Microsoft Defender Antivirus updates itself three ways, and only one of them is the signature file most admins think about. The platform and engine also change every month, they arrive through Windows Update on their own gradual schedule, and when a release misbehaves it is the platform you need to roll back. In this post I'll explain what each update is, how to put devices into update channels with Intune so your pilot machines take the hit first, how to read the versions on a device and in reports, and what the supported rollback looks like.
How it works#
| Component | Delivered as | Cadence | Version format and example |
|---|---|---|---|
| Antimalware platform (the service and client binaries) | KB4052623, a product update through Windows Update, WSUS, Configuration Manager or a UNC share | Monthly | 4.18.YYMM0.X, for example 4.18.26080.4 (August 2026) |
| Scanning engine | Bundled with security intelligence updates (KB2267602) | Monthly | 1.1.YYMM0.X, for example 1.1.26080.3 |
| Security intelligence (signatures) | KB2267602, plus dynamic updates from cloud protection | Several times a day | 1.NNN.NNN.0, for example 1.459.287.0 |
Monthly updates go out gradually: first to Beta channel subscribers, then throttled to Preview subscribers, then to everyone else scaling from 10 to 100 percent while Microsoft watches for problems. In WSUS that shows up as several packages for the same month. Support follows the same rhythm: the latest platform and engine get security and critical fixes, the two previous versions (N-2) are in technical upgrade support only, and anything older is unsupported. The platform versions that shipped inside Windows 10 and Windows Server 2016 and 2019 are all in the upgrade-only phase, so a freshly built server is out of support until KB4052623 lands. One more behaviour worth knowing: a platform update can be postponed while features such as Endpoint DLP or device control are monitoring running processes, and is retried after a reboot.
Step-by-step#
1. Design the rings#
Channel control needs platform 4.18.2106.6 or later. The monthly channels and Microsoft's suggested use:
| Channel (as Microsoft lists them) | What it does | Suggested population |
|---|---|---|
| Beta Channel - Prerelease | First to get new monthly updates; Windows Insider devices are here by default | Test environments only |
| Current Channel (Preview) | Earliest in the gradual release | Pre-production and validation |
| Current Channel (Staged) | Later in the gradual release | A representative ~10% of production |
| Current Channel (Broad) | Only after the gradual release completes | The bulk of production (~10-100%) |
| Critical: Time Delay | 48-hour delay | Critical systems and datacenter machines only |
| Not configured | Microsoft picks the channel, which may be an early one | Fine for most devices, not for critical ones |
Security intelligence has its own channel setting with only Current Channel (Staged), Current Channel (Broad) and Not configured; the Defender CSP currently documents Staged as equivalent to Broad, so do not design around a timing gap between them. A fourth setting, Disable gradual rollout of Microsoft Defender updates (Disable Gradual Release in the settings catalog), overrides the channel settings and opts the device out of the gradual rollout for both monthly and security intelligence updates. Microsoft's advice is to keep some devices on Preview and Staged so both you and Microsoft catch environment-specific problems before Broad.
2. Build one Entra group per ring#
Dynamic device groups work well here: a Windows Insider or lab group for Beta, a validation group for Preview, a representative slice (mixed hardware, mixed roles) for Staged, and the rest on Broad or Not configured. Put domain controllers, hypervisors and other machines you cannot afford to touch on Critical: Time Delay.
3. Create the Intune policy#
In the Microsoft Intune admin center create a Settings catalog policy for Windows, open the Defender category and configure Platform Updates Channel, Engine Updates Channel, Security Intelligence Updates Channel and, if needed, Disable Gradual Release. The same settings are available in the Defender Update controls profile of an endpoint security Antivirus policy, which also reaches devices managed through security settings management. If you must use a custom OMA-URI, the values are:
| OMA-URI | Values |
|---|---|
./Device/Vendor/MSFT/Defender/Configuration/PlatformUpdatesChannel | 0 Not configured, 2 Beta, 3 Preview, 4 Staged, 5 Broad, 6 Critical: Time Delay |
./Device/Vendor/MSFT/Defender/Configuration/EngineUpdatesChannel | 0 Not configured, 2 Beta, 3 Preview, 4 Staged, 5 Broad, 6 Critical: Time Delay |
./Device/Vendor/MSFT/Defender/Configuration/SecurityIntelligenceUpdatesChannel | 0 Not configured, 4 Staged, 5 Broad |
./Device/Vendor/MSFT/Defender/Configuration/DisableGradualRelease | 0 False, 1 True |
Watch out: use one management authority. The MDMWinsOverGP behaviour does not apply to the Defender CSP, so a Group Policy under Windows Components › Microsoft Defender Antivirus that sets a different channel will fight your Intune policy. Remove the GPO settings when you move to Intune.
4. Check a device#
# Versions actually running
Get-MpComputerStatus | Select-Object AMProductVersion, AMEngineVersion, AMServiceVersion,
AntivirusSignatureVersion, AntivirusSignatureLastUpdated, AMRunningMode
# Channel configuration the device has applied
Get-MpPreference | Select-Object PlatformUpdatesChannel, EngineUpdatesChannel,
DefinitionUpdatesChannel, DisableGradualRelease
# Policy-backed values written by Intune or Group Policy
Get-ItemProperty 'HKLM:\SOFTWARE\Policies\Microsoft\Windows Defender' |
Select-Object PlatformRing, EngineRing, SignaturesRingAMProductVersion is the platform, AMEngineVersion the engine and AntivirusSignatureVersion the security intelligence version. The same cmdlet, Set-MpPreference, accepts -PlatformUpdatesChannel, -EngineUpdatesChannel and -DefinitionUpdatesChannel with the values Beta, Preview, Staged, Broad, Delayed or NotConfigured if you need to move a single machine quickly.
5. Watch the fleet#
In Intune, Reports › Microsoft Defender Antivirus opens the Summary page; the Reports tab holds the Antivirus agent status report, where Columns exposes the full set of fields reported through the Defender CSP so you can sort by version. Endpoint security › Antivirus adds the Unhealthy endpoints and Active malware tabs. In the Microsoft Defender portal, Reports › Endpoints › Device health › Microsoft Defender Antivirus health summarises platform versions across onboarded devices and lets you export the full inventory.
Verify#
- Within a release cycle, Preview devices report the new
AMProductVersionfirst, Staged later, and Broad only after the gradual release completes; compare what you see against the versions listed in the Microsoft Defender for Endpoint release notes. Get-MpPreferenceon a device in each ring returns the channel you assigned, and the Intune policy report shows Succeeded for the three channel settings.- The Antivirus health report shows no supported device more than two platform versions behind the current one.
Tips and gotchas#
Rolling back a bad platform#
Microsoft documents the rollback through MpCmdRun.exe, which lives in the current platform folder:
cd /d "%ProgramData%\Microsoft\Windows Defender\Platform\<current platform version>"
MpCmdRun.exe -RevertPlatform
MpCmdRun.exe -ResetPlatform
MpCmdRun.exe -RemoveDefinitions -Engine
MpCmdRun.exe -RemoveDefinitions -All
MpCmdRun.exe -RemoveDefinitions -DynamicSignatures-RevertPlatform returns to the previous platform version, -ResetPlatform goes all the way back to the version shipped with the operating system in %ProgramFiles%\Windows Defender, -RemoveDefinitions -Engine reverts the engine, and the other two roll back security intelligence. Rollback is a pause, not a fix: the device will take the same update again on its next cycle unless you move the ring to Critical: Time Delay, decline the package in WSUS or Configuration Manager, or wait for Microsoft to publish a corrected release. Do it on a handful of devices while you investigate; a fleet sitting on an old platform is a bigger risk than most update bugs.
Devices stuck on an old platform#
- Check how the device gets updates. If it uses WSUS or Configuration Manager, confirm KB4052623 is approved; because of phased release there are several packages per month, and declining the wrong one leaves devices behind.
- A platform update waiting on Endpoint DLP or device control is retried after a reboot, so a device that never restarts never updates.
- If you deploy the platform manually or with a non-Microsoft tool, install version 4.18.2001.10 from the Microsoft Update Catalog before jumping to the latest release on very old installations.
- Devices in Not configured are assigned a channel by Microsoft and may update days apart; that is expected, not a fault.
- To force the newest signature on a device in a delayed security intelligence channel, remove the channel policy first, then run
MpCmdRun.exe -SignatureUpdate. - Update the antivirus even on devices where it runs in passive mode behind another product; the platform and engine still matter for EDR in block mode.