Jan 31 2022 08:04 AM
Hello, We onboarded several Windows Server 2012 R2 VM and physical servers on to Microsoft Defender for Endpoint using the new onboarding package by following this doc "https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-server-endpoints...".
Since then we are experiencing random freezes of several Windows Server 2012 R2 servers. The freezes only happens on Windows Server 2012 R2, our other Windows servers, including 2016 enrolled with the same package are fine.
We already applied the latest cumulative updates for the OS, .Net, Antimalware platform and Defender for Endpoint platform. Even after we have applied the latest version of updates the freezes keep happening.
As of now, we are running on antimalware platform 1.1.1800.4 and product platform 4.18.2111.5 / 4.18.2201.6
It looks like that by disabling the Antimalware by using the Group Policy "Turn off Microsoft Defender Antivirus" the freezes cease to happen.
We already investigated using the Windows logs but they are not written after the VM freeze so we did not find any traces. We collected a complete memory dump from the VMware ESXi hypervisor and we converted it into memory.dmp file and opened it with WinDbg. We found no evidence also in the dump file.
Do anyone have the same problem?
Jan 31 2022 02:27 PM
Jan 31 2022 11:49 PM
Feb 17 2022 01:52 AM
Feb 17 2022 02:01 AM
Feb 17 2022 02:31 AM
Feb 17 2022 08:31 AM
Feb 17 2022 09:33 AM
Feb 17 2022 11:31 AM
Sep 01 2022 04:30 AM
Hello @LucaCavana,
did you ever come to root cause of the freeze? We are having similar issue, on the case with MS Premier Support and their analysis points to Kernel Extended Attributes (Kernel Extended Attributes - Windows drivers | Microsoft Docs), but the only recommendation is to upgrade to newer OS.
Thanks, Vojtech
Sep 01 2022 05:18 AM
@Vojtech_Fiurasek Hello,
we removed the old EDR solution, this stopped the freezes.
Sep 23 2022 05:45 AM
HI, how did you remove the old EDR solution? I'm having the same scenario.@LucaCavana
Sep 23 2022 05:47 AM
Mar 17 2023 08:58 PM - edited Mar 17 2023 09:01 PM
We're having the same issue. During MS patch night we randomly have several Windows 2012R2 just completely freeze where we have to hard reboot them. And the patches rolls back.
All this happened after moving from Cylance to Defender ATP (EDR) and Defender AV. It's been a nightmare!
Anyone else having similar issues?