%3CLINGO-SUB%20id%3D%22lingo-sub-1519584%22%20slang%3D%22en-US%22%3ESHA-2%20signing%20enforcement%20on%20Windows%207%20and%20Windows%20Server%202008%20R2%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1519584%22%20slang%3D%22en-US%22%3E%3CP%3EMicrosoft%20Defender%20ATP%20running%20on%20Windows%207%20and%20Windows%20Server%202008R2%20is%20moving%20to%20exclusively%20use%20SHA-2%20signing%2C%20which%20will%20help%20drive%20greater%20security%20for%20our%20customers.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThis%20change%20does%20not%20require%20any%20action%20unless%20you%20are%20running%20Microsoft%20Defender%20ATP%20on%20Windows%207%20or%20Windows%20Server%202008%20R2.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ECustomers%20that%20are%20running%20on%20these%20OS%20versions%20are%20required%20to%20take%20the%20following%20actions%20before%20%3CSTRONG%3ENovember%26nbsp%3B2%2C%202020%3C%2FSTRONG%3E%20or%20their%20agents%20will%20stop%20sending%20data%20to%20Microsoft%20Defender%20ATP%3A%3C%2FP%3E%0A%3COL%3E%0A%3CLI%3EInstall%20the%20SHA-2%20signing%20Windows%20updates%20for%20your%20OS%20as%20described%20in%20-ERR%3AREF-NOT-FOUND-2019%20SHA-2%20Code%20Signing%20Support%20requirement%20for%20Windows%20and%20WSUS%3C%2FLI%3E%0A%3CLI%3EUpdate%20to%20the%20latest%20version%20of%20the%20Log%20Analytics%20Windows%20agent%20(-ERR%3AREF-NOT-FOUND-Windows%2064-bit%20agent%26nbsp%3Bor%26nbsp%3B-ERR%3AREF-NOT-FOUND-Windows%2032-bit%20agent)%3C%2FLI%3E%0A%3C%2FOL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EMore%20information%20about%20SHA-2%20signing%20enforcement%20is%20available%20in%20the%20-ERR%3AREF-NOT-FOUND-documentation.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EFor%20further%20questions%2C%20please%20feel%20free%20to%20reach%20out%3CSPAN%3E%20Microsoft%20Defender%20ATP%20Support.%20%3C%2FSPAN%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThank%20you%2C%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3EThe%20Microsoft%20Defender%20ATP%20team%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-1519584%22%20slang%3D%22en-US%22%3E%3CP%3EMicrosoft%20Defender%20ATP%20running%20on%20Windows%207%20and%20Windows%20Server%202008R2%20is%20moving%20to%20exclusively%20use%20SHA-2%20signing%2C%20which%20will%20help%20drive%20greater%20security%20for%20our%20customers.%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22MSC16_slalom_016.jpg%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F205097iD2C105E55C9806D5%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22MSC16_slalom_016.jpg%22%20alt%3D%22MSC16_slalom_016.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1519584%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ELog%20Analytics%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ELog%20Analytics%20AMA%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOMS%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOMS%20Log%20Analytics%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Esha-2%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Esigning%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EUpgrade%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EUpgrade%20Process%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWindows%207%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1656716%22%20slang%3D%22en-US%22%3ERe%3A%20SHA-2%20signing%20enforcement%20on%20Windows%207%20and%20Windows%20Server%202008%20R2%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1656716%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%20I%20thought%20%22Windows%207%22%20and%20%222008%20Server%22%20were%20not%20supported%20by%20Defender%3F%20have%20I%20misunderstood%20this%3F%20Are%20you%20saying%20that%20you%20can%20now%20support%20and%20protect%20these%20operating%20systems%20in%20Defender%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1658714%22%20slang%3D%22en-US%22%3ERe%3A%20SHA-2%20signing%20enforcement%20on%20Windows%207%20and%20Windows%20Server%202008%20R2%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1658714%22%20slang%3D%22en-US%22%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWindows%207%20support%20was%20announced%20two%20years%20ago-%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fwww.microsoft.com%2Fen-us%2Fmicrosoft-365%2Fblog%2F2018%2F02%2F12%2Fannouncing-windows-defender-atp-support-for-windows-7-and-windows-8-1%2F%23%3A~%3Atext%3DStarting%2520this%2520summer%252C%2520customers%2520moving%2Cstay%2520current%2520with%2520Windows%252010%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.microsoft.com%2Fen-us%2Fmicrosoft-365%2Fblog%2F2018%2F02%2F12%2Fannouncing-windows-defender-atp-support-for-windows-7-and-windows-8-1%2F%23%3A~%3Atext%3DStarting%2520this%2520summer%252C%2520customers%2520moving%2Cstay%2520current%2520with%2520Windows%252010%3C%2FA%3E.%3C%2FP%3E%0A%3CP%3EWindows%20server%202008%20support%20was%20announced%201%20year%20ago%20-%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fmicrosoft-defender-atp%2Fmicrosoft-defender-atp-edr-support-for-windows-server-2008-r2%2Fba-p%2F876819%22%20target%3D%22_blank%22%20rel%3D%22noopener%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fmicrosoft-defender-atp%2Fmicrosoft-defender-atp-edr-support-for-windows-server-2008-r2%2Fba-p%2F876819%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Microsoft

Microsoft Defender ATP running on Windows 7 and Windows Server 2008R2 is moving to exclusively use SHA-2 signing, which will help drive greater security for our customers.

 

This change does not require any action unless you are running Microsoft Defender ATP on Windows 7 or Windows Server 2008 R2.

 

Customers that are running on these OS versions are required to take the following actions before November 2, 2020 or their agents will stop sending data to Microsoft Defender ATP:

  1. Install the SHA-2 signing Windows updates for your OS as described in 2019 SHA-2 Code Signing Support requirement for Windows and WSUS
  2. Update to the latest version of the Log Analytics Windows agent (Windows 64-bit agent or Windows 32-bit agent)

 

More information about SHA-2 signing enforcement is available in the documentation.

 

For further questions, please feel free to reach out Microsoft Defender ATP Support.  

 

Thank you, 

The Microsoft Defender ATP team 

2 Comments
Occasional Visitor

Hi, I thought "Windows 7" and "2008 Server" were not supported by Defender? have I misunderstood this? Are you saying that you can now support and protect these operating systems in Defender?

Microsoft