Windows Defender Antimalware Platform 4.18.2101.4 - Problems with group policy and AD MMC

%3CLINGO-SUB%20id%3D%22lingo-sub-2102631%22%20slang%3D%22en-US%22%3EWindows%20Defender%20Antimalware%20Platform%204.18.2101.4%20-%20Problems%20with%20group%20policy%20and%20AD%20MMC%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2102631%22%20slang%3D%22en-US%22%3E%3CDIV%20class%3D%22thread-message-content-body-text%20thread-full-message%22%3E%3CP%3EToday%20the%20Windows%20Defender%20Antimalware%20Platform%20was%20updated%20automatically%20from%20version%204.18.2011.6%20-%26gt%3B%204.18.2101.4%20on%20my%20computer.%3C%2FP%3E%3CP%3EI%20didn't%20notice%20it%20at%20first%20but%20since%20this%20morning%20I%20was%20experiencing%20the%20following%20problems%20on%20my%20computer%3A%3C%2FP%3E%3CP%3E-%20LDAP%20queries%20to%20the%20domain%20controllers%20took%20a%20long%20time%3C%2FP%3E%3CP%3E-%20Opening%20the%20Active%20Directory%20Users%20%26amp%3B%20Computers%20MMC%20add-in%20took%20a%20very%20long%20time%20and%20when%20opening%20the%20OUs%2C%26nbsp%3B%26nbsp%3Bthe%20MMC%20console%20stopped%20responding.%20Also%20when%20choosing%20to%20change%20the%20domain%20controllers%2C%20the%20domain%20controllers%20were%20not%20populated.%3C%2FP%3E%3CP%3E-%20Group%20policy%20updates%20were%20very%20slow%20(from%204%20seconds%20on%20normal%20computer%20to%20more%20than%202%20minutes%20on%20my%20affected%20computer)%3C%2FP%3E%3CP%3E-%20Remote%20Control%20of%20computers%20with%20Configuration%20Manager%20didn't%20work%20anymore.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20was%20searching%20almost%20the%20whole%20day%20with%20group%20policy%20debugging%20and%20LDAP%20network%20sniffing%20because%20I%20thought%20that%20it%20was%20a%26nbsp%3B%26nbsp%3Bproblem%20with%20the%20domain%20controllers.%20(I%20installed%20the%20monthly%20security%20updates%20this%20weekend%20on%20them)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20I%20reviewed%20my%20event%20viewer%20once%20more%2C%20I%20saw%20the%20information%20message%20from%20this%20morning%20that%20the%20antimalware%20platform%20was%20updated.%3C%2FP%3E%3CP%3EAfter%20reverting%20to%20the%20previous%20version%20with%20%22%25programdata%25%5Cmicrosoft%5Cwindows%20defender%5Cplatform%5C%3CVERSION%3E%5Cmpcmdrun.exe%22%20-revertplatform%26nbsp%3Bthe%20problems%20suddenly%20disappeared.%3C%2FVERSION%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAnyone%20else%20experiencing%20problems%20with%20this%20update%3F%3C%2FP%3E%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2107885%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20Defender%20Antimalware%20Platform%204.18.2101.4%20-%20Problems%20with%20group%20policy%20and%20AD%20MMC%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2107885%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F944921%22%20target%3D%22_blank%22%3E%40D4rtual%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECan%20confirm%20that%20we%20are%20seeing%20issues%20with%20group%20policy%20processing%20times%20jumping%20to%205%20minutes%20after%20Defender%20Platform%20was%20upgraded%20to%204.18.2101.4%20few%20days%20ago.%20Reverting%20back%20to%204.18.2011.6%20fixes%20this%20issue.%20Windows%2010%20version%20where%20I%20have%20confirmed%20this%20are%201809%20and%201909.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20logged%20a%20ticket%20with%20Microsoft%20Premier%20Support.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2111832%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20Defender%20Antimalware%20Platform%204.18.2101.4%20-%20Problems%20with%20group%20policy%20and%20AD%20MMC%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2111832%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F420588%22%20target%3D%22_blank%22%3E%40pgrubor%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI'm%20opening%20a%20case%20for%20this%20now%2C%20as%20well.%26nbsp%3B%20Does%20it%20seem%20like%204.18.2101.4%20was%20pulled%3F%26nbsp%3B%20Seemed%20like%20it%20was%20released%20on%201%2F25%2F2021.%26nbsp%3B%20I%20seem%20to%20have%20a%20mix%20of%20clients%20on%20that%20version%2C%20and%204.18.2011.6.%26nbsp%3B%20Both%20claim%20to%20be%20'completely%20up%20to%20date.'%26nbsp%3B%20Documentation%20seems%20to%20show%20that%202011.6%20is%20the%20latest%20version.......%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20traction%20on%20your%20case%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

Today the Windows Defender Antimalware Platform was updated automatically from version 4.18.2011.6 -> 4.18.2101.4 on my computer.

I didn't notice it at first but since this morning I was experiencing the following problems on my computer:

- LDAP queries to the domain controllers took a long time

- Opening the Active Directory Users & Computers MMC add-in took a very long time and when opening the OUs,  the MMC console stopped responding. Also when choosing to change the domain controllers, the domain controllers were not populated.

- Group policy updates were very slow (from 4 seconds on normal computer to more than 2 minutes on my affected computer)

- Remote Control of computers with Configuration Manager didn't work anymore.

 

 

I was searching almost the whole day with group policy debugging and LDAP network sniffing because I thought that it was a  problem with the domain controllers. (I installed the monthly security updates this weekend on them)

 

When I reviewed my event viewer once more, I saw the information message from this morning that the antimalware platform was updated.

After reverting to the previous version with "%programdata%\microsoft\windows defender\platform\<version>\mpcmdrun.exe" -revertplatform the problems suddenly disappeared.

 

Anyone else experiencing problems with this update?

10 Replies

@D4rtual 

Can confirm that we are seeing issues with group policy processing times jumping to 5 minutes after Defender Platform was upgraded to 4.18.2101.4 few days ago. Reverting back to 4.18.2011.6 fixes this issue. Windows 10 version where I have confirmed this are 1809 and 1909.

 

I have logged a ticket with Microsoft Premier Support.

@pgrubor 

 

I'm opening a case for this now, as well.  Does it seem like 4.18.2101.4 was pulled?  Seemed like it was released on 1/25/2021.  I seem to have a mix of clients on that version, and 4.18.2011.6.  Both claim to be 'completely up to date.'  Documentation seems to show that 2011.6 is the latest version.......

 

Any traction on your case?

@acjuelich

I've experienced the same issues and come across this thread. 4.18.2101.4 was definitely pulled as MECM shows it as expired and superseded on 1/30.

 

4.18.2101.8 was released today and from my limited testing so far it appears to resolve the issue.

@adamgrieger we have seen issues with 4.18.2101.4 and .8  it looks like there is something still going on. Hopefully, your testing goes well but I would continue to test at this point.

 

@pgrubor Did you get a response from Premier on this?  Some folks are saying that 2101.4 and 2101.8 are now marked as superseded.

@CPetrey 

 

4.18.2101.8 is available and we do not have those group policy issue anymore with this version. 4.18.2101.4 is gone.  

All,

I see that version 4.18.2101.8 is expired since yesterday, so I don't know what was wrong with that version. Microsoft released a new version 4.18.2101.9 on WSUS.

 

The release notes are still mentioning version 4.18.2101.8 however...

Manage Microsoft Defender Antivirus updates and apply baselines - Windows security | Microsoft Docs

@D4rtual 

 

I created a case with MSFT and they admit to the issues but have not given me any official statement or explanation.  I told them the case will not be closed until this is admitted to and explained.  We will see what happens.

@acjuelich Got info from premier support today that the issue was fixed in platform version 4.18.2101.9. I tested it on W10 1909 and looks fine so far.

Windows Defender 4.18.2101.9 does not comply with policy. Compliance requires real time protection enabled