Microsoft’s Windows Endpoint Security Ecosystem Summit took place on September 10, 2024, at the company’s Redmond, Washington, headquarters, after the July CrowdStrike update outage. It brought together major endpoint-security vendors and government officials to discuss safer software deployment, Windows resilience and the trade-offs of moving security capabilities outside the Windows kernel. Microsoft later stressed that the meeting was a forum for discussion, not a decision-making session, so it produced no binding policy or agreement to remove antivirus software from kernel mode.
Why Microsoft convened the summit
CrowdStrike released the update that began disrupting IT systems globally on July 18, 2024. In a July 20 response, Microsoft estimated that 8.5 million Windows devices were affected—less than 1% of all Windows machines. The incident highlighted how a defective endpoint-security update can cause failures across many organizations at once.
On August 23, Microsoft announced a September 10 meeting for endpoint-security companies and government representatives. Its stated goals were to discuss security, safe deployment practices, resilient system design and practical actions for shared customers, while improving transparency between industry and governments.
What happened at the September 10 meeting
Microsoft’s September 12 recap described the gathering as a forum involving endpoint-security vendors and officials from the United States and Europe. Named corporate participants were Broadcom, CrowdStrike, ESET, SentinelOne, Sophos, Trellix and Trend Micro. Microsoft did not publish a complete roster of government attendees.
#1 Best Overall
David Weston, Microsoft’s corporate vice president for Enterprise and OS Security, wrote: “Although this was not a decision-making meeting, we believe in the importance of transparency and community engagement.” That qualification is central: the summit recorded themes and vendor views, rather than adopting a technical standard, vote or timetable.
The central issue: kernel access versus resilience
Windows security products may use kernel-mode access for functions that require deep visibility or protection. Running more security components outside the kernel could reduce the chance that a faulty update crashes the operating system, but it cannot automatically deliver equivalent protection, performance or anti-tampering capabilities.
The discussion therefore was not a simple choice between “kernel access” and “no kernel access.” It involved balancing four objectives:
Rank #2
- Security capability: preserving the protections vendors say can require kernel access.
- Stability: limiting the damage a defective update can cause to Windows.
- Performance: avoiding changes that impose unacceptable system overhead.
- Choice: keeping the ecosystem open to competing cybersecurity products.
ESET said kernel access should remain an option for cybersecurity products and stated: “ESET supports modifications to the Windows ecosystem that demonstrate measurable improvements to stability, on condition that any change must not weaken security, affect performance, or limit the choice of cybersecurity solutions.”
What vendors said about preventing another widespread failure
Stronger engineering and deployment controls
SentinelOne Chief Product and Technology Officer Ric Smith emphasized transparency and stringent engineering, testing and deployment practices: “We believe that transparency is critical and strongly agree with Microsoft that security companies must live up to stringent engineering, testing and deployment standards and follow software development and deployment best practices.”
Those themes include compatibility testing across Windows configurations, staged releases, monitoring after deployment, rapid rollback and recovery procedures, and clear communication when an update causes trouble. The summit announcement and recap identified these as resilience priorities; they were not published as a completed industry rulebook.
Rank #3
Incremental cooperation
Sophos characterized the summit as an initial step in an incremental process. That description fits the published outcome: participants discussed ways to improve the ecosystem, but Microsoft did not announce a signed resolution, mandatory vendor requirements or a completion date.
CrowdStrike’s response
CrowdStrike Vice President and Counsel, Privacy and Cyber Policy Drew Bagley said: “We appreciated the opportunity to join these important discussions with Microsoft and industry peers on how best to collaborate in building a more resilient and open Windows endpoint security ecosystem that strengthens security for our mutual customers.”
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Did Microsoft and CrowdStrike agree to remove antivirus from the kernel?
No. The public recap does not describe an agreement between Microsoft and CrowdStrike to eliminate kernel access, nor does it say that all participants endorsed that approach. It presents differing priorities: reducing systemic failure risk, improving testing and recovery, and retaining security capabilities and product choice where they are needed.
Rank #4
Microsoft’s later work discussed tools that could help security products follow secure-by-design practices, use anti-tampering protections and meet performance requirements outside kernel mode. Those ideas were reported as development work with vendor feedback still being collected, not as a summit resolution.
What Microsoft worked on afterward
Later reporting in November 2024 described Microsoft’s Windows Resiliency Initiative. Reported elements included a recovery environment intended to speed restoration after a serious failure and tools to support user-mode security products. The initiative also addressed secure design, recovery and operating requirements outside kernel mode.
This follow-up should not be presented as something the summit formally approved. The later reports noted that some of the work predated the CrowdStrike outage, and no delivery timeline was supplied at that point. Recovery improvements also complement—rather than replace—the need for prevention, testing and controlled deployment.
Free tools Windows power users keep installed
One-click scans. No signup required.
Timeline
| Date | Event | What it established |
|---|---|---|
| July 18, 2024 | CrowdStrike update begins affecting IT systems globally | Start of the incident identified by Microsoft |
| July 20, 2024 | Microsoft publishes its response | Microsoft estimates 8.5 million affected Windows devices, fewer than 1% of Windows machines |
| August 23, 2024 | Microsoft announces the summit | Planned discussion of safe deployment, resilience and ecosystem cooperation |
| September 10, 2024 | Summit held in Redmond | Vendors and US and European government officials discuss possible improvements |
| September 12, 2024 | Microsoft publishes its recap | Initial themes and vendor comments; explicitly not a decision-making meeting |
| November 2024 | Windows Resiliency Initiative reported | Recovery and user-mode work described as later follow-up, with some work predating the outage |
How large was the outage?
Microsoft’s own estimate was 8.5 million Windows devices, or less than 1% of all Windows machines. A separate estimate cited in a September 24, 2025 House hearing opening statement by Ranking Member Eric Swalwell attributed Parametrix with estimating that 25% of Fortune 500 companies were affected and that losses reached $5.4 billion. Those figures were relayed in a committee member’s statement, not supplied by Microsoft and not a statistic from the summit.
What the summit did not establish
- No binding requirement to remove endpoint-security software from the Windows kernel.
- No published vote, signed resolution or formal technical standard.
- No complete public list of government attendees.
- No measured improvement that can be attributed to the summit itself.
- No announced completion date for Microsoft’s later resiliency tools.
Bottom line for Windows customers
The summit was Microsoft’s structured attempt to bring Windows, security vendors and government representatives together after a major supply-chain-style software failure. Its practical message was to improve engineering, testing, deployment controls and recovery while preserving effective security and product choice. It was a starting point for continued work—not a decision to abolish kernel access or a guarantee that similar outages could never happen.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

