← Back to all briefings
Infrastructure 5 min read Published Updated Credibility 40/100

Microsoft Defender ATP for Linux enters public preview

Microsoft opened a public preview of Defender Advanced Threat Protection for several Linux distributions, giving security teams cross-platform EDR telemetry and anti-malware coverage to harden mixed fleets.

Timeline plotting source publication cadence sized by credibility.
1 publication timestamps supporting this briefing. Source data (JSON)

Executive briefing: Microsoft announced Microsoft Defender ATP for Linux public preview on . Packages for RHEL, CentOS, Ubuntu, Debian, and SUSE add endpoint detection and response (EDR), command-line anti-malware scans, and centralized alerting through the Defender Security Center alongside Windows telemetry.

Operator action: Evaluate the preview in a test tenant, enable canary groups for supported Linux servers, and validate audit/collection policies before broad rollout. Confirm kernel and library prerequisites, integrate Defender alerts into SIEM workflows, and update endpoint baselines to reflect the new agent and exclusions for mission-critical workloads.

Sources: Microsoft provides distribution-specific installation guides and notes on supported environments within the preview announcement.

Timeline plotting source publication cadence sized by credibility.
1 publication timestamps supporting this briefing. Source data (JSON)
Horizontal bar chart of credibility scores per cited source.
Credibility scores for every source cited in this briefing. Source data (JSON)

Continue in the Infrastructure pillar

Return to the hub for curated research and deep-dive guides.

Visit pillar hub

Latest guides

  • Endpoint Detection and Response
  • Linux
  • Microsoft Defender
Back to curated briefings