New
#41
Thanks!
This fits the pattern we're seeing about why some machines update their Defender platform's more frequently and often well in advance of other machines without it.
For instance under 1909, and when these registry keys were in place for me, I got 3 Platform versions in one month.
MS Antimalware Platform 4.18.2001.6 only on one PC
The question remains, what exactly triggers this registry change?
My current speculation is when a user goes looking enough times for Windows Defender Definition updates, either manually or via a custom task, such that the telemetry behavior is considered by Microsoft, much like with a CU, to be a form of user consent to be a guinea pig that's out looking for trouble, i.e. a Seeker. ;o)
Always curious about such things, I'm currently writing a scheduled task to check the Key:
to see when changes take place, hoping this evidence might shed some light on the logic.Code:HKLM\SOFTWARE\Microsoft\Windows Defender\MpEngine
i just got platform update to 4.18.2006.9.
Good day. MS is beginning to roll it out but it is not yet on MS Catalog.
Now i got platform update to 4.18.2006.10
and it is now at update catalog.
https://www.catalog.update.microsoft...q=4.18.2006.10
Just got updated to 4.18.2006.10. Was on 4.18.2005.5. Never got 4.18.2006.9.
Yup showing 4.18.2006.10 here, don't think i got .9 version as far as i know. in fact didn't even hardly notice it updated this time for some reason lol
I was on 4.18.2005.5.
I never got 4.18.2006.6 nor 4.18.2006.9
I just now received 4.18.2006.10 when I manually ran my task:
C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2006.10-0\MpCmdRun.exe -signatureUpdate
After my clean install of 2004 my MpEngine registry key still has no sub-keys:
@Warre1 I'd be curious to see if you have under yours these three sub-keys that have been tied to those machines getting these interim Platform updates like 4.18.2006.6 and 4.18.2006.9 :Code:HKLM\SOFTWARE\Microsoft\Windows Defender\MpEngine
Code:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\MpEngine MpCampGradualRelease REG_DWORD 0x1 MpCampRing REG_DWORD 0x3 MpEngineRing REG_DWORD 0x3
I used to have those sub- keys now they are gone.