Windows 10/11 - Update for Microsoft Defender for Endpoint - KB5005292

JACOB, Jacob 5 Reputation points
2026-09-17T10:00:19.06+00:00

Issue: Windows Update keeps failing to install.

Error: ***Windows 10/11 - Update for Microsoft Defender for Endpoint - KB5005292 (Version 10.8838.26060.15013) - Current Channel (Broad). Install error - 0x800700aa

Any recommendation ?***

Windows for business | Windows 365 Business
0 comments No comments

3 answers

Sort by: Oldest
  1. Harry Phan 33,320 Reputation points Independent Advisor
    2026-09-17T10:41:43.8866667+00:00

    Hello,

    The error 0x800700aa when installing KB5005292 usually indicates a revision mismatch between the Defender for Endpoint sensor already installed and the update package being offered. In short, the update is failing because your system already has a newer or incompatible sensor version, so Windows Update cannot apply this package.

    KB5005292 is a recurring cumulative update for the Microsoft Defender for Endpoint EDR sensor. Microsoft reuses the same KB number for different sensor builds, and the update only applies if the locally installed sensor version is lower than the package version. If your endpoint already has an equal or newer build, the installer exits with this error. To confirm, you should check the installed sensor version directly. Open PowerShell and run:

    
    Get-ItemProperty -Path 'Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Advanced Threat Protection\' -Name 'InstallLocation'
    
    

    Then navigate to that path and check the version of MsSense.exe. Compare it against the version listed in the KB5005292 article and the update package being offered. If your installed version is already equal or higher, the update is not needed, and the failure is expected behavior.

    If the installed version is lower but the update still fails, the issue may be caused by WSUS or Intune offering a mismatched package branch. In that case, you can manually update the Defender platform by downloading the latest package from the Microsoft Update Catalog (catalog.update.microsoft.com in Bing) or by running:

    
    "%ProgramFiles%\Windows Defender\MpCmdRun.exe" -SignatureUpdate -MMPC
    
    

    This forces the sensor to update directly from Microsoft Malware Protection Center. Also, verify that your WSUS or SCCM server has approved the latest Defender updates; otherwise, endpoints will continue to fail with revision mismatch.

    In summary, the error is not a corruption but a version conflict. Either your system already has the required build, or the offered package does not match your installed branch. Confirm the installed sensor version, and if necessary, update manually from the Microsoft Update Catalog or adjust WSUS approvals.

    I hope you've found something useful here. If it helps you get more insight into the issue, it's appreciated to accept the answer. Should you have more questions, feel free to leave a message. Have a nice day!

    HP.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments

  2. Piotr Sabiniewicz 0 Reputation points
    2026-09-18T06:47:37.18+00:00

    Hello,
    I have excatly the same issue on my corporate PC.
    My current MSsense is .FileVersion 10.8837.26060.2029

    Update:
    My device is running MsSense.exe version 10.8837.26060.2029 and Windows Update is offering KB5005292 version 10.8838.26060.15013 (Current Channel Broad). Since the installed sensor version is lower than the offered package version, this does not appear to be a "newer version already installed" scenario. The installation consistently fails with 0x800700AA. Defender platform version is 4.18.26080.4. Can Microsoft confirm whether there is a known issue with this specific Broad Channel release or a revision/package mismatch affecting Intune-managed devices?

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments

  3. Jtrucizna 0 Reputation points
    2026-09-22T07:45:58.24+00:00

    Hello,

    We experienced a similar issue with the exact same version, 10.8838.26060.15013, and I opened a support case with Microsoft last week.

    In our environment, the update started installing successfully through the Windows Update service as of yesterday.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.