After the July 19, 2024, CrowdStrike outage, Sophos CEO Joe Levy said endpoint-security vendors and Microsoft were examining how security software interacts with Windows, how updates are rolled out, and how failures can be contained. At a September 10, 2024, summit, Microsoft discussed possible improvements to Windows interfaces and less disruptive handling of security-tool errors; Levy described the meeting as collaborative, not punitive. The proposals were directions under discussion, not proof that specific changes had shipped.
What happened before the summit
A faulty CrowdStrike Falcon sensor/content update caused a Windows outage beginning July 19, 2024. Microsoft said 8.5 million Windows devices were affected, according to reporting by CRN and Axios. That figure describes the reported reach of this incident; it is not a measure of the relative risk of security vendors or the chance of another outage.
Microsoft hosted an endpoint-security ecosystem summit at its Redmond, Washington, headquarters on September 10, 2024, with executives from Sophos, CrowdStrike, and other vendors. Levy told CRN the goal was to share best practices, improve the Microsoft Virus Initiative (MVI), reduce the likelihood of another incident, and limit the impact if one occurred.
What Microsoft and vendors were reconsidering
Levy said Microsoft was not proposing simply to punish vendors or take away their kernel access. Kernel-level work can support endpoint monitoring and protection, including resistance to attackers who try to evade or disable security tools. But software running in the operating-system kernel can also affect Windows itself when it fails.
#1 Best Overall
The discussion therefore concerned how to retain the protection security products need while reducing unnecessary exposure to system-wide failure. Levy said Microsoft was open to exploring improved native interfaces and different ways for Windows to handle adverse interactions with security tools. He described Microsoft’s kernel developers as active listeners.
Reduce kernel complexity and contain errors
Among the engineering directions discussed were limiting the amount and complexity of code in the kernel, separating privileges, and moving more complicated logic into user space where practical. Participants also discussed improved error handling, rollback, testing, and common deployment-safety practices. These were topics under consideration, not evidence that any one technical solution had been delivered.
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
Moving work outside the kernel could reduce some kinds of failure exposure, but it is not a risk-free swap: an alternative still needs to provide effective security and anti-tampering protections at acceptable performance. The September 2024 reporting does not establish a current release date or confirm that Microsoft’s proposed capabilities have since shipped.
Make updates measurable and stoppable
Levy described Sophos’s update process as staged: test internally, release to employee groups, then roll out to portions of its customer population while monitoring telemetry. If adverse effects appear, he said, the company can pause the deployment. This is Levy’s account of Sophos practice, not a description of every vendor’s process or a measured guarantee against outages.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
Microsoft’s summit follow-up also highlighted measured rollouts across diverse endpoints, product-health information, compatibility testing, incident response, and the ability to pause or roll back updates. As The Register quoted Microsoft: “We face a common set of challenges in safely rolling out updates to the large Windows ecosystem, from deciding how to do measured rollouts with a diverse set of endpoints to being able to pause or rollback if needed.” The Register’s September 13, 2024, report and Axios described work on capabilities intended to support security vendors outside kernel mode while addressing performance, anti-tampering, and secure-design requirements. They reported plans and discussion, not present-day availability.
What the discussion means for organizations
The outage renewed a broader resilience question: what happens if a critical endpoint-security component fails across an organization? Levy warned about a “risk of monocultures,” where dependence on one architecture or vendor can leave no quick recovery path if that component breaks. He also acknowledged that diversifying endpoint security is harder than distributing workloads among multiple cloud providers.
Rank #4
That observation is not a blanket recommendation to run overlapping endpoint products. Multiple agents can bring their own compatibility and operational complications, and the interview did not assess those trade-offs. Instead, organizations can use the questions below to evaluate resilience without assuming that any vendor or architecture is immune to failure.
- How much security work runs in kernel mode, and what can be moved to user space without weakening protection?
- How does the product resist tampering, evasion, or attempts to disable it?
- How are updates tested, staged, monitored, paused, or rolled back?
- What compatibility and product-health signals are available across the organization’s range of endpoint configurations?
- How would a failure be contained, and how quickly could the organization recover?
- What performance or resource costs come with alternative interfaces?
- Does the endpoint architecture have a single point of failure, and is there a practical recovery path if it fails?
Levy put the challenge this way: “I will never make the claim that we won’t have an incident of this sort.” He also said, “What I would say is, we should do as much as we need to, and no more.” The source reports do not provide comparative vendor failure rates, independent benchmarks, or evidence that staged rollouts prevent a specific share of incidents. They do not support ranking Sophos, CrowdStrike, Microsoft, or other summit participants.
Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
Sources and timing
The account of Levy’s remarks and Sophos’s described rollout process comes from CRN’s September 2024 interview with Joe Levy. Microsoft’s follow-up was reported by The Register and Axios on September 13, 2024. Those reports establish what was discussed or announced at that time; they do not establish current implementation status.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




