<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>rss.livelink.threads-in-node</title>
    <link>https://techcommunity.microsoft.com/t5/microsoft-security/ct-p/microsoft-security</link>
    <description>rss.livelink.threads-in-node</description>
    <pubDate>Wed, 10 Jun 2026 09:56:16 GMT</pubDate>
    <dc:creator>microsoft-security</dc:creator>
    <dc:date>2026-06-10T09:56:16Z</dc:date>
    <item>
      <title>Level up your Azure Network Security Skills with our Upcoming Webinar Series</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/level-up-your-azure-network-security-skills-with-our-upcoming/ba-p/4525584</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;As network and application-layer threats continue to evolve, security and infrastructure teams need more than product knowledge. They need practical, scenario-driven guidance they can apply to real workloads. To support that, the Azure Network Security team is hosting a series of upcoming technical webinars covering the capabilities our customers rely on every day:&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-drs?tabs=drs21" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Azure Web Application Firewall (WAF),&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt; &lt;A href="https://learn.microsoft.com/en-us/azure/firewall/firewall-copilot" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Azure Firewall,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt; &lt;A href="https://learn.microsoft.com/en-us/azure/ddos-protection/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Azure DDoS Protection&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; and &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/bastion/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Azure Bastion&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Each session is focused on demos, the latest enhancements, and the design and operational decisions you face when securing modern Azure environments. Whether you are protecting customer-facing web applications, hardening east-west and egress traffic, or securing remote administrative access at scale, there is a session in this lineup for you.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;These webinars are ideal for Security Architects and Engineers, Network and Infrastructure teams, SOC Analysts, Cloud Platform Owners, Partner Technical Consultants, and any practitioner responsible for the security posture of workloads running on Azure.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Below is the schedule of the upcoming live deliveries.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Upcoming Events &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H3&gt;
&lt;H5&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Azure WAF Layer 7 DDoS defense in practice&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Date and time: Thursday, June 18, 2026, at 8am PST&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://securitycommunity.microsoft.com/VirtualEvents/Webinar-Details/?id=1776dc8f-c353-f111-bec7-000d3a58d82a" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;View event details and join&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;As web applications become primary targets for sophisticated application-layer attacks, Azure Web Application Firewall continues to evolve to meet the needs of modern application security teams facing volumetric and targeted application-layer threats. In this webinar, we will explore how Azure WAF enables a layered, adaptive approach to application-layer DDoS mitigation, helping organizations detect and block malicious request patterns through intelligent inspection, control traffic flow to prevent resource exhaustion from abusive sources, progressively challenge suspicious clients to verify legitimacy without disrupting real users, and combine multiple defense mechanisms into a cohesive mitigation strategy that adapts to evolving attack techniques. Whether you're securing customer-facing web apps or business-critical services, this session will equip you with practical approaches to building resilient application-layer defenses on Azure.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Azure Firewall IDPS Detections and Sentinel Integration&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Date and time: Thursday, July 9, 2026, at 8am PST&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://securitycommunity.microsoft.com/VirtualEvents/Webinar-Details/?id=125d3fb9-c653-f111-bec6-000d3a5bf7ee" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;View event details and join&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;As network threats grow in complexity, organizations need visibility that extends beyond simple traffic filtering into intelligent detection and unified investigation workflows. Azure Firewall's Intrusion Detection and Prevention capabilities continue to evolve to meet the needs of modern security operations teams facing advanced lateral movement, exploitation attempts, and command-and-control activity. In this webinar, we will explore how Azure Firewall identifies malicious network patterns in real time, how detection signals flow seamlessly into Microsoft Sentinel to enrich the broader security narrative, and how security teams can correlate firewall intelligence with other data sources to accelerate threat hunting, streamline incident response, and build a more connected and actionable view of their network security posture.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;What's New in Azure Bastion&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Date and time: Thursday, July 23, 2026, at 8am PST&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://securitycommunity.microsoft.com/VirtualEvents/Webinar-Details/?id=3a4e6d94-ca53-f111-bec6-6045bd06ff19" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;View event details and join&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Secure remote access to cloud workloads remains a critical requirement as organizations scale their Azure environments and adapt to evolving operational demands. Azure Bastion continues to evolve to meet the needs of modern infrastructure teams seeking seamless, browser-based connectivity without exposing virtual machines to the public internet. In this webinar, we'll explore the latest enhancements to Azure Bastion covering new capabilities that improve connectivity options, streamline the administrative experience, expand protocol and session support, and strengthen the overall security posture of remote access workflows. Whether you're managing a handful of VMs or operating at enterprise scale, this session will bring you up to speed on what's new and how these improvements can simplify and secure your day-to-day operations.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;What's New in Azure Firewall&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Date and time: Thursday, August 6, 2026, at 8am PST&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://securitycommunity.microsoft.com/VirtualEvents/Webinar-Details/?id=96d39a8e-bc5e-f111-a826-6045bd023cfc" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;View event details and join&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;As network architectures grow more distributed and threat landscapes more dynamic, organizations need a cloud-native firewall that keeps pace with both modern workload patterns and adversary techniques. Azure Firewall continues to evolve to meet the needs of network and security teams managing hybrid environments, multi-region deployments, and increasingly complex east-west and north-south traffic flows. In this webinar, we will explore the latest enhancements to Azure Firewall covering new policy and rule management capabilities, improvements that expand protocol and traffic inspection coverage, and deeper integrations across the Azure security ecosystem to streamline operations. Whether you are standardizing perimeter protection across a global Azure footprint or modernizing segmentation for business-critical workloads, this session will bring you up to speed on what is new and how these improvements can simplify and strengthen your day-to-day network security operations.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;What's New in Azure Web Application Firewall&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Date and time: Thursday, August 27, 2026, at 8am PST&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://securitycommunity.microsoft.com/VirtualEvents/Webinar-Details/?id=541a5162-4655-f111-bec7-000d3a5ad9f6" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;View event details and join&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Web applications remain primary entry points for attackers, and organizations need a Web Application Firewall that adapts as quickly as the threats targeting their workloads. Azure Web Application Firewall continues to evolve to meet the needs of modern application security teams defending against an expanding mix of OWASP-class attacks, automated abuse, and business logic threats across diverse hosting models. In this webinar, we will explore the latest enhancements to Azure WAF. We will cover new detection and rule capabilities that improve protection accuracy, tuning and exclusion improvements that reduce false positives without weakening coverage, and expanded visibility and analytics that accelerate investigation. Whether you are securing customer-facing web apps or managing WAF policies at scale, this session will bring you up to speed on what's new and how these improvements can simplify and strengthen your application protection strategy&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Past Recordings:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;View additional past webinars from &lt;/SPAN&gt;&lt;A href="https://www.youtube.com/playlist?list=PLmAptfqzxVEVh3-ecmlrdQJ3XAay97KNb" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Azure Network Security &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;on Microsoft Security Community&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt; YouTube&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Stay connected with the Azure Network Security community&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Influence product feedback and join the &lt;/SPAN&gt;&lt;A href="https://www.youtube.com/playlist?list=PLmAptfqzxVEVh3-ecmlrdQJ3XAay97KNb" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Threat Protection Advisors Program&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Stay up-to-date and fo&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;llow the &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/category/azure-network-security/blog/azurenetworksecurityblog" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Azure Network Security Blog | Microsoft Community Hub&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Engage with &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;p&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;eers&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;, &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ask and answer questions &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;in the &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/category/azure-network-security/discussions/azurenetworksecurity" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Azure Network Security discussion board&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Learn and Engage with the Microsoft Security Community &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="o" data-font="Courier New" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Courier New&amp;quot;,&amp;quot;469769242&amp;quot;:[9675],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;o&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Log in and follow this &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-security-product/blog/microsoft-security-blog" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Security Community Blog&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; and post/ interact in the &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-security" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Security Community discussion spaces&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="o" data-font="Courier New" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Courier New&amp;quot;,&amp;quot;469769242&amp;quot;:[9675],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;o&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Follow = Click the heart in the upper right when you're logged in &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;🤍&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="o" data-font="Courier New" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Courier New&amp;quot;,&amp;quot;469769242&amp;quot;:[9675],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;o&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="3" data-aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Join the &lt;/SPAN&gt;&lt;A href="https://aka.ms/AAycdmn" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Security Community&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; and be notified of upcoming events, product feedback surveys, and more.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="o" data-font="Courier New" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Courier New&amp;quot;,&amp;quot;469769242&amp;quot;:[9675],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;o&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="4" data-aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Get early access to Microsoft Security products and provide feedback to engineers by joining the &lt;/SPAN&gt;&lt;A href="https://aka.ms/AAyclfq" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Security Advisors.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="o" data-font="Courier New" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Courier New&amp;quot;,&amp;quot;469769242&amp;quot;:[9675],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;o&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="5" data-aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Learn about the &lt;/SPAN&gt;&lt;A href="https://aka.ms/MVPMDOvideo" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft MVP Program.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="o" data-font="Courier New" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Courier New&amp;quot;,&amp;quot;469769242&amp;quot;:[9675],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;o&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="6" data-aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Join the &lt;/SPAN&gt;&lt;A href="https://aka.ms/AAyclgu" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Security Community LinkedIn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; and the &lt;/SPAN&gt;&lt;A href="https://www.linkedin.com/company/microsoft-entra/posts/?feedView=all" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Entra Community LinkedIn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 09 Jun 2026 17:09:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/level-up-your-azure-network-security-skills-with-our-upcoming/ba-p/4525584</guid>
      <dc:creator>andrewmathu</dc:creator>
      <dc:date>2026-06-09T17:09:00Z</dc:date>
    </item>
    <item>
      <title>Ask Microsoft Anything: Microsoft Defender expands protection to AWS RDS</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-cloud/ask-microsoft-anything-microsoft-defender-expands-protection-to/m-p/4526819#M2150</link>
      <description>&lt;P&gt;Hey all! We are currently answering questions over on the event page here:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://aka.ms/DefenderAWSExpansionAMA" target="_blank"&gt;https://aka.ms/DefenderAWSExpansionAMA&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Come join and learn something about Defender for Cloud and the expansion of protection!&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2026 16:19:01 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-cloud/ask-microsoft-anything-microsoft-defender-expands-protection-to/m-p/4526819#M2150</guid>
      <dc:creator>Trevor_Rusher</dc:creator>
      <dc:date>2026-06-09T16:19:01Z</dc:date>
    </item>
    <item>
      <title>Elevate your telemetry using custom data collection in Microsoft Defender</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/elevate-your-telemetry-using-custom-data-collection-in-microsoft/ba-p/4512530</link>
      <description>&lt;P&gt;At Ignite in November, we announced that Microsoft Defender is now the only endpoint protection solution that allows data-hungry security teams to meet specific telemetry needs by optimizing their data collection right within the Defender portal, without the need to rely on fragmented and siloed solutions. Since then, we've heard from customers that this tool has been a game changer, enabling them to hunt through new data types as well as richer data on events already reported. The release of custom data collection was a key milestone in our ongoing journey to make Defender easy to manage and customize.&lt;/P&gt;
&lt;P&gt;Security teams have been asking for guidance and examples of how to get the most out of the tool, so today we're sharing how some organizations can use custom data collection and dynamic tagging to detect command and control (C2) communications, giving defenders elevated visibility and deeper telemetry into attacker activity across the environment.&lt;/P&gt;
&lt;H4&gt;See the data you want to see&lt;/H4&gt;
&lt;P&gt;Defender's default telemetry is tuned to balance performance and signal-to-noise across millions of devices, so it focuses on the events most useful for high-fidelity detection at fleet scale, but many organizations want richer, more granular signals for deeper hunting, compliance, or auditing purposes. Custom data collection lets you go beyond what Defender already captures without ever leaving the Defender portal. Easily build custom collection rules based on your organization’s specific needs using natural language; no PhD required! It includes several highly requested data types, including AMSI for hunting over script content, and Kerberos for hunting auth-based and network attacks.&lt;/P&gt;
&lt;P&gt;This truly integrated custom data offering is possible thanks to Microsoft’s platform approach, as the additional telemetry can be collected and analyzed via Defender and stored via Microsoft Sentinel. It puts you in complete control of any customized, add-on data, including exactly which data types are collected and how long they are stored. No other security solution has fully integrated and customizable telemetry collection and analysis.&lt;/P&gt;
&lt;H4&gt;Example custom telemetry scenario: detecting C2 communications&lt;/H4&gt;
&lt;P&gt;Many organizations have a set of assets that require special attention, like internet-facing servers, domain controllers, and other high-value endpoints where deeper telemetry can make the difference between catching an intrusion early and discovering it after the damage is done.&lt;/P&gt;
&lt;P&gt;Imagine your organization has received threat intelligence on attacks using stealthy C2 frameworks: HTTPS beacons with jittered intervals, DNS-based data exchange, and persistence via scheduled tasks and registry modifications. You want richer visibility into those internet-facing servers and high-value endpoints so you can hunt for these patterns proactively, instead of reconstructing them after the fact.&lt;/P&gt;
&lt;P&gt;Dynamic tags scope these high-value devices into a targeted group, and custom data collection captures the extra process, network, and registry events from them, giving analysts the telemetry they need to hunt for beaconing, suspicious DNS patterns, and persistence before attackers establish a foothold.&lt;/P&gt;
&lt;P&gt;To detect C2 communications using dynamic tagging, follow these steps:&lt;/P&gt;
&lt;H4&gt;&lt;U&gt;&lt;STRONG&gt;Step 1: Tag your devices&lt;/STRONG&gt;&lt;/U&gt;&lt;/H4&gt;
&lt;P&gt;Custom Data Collection rules are scoped to&amp;nbsp;&lt;STRONG&gt;dynamic tags; &lt;/STRONG&gt;once set,&lt;STRONG&gt; &lt;/STRONG&gt;those tags are automatically applied and removed based on conditions you define. Configure them in&amp;nbsp;&lt;STRONG&gt;Settings &amp;gt; Microsoft Defender XDR &amp;gt; Asset Rule Management&lt;/STRONG&gt;.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Tag&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Rule name&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Conditions&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Tag to apply&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Internet-facing servers&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;InternetFacing-Servers&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Internet facing = true AND OS platform equals&amp;nbsp;Windows Server 2022&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;C2-Watchlist&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Devices under active investigation&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;HighSev-Investigation&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Manual tag equals&amp;nbsp;UnderInvestigation&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;HighSev-Verbose&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;&lt;img /&gt;&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;Bringing manual tags into the dynamic model&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;Custom data collection is built around&amp;nbsp;&lt;STRONG&gt;dynamic tags&lt;/STRONG&gt;&amp;nbsp;by design: one leading, unified tagging experience that's more flexible and customizable. Dynamic tags can be driven by device properties, group membership, OS,&amp;nbsp;&lt;EM&gt;or&lt;/EM&gt;&amp;nbsp;by existing manual tags, so anything your team already tags manually flows naturally into custom data collection through a simple Asset Rule Management rule, exactly as Tag 2 above does.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In this example, analysts manually tag a device&amp;nbsp;UnderInvestigation&amp;nbsp;during incident response. The dynamic rule picks up that manual tag and applies&amp;nbsp;HighSev-Verbose, which custom data collection rules can target. The analyst doesn't need to know about dynamic tags they tag the device the way they always have, and custom data collection activates &lt;STRONG&gt;automatically&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;H4&gt;&lt;U&gt;&lt;STRONG&gt;Step 2: Build your collection rules&lt;/STRONG&gt;&lt;/U&gt;&lt;/H4&gt;
&lt;P&gt;Navigate to&amp;nbsp;&lt;STRONG&gt;Settings &amp;gt; Endpoints &amp;gt; Rules &amp;gt; Custom Data Collection&lt;/STRONG&gt;. Select your Microsoft Sentinel workspace in the top-right corner.&lt;/P&gt;
&lt;P&gt;Before creating rules, confirm you meet every prerequisite in the&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-endpoint/create-custom-data-collection-rules" target="_blank" rel="noopener"&gt;custom data collection documentation&lt;/A&gt;&amp;nbsp;, in particular, your tenant must be onboarded to the&amp;nbsp;&lt;STRONG&gt;Unified Security Operations Platform (USOP)&lt;/STRONG&gt;.&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;Rule 1: Outbound network connections from high-risk processes&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;Capture connections from processes commonly abused by C2 frameworks living-off-the-land binaries and scripting engines.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Setting&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Value&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Rule name&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;C2-OutboundConnections&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Table&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;DeviceCustomNetworkEvents&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Action&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Connection Success&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Condition&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;InitiatingProcessFileName Equals: powershell.exe,&amp;nbsp;rundll32.exe,&amp;nbsp;regsvr32.exe,&amp;nbsp;mshta.exe,&amp;nbsp;certutil.exe,&amp;nbsp;msiexec.exe&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Scope&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Devices tagged&amp;nbsp;C2-Watchlist&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;H5&gt;&lt;STRONG&gt;Rule 2: DNS query activity&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;Many C2 frameworks use DNS for beaconing or data exchange. Default telemetry captures limited DNS data. This rule collects all DNS queries from monitored devices.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Setting&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Value&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Rule name&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;C2-DNSActivity&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Table&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;DeviceCustomNetworkEvents&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Action&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Connection Success&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Condition&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;RemotePort equals&amp;nbsp;53&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Scope&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Devices tagged&amp;nbsp;C2-Watchlist&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H5&gt;&lt;STRONG&gt;Rule 3: Persistence mechanisms&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;C2 implants establish persistence via scheduled tasks, registry run keys, or services. Capture process creation events for common persistence tools.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Setting&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Value&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Rule name&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;C2-Persistence&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Table&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;DeviceCustomProcessEvents&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Action&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Process Created&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Condition&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;FileName in (schtasks.exe,&amp;nbsp;reg.exe,&amp;nbsp;sc.exe,&amp;nbsp;at.exe)&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Scope&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Devices tagged&amp;nbsp;C2-Watchlist&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H5&gt;&lt;STRONG&gt;Rule 4: Full process and script telemetry during investigations&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;When a device gets the&amp;nbsp;HighSev-Verbose&amp;nbsp;tag, collect everything.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Setting&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Value&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Rule name&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;HighSev-AllProcesses&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Table&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;DeviceCustomProcessEvents&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Action&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Process Created&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Condition&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Broad (all process creation events)&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Scope&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Devices tagged&amp;nbsp;HighSev-Verbose&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Setting&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Value&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Rule name&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;HighSev-ScriptCapture&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Table&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;DeviceCustomScriptEvents&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Action&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Script execution&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Condition&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Broad (all script events) – add a condition which is always true such as&lt;/P&gt;
&lt;P&gt;FileName not equals “”&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Scope&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Devices tagged&amp;nbsp;HighSev-Verbose&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;Collection profiles summary&lt;/STRONG&gt;&lt;/H5&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Tag&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Rules active&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;What gets collected&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Use case&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;C2-Watch&amp;nbsp;list&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;OutboundConnections, DNSActivity, Persistence&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Network connections from, DNS queries, persistence tool usage, DLL sideloading&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Persistent C2 monitoring&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;HighSev-Verbose&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;AllProcesses, ScriptCapture&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Every process creation, all script execution&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Full-depth incident response&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;Important:&lt;/STRONG&gt;&amp;nbsp;when you remove the&amp;nbsp;HighSev-Verbose&amp;nbsp;tag after closing an incident, collection automatically drops back to baseline, no manual rule cleanup needed. This is what makes verbose collection safe to leave configured: it's only active while the tag is.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H4&gt;&lt;U&gt;&lt;STRONG&gt;Step 3: Hunt&lt;/STRONG&gt;&lt;/U&gt;&lt;/H4&gt;
&lt;P&gt;Rules deploy within 20 minutes to an hour. Query the data in AH directly.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Detect beaconing patterns processes making regular-interval outbound connections:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;STRONG&gt;Find DNS queries to high-entropy domains (potential DGA):&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Spot persistence being established:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Leverage the telemetry from your new collection rule into a Custom Detection so high-value findings raise alerts automatically, instead of waiting for the next manual hunt.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Custom data collection effectively extends your endpoint protection into a targeted, general-purpose log collector, one that's now ready to serve advanced hunting, custom detections,&amp;nbsp;&lt;EM&gt;and&lt;/EM&gt; auditing or regulatory use cases, while default fleet-wide telemetry stays tuned for performance and signal-to-noise. By combining dynamic tagging with purpose-built collection rules, your highest-risk devices are always streaming the signals that matter most, ready for detection and investigation before and during an incident.&lt;/P&gt;
&lt;H4&gt;Learn more&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;To learn more about endpoint protection with Microsoft Defender, check out our&amp;nbsp;&lt;A href="https://www.microsoft.com/security/business/endpoint-security/microsoft-defender-endpoint" target="_blank" rel="noopener"&gt;website&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;To learn more about Microsoft Security solutions, visit our &lt;A href="https://www.microsoft.com/en-us/security/business" target="_blank" rel="noopener"&gt;website.&lt;/A&gt; Bookmark the &lt;A href="https://www.microsoft.com/security/blog/" target="_blank" rel="noopener"&gt;Security blog&lt;/A&gt; to keep up with our expert coverage on security matters. Follow us on LinkedIn (&lt;A href="https://www.linkedin.com/showcase/microsoft-security/" target="_blank" rel="noopener"&gt;Microsoft Security&lt;/A&gt;) and X (&lt;A href="https://twitter.com/@MSFTSecurity" target="_blank" rel="noopener"&gt;@MSFTSecurity&lt;/A&gt;) for the latest news and updates on cybersecurity.&lt;/LI&gt;
&lt;LI&gt;To learn more about custom data collection and how to get started, see our &lt;A href="https://learn.microsoft.com/en-us/defender-endpoint/create-custom-data-collection-rules" target="_blank" rel="noopener"&gt;documentation&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 09 Jun 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/elevate-your-telemetry-using-custom-data-collection-in-microsoft/ba-p/4512530</guid>
      <dc:creator>Theo_Cohen</dc:creator>
      <dc:date>2026-06-09T16:00:00Z</dc:date>
    </item>
    <item>
      <title>Exempt a specific container in MDC</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-cloud/exempt-a-specific-container-in-mdc/m-p/4526806#M2149</link>
      <description>&lt;P&gt;I have this recommendation showing in defender.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Immutable (read-only) root filesystem should be enforced for containers&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;There are multiple containers inside AKS that are showing as "Unhealthy"&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;airflow/db1&lt;/LI&gt;&lt;LI&gt;airflow/sql1&lt;/LI&gt;&lt;LI&gt;airflow/scheduler1&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Is there a way to exempt a specific container or the whole recommendation has to be exempted.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2026 15:25:11 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-cloud/exempt-a-specific-container-in-mdc/m-p/4526806#M2149</guid>
      <dc:creator>ABhatia610</dc:creator>
      <dc:date>2026-06-09T15:25:11Z</dc:date>
    </item>
    <item>
      <title>Detecting AI agents and non-human identities in Microsoft Sentinel: the classic-agent blind spot</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-sentinel/detecting-ai-agents-and-non-human-identities-in-microsoft/m-p/4526787#M12940</link>
      <description>&lt;P&gt;Build 2026 made the direction official. The industry is moving from the app era into the agent era, and Microsoft spent a real share of the keynote on securing agents across their lifecycle, from discovering what is exploitable to governing what is running in production. On the identity side the centerpiece is Microsoft Entra Agent ID, now generally available, which gives AI agents first-class identities and extends Conditional Access, Identity Protection, and full audit logging to them.&lt;/P&gt;&lt;P&gt;That is good news for agents you build the new way. It is not the whole picture, and the gap is where most SOCs will get hurt first.&lt;/P&gt;&lt;H3&gt;Modern agents are covered. Classic agents are not.&lt;/H3&gt;&lt;P&gt;Entra Agent ID draws a hard line between two kinds of agent.&lt;/P&gt;&lt;P&gt;Modern agents are created through the Agent ID platform, each backed by an agent identity blueprint. They carry a proper Agent ID, a full audit trail, and the complete set of governance capabilities, including Identity Protection for Agents, which establishes a baseline for an agent's normal activity and flags anomalies automatically.&lt;/P&gt;&lt;P&gt;Classic agents are everything that came before, or that gets built outside the platform: AI agents implemented as ordinary service principals or app registrations, for example Copilot Studio agents created before Agent ID was enabled, or any home-grown automation calling Graph with client credentials. In the Entra agent registry they appear with "Has Agent ID: No," and that flag matters, because the Agent ID protections apply to identities that actually hold an Agent ID. Classic agents sit outside Identity Protection for Agents and Conditional Access for Agents.&lt;/P&gt;&lt;P&gt;Here is the uncomfortable part. The non-human identities you already run, the service principals behind your pipelines, your integrations, your scripts, your pre-platform Copilot Studio bots, are almost all classic agents. They tend to outnumber your human accounts, they have no MFA in any meaningful sense, and a credential added to one does not show up in the Azure portal. The new platform protections do not reach them. Until you migrate them, the only place you get detection coverage on that population is your SIEM.&lt;/P&gt;&lt;P&gt;So this is the job Sentinel does that Agent ID does not: detect risky behavior on the classic, service-principal-backed agents that the platform cannot yet protect.&lt;/P&gt;&lt;H3&gt;The telemetry you have, and the one switch people forget&lt;/H3&gt;&lt;P&gt;Three tables carry most of the signal.&lt;/P&gt;&lt;P&gt;AADServicePrincipalSignInLogs records service principal authentications, the client-credentials sign-ins your agents and automation use. No user, no MFA, just an app proving it holds a secret or certificate.&lt;/P&gt;&lt;P&gt;AADManagedIdentitySignInLogs does the same for managed identities.&lt;/P&gt;&lt;P&gt;AuditLogs records directory changes, including the one that matters most for persistence: a new credential added to an application or service principal.&lt;/P&gt;&lt;P&gt;One practical warning before any of this works. Service principal and managed identity sign-in logs are not streamed by default. You have to enable those categories explicitly in the Entra diagnostic settings feeding your workspace. Plenty of teams write the detection, never check, and never notice the table is empty. Verify that first.&lt;/P&gt;&lt;H3&gt;Detection 1: a new credential on a service principal or app&lt;/H3&gt;&lt;P&gt;Adding a secret or certificate to an existing service principal is one of the cleanest persistence techniques in a Microsoft cloud. The attacker compromises a privileged user or app, drops a fresh credential on a service principal that already holds useful Graph permissions, and now has access that survives password resets and session revocation. It maps to MITRE T1098.001, Account Manipulation: Additional Cloud Credentials. For a classic agent it is especially nasty, because there is no Identity Protection baseline watching it.&lt;/P&gt;&lt;LI-CODE lang="kusto"&gt;// Detection 1: new secret or certificate added to an application or service principal
// MITRE T1098.001 - Account Manipulation: Additional Cloud Credentials
AuditLogs
| where OperationName has_any ("Add service principal", "Certificates and secrets management")
| where Result =~ "success"
| extend Initiator = coalesce(
        tostring(InitiatedBy.user.userPrincipalName),
        tostring(InitiatedBy.app.displayName))
| extend InitiatorIp = tostring(InitiatedBy.user.ipAddress)
| mv-apply Target = TargetResources on (
    where Target.type =~ "Application"
    | extend TargetName  = tostring(Target.displayName),
             TargetId    = tostring(Target.id),
             KeyChanges  = Target.modifiedProperties
  )
| mv-apply Prop = KeyChanges on (
    where tostring(Prop.displayName) =~ "KeyDescription"
    | extend NewKeys = parse_json(tostring(Prop.newValue)),
             OldKeys = parse_json(tostring(Prop.oldValue))
  )
| extend AddedKeys = set_difference(NewKeys, OldKeys)
| where array_length(AddedKeys) &amp;gt; 0
| project TimeGenerated, Initiator, InitiatorIp, TargetName, TargetId, AddedKeys
| order by TimeGenerated desc&lt;/LI-CODE&gt;&lt;P&gt;The operation filter catches the three shapes this event takes in the log: "Add service principal," "Add service principal credentials," and "Update application - Certificates and secrets management." The modifiedProperties parsing isolates the KeyDescription change, and set_difference confirms a key was actually added rather than removed, so rotating out an old credential does not, on its own, fire the rule.&lt;/P&gt;&lt;P&gt;False positives come from legitimate rotation and from automation that provisions app credentials (CI/CD, infrastructure as code). The initiator is the discriminant. A credential added by your deployment pipeline's service account at the usual time is routine. The same change initiated by an interactive admin out of hours, or by an account that never normally touches app credentials, is what you want to surface. Allow-list the expected initiators, not the targets.&lt;/P&gt;&lt;H3&gt;Detection 2: a classic agent signing in from a first-seen IP&lt;/H3&gt;&lt;P&gt;A service principal that has only ever authenticated from your Azure regions and suddenly signs in from somewhere new is a strong signal that its credential has been lifted and is being used elsewhere. Service principals have stable, boring network behavior, which makes a first-seen IP a far cleaner indicator for them than it is for roaming human users. This is the behavioral baseline Identity Protection gives you for free on modern agents, rebuilt in KQL for the classic ones it ignores. MITRE T1078.004, Valid Accounts: Cloud Accounts.&lt;/P&gt;&lt;LI-CODE lang="kusto"&gt;// Detection 2: classic-agent service principal signing in from a previously unseen IP
// MITRE T1078.004 - Valid Accounts: Cloud Accounts
let baseline  = 14d;
let detection = 1d;
let KnownIPs =
    AADServicePrincipalSignInLogs
    | where TimeGenerated between (ago(baseline + detection) .. ago(detection))
    | where tostring(ResultType) == "0"
    | summarize KnownIPSet = make_set(IPAddress) by AppId;
AADServicePrincipalSignInLogs
| where TimeGenerated &amp;gt; ago(detection)
| where tostring(ResultType) == "0"
| lookup kind=leftouter KnownIPs on AppId
| where set_has_element(KnownIPSet, IPAddress) == false
| summarize FirstSeen = min(TimeGenerated),
            Resources = make_set(ResourceDisplayName, 10)
  by ServicePrincipalName, AppId, IPAddress
| order by FirstSeen desc&lt;/LI-CODE&gt;&lt;P&gt;The query builds a per-application baseline of source IPs over the previous two weeks, then flags any successful sign-in today from an address outside that set. Two tuning notes. Brand-new service principals have no baseline, so they surface on first use. That is usually worth seeing once, but you can exclude AppIds younger than the baseline window if it gets noisy. And if your agents egress through shifting cloud IP ranges, widen the comparison from an exact IP to the autonomous system number or a known-range allow-list, otherwise you will chase your own infrastructure.&lt;/P&gt;&lt;P&gt;This complements Agent ID, it does not replace it!&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The endgame is not to run these rules forever. It is to shrink the population they apply to.&lt;/STRONG&gt; Inventory your tenant for agents marked "Has Agent ID: No," prioritize the ones holding sensitive Graph permissions, and migrate them onto the Agent ID platform, where Identity Protection and Conditional Access take over the baselining you are doing here by hand. Microsoft has signaled a migration path from classic to modern agents. Treat these two detections as the coverage you need in the meantime, and as a permanent safety net for anything that never makes the move.&lt;/P&gt;&lt;P&gt;If you do one thing this week: enable the service principal sign-in log category, deploy detection 1, and pull a list of every service principal that had a credential added in the last 90 days. That list alone tends to be more interesting than people expect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers, Marcel&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2026 13:57:23 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-sentinel/detecting-ai-agents-and-non-human-identities-in-microsoft/m-p/4526787#M12940</guid>
      <dc:creator>Marcel_Graewer</dc:creator>
      <dc:date>2026-06-09T13:57:23Z</dc:date>
    </item>
    <item>
      <title>Ways to fetch quarantine files</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/ways-to-fetch-quarantine-files/m-p/4526637#M6884</link>
      <description>&lt;P&gt;We are working with quarantine files and have a few questions:&lt;/P&gt;&lt;P&gt;1. Is there a public API available to retrieve quarantined files from Microsoft Defender for Endpoint?&lt;/P&gt;&lt;P&gt;2. Is there a documented method to map an alert or a file SHA-1/SHA-256 hash to the corresponding object in the Defender quarantine store?&lt;/P&gt;&lt;P&gt;3. Is there a way to retrieve quarantined files other than using a PowerShell script through the Live Response API?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2026 05:36:57 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/ways-to-fetch-quarantine-files/m-p/4526637#M6884</guid>
      <dc:creator>Dhwani_Shah</dc:creator>
      <dc:date>2026-06-09T05:36:57Z</dc:date>
    </item>
    <item>
      <title>Tools for Azure AD B2C migration now available</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/tools-for-azure-ad-b2c-migration-now-available/ba-p/4525678</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you rely on Azure AD B2C for customer identity, you’re likely starting to evaluate what comes next. With &lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/what%E2%80%99s-new-in-microsoft-entra-%E2%80%93-march-2025/4352581" target="_blank" rel="noopener"&gt;Azure AD B2C no longer receiving new features&lt;/A&gt; and several features recently added to Microsoft Entra External ID, planning your migration is easier and can help you with this important next step in your identity strategy.&lt;/P&gt;
&lt;P&gt;Below you’ll find tooling, guidance, and a partner ecosystem resource to help you migrate with confidence. This post walks through what’s available and how to get started.&lt;/P&gt;
&lt;H2&gt;What’s new: Platform updates and migration tooling&lt;/H2&gt;
&lt;P&gt;Microsoft has invested significantly in Microsoft Entra External ID to help Azure AD B2C customers migrate with confidence and ease. Over the past three months, several new features have reached general availability.&lt;/P&gt;
&lt;P&gt;Azure AD B2C Migration tooling:&amp;nbsp;Just-in-Time (JIT) migration, High-Scale Compatibility (HSC) mode, and the published Migration Guidance document and architecture blueprint.&lt;/P&gt;
&lt;P&gt;Native authentication GA features in Entra External ID: Email and SMS one-time passcode (OTP) MFA, social identity providers via browser-delegated (web-view) flows, single sign-on (SSO) from native apps to web views, and refresh token transfer to Apple Watch.&lt;/P&gt;
&lt;P&gt;Web and federated in Entra External ID: Sign-in and sign-up with alias, Microsoft Entra ID federation with External ID (public preview), and self-service password reset (SSPR) with phone SMS OTP.&lt;/P&gt;
&lt;P&gt;For a complete list of recent platform updates, see the &lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/what%E2%80%99s-new-in-microsoft-entra-%E2%80%93-march-2026/4502150" target="_blank" rel="noopener"&gt;What’s new in Microsoft Entra&lt;/A&gt; blog.&lt;/P&gt;
&lt;H2&gt;Where Azure AD B2C stands today&lt;/H2&gt;
&lt;P&gt;Azure AD B2C has reached a significant milestone in its lifecycle. It has served as a reliable foundation for customer identity, and that doesn’t change for existing customers. What has changed is where Microsoft is investing going forward. Two facts define what that means for existing customers:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;May 2025 — End of sale:&amp;nbsp;&lt;/STRONG&gt;New Azure AD B2C tenants can no longer be&amp;nbsp;purchased. Existing tenants&amp;nbsp;remain&amp;nbsp;supported.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;No new features:&amp;nbsp;&lt;/STRONG&gt;All platform innovation is now exclusive to Microsoft Entra External ID. Azure AD B2C will not receive new capabilities going forward.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Your existing Azure AD B2C environment continues to function. Starting your migration early helps you stay in control of sequencing, validation, and user experience. For questions about planning,&amp;nbsp;&lt;A href="mailto:aadb2cmigrationsupport@microsoft.com" target="_blank" rel="noopener"&gt;contact support&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;What is Microsoft Entra External ID?&lt;/H2&gt;
&lt;P&gt;Microsoft Entra External ID is a purpose-built, next-generation customer identity platform. It is not a rebrand of Azure AD B2C. It is a new foundation designed to simplify implementation, improve extensibility, and align with the broader Microsoft Entra ecosystem. Key platform improvements include the following.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Modern extensibility model — &lt;/STRONG&gt;Custom authentication extensions replace complex custom policy XML, helping reduce&amp;nbsp;&amp;nbsp; implementation complexity.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Entra ecosystem integration — &lt;/STRONG&gt;Full alignment with Microsoft Entra ID, Conditional Access, Identity Governance, and Microsoft’s broader security stack.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Continuous platform innovation —&amp;nbsp;&lt;/STRONG&gt;Native Authentication SDKs, advanced branding controls, fraud protection, and&amp;nbsp;passwordless-first flows are built exclusively into External ID.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Improved observability — &lt;/STRONG&gt;Enhanced monitoring, diagnostics, and audit capabilities for identity and security teams.&lt;/P&gt;
&lt;H2&gt;&lt;BR /&gt;Migration tooling&lt;/H2&gt;
&lt;P&gt;Two primary migration paths are available, and both are now generally available.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Just-in-Time (JIT) Migration&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;High-Scale Compatibility (HSC) Mode&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Status&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Generally available&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Generally available&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Best for&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Most customers seeking a clean cutover with minimal user disruption&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;High-scale environments (5M+ users) or complex architectural constraints&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;How it works&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Migrates users progressively as they sign in — no bulk&amp;nbsp;password reset&amp;nbsp;required&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Moves application traffic to External ID first&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Key benefit&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Full External ID feature parity from day one with minimal user impact&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Supports parallel operation of B2C and External ID during transition, reducing cutover risk&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Documentation&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;A href="https://review.learn.microsoft.com/en-us/entra/external-id/customers/how-to-migrate-passwords-just-in-time?branch=main" target="_blank" rel="noopener"&gt;JIT Migration Documentation&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;A href="https://review.learn.microsoft.com/en-us/entra/external-id/customers/enable-external-id-high-scale-compatibility-mode?branch=main" target="_blank" rel="noopener"&gt;HSC Mode Documentation&amp;nbsp;&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Choosing between JIT and HSC is less about technical capability and more about migration priorities. JIT prioritizes user experience and simplicity, while HSC prioritizes scale and operational continuity.&lt;/P&gt;
&lt;P&gt;Alongside these tools, Microsoft has published a comprehensive &lt;A href="https://review.learn.microsoft.com/en-us/entra/external-id/customers/plan-your-migration-from-b2c-to-external-id?branch=main&amp;amp;branchFallbackFrom=pr-en-us-11930" target="_blank" rel="noopener"&gt;migration guide&lt;/A&gt; and architecture blueprint covering end-to-end migration scenarios, credential migration approaches, and application sequencing guidance.&lt;/P&gt;
&lt;H2&gt;Partner ecosystem&lt;/H2&gt;
&lt;P&gt;For organizations with complex environments, migration is not just a technical exercise. It involves coordinating identity flows, applications, and user experiences across systems.&lt;/P&gt;
&lt;P&gt;Microsoft has established a global ecosystem of qualified migration partners across EMEA, the Americas, LATAM, ANZ, and the Middle East.&lt;/P&gt;
&lt;P&gt;Partner support includes:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Mapping custom policies to External ID equivalents&lt;/LI&gt;
&lt;LI&gt;Designing credential migration strategies&lt;/LI&gt;
&lt;LI&gt;Sequencing application cutovers&lt;/LI&gt;
&lt;LI&gt;Running staged validation and testing&lt;/LI&gt;
&lt;LI&gt;Supporting production deployment&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Qualified partners meet criteria such as proven Azure AD B2C experience, active engagement with External ID, and participation in Microsoft migration readiness programs.&lt;/P&gt;
&lt;P&gt;Examples include EY, Avanade, Edgile, Slalom, Plan B, WhoIAM, and Grit.&lt;/P&gt;
&lt;P&gt;You can explore the full partner directory in the &lt;A href="https://learn.microsoft.com/en-us/entra/external-id/customers/services-integration-partners" target="_blank" rel="noopener"&gt;Migration partner directory&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;Next steps: How to get started&lt;/H2&gt;
&lt;P&gt;The organizations that navigate migration most successfully are the ones that start planning early. Beginning now gives you greater control over sequencing, application transitions, and user experience changes before they become urgent. Migration challenges rarely come from the tooling itself; they come from coordination across systems, teams, and timelines.&lt;/P&gt;
&lt;P&gt;A structured approach can help accelerate progress:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt; Assess&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;UL&gt;
&lt;LI&gt;Inventory Applications, user populations, and custom policies&lt;/LI&gt;
&lt;LI&gt;Understand dependencies and integrations&lt;/LI&gt;
&lt;LI&gt;Inventory applications, user populations, and custom policies&lt;/LI&gt;
&lt;LI&gt;Understand dependencies and integrations&lt;/LI&gt;
&lt;/UL&gt;
&lt;OL start="2"&gt;
&lt;LI&gt;&lt;STRONG&gt; Decide&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;UL&gt;
&lt;LI&gt;Review migration guidance&lt;/LI&gt;
&lt;LI&gt;Choose between JIT and HSC based on your priorities&lt;/LI&gt;
&lt;/UL&gt;
&lt;OL start="3"&gt;
&lt;LI&gt;&lt;STRONG&gt; Execute&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;UL&gt;
&lt;LI&gt;Run a proof of concept in a non-production environment&lt;/LI&gt;
&lt;LI&gt;Validate identity flows and user experience&lt;/LI&gt;
&lt;LI&gt;Engage a &lt;A href="https://learn.microsoft.com/en-us/entra/external-id/customers/services-integration-partners" target="_blank" rel="noopener"&gt;qualified partner&lt;/A&gt; if needed&lt;/LI&gt;
&lt;LI&gt;Align with your Microsoft account team&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Migrating from Azure AD B2C to Microsoft Entra External ID is an opportunity to modernize your customer identity platform while reducing operational complexity. With the right planning, tooling, and support available today, you can move forward with confidence while maintaining a seamless experience for your users.&lt;/P&gt;
&lt;P&gt;For additional support, &lt;A href="mailto:aadb2cmigrationsupport@microsoft.com" target="_blank" rel="noopener"&gt;contact support&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;-Namita Singh - Senior Product Manager, Microsoft Entra External ID&lt;/P&gt;
&lt;P&gt;-Pawan Nrisimha - Principal Manager of Product, Microsoft Entra External ID&lt;/P&gt;
&lt;P&gt;-Isaac Christian - Product Marketing Manager, Microsoft Entra&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/external-id/external-identities-overview" target="_blank" rel="noopener"&gt;Microsoft Entra External ID – Platform Overview&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://review.learn.microsoft.com/en-us/entra/external-id/customers/plan-your-migration-from-b2c-to-external-id?branch=main&amp;amp;branchFallbackFrom=pr-en-us-11930" target="_blank" rel="noopener"&gt;Azure AD B2C Migration Guide &amp;amp; Architecture Blueprint&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://review.learn.microsoft.com/en-us/entra/external-id/customers/how-to-migrate-passwords-just-in-time?branch=main" target="_blank" rel="noopener"&gt;Just-in-Time Migration Documentation&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://review.learn.microsoft.com/en-us/entra/external-id/customers/enable-external-id-high-scale-compatibility-mode?branch=main" target="_blank" rel="noopener"&gt;High-Scale Compatibility (HSC) Mode Documentation&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/external-id/customers/services-integration-partners" target="_blank" rel="noopener"&gt;Qualified Migration Partner Directory&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 08 Jun 2026 20:38:36 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/tools-for-azure-ad-b2c-migration-now-available/ba-p/4525678</guid>
      <dc:creator>NamitaSingh</dc:creator>
      <dc:date>2026-06-08T20:38:36Z</dc:date>
    </item>
    <item>
      <title>Microsoft Entra ID security updates: What organizations need to do now</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/microsoft-entra-id-security-updates-what-organizations-need-to/ba-p/4522024</link>
      <description>&lt;P&gt;Microsoft Entra ID continues to strengthen identity security by modernizing how authentication and access policies are enforced. As part of this effort, Microsoft is retiring legacy capabilities and closing gaps that attackers could exploit. These updates focus on three key areas: replacing Custom controls with External MFA, enforcing Conditional Access consistently during credential registration, and requiring explicitly registered authentication methods for self-service password reset (SSPR). Together, these changes help ensure that your security policies are applied uniformly and backed by strong, user-verified signals.&lt;/P&gt;
&lt;H2&gt;Key points&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;Custom controls are being deprecated in favor of External MFA. Existing configurations keep working during the transition, but you should begin migration planning now. Custom controls retire September 30, 2026, and reach end of life in May 2027.&lt;/LI&gt;
&lt;LI&gt;Conditional Access will be enforced consistently during credential registration. Starting July 6, 2026, policies targeting the Register security information action will also apply to Windows Hello for Business provisioning and macOS Platform Single Sign-on registration. Test policies in report-only mode before then.&lt;/LI&gt;
&lt;LI&gt;SSPR will require explicitly registered authentication methods. A registration campaign begins July 6, 2026, and from September 7, 2026, SSPR will accept only registered methods — directory-sourced phone numbers and email addresses that were never formally registered will no longer be accepted.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Deprecation of Custom controls&lt;/H2&gt;
&lt;H3&gt;&lt;U&gt;What’s changing?&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;Microsoft Entra ID is deprecating Custom controls in favor of &lt;A href="https://learn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-external-method-provider" target="_blank" rel="noopener"&gt;External MFA&lt;/A&gt;, a more integrated, standards-based capability for incorporating third-party MFA providers directly into Conditional Access. External MFA delivers deeper policy integration, a more seamless user experience, and greater flexibility than the legacy Custom controls model. While existing Custom controls configurations will continue to function during the transition period, organizations should begin planning their migration to External MFA.&lt;/P&gt;
&lt;H3&gt;&lt;U&gt;When will you see this change?&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;Custom controls will be retired on September 30, 2026, and the service will reach end of life in May 2027.&lt;/P&gt;
&lt;H3&gt;&lt;U&gt;Who will be affected by this change?&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;This update affects organizations currently using Custom controls to integrate third-party MFA providers with Conditional Access.&lt;/P&gt;
&lt;H3&gt;&lt;U&gt;How will this affect your organization?&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;Organizations relying on Custom controls will need to transition to External MFA to maintain support and continue using third-party MFA solutions within Microsoft Entra ID. Moving to External MFA also enables more consistent Conditional Access enforcement and improved integration with Microsoft Entra security capabilities.&lt;/P&gt;
&lt;H3&gt;&lt;U&gt;What do you need to do to prepare?&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;Organizations should:&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Review existing Custom controls integrations&lt;/LI&gt;
&lt;LI&gt;Evaluate External MFA migration requirements&lt;/LI&gt;
&lt;LI&gt;Test Conditional Access policies and user experiences before migration&lt;/LI&gt;
&lt;LI&gt;Begin migration planning ahead of the retirement date&lt;/LI&gt;
&lt;LI&gt;Read more in the &lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/external-mfa-in-microsoft-entra-id-is-now-generally-available/4488926" target="_blank" rel="noopener"&gt;External MFA General Availability&lt;/A&gt; announcement and &lt;A href="https://learn.microsoft.com/en-us/entra/identity/conditional-access/how-to-migrate-custom-controls-external-mfa?tabs=microsoft-entra-admin-center" target="_blank" rel="noopener"&gt;migration guidance.&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Consistent Conditional Access enforcement for credential registration&lt;/H2&gt;
&lt;H3&gt;&lt;U&gt;What’s changing?&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;Microsoft is strengthening Conditional Access enforcement during credential registration flows to close a long-standing enforcement gap.&lt;/P&gt;
&lt;P&gt;Today, policies targeting the &lt;STRONG&gt;Register security information&lt;/STRONG&gt; user action are enforced in My Security Info and Microsoft Authenticator, but not during Windows Hello for Business provisioning or macOS Platform Single Sign-on registration. Conditional Access policies will be enforced consistently across these registration experiences. If users do not meet policy requirements, they will be prompted to satisfy those requirements before completing registration. MFA will continue to be required by default for passwordless credential enrollment, with Conditional Access providing an additional layer of control.&lt;/P&gt;
&lt;H3&gt;&lt;U&gt;When will you see this change?&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;This update will roll out during the week of &lt;STRONG&gt;July 6, 2026 &lt;/STRONG&gt;to all tenants.&lt;/P&gt;
&lt;H3&gt;&lt;U&gt;Who will be affected by this change?&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;This change affects organizations using:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Conditional Access policies scoped to registration flows&lt;/LI&gt;
&lt;LI&gt;Windows Hello for Business&lt;/LI&gt;
&lt;LI&gt;macOS Platform Single Sign-on&lt;/LI&gt;
&lt;LI&gt;Passwordless credential enrollment scenarios&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;&lt;U&gt;How will this affect your organization?&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;Organizations may see additional prompts or enforcement steps during device setup and credential registration if users do not meet Conditional Access requirements. This change ensures registration flows are governed by the same security controls already applied across other authentication experiences.&lt;/P&gt;
&lt;H3&gt;&lt;U&gt;What do you need to do to prepare?&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;Organizations should review existing registration policies and validate that users can meet Conditional Access requirements during onboarding and device setup. Microsoft recommends testing policies in report-only mode before enforcement begins.&lt;/P&gt;
&lt;H2&gt;SSPR update: Registered authentication methods required&lt;/H2&gt;
&lt;H3&gt;&lt;U&gt;What’s changing?&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;Microsoft is updating Microsoft Entra self-service password reset (SSPR) so that only explicitly registered authentication methods can be used for verification. Directory-sourced phone numbers or email addresses stored only as user object properties—but never formally registered as authentication methods—will no longer be accepted. This change aligns SSPR with Entra ID’s broader authentication model by requiring verification methods tied to user intent and proof of possession.&lt;/P&gt;
&lt;H3&gt;&lt;U&gt;When will you see this change?&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;Beginning &lt;STRONG&gt;July 6, 2026&lt;/STRONG&gt;, Microsoft will deploy an &lt;STRONG&gt;SSPR registration campaign&lt;/STRONG&gt; that prompts affected administrators and end users to register authentication methods ahead of enforcement. No administrator action is required to enable this campaign.&lt;/P&gt;
&lt;P&gt;Starting &lt;STRONG&gt;September 7, 2026&lt;/STRONG&gt;, SSPR will accept &lt;STRONG&gt;only authentication methods that users or administrators have explicitly registered&lt;/STRONG&gt;.&lt;/P&gt;
&lt;H3&gt;&lt;U&gt;Who will be affected by this change?&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;This update affects organizations and users that still rely on unregistered directory-based phone numbers or email addresses for password reset verification.&lt;/P&gt;
&lt;H3&gt;&lt;U&gt;How will this affect your organization?&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;Users without registered authentication methods may experience interruptions during password reset or account recovery flows after enforcement begins. Organizations may also see an increase in registration prompts during the transition period.&lt;/P&gt;
&lt;H3&gt;&lt;U&gt;What do you need to do to prepare?&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;Organizations should:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Review &lt;A href="https://entra.microsoft.com/" target="_blank" rel="noopener"&gt;authentication method registration coverage&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Identify users relying on unregistered directory values&lt;/LI&gt;
&lt;LI&gt;Encourage users to register approved authentication methods&lt;/LI&gt;
&lt;LI&gt;Communicate upcoming changes to users and help desk teams&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Microsoft will prompt affected users and administrators during the transition period to help organizations prepare before enforcement begins.&lt;/P&gt;
&lt;P&gt;Now is the time to review your current configurations, identify where these changes apply in your environment, and begin preparing your users and admins before enforcement milestones arrive. Start by assessing any Custom controls dependencies, validating registration-related Conditional Access policies, and confirming that authentication methods used for SSPR are explicitly registered.&lt;/P&gt;
&lt;P&gt;- &lt;A class="lia-external-url" href="https://www.linkedin.com/in/swaroopk" target="_blank" rel="noopener"&gt;Swaroop Krishnamurthy, Principal Product Manager&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/external-mfa-in-microsoft-entra-id-is-now-generally-available/4488926" target="_blank" rel="noopener"&gt;External MFA in Microsoft Entra ID (general availability announcement)&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/entra/identity/conditional-access/" target="_blank" rel="noopener"&gt;Conditional Access in Microsoft Entra ID&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/entra/identity/authentication/" target="_blank" rel="noopener"&gt;Authentication methods in Microsoft Entra ID&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/entra/identity/authentication/concept-sspr-howitworks" target="_blank" rel="noopener"&gt;Microsoft Entra self-service password reset (SSPR)&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/mysecurityinfo" target="_blank" rel="noopener"&gt;Register security information (My Security Info)&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 08 Jun 2026 18:47:46 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/microsoft-entra-id-security-updates-what-organizations-need-to/ba-p/4522024</guid>
      <dc:creator>Swaroop Krishnamurthy</dc:creator>
      <dc:date>2026-06-08T18:47:46Z</dc:date>
    </item>
    <item>
      <title>Microsoft Defender now monitors RPC activity</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/microsoft-defender-now-monitors-rpc-activity/ba-p/4523368</link>
      <description>&lt;P&gt;Remote procedure call (RPC) is a protocol commonly abused by attackers that allows functions implemented in a separate process, and potentially on a remote machine, to be called as if they were local. Many core Windows and Active Directory capabilities are built on or make use of RPC, which makes it an attractive target. To help protect against remote RPC-based attacks, Microsoft Defender now monitors remote RPC calls, disrupts malicious activity that leverages them, and surfaces relevant telemetry in advanced hunting.&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;RPC basics&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;While &lt;A href="https://learn.microsoft.com/en-us/windows/win32/rpc/rpc-start-page" target="_blank" rel="noopener"&gt;RPC is a rich and complicated protocol&lt;/A&gt;, the main components that are relevant for security monitoring purposes are:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;U&gt;Interface&lt;/U&gt;: A logical grouping of functionality exposed by an RPC server. Interfaces are identified by UUID. Example interfaces include Task Scheduler, Remote Registry, and the Service Control Manager, each exposing functionality related to a different Windows OS component.&lt;/LI&gt;
&lt;LI&gt;&lt;U&gt;OpNum&lt;/U&gt;: Stands for Operation Number, an ordinal that denotes a specific function exposed by an RPC interface. Examples include RCreateServiceW (OpNum 12, Service Control Manager interface) and BaseRegQueryValue (OpNum 17, Remote Registry interface).&lt;/LI&gt;
&lt;/OL&gt;
&lt;H5&gt;&lt;STRONG&gt;Many remote attack techniques and tactics are based on RPC, for example:&lt;/STRONG&gt;&lt;/H5&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;U&gt;Lateral movement&lt;/U&gt;: often abuses RPC functionality for remotely creating tasks, services or invoking WMI.&lt;/LI&gt;
&lt;LI&gt;&lt;U&gt;Credential theft&lt;/U&gt;: DCsync attacks, which abuse privileged compromised accounts to remotely extract credential material from Active Directory, are based on RPC functionality for directory replication. SecretsDump and similar attacks, which remotely extract SAM or LSA secrets, are based on querying a device’s registry remotely, using RPC.&lt;/LI&gt;
&lt;LI&gt;&lt;U&gt;Privilege escalation&lt;/U&gt;: Multiple authentication coercion attacks abuse benign RPC interfaces to coerce servers to authenticate an attacker.&lt;/LI&gt;
&lt;LI&gt;&lt;U&gt;Discovery&lt;/U&gt;: Tools such as SharpHound leverage RPC calls to enumerate users, sessions and shares.&lt;/LI&gt;
&lt;/OL&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;For a more comprehensive mapping of RPC interfaces to attack techniques, see&amp;nbsp;&lt;A href="https://github.com/jonny-jhnson/MSRPC-to-ATTACK" target="_blank" rel="noopener"&gt;work&lt;/A&gt; by Jonathan Johnson.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H5&gt;&lt;STRONG&gt;RPC auditing in Defender&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;Since RPC is so heavily used on Windows systems and in Active Directory domains, monitoring remote RPC traffic using network monitors is often expensive and infeasible. Additionally, if the underlying transport protocol is encrypted (such as SMB3), it might be impossible to observe RPC traffic.&lt;/P&gt;
&lt;P&gt;To enable efficient auditing of remote RPC activity regardless of transport-layer protection, Defender research and engineering expanded the existing RPC integration with the Windows Filtering Platform (WFP) to support OpNum-level granularity. This makes it possible to identify and audit the specific RPC function being invoked, rather than only the RPC interface.&lt;/P&gt;
&lt;P&gt;This capability is designed to help detect remote RPC-based attack techniques, where an attacker interacts with RPC interfaces exposed by a target device. For that reason, Defender focuses this monitoring on inbound remote RPC calls observed on the RPC server host. The telemetry is collected using audit-only WFP filters, which do not interfere with normal traffic, while still providing visibility into suspicious remote activity targeting the device. This approach does not require visibility into the source device.&lt;/P&gt;
&lt;P&gt;Local RPC calls, such as inter-process communication on the same device over local transport, and outbound RPC client calls are outside the scope of this monitoring mechanism.&lt;/P&gt;
&lt;P&gt;Using this capability, Defender monitors selected RPC calls, leverages the resulting telemetry to detect malicious activity, and exposes monitored calls in advanced hunting. Defender dynamically monitors selected remote operations from interfaces including, but not limited to: Remote Registry, Service Control Manager, Task Scheduler, and Windows Management Instrumentation (WMI). RPC monitoring for workstations is generally available, while server monitoring is currently in gradual rollout.&lt;/P&gt;
&lt;P&gt;RPC-based detections and disruption triggers are already available in Defender and include detections such as:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Ongoing hands-on-keyboard attack via Impacket toolkit&lt;/LI&gt;
&lt;LI&gt;Suspicious service creation initiated remotely&lt;/LI&gt;
&lt;LI&gt;Indication of local security authority secrets theft&lt;/LI&gt;
&lt;LI&gt;Unusual RPC user and session discovery&lt;/LI&gt;
&lt;LI&gt;Authentication coercion attack&lt;/LI&gt;
&lt;/OL&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;H5&gt;&lt;STRONG&gt;Example Advanced Hunting queries&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;1. Remote registry key save events, abused for remote credential dumping.&lt;/P&gt;
&lt;LI-CODE lang=""&gt;let remoteRegistryInterface = '338cd001-2244-31f1-aaaa-900038001003'; 
let registrySaveOpnums = dynamic([20, 31]); // BaseRegSaveKey, BaseRegSaveKeyEx 
DeviceEvents 
| where ActionType == 'InboundRemoteRpcCall' 
| extend AdditionalFields = parse_json(AdditionalFields) 
| extend RpcInterface = tostring(AdditionalFields.RpcInterfaceUuid), OpNum = toint(AdditionalFields.RpcOpNum) 
| where RpcInterface == remoteRegistryInterface and OpNum in(registrySaveOpnums) &lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Remote Service Creation events, could indicate lateral movement:&lt;/P&gt;
&lt;LI-CODE lang=""&gt;let remoteServicesInterface = '367abb81-9844-35f1-ad32-98f038001003'; 
let serviceCreationOpnums = dynamic([12, 24, 44, 45, 60]); // RCreateServiceW, RCreateServiceA, RCreateServiceWOW64A, RCreateServiceWOW64W, RCreateWowService 
DeviceEvents 
| where ActionType == 'InboundRemoteRpcCall' 
| extend AdditionalFields = parse_json(AdditionalFields) 
| extend RpcInterface = tostring(AdditionalFields.RpcInterfaceUuid), OpNum = toint(AdditionalFields.RpcOpNum) 
| where RpcInterface == remoteServicesInterface and OpNum in(serviceCreationOpnums) &lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. Session discovery events, could indicate account discovery:&lt;/P&gt;
&lt;LI-CODE lang=""&gt;let srvsvcInterface = '4b324fc8-1670-01d3-1278-5a47bf6ee188'; 
let netrSessionEnumOpnum = 12; 
DeviceEvents 
| where ActionType == 'InboundRemoteRpcCall' 
| extend AdditionalFields = parse_json(AdditionalFields) 
| extend RpcInterface = tostring(AdditionalFields.RpcInterfaceUuid), OpNum = toint(AdditionalFields.RpcOpNum) 
| where RpcInterface == srvsvcInterface and OpNum == netrSessionEnumOpnum 
| summarize dcount(DeviceId) by AccountName, AccountDomain, AccountSid &lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check out the advanced hunting tab to see monitored RPC activity in your environment and stay tuned for more updates from Defender.&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;Learn more&lt;/STRONG&gt;&lt;/H5&gt;
&lt;UL&gt;
&lt;LI&gt;To learn more about endpoint protection with Microsoft Defender, check out our&amp;nbsp;&lt;A href="https://www.microsoft.com/security/business/endpoint-security/microsoft-defender-endpoint" target="_blank" rel="noopener"&gt;website&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;To learn more about Microsoft Security solutions, visit our &lt;A href="https://www.microsoft.com/en-us/security/business" target="_blank" rel="noopener"&gt;website.&lt;/A&gt; Bookmark the &lt;A href="https://www.microsoft.com/security/blog/" target="_blank" rel="noopener"&gt;Security blog&lt;/A&gt; to keep up with our expert coverage on security matters. Follow us on LinkedIn (&lt;A href="https://www.linkedin.com/showcase/microsoft-security/" target="_blank" rel="noopener"&gt;Microsoft Security&lt;/A&gt;) and X (&lt;A href="https://twitter.com/@MSFTSecurity" target="_blank" rel="noopener"&gt;@MSFTSecurity&lt;/A&gt;) for the latest news and updates on cybersecurity.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 09 Jun 2026 16:55:28 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/microsoft-defender-now-monitors-rpc-activity/ba-p/4523368</guid>
      <dc:creator>EdanZwick</dc:creator>
      <dc:date>2026-06-09T16:55:28Z</dc:date>
    </item>
    <item>
      <title>Security Review for Microsoft Edge version 149</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-baselines/security-review-for-microsoft-edge-version-149/ba-p/4526371</link>
      <description>&lt;P&gt;We have reviewed the new settings in Microsoft Edge version 149 and determined that there are no additional security settings that require enforcement. The Microsoft Edge version 139 security baseline continues to be our recommended configuration which can be downloaded from the &lt;A href="https://www.microsoft.com/download/details.aspx?id=55319" target="_blank" rel="noopener"&gt;Microsoft Security Compliance Toolkit&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Microsoft Edge version 149 introduced 7 new Computer and User settings; we have included a spreadsheet listing the new settings to make it easier for you to find.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As a friendly reminder, all available settings for Microsoft Edge are documented&amp;nbsp;&lt;A href="https://docs.microsoft.com/en-us/DeployEdge/microsoft-edge-policies" target="_blank" rel="noopener"&gt;here&lt;/A&gt;, and all available settings for Microsoft Edge Update are documented&amp;nbsp;&lt;A href="https://docs.microsoft.com/en-us/DeployEdge/microsoft-edge-update-policies" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please continue to give us feedback through the&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/t5/Microsoft-Security-Baselines/bd-p/Security-Baselines" target="_blank" rel="noopener"&gt;Security Baselines Discussion site&lt;/A&gt; or this post.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2026 11:32:08 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-baselines/security-review-for-microsoft-edge-version-149/ba-p/4526371</guid>
      <dc:creator>Rick_Munck</dc:creator>
      <dc:date>2026-06-08T11:32:08Z</dc:date>
    </item>
    <item>
      <title>The Worm in the Supply Chain: How Defender for Endpoint and Sentinel for SAP BTP Caught Shai-Hulud</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/the-worm-in-the-supply-chain-how-defender-for-endpoint-and/ba-p/4526246</link>
      <description>&lt;P&gt;On &lt;STRONG&gt;29 April 2026&lt;/STRONG&gt;, malicious versions of multiple SAP ecosystem npm packages were briefly published, creating a supply-chain exposure for SAP Cloud Application Programming (CAP) development environments and CI/CD pipelines.&lt;/P&gt;
&lt;P&gt;For a brief window that morning, affected developers have executed a credential-stealing payload on a workstation or, in higher-impact cases, within a CI/CD pipeline.&lt;/P&gt;
&lt;P&gt;SAP developers don't usually think of themselves as a juicy npm target. CAP, BTP, Fiori - that's enterprise turf, not crypto-stealer type territory – Until it is. Join me for the ride.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;See our &lt;/EM&gt;&lt;A href="https://demos.microsoft.com/Microsoft/play/6373" target="_blank" rel="noopener"&gt;&lt;EM&gt;latest click-video&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt; for an even more dynamic experience of SAP compromises.&lt;/EM&gt;&lt;/P&gt;
&lt;H1&gt;Affected packages and scope&lt;/H1&gt;
&lt;P&gt;Four official npm packages from the SAP development ecosystem were published in malicious versions that day. Security researchers are calling the campaign "Mini Shai-Hulud" - the little cousin of the worm family that has been chewing its way through open-source registries for months. So, the "mini" part is a generous description in my opinion.&lt;/P&gt;
&lt;P&gt;Shai-Hulud has wriggled directly into the SAP supply chain, and that detail alone deserves a pause... &lt;STRONG&gt;SAP CAP&lt;/STRONG&gt; is now interesting enough to &lt;STRONG&gt;have become a target&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;Four packages, all wearing legitimate SAP branding, all quietly swapped for evil twins:&lt;/P&gt;
&lt;LI-CODE lang=""&gt;@cap-js/sqlite v2.2.2
@cap-js/postgres v2.2.2
@cap-js/db-service v2.10.1 
mbt v1.2.48&lt;/LI-CODE&gt;
&lt;P&gt;These packages are not peripheral dependencies. The @cap-js/* modules are part of the SAP CAP Model used across custom development on SAP BTP, while mbt is the Cloud MTA Build Tool commonly embedded in CI/CD workflows that package and deploy Multi-Target Applications to BTP and on-premises environments. At roughly &lt;A href="https://labs.cloudsecurityalliance.org/research/csa-research-note-mini-shai-hulud-multi-ecosystem-supply-cha/" target="_blank" rel="noopener"&gt;930,000 weekly downloads&lt;/A&gt;, the combined exposure created meaningful downstream attack surface.&lt;/P&gt;
&lt;P&gt;The good news: SAP spotted the compromise fast, yanked the bad versions, and shipped clean replacements. The official guidance lives in SAP Security Note &lt;A href="https://me.sap.com/notes/3747787" target="_blank" rel="noopener"&gt;3747787&lt;/A&gt; - which carries the list of indicators of compromise, file hashes, and mitigation steps.&lt;/P&gt;
&lt;P&gt;Enough theory and evidence talk! Now, SHOW ME the detection!&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;EM&gt;When the worm stirs beneath the sand, weak defenses vanish first.&lt;/EM&gt;&lt;/P&gt;
&lt;H1&gt;Observed telemetry in Microsoft Security products&lt;/H1&gt;
&lt;P&gt;See below excerpt of Microsoft Defender for Endpoint from a compromised developer machine. The worm was neutralized immediately. Check the detection time (same day of release):&lt;/P&gt;
&lt;LI-CODE lang=""&gt;Windows Defender AV detected malware
ToString: DefenderDetection: File: /Users/User***/Projects/dara-api-manager-ui/node_modules/mbt/File***.js, Sha256: *** [Trojan:JS/SPchnStlr.BB],

BlockingStatus: Prevented, BlockingStatusPriority: 900 DetectionTime: 2026-04-29 11:52:11Z DetectorName: 

Microsoft.Cyber.ObservationDetectors.DefenderConcreteDetector Observations (2): DefenderObservation
Description: Defender detected and quarantined 'Trojan:JS/SPchnStlr.BB' in file 'File***.js' ThreatCategory = Trojan, ThreatFamily = SPchnStlr,&lt;/LI-CODE&gt;
&lt;H1&gt;How the Threat Actors Operationalized the Stolen Data&lt;/H1&gt;
&lt;P&gt;The compromise allowed harvesting GitHub tokens, AWS/Azure/GCP secrets, npm credentials, Kubernetes config, SSH keys,&amp;nbsp;&lt;EM&gt;.npmrc&lt;/EM&gt;&amp;nbsp;and .&lt;EM&gt;git-credentials files&lt;/EM&gt;, and CI/CD environment variables.&lt;/P&gt;
&lt;P&gt;The hackers&amp;nbsp;created a public GitHub repository&amp;nbsp;&lt;STRONG&gt;on the victim’s own account&lt;/STRONG&gt;, tagged with the description&amp;nbsp;&lt;EM&gt;“A Mini Shai-Hulud has Appeared“ &lt;/EM&gt;to&lt;EM&gt; &lt;/EM&gt;exfiltrate their reaping.&amp;nbsp;Within hours, more than a thousand such repositories were visible in &lt;A href="https://github.com/search?q=%22A+Mini+Shai-Hulud+has+Appeared%22&amp;amp;type=repositories" target="_blank" rel="noopener"&gt;public GitHub search&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-clear-both"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For additional views on the topic check out the blogs of our Sentinel for SAP &lt;A href="https://learn.microsoft.com/en-us/azure/sentinel/sap/solution-partner-overview" target="_blank" rel="noopener"&gt;partners&lt;/A&gt;: &lt;A href="https://onapsis.com/blog/sap-cap-mini-shai-hulud-supply-chain-attack/" target="_blank" rel="noopener"&gt;Onapsis&lt;/A&gt;, &lt;A href="https://pathlock.com/blog/security-alerts/sap-npm-supply-chain-incident-malicious-packages-impact-cap-mta/" target="_blank" rel="noopener"&gt;Pathlock&lt;/A&gt;, and &lt;A href="https://securitybridge.com/blog/a-mini-shai-hulud-has-appeared-when-the-npm-supply-chain-reaches-into-sap/" target="_blank" rel="noopener"&gt;SecurityBridge&lt;/A&gt;.&lt;/P&gt;
&lt;H1&gt;Containment and Impact Reduction&lt;/H1&gt;
&lt;P&gt;If you were not as lucky as the developer using Defender for Endpoint and VS Code, you need end to end monitoring of your landscape in and around SAP. Once the worm is loose with cloud tokens it may appear in various unexpected places.&lt;/P&gt;
&lt;P&gt;Microsoft Sentinel Solution for SAP covers your ERP crown jewels, your SAP BTP landscape and allows informed correlation with the rest of your IT estate. Microsoft’s correlation engine:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;ensures traceability&lt;/LI&gt;
&lt;LI&gt;automatic attack disruption and&lt;/LI&gt;
&lt;LI&gt;just-in-time hardening of potential attack paths.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Developers using the cloud-based IDE SAP Business Application Studio are out of reach by Defender for Endpoint but profit from threat monitoring through Sentinel for SAP BTP integrating SAP BTP’s malware scanner the same way.&lt;/P&gt;
&lt;P&gt;See this in action in &lt;A href="https://demos.microsoft.com/Microsoft/play/6373" target="_blank" rel="noopener"&gt;this click-video&lt;/A&gt; and in below screenshot.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SOC analysts get actionable insights and tailored guidance from Security Copilot once SAP BTP signals are added to the Microsoft incident graph - no matter where the threat involving SAP originates from.&lt;/P&gt;
&lt;H1&gt;Getting Started with Sentinel Solution for SAP&lt;/H1&gt;
&lt;P&gt;Rollout of Sentinel for SAP BTP can happen immediately. Learn more from our &lt;A href="https://learn.microsoft.com/azure/sentinel/sap/sap-btp-solution-overview" target="_blank" rel="noopener"&gt;deployment guide&lt;/A&gt;. Check out the &lt;A href="https://learn.microsoft.com/en-us/azure/sentinel/sap/sap-btp-security-content" target="_blank" rel="noopener"&gt;security content&lt;/A&gt; reference for more info out-of-the-box detections.&lt;/P&gt;
&lt;P&gt;Sentinel for SAP which covers your ERP solutions and more, requires configuration of SAP Integration Suite as intermediary step. Learn more from our &lt;A href="https://learn.microsoft.com/azure/sentinel/sap/deployment-overview?tabs=agentless" target="_blank" rel="noopener"&gt;deployment guide&lt;/A&gt;. Check out the &lt;A href="https://learn.microsoft.com/en-us/azure/sentinel/sap/sap-solution-security-content?pivots=connection-agentless" target="_blank" rel="noopener"&gt;security content&lt;/A&gt; reference for more info out-of-the-box detections&lt;/P&gt;
&lt;H1&gt;Final Words&lt;/H1&gt;
&lt;P&gt;This incident illustrates how far the SAP BTP attack surface now extends and why patching alone is insufficient once malicious code reaches developer tooling and build infrastructure. Effective defense also requires telemetry, correlation, and response coverage across SAP and non-SAP environments.&lt;/P&gt;
&lt;P&gt;See you out there folks!&lt;/P&gt;
&lt;P&gt;#Kudos to Mahesh Mandva and&amp;nbsp;Cameron Gardiner on riding shai-holud with me.&lt;/P&gt;
&lt;P&gt;Feel free to reach out to talk more about SAP Cyber Security.&lt;/P&gt;
&lt;P&gt;Cheers, Martin&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Useful Links&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://me.sap.com/notes/3747787" target="_blank"&gt;SAP Note 3747787 with mitigation guide&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://labs.cloudsecurityalliance.org/research/csa-research-note-mini-shai-hulud-multi-ecosystem-supply-cha/" target="_blank"&gt;Mini Shai-Hulud: Multi-Ecosystem Developer Supply Chain Attack – Lab Space&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://demos.microsoft.com/Microsoft/play/6373" target="_blank"&gt;Click-Demo for SAP Cyber Security with Microsoft&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/sentinel/sap/sap-solution-security-content?pivots=connection-agentless" target="_blank"&gt;Sentinel for SAP Security Content | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/sentinel/sap/sap-btp-security-content" target="_blank"&gt;Sentinel for SAP BTP Security Content | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 08 Jun 2026 10:52:16 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/the-worm-in-the-supply-chain-how-defender-for-endpoint-and/ba-p/4526246</guid>
      <dc:creator>MartinPankraz</dc:creator>
      <dc:date>2026-06-08T10:52:16Z</dc:date>
    </item>
    <item>
      <title>MSSP migration to Unified portal: how are you sequencing your customer portfolio?</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-sentinel/mssp-migration-to-unified-portal-how-are-you-sequencing-your/m-p/4526191#M12939</link>
      <description>&lt;P&gt;Following the automation and SOAR discussion, I wanted to open a conversation specifically focused on the MSSP and multi-tenant side of the migration, because this is where the coordination challenges are an order of magnitude higher than the technical ones.&lt;/P&gt;&lt;P&gt;A few things I am working through before writing this up as Part 5 of the migration series.&lt;/P&gt;&lt;P&gt;On Workspace Manager: Microsoft's own documentation now points you away from Workspace Manager at the point of onboarding to the Defender portal, directing you to Microsoft Defender multitenant management instead. For MSSPs who built their operating model around Workspace Manager, this is a significant structural change. For those implementing now, the recommendation is to go straight to the multitenant portal. I am interested in what the transition has looked like in practice for teams who were mid-flight on Workspace Manager when this became clear.&lt;/P&gt;&lt;P&gt;On access delegation: one of the more honest framings I want to include in the article is around the GDAP plus Unified RBAC gap. A Microsoft employee confirmed in the RSAC 2026 thread that Unified RBAC support for GDAP in the Defender portal is on the roadmap with no firm date. MSSPs choosing between Entra B2B and the governance relationships model today are making an architectural call that is difficult to reverse. I want to present this accurately, and real experience from practitioners will sharpen that framing.&lt;/P&gt;&lt;P&gt;On the connector deployment constraint: you cannot deploy connectors from a managed workspace configured with Azure Lighthouse alone, you also need GDAP. This makes a layered delegation architecture, Lighthouse plus GDAP plus B2B or governance relationships, necessary rather than optional. I am curious whether MSSPs are already running this layered model or whether most are still trying to make Lighthouse work as a single mechanism.&lt;/P&gt;&lt;P&gt;On migration sequencing: the question I want to ask specifically is how teams are structuring their customer portfolio migration. Are you running waves based on customer complexity, based on contract renewal timing, based on customer risk appetite, or some other factor? And when something goes wrong in one tenant's migration, how are you containing the impact on the rest of the programme?&lt;/P&gt;&lt;P&gt;Sharing the full article once it is written. Happy to discuss anything above in more detail in the thread.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2026 01:13:15 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-sentinel/mssp-migration-to-unified-portal-how-are-you-sequencing-your/m-p/4526191#M12939</guid>
      <dc:creator>AnthonyPorter</dc:creator>
      <dc:date>2026-06-08T01:13:15Z</dc:date>
    </item>
    <item>
      <title>Enhancements to Device Status API &amp; Logged-In User Email in Endpoint DLP</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-purview-blog/enhancements-to-device-status-api-logged-in-user-email-in/ba-p/4512046</link>
      <description>&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;1. The Real‑World Problem Endpoint DLP analyst Faced (What Was Missing Earlier)&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-text-type="withSpacing"&gt;Before the introduction of the Device Status API enhancements and logged‑in user visibility, Endpoint DLP teams consistently struggled in below discussed areas:&lt;/P&gt;
&lt;P data-text-type="withSpacing"&gt;&lt;STRONG&gt;Device Visibility Was Fragmented and Manual -&amp;nbsp;&lt;/STRONG&gt;Customers repeatedly told us:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;We know some devices are unhealthy, but we don’t know who owns them.&lt;/LI&gt;
&lt;LI&gt;We export the onboarding table to Excel every week just to understand drift.&lt;/LI&gt;
&lt;LI&gt;By the time we detect a policy issue, the user is already blocked or impacted.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-text-type="withSpacing"&gt;In practice, this meant:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Device onboarding views were static snapshots, not operationally actionable.&lt;/LI&gt;
&lt;LI&gt;Admins relied on manual Excel exports to track onboarding, drift, and health.&lt;/LI&gt;
&lt;LI&gt;Reporting pipelines were brittle and always out of date.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;2. Device Status API: Why Customers Asked for This (Beyond “Reporting”)&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-text-type="withSpacing"&gt;The Hidden Cost of Excel‑Driven Operations as earlier, customers had to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Export device onboarding data manually.&lt;/LI&gt;
&lt;LI&gt;Rebuild dashboards every time they needed updated insight.&lt;/LI&gt;
&lt;LI&gt;Repeat this process weekly or even daily for compliance and SOC reviews.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-text-type="withSpacing"&gt;This approach failed at scale and created blind spots during incidents. When a device policy sync failed or appeared unhealthy, admins had no real‑time, view to answer basic questions like:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Is this device configured correctly?&lt;/LI&gt;
&lt;LI&gt;Is the OS or Defender version lagging?&lt;/LI&gt;
&lt;LI&gt;Is the issue widespread or isolated?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;3&lt;U&gt;. What the Improvement Unlocks (New Operational Reality)&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-text-type="withSpacing"&gt;From Static Views to Continuous Monitoring with the Device Status API:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Device health, configuration status, policy sync state, OS version, and Defender version become query able signals&lt;/LI&gt;
&lt;LI&gt;Customers can power custom reporting and Advanced Hunting queries that are always current&lt;/LI&gt;
&lt;LI&gt;SOC and Endpoint teams finally share a single source of device truth&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This fundamentally changes how customers monitor Endpoint DLP not as a setup task, but as a living control plane. The Device Status API directly addresses this gap by making device‑level status continuously available through Advanced Hunting, allowing customers to build living dashboards instead of static reports.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;4. The Old Workflow (Customer Pain)&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Historically, when a device showed:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Policy Sync Failed&lt;/LI&gt;
&lt;LI&gt;Unhealthy&lt;/LI&gt;
&lt;LI&gt;Configuration mismatch&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-text-type="withSpacing"&gt;&amp;nbsp;Admins had to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Leave the Purview console&lt;/LI&gt;
&lt;LI&gt;Open Microsoft Defender for Endpoint or Intune&lt;/LI&gt;
&lt;LI&gt;Correlate device IDs or names&lt;/LI&gt;
&lt;LI&gt;Identify the user&lt;/LI&gt;
&lt;LI&gt;Start remediation&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-text-type="withSpacing"&gt;This context‑switching cost time, accuracy, and confidence.&lt;/P&gt;
&lt;P data-text-type="withSpacing"&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;&lt;U&gt;5. The New Reality: User Context Where It Matters&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-text-type="withSpacing"&gt;Admins can now see who is logged in directly on the device onboarding page, aligning Windows with the macOS experience like:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Immediate user context during device issues.&lt;/LI&gt;
&lt;LI&gt;Faster outreach and remediation.&lt;/LI&gt;
&lt;LI&gt;One unified investigative surface.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-text-type="withSpacing"&gt;What used to require three portals and multiple teams now happens in One Place.&lt;/P&gt;
&lt;P data-text-type="withSpacing"&gt;&lt;STRONG&gt;&lt;U&gt;6. When Customers Actually Needed This Data (But Didn’t Have It)&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-text-type="withSpacing"&gt;This improvement wasn’t driven by curiosity it was driven by failure points in production. Some of the common customer scenarios listed below:&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;&lt;STRONG&gt;Scenario&lt;/STRONG&gt;&lt;/th&gt;&lt;th&gt;&lt;STRONG&gt;Before&lt;/STRONG&gt;&lt;/th&gt;&lt;th&gt;&lt;STRONG&gt;Now / After Improvement&lt;/STRONG&gt;&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th&gt;&lt;STRONG&gt;Scenario 1: Quarterly Compliance Reviews&lt;/STRONG&gt;&lt;/th&gt;&lt;td&gt;Teams exported Excel files days before audits, resulting in stale data. Auditors questioned the reliability of reports.&lt;/td&gt;&lt;td&gt;Advanced Hunting queries power live compliance dashboards. Reports are defensible because the data is always current.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th&gt;&lt;STRONG&gt;Scenario 2: Incident Post‑Mortems&lt;/STRONG&gt;&lt;/th&gt;&lt;td&gt;Teams struggled to answer whether devices were healthy at the time of the incident or if policies were enforced versus just configured. Reviews relied on assumptions.&lt;/td&gt;&lt;td&gt;Device status, policy sync state, and OS/Defender versions are query able facts. Incident reviews shift from guesswork to evidence‑based analysis.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th&gt;&lt;STRONG&gt;Scenario 3: Silent Policy Drift&lt;/STRONG&gt;&lt;/th&gt;&lt;td&gt;Devices drifted due to OS updates, sensor lag, or configuration changes. Issues surfaced only after a DLP violation occurred.&lt;/td&gt;&lt;td&gt;Policy drift becomes detectable before enforcement failures. Endpoint DLP acts as a reliability signal rather than a last‑line alarm.&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;&lt;U&gt;7. New enhancement on Device Status API&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Device status API provides admins with access to device level information to integrate onboarded device information to custom reporting or use in advanced hunting queries.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;It has helped admins track down users associated with devices instead reaching out to Entra, on-premises Active Directory, or Intune team.&lt;/LI&gt;
&lt;LI&gt;During troubleshooting, if a device is not receiving policies on time, the device API allows quick identification of the device owner and assists in enabling always-on diagnostics or collecting logs directly from the device via Purview console.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;8. Steps to capture User UPN&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Admin can find the device status by login to &lt;U&gt;Security.microsoft.com&lt;/U&gt;&amp;nbsp;as security admin. Click on Investigation and responses &amp;gt; Hunting &amp;gt; Advanced hunting.&lt;/LI&gt;
&lt;LI&gt;Device data can be found under&amp;nbsp;&lt;STRONG&gt;DLPInfo&lt;/STRONG&gt;&amp;nbsp;JSON Column in the&amp;nbsp;&lt;STRONG&gt;Deviceinfo&lt;/STRONG&gt; table&lt;/LI&gt;
&lt;/OL&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;3. Once we run above or any custom query as per requirement, you would see below as response.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;4. Click on the &lt;STRONG&gt;loggedonuser field&lt;/STRONG&gt; and expand the right-side information and look for DLPUPN under inspect record.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;9. User login details on the Purview onboarding page&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Admins now can see who is currently logged in on the device onboarding page. This update aligns the Windows experience with macOS, allowing admins to respond quickly if necessary.&lt;/LI&gt;
&lt;LI&gt;In the past, when a device displayed a "Policy Sync Failed" or "Unhealthy" status, it was necessary to switch to Microsoft Defender for Endpoint (MDE) or Intune to identify the affected user. With this update, all relevant information is now accessible in a single view, streamlining the process.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-text-type="withSpacing"&gt;&lt;STRONG&gt;Benefits&amp;nbsp;&lt;/STRONG&gt;-&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Admins gain faster confirmation of device ownership and user context without extra investigation.&lt;/LI&gt;
&lt;LI&gt;It simplifies troubleshooting onboarding or policy issues by surfacing the user alongside other device insights like status and IP.&lt;/LI&gt;
&lt;LI&gt;No impact on users or DLP policies occurs, and it's enabled by default with no action required.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-text-type="withSpacing"&gt;&lt;STRONG&gt;&lt;U&gt;10.Steps to find User UPN on Purview admin console&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Login to Purview.microsoft.com with compliance admin &amp;gt; Select settings &amp;gt; Device onboarding &amp;gt; Select device&lt;/P&gt;
&lt;P data-text-type="withSpacing"&gt;&lt;STRONG&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P data-text-type="withSpacing"&gt;&lt;STRONG&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;U&gt;Final Takeaway: Why This Matters More Than It First Appears&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-center"&gt;"These enhancements evolve Endpoint DLP from a static, deployment‑centric control into a continuously observable, user‑context aware security signal, significantly reducing investigation time, operational overhead, and trust gaps at scale"&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2026 19:34:11 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-purview-blog/enhancements-to-device-status-api-logged-in-user-email-in/ba-p/4512046</guid>
      <dc:creator>Harysh9</dc:creator>
      <dc:date>2026-06-05T19:34:11Z</dc:date>
    </item>
    <item>
      <title>Extend Microsoft Purview data protection to AWS Bedrock agents for cross-cloud AI governance</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-purview-blog/extend-microsoft-purview-data-protection-to-aws-bedrock-agents/ba-p/4525984</link>
      <description>&lt;P&gt;Organizations are moving fast with AI, and many of those AI workloads are not staying in one cloud. A team might use Microsoft 365 and Microsoft Purview for governance and in addition to Microsoft Foundry they may still choose to run an AI agent on AWS Bedrock or on the Google Cloud Platform. The technical challenge is straightforward: how do you keep one consistent set of data security, governance, and compliance controls when the agent itself runs outside Microsoft Azure?&lt;/P&gt;
&lt;P&gt;This is where Microsoft Purview becomes the central policy engine for your data estate. In this post, we show why that matters and then walk through a practical example: an expense approval agent running on Amazon Bedrock, protected by Microsoft Purview Data Loss Prevention (DLP) policies.&lt;/P&gt;
&lt;img&gt;Fig 1. AWS console page showing "&lt;STRONG&gt;ExpenseApprovalAgent&lt;/STRONG&gt;" details of the Agent blade&lt;/img&gt;
&lt;P&gt;&lt;STRONG&gt;Why Purview should be the central policy engine&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Most organizations do not want separate policy stacks for every cloud, every model endpoint, and every app team. That leads to duplicated controls, inconsistent enforcement, and audit gaps. The better model is to separate where workloads run from where policy decisions are made.&lt;/P&gt;
&lt;P&gt;That is the value proposition for Microsoft Purview in cross-cloud AI scenarios.&lt;/P&gt;
&lt;P&gt;Purview gives you:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;A consistent policy layer for sensitive information types such as credit card numbers, Social Security numbers, financial data, and other regulated content.&lt;/LI&gt;
&lt;LI&gt;A governance plane that can extend beyond Microsoft-hosted workloads into multi-cloud environments.&lt;/LI&gt;
&lt;LI&gt;A compliance framework with auditability, policy traceability, and a familiar operational model for security and compliance teams.&lt;/LI&gt;
&lt;LI&gt;A way to apply data-aware controls to AI interactions, not just to storage locations.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;In practical terms, that means the same organization that already trusts Purview to govern Exchange, SharePoint, Teams, and Copilot can use Purview to govern prompts and responses in a Bedrock-based agent as well.&lt;/P&gt;
&lt;P&gt;The key architectural shift is this: your app does not need to invent its own data policy engine. It can call Purview at the points where risk exists.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What this Bedrock agent demonstrates&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The sample solution in this blog is a cross-cloud AI pattern:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The frontend is a single-page browser-based chat app.&lt;/LI&gt;
&lt;LI&gt;Users authenticate with Microsoft Entra ID via MSAL.&lt;/LI&gt;
&lt;LI&gt;The backend runs in AWS Lambda.&lt;/LI&gt;
&lt;LI&gt;The model is Amazon Bedrock using Nova 2 Lite.&lt;/LI&gt;
&lt;LI&gt;Microsoft Purview evaluates prompts and model responses for DLP policy violations.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This matters because it proves a broader point: Microsoft Purview can govern AI interactions even when the model and compute are not running in Azure.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The core architecture&lt;/STRONG&gt;&lt;/P&gt;
&lt;img&gt;Fig. 2 Architectural overview of the solution&lt;/img&gt;
&lt;P&gt;As shown above the end-to-end flow follows this pattern:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;A user signs in through Microsoft Entra ID from the frontend.&lt;/LI&gt;
&lt;LI&gt;The frontend sends the user's access token and prompt to an API endpoint in AWS.&lt;/LI&gt;
&lt;LI&gt;The Lambda function exchanges that token using the On-Behalf-Of flow so Purview can evaluate under the signed-in user's identity.&lt;/LI&gt;
&lt;LI&gt;Purview scans the full prompt for sensitive information before the model is called.&lt;/LI&gt;
&lt;LI&gt;If the prompt is allowed, the Lambda function sends the request to Amazon Bedrock.&lt;/LI&gt;
&lt;LI&gt;Purview scans the model response before it is returned to the user.&lt;/LI&gt;
&lt;LI&gt;The frontend shows the result along with a Purview evaluation badge.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;That gives you two strong governance controls:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;In-line data loss prevention enforcement, which can block risky requests before they ever reach the model.&lt;/LI&gt;
&lt;LI&gt;Response-time enforcement, which can stop sensitive data from being returned even if a model generates it.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The implementation also uses the user's identity for policy evaluation. That is important because governance decisions should reflect who is asking, not just what application is running.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Why this pattern is useful for security, governance, and compliance teams&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;There are three reasons this pattern is worth paying attention to.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;First&lt;/STRONG&gt;, it aligns policy with risk rather than with hosting location. The compute might run in Lambda and the model might be in Bedrock, but Purview still remains the policy decision point.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Second&lt;/STRONG&gt;, it improves operational clarity. Security teams do not have to learn a different governance toolchain for each AI stack. They can keep using Purview concepts, policy models, and audit workflows.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Third&lt;/STRONG&gt;, it supports real-world adoption. Most large enterprises are hybrid and multi-cloud already. A governance pattern that only works for one vendor's runtime is not enough.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Policy definition in Purview&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Two polices are needed to enforce DLP-a collection policy for Enterprise AI Apps and a DLP policy&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Collection policy&lt;/LI&gt;
&lt;/OL&gt;
&lt;img /&gt;
&lt;P&gt;&lt;STRONG&gt;2. DLP policy&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Follow the steps outlined here to create the DLP policy for Enterprise AI Apps. Sample provided:&lt;STRONG&gt; &lt;A href="https://github.com/microsoft/purview-api-samples/tree/main/DLPforCustomAIApps" target="_blank" rel="noopener"&gt;purview-api-samples/DLPforCustomAIApps at main · microsoft/purview-api-samples&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;To replicate this scenario,&lt;/STRONG&gt; &lt;STRONG&gt;follow this link to the official GitHub repo: &amp;nbsp;&lt;A href="https://github.com/microsoft/purview-api-samples/tree/main/AWSBedrock" target="_blank" rel="noopener"&gt;purview-api-samples/AWSBedrock at main · microsoft/purview-api-samples&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Once deployed, you will have:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;An AWS Lambda function that calls Amazon Bedrock.&lt;/LI&gt;
&lt;LI&gt;A browser frontend that authenticates with Microsoft Entra ID.&lt;/LI&gt;
&lt;LI&gt;Microsoft Purview evaluating both prompts and responses.&lt;/LI&gt;
&lt;LI&gt;A demo flow where safe prompts succeed and sensitive prompts are blocked.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;With the App and agent deployed, now comes the moment when the architectural value becomes clear. The model runtime is AWS Bedrock, but the policy decision is still coming from Microsoft Purview. Below screenshot shows the prompt containing sensitive information being blocked based on the policy evaluation by Purview.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Minimal code integration requirements using the SDK&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Below is the code needed to perform the integration between Purview and Bedrock to perform the in and outbound inspection of content destined to and from the Bedrock model.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;STRONG&gt;Results of Purview’s verdict presented to user in the App UI&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;STRONG&gt;Review governance evidence in Purview Data Security Posture Management&lt;/STRONG&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;STRONG&gt;Summary&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The bigger story here is not just that Microsoft Purview can protect an Amazon Bedrock agent. It is that organizations can centralize data security, governance, and compliance policy even while their AI architecture becomes more distributed across multiple clouds.&lt;/P&gt;
&lt;P&gt;That is the operational win. Developers keep the freedom to choose the best runtime and model platform. Security and compliance teams keep a central policy engine they already understand and trust. AI applications can be multi-cloud, but your data protection model does not have to be fragmented.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://learn.microsoft.com/en-us/purview/developer/configurepurview" target="_blank" rel="noopener"&gt;Configure Microsoft Purview - purview-sdk | Microsoft Learn&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://learn.microsoft.com/en-us/purview/developer/" target="_blank" rel="noopener"&gt;Microsoft Purview Developer Platform Documentation - purview-sdk | Microsoft Learn&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2026 21:17:12 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-purview-blog/extend-microsoft-purview-data-protection-to-aws-bedrock-agents/ba-p/4525984</guid>
      <dc:creator>Inwafula</dc:creator>
      <dc:date>2026-06-09T21:17:12Z</dc:date>
    </item>
    <item>
      <title>Operational Notes on Microsoft Security Copilot Agents in Defender XDR and Microsoft Entra ID</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr/operational-notes-on-microsoft-security-copilot-agents-in/m-p/4525826#M2696</link>
      <description>&lt;P&gt;Microsoft Security Copilot is now becoming more visible inside day-to-day security operations, especially through embedded experiences and agent-based workflows across Microsoft Defender XDR, Microsoft Entra ID, Microsoft Intune, and Microsoft Purview.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Instead of looking at Security Copilot only as a standalone prompt interface, SOC and identity teams should also understand how Security Copilot agents are deployed, how they consume Security Compute Units, how they appear in operational workflows, and where activity can be monitored.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This post summarizes practical observations from a security operations perspective, with a focus on Microsoft Defender XDR, Microsoft Entra ID, usage monitoring, and KQL-based activity review.&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;H1&gt;Licensing &amp;amp; Capacity Units&lt;/H1&gt;&lt;H3&gt;Requirements&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;Requires eligible Microsoft security licensing, typically:&lt;UL&gt;&lt;LI&gt;Microsoft 365 E5&lt;/LI&gt;&lt;LI&gt;Microsoft 365 E7&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;Security Compute Units (SCUs)&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;Security Copilot capacity is measured using&amp;nbsp;&lt;STRONG&gt;Security Compute Units (SCUs)&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;SCUs are billed based on&amp;nbsp;&lt;STRONG&gt;provisioned capacity&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Indicative pricing:&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;$4 per Provisionied SCU/hour&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;$6 per Overage SCU/hour&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Billing is calculated&amp;nbsp;&lt;STRONG&gt;hourly&lt;/STRONG&gt;, based on the amount of SCUs provisioned.&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;Included Capacity&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;Organizations with:&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;1,000 Microsoft 365 E5 licenses&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Receive:&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;400 included SCUs&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Included SCUs are shared across the tenant within a common capacity pool.&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;Scaling&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;SCU capacity can be scaled dynamically based on operational requirements and workload demand.&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;Data Retention&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;Security Copilot session and interaction data without active SCU-backed retention is typically retained for:&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;90 days&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H1&gt;Security Copilot Agents - Microsoft Defender&lt;/H1&gt;&lt;P&gt;This section outlines the Microsoft Security Copilot agents currently available in the Microsoft Defender portal.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Name&lt;/STRONG&gt;&lt;STRONG&gt;Key characteristics &lt;/STRONG&gt;Security Alert Triage Agent (Preview)&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Manual setup from Defender portal&lt;/LI&gt;&lt;LI&gt;Automatically creates Unified RBAC custom role&lt;/LI&gt;&lt;LI&gt;Runs automatically when a user reports a suspicious email or when a new supported alert is generated, supported alert sources:&amp;nbsp;MDI, MDC, MDO&lt;/LI&gt;&lt;LI&gt;If an alert tuning rule is enabled, it will be automatically disabled when the agent is deployed.&lt;/LI&gt;&lt;LI&gt;Creates and connects with agentic user account:&amp;nbsp;Phishing Triage Agent (Security Copilot)&lt;/LI&gt;&lt;LI&gt;Automatic alert assignment to SecurityCopilotAgentUser-db16fec3-f1fb-4632-843e-46d07408c584@&amp;lt;tenant-domain&amp;gt;Alert was assigned to Phishing Triage Agent (Security Copilot).&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Adds Tag Agent&amp;nbsp;&lt;/STRONG&gt;to the created Incidents&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Threat Hunting Agent&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Manual setup from Defender portal&lt;/LI&gt;&lt;LI&gt;Automatically creates Unified RBAC custom role&lt;/LI&gt;&lt;LI&gt;This agent runs manually. There isn't an automatic trigger.&lt;/LI&gt;&lt;LI&gt;Creates and connects with agentic user account:&amp;nbsp;Threat Hunting Agent (Security Copilot)&lt;/LI&gt;&lt;LI&gt;Analyst Questions in natural language&lt;/LI&gt;&lt;LI&gt;Generates and executed KQL queries in Advanced hunting&lt;/LI&gt;&lt;LI&gt;Provides charts, dynamic follow-up questions and remediation actions recommendations&lt;/LI&gt;&lt;LI&gt;No activity is identified from agent's identity during agent execution&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Threat Intelligence Briefing Agent&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Manual setup from Defender portal&lt;/LI&gt;&lt;LI&gt;Provides automated TI briefing summary&lt;/LI&gt;&lt;LI&gt;Configured from&amp;nbsp;&lt;A href="https://security.microsoft.com/securitysettings/defender/agent_configuration-threatintelligencebriefingagent" target="_blank" rel="noopener"&gt;https://security.microsoft.com/securitysettings/defender/agent_configuration-threatintelligencebriefingagent&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Security Analyst Agent&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Manual setup from Defender portal&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Dynamic Threat Detection Agent (Preview)&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Automatically enabled&lt;/LI&gt;&lt;LI&gt;always-on, runs continuously in the background&lt;/LI&gt;&lt;LI&gt;Correlates:&amp;nbsp;Alerts, Security events, Behavioral anomalies,&amp;nbsp; TI signals&lt;/LI&gt;&lt;LI&gt;Generates Alerts with&amp;nbsp;&lt;STRONG&gt;Detection Source: Security Copilot&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;The Alerts can be correlated with existing Multi-Stage Incidents&lt;/LI&gt;&lt;LI&gt;No agentic user account identity is used by this agent&lt;/LI&gt;&lt;LI&gt;Available free of charge during public preview, will begin consuming Security Compute Units (SCUs) once generally available (GA)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Incidents handled by&amp;nbsp;&lt;STRONG&gt;Security Alert Triage Agent&lt;/STRONG&gt;:&lt;/P&gt;&lt;img /&gt;&lt;img /&gt;&lt;P&gt;Alerts created by&amp;nbsp;&lt;STRONG&gt;Dynamic Threat Detection Agent&lt;/STRONG&gt;:&lt;/P&gt;&lt;img /&gt;&lt;img /&gt;&lt;P&gt;Execution of &lt;STRONG&gt;Threat Hunting Agent&lt;/STRONG&gt;:&lt;/P&gt;&lt;img /&gt;&lt;img /&gt;&lt;P&gt;View agents in use: &lt;A href="https://security.microsoft.com/security-copilot/agents" target="_blank" rel="noopener"&gt;https://security.microsoft.com/security-copilot/agents&lt;/A&gt;&lt;/P&gt;&lt;img /&gt;&lt;img /&gt;&lt;P&gt;View Unified RBAC custom roles:&amp;nbsp;&lt;A href="https://security.microsoft.com/mtp_roles" target="_blank" rel="noopener"&gt;https://security.microsoft.com/mtp_roles&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;img /&gt;&lt;img /&gt;&lt;P&gt;View Security Copilot user identities in Microsoft Entra ID:&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&lt;STRONG&gt;Notes:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;CloudAppEvents activity logs only from the following agents:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Phishing Triage Agent&lt;/LI&gt;&lt;LI&gt;Conditional Access Optimization Agent&lt;/LI&gt;&lt;/UL&gt;&lt;H1&gt;Security Copilot Agents - Microsoft Entra ID&lt;/H1&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Conditional Access Optimization Agent&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;H1&gt;Usage Monitoring&lt;/H1&gt;&lt;P&gt;Sign-in to Security Copilot portal using Global Admin account and navigate to the following location:&amp;nbsp;&lt;A href="https://securitycopilot.microsoft.com/usage-monitoring" target="_blank" rel="noopener"&gt;https://securitycopilot.microsoft.com/usage-monitoring&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Reference:&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/copilot/security/manage-usage" target="_blank" rel="noopener"&gt;https://learn.microsoft.com/en-us/copilot/security/manage-usage&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;H1&gt;Logging Activity&lt;/H1&gt;&lt;P&gt;Copilot Agents Management:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CloudAppEvents&lt;/P&gt;&lt;P&gt;| where ActionType contains "CopilotAgent"&lt;/P&gt;&lt;P&gt;| extend AgentName = RawEventData.AgentName&lt;/P&gt;&lt;P&gt;| extend Workload = RawEventData.Workload&lt;/P&gt;&lt;P&gt;| extend ResultStatus = RawEventData.ResultStatus&lt;/P&gt;&lt;P&gt;| project TimeGenerated, ActionType, ResultStatus, AgentName, Application, Workload&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All Copilot Workload data:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CloudAppEvents&lt;/P&gt;&lt;P&gt;| extend Workload = RawEventData.Workload&lt;/P&gt;&lt;P&gt;| where Workload == "Copilot"&lt;/P&gt;&lt;P&gt;| summarize EventCount = count() by ActionType, AccountDisplayName&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2026 09:31:28 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr/operational-notes-on-microsoft-security-copilot-agents-in/m-p/4525826#M2696</guid>
      <dc:creator>klianos</dc:creator>
      <dc:date>2026-06-05T09:31:28Z</dc:date>
    </item>
    <item>
      <title>Microsoft Defender for Cloud Customer Newsletter</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-cloud/microsoft-defender-for-cloud-customer-newsletter/ba-p/4525656</link>
      <description>&lt;H1&gt;What's new in Defender for Cloud?&lt;/H1&gt;
&lt;P&gt;Defender for Cloud is now integrated into the Defender portal to bring together cloud security posture management and threat protection in a single experience. Read more about it &lt;A href="https://aka.ms/mdc_DefenderPortal" target="_blank"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;Cloud security reporting in the Defender portal is now in public preview&lt;/H2&gt;
&lt;P&gt;Customers can now create, customize, and share security insights across the organization through Defender portal’s integrated cloud security reporting capabilities. With these reporting capabilities, customers can view built-in reports like CNAPP Executive Summary, create custom reports, export to PDF and more. For more details, please refer to this &lt;A href="https://aka.ms/mdc_Defenderportal_reporting" target="_blank"&gt;documentation&lt;/A&gt;.&lt;/P&gt;
&lt;P data-ogsc="rgb(0, 0, 0)"&gt;&lt;A href="https://aka.ms/MDCNewsJust" target="_blank"&gt;Check out other updates from last month here!&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-ogsc="rgb(0, 0, 0)"&gt;&lt;A href="https://aka.ms/mdc_mtpblog" target="_blank"&gt;Check out monthly news for the rest of the MTP suite here!&lt;/A&gt; &amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Blog(s) of the month&lt;/H2&gt;
&lt;P&gt;In May, our team published the following blog posts we would like to share:&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/MDCNewsBlog1" target="_blank"&gt;Better together with Azure WAF + Defender for Storage + Defender for Azure SQL Databases&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/MDCNewsBlog2" target="_blank"&gt;Public preview: Expanded coverage and unified management for SQL VA Express Configuration | Microsoft Community Hub&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 data-ogsc="rgb(0, 0, 0)"&gt;Defender for Cloud in the field&lt;/H2&gt;
&lt;P data-ogsc="rgb(0, 0, 0)"&gt;Check out the two short videos on Defender Portal integration and Start Secure Stay Secure with Defender for Cloud&lt;/P&gt;
&lt;UL data-editing-info="{&amp;quot;applyListStyleFromLevel&amp;quot;:true,&amp;quot;orderedStyleType&amp;quot;:1}"&gt;
&lt;LI data-ogsc="rgb(0, 0, 0)"&gt;&lt;A href="https://aka.ms/mdc_youtube_Defenderportal" data-ogsc="rgb(5, 99, 193)" target="_blank"&gt;&lt;U data-ogsc=""&gt;Microsoft Defender for Cloud deeply integrates with Microsoft Defender&lt;/U&gt;&lt;/A&gt;&lt;/LI&gt;
&lt;LI data-ogsc="rgb(0, 0, 0)"&gt;&lt;A href="https://aka.ms/mdc_youtube_startsecurestaysecure" data-ogsc="rgb(5, 99, 193)" target="_blank"&gt;&lt;U data-ogsc=""&gt;Start secure and stay secure with Microsoft Defender for Cloud&lt;/U&gt;&lt;/A&gt;&lt;/LI&gt;
&lt;LI data-ogsc="rgb(0, 0, 0)"&gt;&lt;A href="https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Faka.ms%2FMDCNewsField&amp;amp;data=05%7C02%7CYura.Lee%40microsoft.com%7C3927ff7829b9416ac31c08dd447f9315%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C638742036921371778%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=Ni9o%2FuGnNm5keL5pEgpww3s46S3nE6EfDiG3Z28cPhI%3D&amp;amp;reserved=0" data-ogsc="rgb(5, 99, 193)" target="_blank"&gt;&lt;U data-ogsc=""&gt;Visit our YouTube page&lt;/U&gt;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 data-ogsc="rgb(0, 0, 0)"&gt;GitHub Community&lt;/H2&gt;
&lt;P data-ogsc="rgb(0, 0, 0)"&gt;Check out this PS script and CLI to help you enable Defender for API at scale:&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-ogsc="rgb(0, 0, 0)"&gt;&lt;A href="https://aka.ms/mdcgit_apiatscale" target="_blank"&gt;Onboard to Defender for API at scale&lt;/A&gt;&lt;/LI&gt;
&lt;LI data-ogsc="rgb(0, 0, 0)"&gt;&lt;A href="https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Faka.ms%2FMDCNewsGit&amp;amp;data=05%7C02%7CYura.Lee%40microsoft.com%7C3927ff7829b9416ac31c08dd447f9315%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C638742036921474195%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=ZBr6NDY28EuqIzivYaky1d%2FBvBAr2oYHDW2vHcYuJKM%3D&amp;amp;reserved=0" target="_blank"&gt;Visit our GitHub page&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 data-ogsc="rgb(0, 0, 0)"&gt;Customer journey&lt;/H2&gt;
&lt;P&gt;Discover how other organizations successfully use Microsoft Defender for Cloud to protect their cloud workloads. This month we are featuring&amp;nbsp;&lt;A href="https://aka.ms/MDCNewsStory1" target="_blank"&gt;Loyens &amp;amp; Loeff&lt;/A&gt;, a law and tax firm, that operates in a high complex environment, sought to modernize the digital workplace with Microsoft 365 Copilot, Defender for Cloud and Purview.&lt;/P&gt;
&lt;H2&gt;Join our community!&lt;/H2&gt;
&lt;P&gt;We offer several customer connection programs within our private communities. By signing up, you can help us&amp;nbsp;shape our products through activities such as reviewing product roadmaps, participating in co-design, previewing features, and staying up-to-date with announcements. Sign up at&amp;nbsp;&lt;A href="https://www.aka.ms/JoinCCP" target="_blank"&gt;aka.ms/JoinCCP.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;We greatly value your input on the types of content that enhance your understanding of our security products. Your insights are crucial in guiding the development of our future public content. We aim to deliver material that not only educates but also resonates with your daily security challenges. Whether it’s through in-depth live webinars, real-world case studies, comprehensive best practice guides through blogs, or the latest product updates, we want to ensure our content meets your needs. Please submit your feedback on which of these formats do you find most beneficial and are there any specific topics you’re interested in&amp;nbsp;&lt;A href="https://aka.ms/PublicContentFeedback" aria-label="Link https://aka.ms/PublicContentFeedback" target="_blank"&gt;https://aka.ms/PublicContentFeedback.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note: If you want to stay current with Defender for Cloud and receive updates in your inbox, please consider subscribing to our monthly newsletter:&amp;nbsp;&lt;A href="https://aka.ms/MDCNewsSubscribe" target="_blank"&gt;https://aka.ms/MDCNewsSubscribe&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2026 18:30:12 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-cloud/microsoft-defender-for-cloud-customer-newsletter/ba-p/4525656</guid>
      <dc:creator>Yura_Lee</dc:creator>
      <dc:date>2026-06-04T18:30:12Z</dc:date>
    </item>
    <item>
      <title>Run Global Secure Access with confidence: Introducing the GSA Operations Guide</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/run-global-secure-access-with-confidence-introducing-the-gsa/ba-p/4524891</link>
      <description>&lt;P&gt;In working with customers, I’ve seen the same pattern again and again: deployment gets the attention, but day 2 operations are where teams need the most structure. This guide is meant to make that part easier—with practical guidance teams can use right away.&lt;/P&gt;
&lt;H2&gt;TL;DR: Your day 2 playbook is here&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;What’s new?&lt;/STRONG&gt; A prescriptive &lt;STRONG&gt;Microsoft Entra Global Secure Access operations guide&lt;/STRONG&gt; on Microsoft Learn&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Why it matters:&lt;/STRONG&gt; It brings actionable, alert-first procedures for teams running Global Secure Access after deployment&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;What’s inside:&lt;/STRONG&gt; A role matrix, automated health checks, capability-specific guides, templates, and automation scripts&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Start here:&lt;/STRONG&gt; &lt;A class="lia-external-url" href="http://aka.ms/GSAOpsGuide" target="_blank" rel="noopener"&gt;Microsoft Entra Global Secure Access operations guide&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;The day 2 gap&lt;/H2&gt;
&lt;P&gt;Deploying Global Secure Access (GSA) is only the beginning. Day 2 challenges raise questions like: &lt;BR /&gt;&lt;EM&gt;Who monitors what? When do checks happen? How do we know everything is healthy?&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;The deployment guide covers rollout, and the product documentation explains configuration. But until now, there was no single resource that explained&amp;nbsp;&lt;STRONG&gt;how to operate Global Secure Access in production&lt;/STRONG&gt;. Customers, FastTrack, and partners built their own runbooks—and rebuilt them for each deployment.&lt;/P&gt;
&lt;P&gt;That ends today.&lt;/P&gt;
&lt;H2&gt;Announcing the Operations Guide&lt;/H2&gt;
&lt;P&gt;The &lt;A class="lia-external-url" href="http://aka.ms/GSAOpsGuide" target="_blank" rel="noopener"&gt;Microsoft Entra Global Secure Access operations guide&lt;/A&gt; is now live on Microsoft Learn.&lt;/P&gt;
&lt;P&gt;This post-deployment playbook delivers prescriptive guidance for&amp;nbsp;&lt;STRONG&gt;running Global Secure Access in production at scale&lt;/STRONG&gt;. It was created by the Global Secure Access customer experience engineering team with input from &lt;STRONG&gt;Thomas Detzner, Janice Ricketts, Jeff Bley, Luis Flores, Marilee Turscak, Peter Lenzke, Mohammad Zmaili, and Ken Withe&lt;/STRONG&gt;.&lt;/P&gt;
&lt;H2&gt;Who this guide empowers&lt;/H2&gt;
&lt;P&gt;This guide is for the teams that keep Global Secure Access running every day: IT administrators, network engineers, and platform operations teams that need clear answers to questions like “Who owns what?” and “How do we prevent issues before they happen?”&lt;/P&gt;
&lt;P&gt;It also equips security leaders with structured reporting so they can demonstrate value and service health to executives. If you’re responsible for Global Secure Access performance, alerting, or automation, this is your new reference playbook. &lt;EM&gt;(And if you haven’t deployed yet, start with the &lt;/EM&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/architecture/gsa-deployment-guide-intro" target="_blank" rel="noopener"&gt;&lt;EM&gt;deployment guide&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt;.)&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;What you’ll gain from this guide&lt;/H2&gt;
&lt;H3&gt;Shared practices that work across any environment&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Know your roles early:&lt;/STRONG&gt; A RACI matrix so responsibilities never overlap&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Manage change with confidence:&lt;/STRONG&gt; A GSA-tailored change-control framework for smooth updates&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Prove success with clarity:&lt;/STRONG&gt; Reporting templates for operators, managers, and executives&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Adopt continuous improvement:&lt;/STRONG&gt; Built-in processes to spot gaps before they become issues&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Capability-specific playbooks structured for speed&lt;/H3&gt;
&lt;P&gt;Every workload (Private Access, Internet Access, Remote Networks, Microsoft Traffic) follows one clear pattern so teams always know what comes next:&lt;BR /&gt;&amp;nbsp;✔ Begin with &lt;STRONG&gt;alert-first monitoring&lt;/STRONG&gt; steps that catch issues early&lt;BR /&gt;&amp;nbsp;✔ Follow &lt;STRONG&gt;daily, weekly, monthly routines&lt;/STRONG&gt; for health maintenance&lt;BR /&gt;&amp;nbsp;✔ Automate critical workflows with &lt;STRONG&gt;Sentinel, Graph API, and PowerShell scripts&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;✔ Track and tune KPIs using measured baselines&lt;BR /&gt;&amp;nbsp;✔ Diagnose and resolve quickly with &lt;STRONG&gt;symptom-to-fix troubleshooting&lt;/STRONG&gt;&lt;/P&gt;
&lt;H3&gt;Don’t start from zero—use the templates&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;Daily health check across all GSA capabilities&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;Ready-made change request forms and notification playbooks&lt;/LI&gt;
&lt;LI&gt;Modular checklists ready for your ITSM process&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Why this guide is different&lt;/H2&gt;
&lt;P&gt;Unlike generic environment monitoring advice, this guide delivers concrete, tested procedures built from field experience. It applies an alert-first approach so teams can act on signals from Microsoft Sentinel and Azure Monitor before dashboards show trouble.&lt;/P&gt;
&lt;P&gt;Each alert comes with an action—nothing is left unanswered. Automation is embedded throughout, including role-based access control (RBAC) hygiene checks and failover tests. Because operations demand clarity, the guide also provides measurable thresholds, baseline methods, and recovery steps that reduce noise and reinforce uptime.&lt;/P&gt;
&lt;H2&gt;Six moves to launch operational maturity&lt;/H2&gt;
&lt;OL&gt;
&lt;LI&gt;Assign roles using the RACI matrix for full coverage&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL start="2"&gt;
&lt;LI&gt;Configure critical alerts before adding custom workflows&lt;/LI&gt;
&lt;LI&gt;Collect 30 days of baseline data before adjusting thresholds&lt;/LI&gt;
&lt;LI&gt;Automate backups and priority alert notifications early&lt;/LI&gt;
&lt;LI&gt;Schedule routine checks using provided templates&lt;/LI&gt;
&lt;LI&gt;Begin structured reporting starting with weekly operations and monthly management reviews&lt;/LI&gt;
&lt;/OL&gt;
&lt;H2&gt;Why it matters for customers and partners&lt;/H2&gt;
&lt;P&gt;This framework reduces time to readiness after deployment, documents a defensible Day 2 plan for audits, cuts escalations by linking every alert to a clear action path, and gives FastTrack and partners a baseline for consistency in engagements.&lt;/P&gt;
&lt;H3&gt;Next up&lt;/H3&gt;
&lt;P&gt;Soon we will publish the GSA Security Operations Guide for Microsoft Entra Global Secure Access, providing a dedicated security monitoring and detection companion to the operational guides for Private Access, Internet Access, Remote Networks, and Microsoft traffic. It brings together the built-in alerts, log sources, Sentinel detections, and cross-signal investigation patterns that security teams need to identify suspicious activity and unauthorized changes across the GSA environment.&lt;/P&gt;
&lt;P&gt;If deployment is still ahead, start with the &lt;A href="https://learn.microsoft.com/en-us/entra/architecture/gsa-deployment-guide-intro" target="_blank" rel="noopener"&gt;GSA Deployment Guide&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;Your move&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/aka.ms/GSAOpsGuide" target="_blank" rel="noopener"&gt; Open the full guide&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Download templates and run your first daily health check today&lt;/LI&gt;
&lt;LI&gt;Post feedback and ideas to help shape future updates&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Thomas Detzner&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/in/thomasdetzner/" target="_blank" rel="noopener"&gt;Thomas Detzner | LinkedIn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://microsoft.sharepoint.com/teams/AzureActiveDirectoryBlogcopy/Shared%20Documents/Entra%20Blog%20Publishing/aka.ms/GSAOpsGuide" target="_blank" rel="noopener"&gt;Microsoft Entra Global Secure Access operations guide&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://aka.ms/IRPlaybooks" target="_blank" rel="noopener"&gt;Microsoft Incident Response Playbooks: response guidance for containment, eradication, and recovery after a SecOps detection is confirmed&lt;/A&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-sentinel-integration" target="_blank" rel="noopener"&gt;Enhance threat detection with Global Secure Access in Microsoft Sentinel: how to stream GSA data into Sentinel, install the solution, enable analytics rules, and use the built-in workbooks.&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/global-secure-access/concept-alerts" target="_blank" rel="noopener"&gt;What are Global Secure Access alerts?: the built-in GSA alert types, what they mean, and where to view them.&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/global-secure-access/concept-global-secure-access-logs-monitoring" target="_blank" rel="noopener"&gt;Global Secure Access logs and monitoring: overview of dashboards, traffic logs, audit logs, enriched Microsoft 365 logs, retention, and monitoring surfaces.&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-access-audit-logs" target="_blank" rel="noopener"&gt;How to access the Global Secure Access audit logs: where to find GSA-related audit activity and how to filter it for operational or security investigations&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-audit-activities" target="_blank" rel="noopener"&gt;Microsoft Entra audit log categories and activities for Global Secure Access: the authoritative list of GSA audit operations and categories for change monitoring&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;&lt;STRONG&gt;Learn more about Microsoft Entra&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2026 18:04:21 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/run-global-secure-access-with-confidence-introducing-the-gsa/ba-p/4524891</guid>
      <dc:creator>tdetzner</dc:creator>
      <dc:date>2026-06-05T18:04:21Z</dc:date>
    </item>
    <item>
      <title>No way to automate restoring user‑reported emails after “no threats found”</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-office/no-way-to-automate-restoring-user-reported-emails-after-no/m-p/4525644#M1152</link>
      <description>&lt;P&gt;When a user reports an email as phishing in Defender, the message gets moved to Deleted Items. After we triage it, if we mark it as “no threats found,” there’s no way to push it back to the user’s inbox as part of that workflow.&lt;/P&gt;&lt;P&gt;That creates a bit of a broken experience:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;User is told the email is safe with our customized email response, but has to go find it themselves&lt;/LI&gt;&lt;LI&gt;In a lot of cases they don’t (Outlook search won’t find it)&lt;/LI&gt;&lt;LI&gt;We end up with follow‑ups like “where did it go?”&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Technically we could restore the email as part of our triage process, but that just shifts the effort onto the SOC. It doesn’t scale, and it’s not really the right place for that work.&amp;nbsp; We have tried to create an automation to do this, but we have not been able to create an advanced hunting query based on our triage result that can then trigger an action to restore it to the mailbox.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So we end up choosing between:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Users having a bad experience, or&lt;/LI&gt;&lt;LI&gt;Analysts doing manual mailbox work&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Neither is ideal.&lt;/P&gt;&lt;P&gt;Other platforms (like Proofpoint) handle this end‑to‑end — once something is confirmed clean, it can be returned to the user automatically.&lt;/P&gt;&lt;P&gt;Right now Defender stops at classification instead of completing the workflow.&lt;/P&gt;&lt;P&gt;Is there a reason this isn’t wired in, or anything on the roadmap to address it?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2026 17:30:51 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-office/no-way-to-automate-restoring-user-reported-emails-after-no/m-p/4525644#M1152</guid>
      <dc:creator>GT_deb</dc:creator>
      <dc:date>2026-06-04T17:30:51Z</dc:date>
    </item>
    <item>
      <title>Prompted to sign in to Microsoft Defender Platform on W11/W2025 using Entra</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr/prompted-to-sign-in-to-microsoft-defender-platform-on-w11-w2025/m-p/4525520#M2694</link>
      <description>&lt;P&gt;Hi Microsoft Defender XDR community,&lt;BR /&gt;&lt;BR /&gt;Since around May 18th, our users on devices that are onboarded to Microsoft Defender for Endpoint are being prompted to sign-in to the following application using Entra on login to Windows.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Application&lt;/P&gt;&lt;P&gt;Microsoft Defender Platform&lt;/P&gt;&lt;P&gt;Application ID&lt;/P&gt;&lt;P&gt;cab96880-db5b-4e15-90a7-f3f1d62ffe39&lt;BR /&gt;&lt;BR /&gt;Is anyone aware of a change that requires user sign-in to Entra as a requirement for Microsoft Defender for Endpoint? I have tried raising a support topic on this topic.&lt;BR /&gt;&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2026 12:40:24 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr/prompted-to-sign-in-to-microsoft-defender-platform-on-w11-w2025/m-p/4525520#M2694</guid>
      <dc:creator>chrisnelmes</dc:creator>
      <dc:date>2026-06-04T12:40:24Z</dc:date>
    </item>
    <item>
      <title>June 4 - Secure Boot AMA</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/june-4-secure-boot-ama/m-p/4525226#M9991</link>
      <description>&lt;img /&gt;
&lt;P&gt;Microsoft is updating the Secure Boot certificates originally issued in 2011 to ensure Windows devices continue to verify trusted boot software. These older certificates begin expiring in June 2026. Devices that haven’t received the newer 2023 certificates will continue to start and operate normally, and standard Windows updates will continue to install. However, these devices will no longer be able to receive new security protections for the early boot process, including updates to Windows Boot Manager, Secure Boot databases, revocation lists, or mitigations for newly discovered boot level vulnerabilities.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Whether you are already working through Secure Boot certificate updates across your estate, or aren't sure where to start, you can get answers to your questions and helpful insights at the next Secure Boot AMA on 8:00 a.m. PDT June 4, 2026. Can't attend live? No problem. Post your questions in advance.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Visit &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-occasion" href="https://techcommunity.microsoft.com/event/windowsevents/ask-microsoft-anything-secure-boot---june-2026/4522056" target="_blank" rel="noopener" data-lia-auto-title="https://aka.ms/AMA/SecureBoot" data-lia-auto-title-active="0"&gt;https://aka.ms/AMA/SecureBoot&lt;/A&gt; to save the date and post your questions.&lt;BR /&gt;&lt;BR /&gt;For detailed, step-by-step guidance, see the following resources:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/securebootplaybook" target="_blank" rel="noopener"&gt;Secure Boot Playbook for Windows client&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/SecureBootForServer" target="_blank" rel="noopener"&gt;Secure Boot playbook for Windows Server&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://support.microsoft.com/en-us/topic/secure-boot-certificate-updates-for-windows-365-71839dd8-2832-44ed-9c60-57c04f99a645" target="_blank" rel="noopener"&gt;Secure Boot Certificate Updates for Windows 365&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://support.microsoft.com/en-us/topic/secure-boot-certificate-updates-for-azure-virtual-desktop-06a8a1bc-2510-4ead-9bea-3698e1d6b1db" target="_blank" rel="noopener"&gt;Secure Boot Certificate Updates for Azure Virtual Desktop&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 03 Jun 2026 17:23:06 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/june-4-secure-boot-ama/m-p/4525226#M9991</guid>
      <dc:creator>Heather_Poulsen</dc:creator>
      <dc:date>2026-06-03T17:23:06Z</dc:date>
    </item>
  </channel>
</rss>

