MDE apparently blocks MacOS Monterey 12.1 / 12.2 upgrades?

%3CLINGO-SUB%20id%3D%22lingo-sub-3078793%22%20slang%3D%22en-US%22%3EMDE%20apparently%20blocks%20MacOS%20Monterey%2012.1%20%2F%2012.2%20upgrades%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3078793%22%20slang%3D%22en-US%22%3E%3CP%3EThe%20last%20days%20we%20have%20encountered%20a%20situation%20where%20the%20upgrade%20to%20MacOS%20Monterey%2012.1%20or%2012.2%20fails.%3CBR%20%2F%3E%3CBR%20%2F%3EAfter%20several%20reboots%20the%20machine%20returns%20to%20the%20state%20before%20the%20upgrade%20started%2C%20with%20the%20addition%20of%20several%20applications%20crashing%20upon%20startup%20and%20needing%20reinstalls%20of%20these.%20This%20has%20happened%20to%20several%20machines%2C%20both%20Intel%20and%20ARM%20models%20when%20trying%20to%20upgrade%20from%20various%20MacOS%20versions%20such%20as%2012.0.1%20and%2011.6.x.%3CBR%20%2F%3E%3CBR%20%2F%3ESeveral%20repeated%20attempts%20give%20the%20same%20result%3A%3CBR%20%2F%3E%3CBR%20%2F%3EIt%20occurred%20that%20we%20might%20have%20a%20compatibility%20issue%20with%20Defender%20ATP%20(101.56.35)%20-%20and%20after%20removing%20this%20application%20completely%20and%20retrying%20the%20OS%20upgrade%2C%20this%20was%20completed%20without%20any%20issues.%3CBR%20%2F%3E%3CBR%20%2F%3EDefender%20ATP%20was%20then%20reinstalled%20and%20now%20works%20without%20issues.%20The%20same%20goes%20for%20other%20applications%20that%20were%20%22corrupted%22%20during%20the%20first%20tries.%20Among%20them%20are%20OneDrive%20and%20Teams.%20After%20a%20%22delete%20and%20reinstall%22%20they%20all%20now%20work%20fine.%3CBR%20%2F%3E%3CBR%20%2F%3EA%20less%20%22Brutal%22%20approach%20is%20also%20tried%20out%20(edit%3A%20which%20did%20not%20help)%20disabling%20various%20Defender%20modules%2C%20but%20this%20is%20rather%20time%20consuming%20since%20we%20do%20not%20know%20the%20result%20before%20the%20whole%20upgrade%20process%20is%20%22complete%22.%3CBR%20%2F%3E%3CBR%20%2F%3EAnyone%20else%20seeing%20a%20similar%20pattern%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3100968%22%20slang%3D%22en-US%22%3ERe%3A%20MDE%20apparently%20blocks%20MacOS%20Monterey%2012.1%20%2F%2012.2%20upgrades%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3100968%22%20slang%3D%22en-US%22%3EYup%2C%20I'm%20seeing%20the%20same%20thing.%20We%20had%20no%20issue%20updating%20to%2012.1.%20Trying%20to%20update%2012.2%20seems%20to%20have%20removed%20rosetta%20(For%20Apple%20silicon%20macs)%2C%20and%20messed%20with%20Teams%20and%20Onedrive.%3CBR%20%2F%3E%3CBR%20%2F%3EIt%20seems%20that%20the%20update%20goes%20through%20but%20when%20they%20go%20to%20check%20the%20system%20they're%20still%20on%2012.1.%20Uninstalling%20Defender%20allows%20the%20update%20to%20run%20through%20fine.%20Hoping%20someone%20can%20find%20a%20solution%20to%20this%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3101620%22%20slang%3D%22en-US%22%3ERe%3A%20MDE%20apparently%20blocks%20MacOS%20Monterey%2012.1%20%2F%2012.2%20upgrades%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3101620%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F83380%22%20target%3D%22_blank%22%3E%40Eric%20Iversen%3C%2FA%3E%2C%3C%2FP%3E%0A%3CP%3E%3CBR%20%2F%3EHi%20Eric%2C%3CBR%20%2F%3EThanks%20for%20reaching%20out%20about%20the%20issue.%20We%20are%20investigating%20the%20upgrade%20issues%20to%20identify%20root%20causes%20and%20plan%20for%20fixes%20in%20coming%20product%20releases.%3C%2FP%3E%0A%3CP%3EPlease%20contact%20Microsoft%20Defender%20for%20Endpoint%20support%20to%20open%20a%20service%20request%20by%20following%20the%20process%20documented%20%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fdocs.microsoft.com%252Fen-us%252Fmicrosoft-365%252Fsecurity%252Fdefender-endpoint%252Fcontact-support%253Fview%253Do365-worldwide%2523open-a-service-request%26amp%3Bdata%3D04%257C01%257Cbsabetghadam%2540microsoft.com%257C4cc5baa8c09148ca25d208d9e5c7196f%257C72f988bf86f141af91ab2d7cd011db47%257C1%257C0%257C637793465561546421%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C3000%26amp%3Bsdata%3DD3jDereh0Mp%252FtUwHmlPaAzsB1i6p%252FKOMZ8LaV2IlHbk%253D%26amp%3Breserved%3D0%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehere%3C%2FA%3E.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3101828%22%20slang%3D%22en-US%22%3ERe%3A%20MDE%20apparently%20blocks%20MacOS%20Monterey%2012.1%20%2F%2012.2%20upgrades%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3101828%22%20slang%3D%22en-US%22%3EYes%2C%20same%20here.%20From%2012.1%20to%2012.2.%20upgrade%20completed%20but%20after%20last%20reboot%2C%20MacOS%20remained%20on%2012.1.%3CBR%20%2F%3E%3CBR%20%2F%3ELooking%20at%20the%20logs%2C%20there%20were%20errors%20related%20to%20DLP%20and%20Defender%20which%20creates%20some%20issue%20with%20the%20upgraded%20disk%20Volume.%20Seems%20like%20the%20Upgrade%20process%20doesn't%20like%20this%20and%20thinks%20there%20is%20an%20issue%20and%20rolls%20back%20to%20the%20previous%20snapshot%20or%20something%20like%20that%20thus%20remaining%20on%2012.1%20instead%20of%20being%20upgraded%20to%2012.2%3CBR%20%2F%3E%3CBR%20%2F%3EI%20was%20able%20to%20get%20it%20through%20after%20I%20added%20com.apple.MobileSoftwareUpdate.UpdateBrainService%20to%20the%20process%20exclusion%20list%20in%20Defender.%20Not%20sure%20if%20that's%20what%20did%20it%20or%20I%20was%20just%20lucky.%3CBR%20%2F%3E%3CBR%20%2F%3EI%20also%20now%20see%20that%20DLP%20(Data%20Loss%20Protection)%20seems%20supported%20in%20MDE%20for%20MacOS%20and%20my%20logs%20were%20full%20or%20errors%20related%20to%20it%20since%20it%20was%20not%20properly%20configured%2Fenabled%20in%20intune%20and%20this%20was%20preventing%20some%20extensions%20in%20MacOS%20from%20being%20loaded%20properly%2C%20possibly%20making%20this%20more%20problematic%20since%20the%20filesystem%20didn't%20seem%20to%20recognize%20the%20DLP%20attributes%20in%20the%20filesystem%20properly%20because%20of%20this.%3CBR%20%2F%3E%3CBR%20%2F%3EI%20properly%20allowed%20and%20enable%20the%20DLP%20loading%20in%20MDE%20(mdatp%20health)%3CBR%20%2F%3E%3CBR%20%2F%3Edata_loss_prevention_status%20%3A%20%22active%22%3CBR%20%2F%3E%3CBR%20%2F%3EAnd%20DLP%20errors%20are%20gone%20and%20it%20seems%20to%20properly%20works%20now.%20as%20I%20see%20logs%20being%20pushed%20to%20365%20Compliance.%20However%2C%20be%20careful%2C%20this%20seems%20to%20have%20a%20huge%20CPU%20and%20IO%20impact%20on%20everything.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3102791%22%20slang%3D%22en-US%22%3ERe%3A%20MDE%20apparently%20blocks%20MacOS%20Monterey%2012.1%20%2F%2012.2%20upgrades%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3102791%22%20slang%3D%22en-US%22%3EThanks%2C%20good%20to%20know%20we%20are%20not%20alone%20in%20this.%20%3A)%3C%2Fimg%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3102792%22%20slang%3D%22en-US%22%3ERe%3A%20MDE%20apparently%20blocks%20MacOS%20Monterey%2012.1%20%2F%2012.2%20upgrades%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3102792%22%20slang%3D%22en-US%22%3EHi%2C%20thanks%20for%20responding%20-%20we%20will%20open%20a%20service%20request.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3102799%22%20slang%3D%22en-US%22%3ERe%3A%20MDE%20apparently%20blocks%20MacOS%20Monterey%2012.1%20%2F%2012.2%20upgrades%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3102799%22%20slang%3D%22en-US%22%3EThanks%20a%20bunch%20-%20so%20it%20might%20not%20be%20a%20bug%20but%20a%20feature%20then.%3CBR%20%2F%3E%3CBR%20%2F%3ENot%20the%20first%20time%20a%20feature%20that%20remains%20in%20a%20%22not%20configured%22%20state%20leads%20to%20unforeseen%20side%20effects.%20We%20will%20have%20a%20closer%20look%20at%20the%20DLP%20settings%20in%20Endpoint%20Manager%2FIntune.%3C%2FLINGO-BODY%3E
Occasional Contributor

The last days we have encountered a situation where the upgrade to MacOS Monterey 12.1 or 12.2 fails.

After several reboots the machine returns to the state before the upgrade started, with the addition of several applications crashing upon startup and needing reinstalls of these. This has happened to several machines, both Intel and ARM models when trying to upgrade from various MacOS versions such as 12.0.1 and 11.6.x.

Several repeated attempts give the same result:

It occurred that we might have a compatibility issue with Defender ATP (101.56.35) - and after removing this application completely and retrying the OS upgrade, this was completed without any issues.

Defender ATP was then reinstalled and now works without issues. The same goes for other applications that were "corrupted" during the first tries. Among them are OneDrive and Teams. After a "delete and reinstall" they all now work fine.

A less "Brutal" approach is also tried out (edit: which did not help) disabling various Defender modules, but this is rather time consuming since we do not know the result before the whole upgrade process is "complete".

Anyone else seeing a similar pattern?

19 Replies
Yup, I'm seeing the same thing. We had no issue updating to 12.1. Trying to update 12.2 seems to have removed rosetta (For Apple silicon macs), and messed with Teams and Onedrive.

It seems that the update goes through but when they go to check the system they're still on 12.1. Uninstalling Defender allows the update to run through fine. Hoping someone can find a solution to this

@Eric Iversen,


Hi Eric,
Thanks for reaching out about the issue. We are investigating the upgrade issues to identify root causes and plan for fixes in coming product releases.

Please contact Microsoft Defender for Endpoint support to open a service request by following the process documented here

Yes, same here. From 12.1 to 12.2. upgrade completed but after last reboot, MacOS remained on 12.1.

Looking at the logs, there were errors related to DLP and Defender which creates some issue with the upgraded disk Volume. Seems like the Upgrade process doesn't like this and thinks there is an issue and rolls back to the previous snapshot or something like that thus remaining on 12.1 instead of being upgraded to 12.2

I was able to get it through after I added com.apple.MobileSoftwareUpdate.UpdateBrainService to the process exclusion list in Defender. Not sure if that's what did it or I was just lucky.

I also now see that DLP (Data Loss Protection) seems supported in MDE for MacOS and my logs were full or errors related to it since it was not properly configured/enabled in intune and this was preventing some extensions in MacOS from being loaded properly, possibly making this more problematic since the filesystem didn't seem to recognize the DLP attributes in the filesystem properly because of this.

I properly allowed and enable the DLP loading in MDE (mdatp health)

data_loss_prevention_status : "active"

And DLP errors are gone and it seems to properly works now. as I see logs being pushed to 365 Compliance. However, be careful, this seems to have a huge CPU and IO impact on everything.
Thanks, good to know we are not alone in this. :)
Hi, thanks for responding - we will open a service request.
Thanks a bunch - so it might not be a bug but a feature then.

Not the first time a feature that remains in a "not configured" state leads to unforeseen side effects. We will have a closer look at the DLP settings in Endpoint Manager/Intune.
Right now I'm in the process of completely disabling DLP agent/daemon for MacOS since it makes the computers very slow and laggy. Especially in the browser (tested with Chrome and Edge). In the browser, the worst effect is when you type something in the search bar, when the DLP daemon runs (along MDE), you will notice that what you type is laggy and has a delay. If you disable DLP daemon and make sure the process doesn't run anymore "ps aux | grep dlpdaemon", you'll notice it's back to being very responsive and fast, as it should.

Make sure you don't see this process running or else, disable it using Intune and policies until they get this behaviour under control as the computers become way too slow when it is enabled and things timeout or even crash (like the update)

/Library/Application Support/Microsoft/DLP/com.microsoft.dlp.daemon.app/Contents/MacOS/dlpdaemon --daemon

You can determine if DLP is enabled if you run "mdatp health"

If you see that data_loss_prevention_status near the end, is not stopped or dormant, it means it is most likely enabled and affecting your performance.
What bugs me the most right now is that even though I disabled DLP through intune and that the config makes it to the Mac and I see it as disabled in mdatp, the dlpdaemon still continues to run and affect performance. Rebooting doesn't fix it, it starts again on the next boot even though it should be disabled.

So far, the only solution I found is to delete Microsoft Defender and wait for Intune to automatically reinstall it. Once you uninstall it, the dlpdaemon goes away after a few seconds as the Defender services stops and unload.

It's as if once it runs at least one time, it will always run, whether you disable it or not in the config. But if it is not allowed to run when install Defender, it will never run and you're good as it doesn't get configured (or something like that) and it will never run unless you enable it later on.

This is most likely a bug of some sort and I hope they fix it because no way I'm going to go manually on each Mac in the company and remove and then reinstall Defender on each of them, hehehe.
Tengo el mismo problema, aplace las actualizaciones de sistema y seguridad por 90 días en lo que se validaba el funcionamento de MacOS Monterey y ya que lo he probado y todo funciona bien, no puedo actualizar los dispositivos, ejecutan todo el proceso, se reiniciar pero regresa a la versión que tenia en un principio, desintale Defender en algunos equipos y se hace la actualizacion de forma correcta! Ojala pronto le den solución ya genere el caso pero no he recibido apoyo al dia de hoy!
They rolled out another update: 101.56.62 but it only says "Bug Fixes". Maybe it fixes this issue. Can you test it ?
Hey, thanks - yes, 101.56.62 does seem to make a big difference - some time before I saw your post here, a colleague just tried out this version after finding it on the preview channel - and tried re-creating the problem by downgrading machines to a previous OS version, then perform the upgrade to 12.2. With this version of MDE installed, the OS upgrade goes through without issues. Have you tried it yet?
I'll be testing a 12.2 to 12.2.1 upgrade myself tonight and a colleague will test the 12.1 to 12.2.1 or 12.2 upgrade also. I'll let you know our results once completed.
My upgrade to from 12.2 to 12.2.1 worked. I'll let you know about my colleague (from 12.1) probably on Monday.
Yes, I can confirm the same problem. Experienced the corruption of multiple applications when I installed 12.2 which led to full reinstall, (didn't have time to troubleshoot then). Then when attempting to install same upgrade without enrolling everything went smooth.
Later that day the computer was enrolled again. Yesterday I attempted to install 12.2.1 and the upgrade "failed" again. However this time no applications got corrupted.
Hi all,

We are experiencing the same thing with multiple Macs.

The workaround we have been using is updating via a bootable MacOS Installer. https://support.apple.com/en-au/HT201372
This apparently seems to be a "hit and miss" kind of issue. Sometimes, it works, sometimes it doesn't, at least with 101.56.62. My colleague upgraded from 12.1 to 12.2.1 and he was successful on first attempt. But I had multiple issues with 101.56.36. Either 101.56.62 improved the chance of success or maybe we were just lucky.

@pmonfette-ns 

 

We seem to have more Hits than Misses.

222 Monterey Total .

123 Monterey on 12.2

58 Monterey on 12.1

41 Monterey on 12.0

No reports of Upgrade issues from 12. to 12.2 so far.

They seem to have updated Defender to take into account a few issues in regards to the latest Monterey releases in the last few days:

https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/mac-whatsnew?view=o365-wor...

Especially in version: 101.59.50, maybe this version is more compatible now with Monterey upgrades ?
I'm running 101.60.91 (the latest from auto-update) and I've been able to upgrade from 12.2.1 to 12.3 without any issue.

I'll be curious to know if others have the same results.