the platform manually or with a non-Microsoft tool, install version 4.18.2001.10 from the Microsoft Update Catalog before jumping to the latest release on very old installations.
  • Devices in Not configured are assigned a channel by Microsoft and may update days apart; that is expected, not a fault.
  • To force the newest signature on a device in a delayed security intelligence channel, remove the channel policy first, then run MpCmdRun.exe -SignatureUpdate.
  • Update the antivirus even on devices where it runs in passive mode behind another product; the platform and engine still matter for EDR in block mode.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)