Forum Discussion
Andrew_Allston
Jul 28, 2020Iron Contributor
.Net Rollup July 2020 on Server 2019 Not detected by Defender ATP
Anyone else having issues with the latest (July 2020) .Net Security Updates not being detected by ATP? All of my server 2019 servers are now reporting they are missing .Net security patches all the w...
Andrew_Allston
Jul 31, 2020Iron Contributor
jamrobot I dug into this a bit more since my post. The actual problem that I see seems to be from the Preview Update Rollup for .NET. KB45567327, which includes KB4562902 (.Net 4.7.2) and KB4562903 (.Net 4.8). I have servers that run 4.7.2 and 4.8, both experience the issue when these are installed. I have confirmed that if I uninstall KB4562902 or KB4562903 and manually install the last GA update rollup KB4566516 (Which includes KB4565625 for 4.7.2 and KB4565632 for 4.8 the issue in ATP goes away. I have blocked the .Net July Preview rollup from installing, I really hope they fix this before it goes out as GA next month. This issue also seems to break Windows Security from launching its GUI, all defender policies seem to work in this state, but it is disconcerting. I would be interested in seeing what they say in regards to your ticket about this issue.
Andrew_Allston
Jul 31, 2020Iron Contributor
jamrobot And I just noticed, like you said, its affecting my Windows 10 Clients now. Also, looking at my Update history it looks like this is the first month a Preview Patch was ever installed by WUFB. I received both the July 2020 Preview Updates for both Windows and .Net. I need to review my settings but I don't think there have been any changes that would impact this.
- Andrew_AllstonAug 03, 2020Iron Contributor
Looks like they fixed the detection issue, but still would love to know why Microsoft is pushing Preview patches like this now, with no notice.
- Aug 06, 2020
Andrew_Allston What patching mechanism are you using? So first off back in May they announced that due to the pandemic they were pausing preview updates. Now that thing have settled down they are no longer pausing them. As long as you do not "check for updates" these won't be installed. If you are using a third party patching tool I would look to see what rules you are doing. Bottom line now that these preview updates are back in the mix, you need to be more aware of your patching rules.
- Andrew_AllstonAug 06, 2020Iron Contributor
SusanBradleyGeek Hi! I use Azure Automation for my servers updates and WUFB (Intune) for my Windows 10 Clients. Both sets of devices installed this round of preview patches, and going back the whole history available to me, none of these devices installed preview patches automatically in the past. And in an interesting turn of events, ATP now detects the patches correctly but the servers that I manually uninstalled the patches from started to report incorrectly that ASR and other security measures were disabled. After reinstalling the patches ATP reports everything correctly again.