Recommended Free Tools
Microsoft’s Windows Endpoint Security Ecosystem Summit was held on September 10, 2024, at the company’s Redmond, Washington, headquarters, following the global CrowdStrike software outage. It brought endpoint-security vendors and government representatives together to discuss safer updates, recovery, system resilience and the future balance between kernel-level and user-mode security. Microsoft’s September 12 recap explicitly said the gathering was a forum, not a decision-making meeting; it produced discussion and initial themes rather than a binding agreement to remove security products from the Windows kernel.
Why Microsoft convened the summit
CrowdStrike released the software update that began affecting IT systems worldwide on July 18, 2024. In a July 20 response, Microsoft estimated that 8.5 million Windows devices were affected—less than 1 percent of all Windows machines. The incident demonstrated how a defective update from a trusted endpoint-security provider could disrupt organizations at global scale.
On August 23, Microsoft announced a September 10 summit for endpoint-security companies and government representatives. Its stated agenda covered safe deployment practices, resilient system design, security, transparency and concrete actions for shared customers. The meeting was intended to improve cooperation across an ecosystem in which Microsoft supplies Windows, security vendors operate on top of it, and public agencies oversee or depend on critical infrastructure.
What happened at the September 10 meeting
Microsoft’s September 12 recap described the event as an initial forum for sharing ideas and responsibilities. Corporate Vice President of Enterprise and OS Security David Weston wrote: “Although this was not a decision-making meeting, we believe in the importance of transparency and community engagement.”
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
The recap framed resilience as a shared responsibility. Topics included engineering and compatibility testing, staged or safer deployment, monitoring, rollback and faster recovery when an update causes a failure. The published material does not report a vote, signed resolution, technical standard, attendance total or quantified improvement resulting from the summit.
Who participated
Microsoft’s recap includes statements from seven endpoint-security companies:
- Broadcom
- CrowdStrike
- ESET
- SentinelOne
- Sophos
- Trellix
- Trend Micro
Microsoft also said government officials from the United States and Europe attended. The official material does not provide a complete government roster, so the companies and regions above should not be treated as a comprehensive attendance list.
Rank #2
Did Microsoft and CrowdStrike agree to remove antivirus from the kernel?
No. The summit did not establish a binding decision to eliminate kernel access, and Microsoft did not announce that all endpoint-security products would be forced into user mode.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Kernel-mode code runs with very high operating-system privileges. That access can support security functions such as monitoring and tamper resistance, but a faulty or incompatible update at that level can have unusually broad consequences. Running more security functions outside the kernel can limit the damage a defective component can cause to Windows, yet it can also affect the capabilities, performance and defenses vendors consider necessary.
The vendor comments show why the issue remained unresolved:
- ESET: “ESET supports modifications to the Windows ecosystem that demonstrate measurable improvements to stability, on condition that any change must not weaken security, affect performance, or limit the choice of cybersecurity solutions.”
- SentinelOne: Chief Product and Technology Officer Ric Smith said, “We believe that transparency is critical and strongly agree with Microsoft that security companies must live up to stringent engineering, testing and deployment standards and follow software development and deployment best practices.”
- CrowdStrike: Vice President and Counsel, Privacy and Cyber Policy Drew Bagley said the company welcomed discussions about “building a more resilient and open Windows endpoint security ecosystem that strengthens security for our mutual customers.”
- Sophos and the other participants: The recap presented the meeting as an incremental step rather than a completed technical settlement.
These positions support stronger assurance and recovery while leaving room for security products to retain kernel access when their functions require it.
The practical resilience measures under discussion
Safer software deployment
Participants discussed stricter engineering, compatibility testing and deployment practices before updates reach large numbers of machines. Staged releases, telemetry and monitoring can expose failures earlier and make it easier to halt distribution.
Rollback and recovery
Resilience also means restoring systems quickly when prevention fails. Recovery procedures, usable rollback paths and tooling that can operate when Windows is impaired are separate from the question of where a security product runs.
Rank #4
Security outside kernel mode
Microsoft explored ways to let security products provide more capability outside the kernel while preserving protections such as anti-tampering. This is a design direction, not a summit mandate, and the trade-offs include functionality, performance and product choice.
What Microsoft worked on afterward
Later reporting in November 2024 described Microsoft’s Windows Resiliency Initiative. Reported work included a recovery environment, tools intended to help security products operate outside kernel mode, anti-tampering protections and performance requirements. Microsoft was still collecting vendor feedback, and no delivery timeline was supplied in that reporting.
The initiative should not be presented as a resolution adopted at the September summit. Later coverage also noted that some of the resiliency work predated the CrowdStrike outage. Faster recovery and user-mode security are follow-up directions, not proof that Windows had already abandoned kernel-based endpoint protection.
How large was the CrowdStrike impact?
Microsoft’s own July 2024 estimate was 8.5 million affected Windows devices, or less than 1 percent of all Windows machines. A separate estimate cited in Ranking Member Eric Swalwell’s opening statement at a September 24, 2025 House hearing attributed 25 percent of Fortune 500 companies and $5.4 billion in losses to Parametrix. Those figures were relayed in a committee member’s statement; they are not Microsoft’s estimate and were not a statistic produced by the summit.
What the summit established—and what it did not
| Question | What the available record shows |
|---|---|
| Was there a real event? | Yes. It took place September 10, 2024, in Redmond. |
| Was it a binding policy meeting? | No. Microsoft called it a forum, not a decision-making meeting. |
| Did participants agree to remove security software from the kernel? | No such agreement was announced. |
| What subjects were discussed? | Safe deployment, testing, resilience, recovery, transparency and possible security capabilities outside kernel mode. |
| Were outcomes measured? | No numerical vote, completion metric or quantified improvement was published. |
| Was a complete government attendee list released? | No. Microsoft identified officials from the United States and Europe but did not publish a full roster. |
Why the distinction matters for Windows customers
Organizations should read the summit as a signal to evaluate update governance and recovery readiness, not as evidence that a particular endpoint product or Windows release has changed policy. The relevant controls include staged deployment, compatibility validation, monitoring, tested rollback procedures and a recovery path that remains usable when a security component fails. Security teams must weigh those controls against the protective functions and performance requirements that may still depend on privileged access.
The Bottom Line
Microsoft’s post-CrowdStrike summit created a channel for vendors and governments to discuss safer deployment and more resilient Windows security. It did not produce a binding agreement to remove antivirus software from the kernel; subsequent resiliency work remained an evolving follow-up with important security, stability and compatibility trade-offs.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

