<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Microsoft Defender XDR Blog articles</title>
    <link>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/bg-p/MicrosoftThreatProtectionBlog</link>
    <description>Microsoft Defender XDR Blog articles</description>
    <pubDate>Thu, 01 Oct 2026 13:50:25 GMT</pubDate>
    <dc:creator>MicrosoftThreatProtectionBlog</dc:creator>
    <dc:date>2026-10-01T13:50:25Z</dc:date>
    <item>
      <title>Integrated Security Operations Center in Microsoft Defender</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/integrated-security-operations-center-in-microsoft-defender/ba-p/4559097</link>
      <description>&lt;P&gt;AI is transforming the attacker’s operating model, accelerating threats to unprecedented speed and scale.&amp;nbsp;Yet many security operations centers still depend on fragmented data, tools, intelligence, and workflows. Analysts spend valuable time rebuilding context and coordinating action across systems, while the economics of operating the SOC become increasingly difficult to sustain. Security operations need a new operating model, one that brings protection and operations together and gives people and agents the shared context they need to defend at scale.&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;On September 23, 2026, Microsoft&amp;nbsp;&lt;/SPAN&gt;&lt;A class="lia-external-url" style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://aka.ms/ISOCannouncement" target="_blank" rel="noopener"&gt;announced&lt;/A&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt; the public preview of Integrated Security Operations Center (ISOC) in Microsoft Defender. The ISOC benefit enables eligible Microsoft Defender Suite, Microsoft 365 E5 and E7 customers to unlock more value from their existing investments by bringing XDR&lt;STRONG&gt;,&lt;/STRONG&gt; SIEM, threat intelligence, automation, and AI together in Microsoft Defender.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2&gt;A new foundation for security operations&lt;/H2&gt;
&lt;P&gt;The ISOC benefit brings protection and operations together in Microsoft Defender, helping eligible customers get more from their Microsoft investments and build the foundation for agentic security.&lt;/P&gt;
&lt;P&gt;Customers benefit from:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Native threat protection:&lt;/STRONG&gt; Microsoft Defender provides threat protection solutions across identities, endpoints, SaaS apps, email and collaboration tools, and cloud workloads.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Integrated security operations:&lt;/STRONG&gt; SIEM capabilities are now available out-of-the-box in Microsoft Defender, giving eligible customers access to security operations capabilities without requiring a traditional SIEM deployment.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Built-in retention: &lt;/STRONG&gt;Retention for eligible customers will extend from 30 to 90 days across all Microsoft Defender data, Azure Activity, and Office 365 Activity, starting November 15, 2026.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Expand visibility&lt;/STRONG&gt;: Starting October 1, eligible customers can expand visibility with more than 500 connectors, using a $2.40 per GB pay-as-you-go ingestion meter. Regional pricing and other terms may vary.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;Built for future:&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt; Bring signals, context, and workflows together in one integrated experience, establishing the foundation for agentic AI security that helps accelerate investigation and response, and improve security outcomes.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Start with Microsoft Defender data. Expand when you need to.&lt;/H2&gt;
&lt;P&gt;ISOC builds on the security data already available across Microsoft Defender and other select Microsoft sources, providing a rich, Microsoft-native foundation for integrated security operations. Supported Microsoft Defender log sources are automatically available without separate ingestion requirements. Eligible customers receive 30 days of included Microsoft Defender data retention in public preview, extending to 90 days starting November 15, 2026.&lt;/P&gt;
&lt;P&gt;Data sources covered by this new benefit include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Microsoft Defender for Endpoint&lt;/LI&gt;
&lt;LI&gt;Microsoft Defender for Office 365&lt;/LI&gt;
&lt;LI&gt;Microsoft Defender for Identity&lt;/LI&gt;
&lt;LI&gt;Microsoft Defender for Cloud Apps&lt;/LI&gt;
&lt;LI&gt;Microsoft Defender for Cloud&lt;/LI&gt;
&lt;LI&gt;Microsoft Entra Identity Protection logs&lt;/LI&gt;
&lt;LI&gt;Azure Activity and audit logs, via connector&lt;/LI&gt;
&lt;LI&gt;Office 365 Activity and audit logs, via connector&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Now in Public Preview&lt;/H2&gt;
&lt;P&gt;Starting today, eligible customers will begin seeing new security operations capabilities roll out in public preview, directly within the Microsoft Defender portal, with no additional configuration. &amp;nbsp;An ISOC workspace is required for broader data ingestion and workspace-dependent capabilities.&lt;/P&gt;
&lt;P&gt;Out of the box capabilities include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Case &lt;/STRONG&gt;&lt;STRONG&gt;management –&lt;/STRONG&gt; The new &lt;STRONG&gt;Cases&lt;/STRONG&gt; experience will help analysts accelerate investigations, streamline response, and improve cross-team coordination. The new Cases experience brings incidents, collaboration, task assignment, automation, AI-powered summaries, and governance into a shared workspace, enabling security teams to manage the entire incident lifecycle in one place. &lt;A class="lia-external-url" href="https://aka.ms/caseindefender" target="_blank" rel="noopener"&gt;Read blog to learn more.&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Workbooks – &lt;/STRONG&gt;Gain real-time visibility into your security operations with custom dashboards. Monitor threats, track trends, measure outcomes, and report on key performance indicators across analysts, SOC managers, and executives.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;Playbook generation in natura&lt;/STRONG&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;l language – &lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;Use natural language to create and orchestrate automation workflows, helping teams move faster and reduce manual effort.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;img&gt;Figure 1: &lt;SPAN style="color: rgb(112, 112, 112);" data-mce-style="color: rgb(112, 112, 112);"&gt;Cases, workbooks and automation appear automatically in the Microsoft Defender portal navigation.&lt;/SPAN&gt;&lt;/img&gt;
&lt;P&gt;An ISOC workspace is required for broader data ingestion and workspace-dependent capabilities like UEBA, Content Hub connectors for additional data ingestion, repositories (CI/CD), and threat intelligence.&lt;/P&gt;
&lt;img&gt;Figure 2: &lt;SPAN data-teams="true"&gt;Create a workspace to unlock more capabilities.&lt;/SPAN&gt;&lt;/img&gt;
&lt;P class="lia-align-left"&gt;Additional security operations capabilities will be added to the ISOC benefit over time as they become available, giving organizations a simple path to start with what is built into Microsoft Defender and expand as their security needs evolve.&lt;/P&gt;
&lt;H2&gt;Frequently asked questions&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;1. Is ISOC a new Microsoft security product?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class=""&gt;ISOC is not a new standalone product. It is a benefit that expands the value of your existing investments in Microsoft Defender Suite, Microsoft 365 E5 and E7 investments by bringing security operations capabilities from our SIEM solution, &lt;A class="lia-external-url" href="https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-sentinel-siem?msockid=34a85b8083e96e6b32864c5b820e6f60#Industryrecognition" target="_blank" rel="noopener"&gt;Microsoft Sentinel&lt;/A&gt;, directly into Microsoft Defender.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;2. Is there a minimum seat requirement?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class=""&gt;No. There is no minimum seat threshold for eligible licenses. Standard product terms apply.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;3. What are the prerequisites to get started with ISOC?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class=""&gt;Customers need an active, eligible Microsoft Defender Suite, Microsoft 365 E5 or E7 license. An Azure subscription is required to create an ISOC workspace and use workspace-dependent capabilities.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;4. What&lt;/STRONG&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;STRONG&gt;is included in the ISOC benefit in public preview?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class=""&gt;Starting September 23, eligible Microsoft 365 E5 and E7&lt;STRONG&gt; &lt;/STRONG&gt;customers without an active Sentinel workspace will receive:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;30 days of included Microsoft Defender data retention, with 90 days planned for November 15.&lt;/LI&gt;
&lt;LI&gt;Out-of-the-box&lt;STRONG&gt; &lt;/STRONG&gt;security operations&lt;STRONG&gt; &lt;/STRONG&gt;capabilities including Case&lt;STRONG&gt; &lt;/STRONG&gt;Management,&lt;STRONG&gt; &lt;/STRONG&gt;Workbooks,&lt;STRONG&gt; &lt;/STRONG&gt;and&lt;STRONG&gt; &lt;/STRONG&gt;playbook&lt;STRONG&gt; &lt;/STRONG&gt;generation in natural&lt;STRONG&gt; &lt;/STRONG&gt;language.&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Additional Microsoft and non-Microsoft data ingestion via 500 connectors in Content Hub, UEBA, Repositories (CI/CD) and threat intelligence (requires an ISOC workspace).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;5. When can I use the $2.40/GB PAYG ingestion meter?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class=""&gt;Starting October 1, 2026, eligible customers can use the $2.40 per GB meter to ingest non-Microsoft data through more than 500 connectors. Regional pricing and other terms may vary.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;6. What should customers who already use Microsoft Sentinel do?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class=""&gt;There is no change for customers currently using Microsoft Sentinel. The current Microsoft Sentinel offering will continue to exist as is. Existing Microsoft Sentinel customers will have the choice to move to ISOC starting November 15, 2026, if they meet the relevant licensing eligibility criteria.&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Get started with ISOC in Microsoft Defender&lt;/H2&gt;
&lt;P&gt;Start with the capabilities available in Microsoft Defender, then create an ISOC workspace when your team needs broader data and workspace-dependent capabilities.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Announcement blog: &lt;A class="lia-external-url" href="https://aka.ms/ISOCannouncement" target="_blank" rel="noopener"&gt;https://aka.ms/ISOCannouncement&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Learn more about ISOC in Microsoft Defender:&amp;nbsp;&lt;A class="lia-external-url" href="https://aka.ms/ISOCDefender" target="_blank" rel="noopener"&gt;https://aka.ms/ISOCDefender&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Get started with Case management: &lt;A class="lia-external-url" href="https://aka.ms/caseindefender" target="_blank" rel="noopener"&gt;https://aka.ms/caseindefender&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Start using the security operations capabilities in Microsoft Defender: &lt;A class="lia-external-url" href="https://aka.ms/ISOC-documentation" target="_blank" rel="noopener"&gt;Documentation&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/integrated-security-operations-center-in-microsoft-defender/ba-p/4559097</guid>
      <dc:creator>TomerBrand</dc:creator>
      <dc:date>2026-09-23T16:00:00Z</dc:date>
    </item>
    <item>
      <title>Reimagining Case Management in Microsoft Defender</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/reimagining-case-management-in-microsoft-defender/ba-p/4558044</link>
      <description>&lt;H4&gt;&lt;STRONG&gt;Security work extends beyond the signal&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Identifying a threat, exposure, or data risk is only the start. Security teams still need to assign ownership, bring together the right context, coordinate investigation and response, document decisions, track actions, and maintain accountability through resolution.&lt;/P&gt;
&lt;P&gt;That work is not identical across organizations. Each team has its own responsibilities, processes, service-level commitments, and automation. Security teams need a work model they can adapt to how their organization operates, rather than forcing every security matter through a fixed workflow.&lt;/P&gt;
&lt;P&gt;The operating model is also changing as AI agents take on more investigation and response work. Analysts, automation, and agents need a shared workspace where work can be delegated, reviewed, and advanced with the right context and human oversight.&lt;/P&gt;
&lt;P&gt;Introducing the Case: the operational unit that brings together security context, people, process, automation, and actions to manage security work through resolution.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Introducing Case Management in Microsoft Defender&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;We are introducing Case Management in Microsoft Defender, starting with Incident Cases, your new home for incident response. Incident Cases bring together the familiar incident experience with powerful new case capabilities, combining alert correlation, response actions, workflow management, collaboration, automation, and lifecycle tracking in a single working experience. Incident Cases become the primary working entity for incident response in Microsoft Defender. They bring the context analysts rely on, including the attack story, alerts, affected assets, evidence, and response information, into the same workspace used to assign work, coordinate the response, track progress, and maintain the operational record.&lt;/P&gt;
&lt;P&gt;Incident Cases build on the Defender Incident experience and the customer investments around it. The result is not a separate ticket layered on top of an investigation. It is one place to understand the security matter and drive the work required to resolve it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Figure 1. An Incident Case brings investigation context and operational workflow into one experience.&lt;/EM&gt;&lt;/img&gt;
&lt;H4&gt;&lt;STRONG&gt;One workspace for the complete response&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Case Management expands the incident response experience around the work security teams need to perform, not only the information they need to review.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Adapt the workflow to how your organization operates&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Security teams can shape Case records and lifecycle management around their operating model. Custom fields and custom statuses allow teams to capture organization-specific information and reflect their processes. SLA policies track targets such as acknowledgement, escalation, and resolution times based on attributes such as status, severity, and team.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Investigate, collaborate, and act in context&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;The Incident Case keeps the investigation context and operational workflow together. Analysts can work with the attack story, alerts, assets, and evidence while managing ownership, status, findings, comments, attachments and tasks from the same Case. Case creation and updates can also trigger automation and playbooks, helping teams apply consistent handling as work progresses.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Maintain accountability from creation through closure&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Case activity provides a record of changes and actions throughout the lifecycle. Case data can also support reports and dashboards across lifecycle, ownership, status, severity, classification, and other Case attributes, giving security leaders greater visibility into how work moves through the organization.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;VIDEO: &amp;nbsp;&lt;A href="https://aka.ms/casedemovideo" target="_blank" rel="noopener"&gt;https://aka.ms/casedemovideo&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;div data-video-id="https://www.youtube.com/watch?v=r1B8SvhhYhE/1790177595426" data-video-remote-vid="https://www.youtube.com/watch?v=r1B8SvhhYhE/1790177595426" class="lia-video-container lia-media-is-center lia-media-size-large"&gt;&lt;iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2Fr1B8SvhhYhE%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3Dr1B8SvhhYhE&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2Fr1B8SvhhYhE%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" allowfullscreen="" style="max-width: 100%"&gt;&lt;/iframe&gt;&lt;/div&gt;
&lt;P&gt;&lt;EM&gt;Video 1. Analysts manage the Case lifecycle while retaining Defender investigation context.&lt;/EM&gt;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Bringing protection and operations closer together&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Case Management is part of Defender’s Integrated Security Operations Center (ISOC) experience, which unifies security operations across protection, investigation, and response. By bringing key SIEM capabilities like cases, workbooks, automation, and reporting together in one platform, Defender helps organizations strengthen security, improve operational efficiency, and build the foundation for agentic security. Learn more in the [ISOC announcement].&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Designed for work shared by people and agents&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;A href="https://www.bing.com/ck/a?!&amp;amp;&amp;amp;p=bce1e20cdad5b05c59cd7e36a91c912fa831a29fe16c8a90693a7f749091ab09JmltdHM9MTc4OTA4NDgwMA&amp;amp;ptn=3&amp;amp;ver=2&amp;amp;hsh=4&amp;amp;fclid=0c575727-a727-61c7-0ffd-4117a6e06054&amp;amp;psq=project+perception+microsoft&amp;amp;u=a1aHR0cHM6Ly93d3cubWljcm9zb2Z0LmNvbS9lbi11cy9zZWN1cml0eS9idXNpbmVzcy9haS1wb3dlcmVkLWN5YmVyc2VjdXJpdHkvcHJvamVjdC1wZXJjZXB0aW9uLWFnZW50aWMtc3lzdGVtP21zb2NraWQ9MGM1NzU3MjdhNzI3NjFjNzBmZmQ0MTE3YTZlMDYwNTQ" target="_blank" rel="noopener"&gt;Project Perception&lt;/A&gt;&amp;nbsp;introduced Microsoft's direction for an agentic security system designed for the realities of AI. Case Management is a foundational component of that vision, providing a shared operational workspace where analysts and AI agents collaborate on the same security matter, with agent work connected directly to investigation context, workflow, and human oversight.&lt;/P&gt;
&lt;P&gt;The first integration links agentic sessions to Incident Cases for the Investigation Agent workflow. From the Case, analysts can connect relevant agentic work to the investigation and see when a session requires human attention. The direction is to expand this approach to additional agentic playbooks and Case types over time.&lt;/P&gt;
&lt;P&gt;As analysts delegate more work to agents, the Case can provide the shared context in which people, automation, and agents contribute to the same security outcome, with human review remaining part of the workflow.&lt;/P&gt;
&lt;img&gt;&lt;SPAN data-teams="true"&gt;&lt;EM&gt;Figure 2. The analyst stays in control of the agentic security workflows happening in the case.&lt;/EM&gt;&lt;/SPAN&gt;&lt;/img&gt;
&lt;P&gt;Looking ahead, this foundation can extend to additional agentic playbooks and Case types—from exposure remediation to threat intelligence—while preserving the context, participants, and processes each workflow requires.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Built for a smooth transition from Incidents&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Incident Cases are designed to preserve existing customer workflows and investments while introducing the Case experience.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Existing Incident-based workbooks, workflows, automations, playbooks (logic apps), and integrations continue to function with Incident Cases.&lt;/LI&gt;
&lt;LI&gt;Existing Incident APIs continue to work on top of the Case schema. New Case-only properties are available through the Case API.&lt;/LI&gt;
&lt;LI&gt;Incident Cases use the existing Incident role-based access control model, with Incident permissions and scoping carried over to Cases.&lt;/LI&gt;
&lt;LI&gt;Each Incident Case has a one-to-one mapping with an Incident during this phase, and no manual migration or reconfiguration is required to begin using the Case experience.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Detailed compatibility and transition guidance are available in &lt;A href="https://aka.ms/caselearningdocs" target="_blank" rel="noopener"&gt;Microsoft Learn&lt;/A&gt;, including information for APIs, automation, reporting, permissions, and integrations.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Availability and get started&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Incident Cases in Microsoft Defender will be available in public preview beginning September 23,2026.&lt;/P&gt;
&lt;P&gt;To learn more and start using Case Management:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/caselearningdocs" target="_blank" rel="noopener"&gt;Microsoft Learn: Case Management in Microsoft Defender&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/casedemovideo" target="_blank" rel="noopener"&gt;Watch the Case Management demo&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/ISOCannouncement" target="_blank" rel="noopener"&gt;Read the Integrated Security Operations Center (ISOC) announcement&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;&lt;A href="https://www.bing.com/ck/a?!&amp;amp;&amp;amp;p=bce1e20cdad5b05c59cd7e36a91c912fa831a29fe16c8a90693a7f749091ab09JmltdHM9MTc4OTA4NDgwMA&amp;amp;ptn=3&amp;amp;ver=2&amp;amp;hsh=4&amp;amp;fclid=0c575727-a727-61c7-0ffd-4117a6e06054&amp;amp;psq=project+perception+microsoft&amp;amp;u=a1aHR0cHM6Ly93d3cubWljcm9zb2Z0LmNvbS9lbi11cy9zZWN1cml0eS9idXNpbmVzcy9haS1wb3dlcmVkLWN5YmVyc2VjdXJpdHkvcHJvamVjdC1wZXJjZXB0aW9uLWFnZW50aWMtc3lzdGVtP21zb2NraWQ9MGM1NzU3MjdhNzI3NjFjNzBmZmQ0MTE3YTZlMDYwNTQ" target="_blank" rel="noopener"&gt;Read the Project Perception announcement&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 23 Sep 2026 15:35:09 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/reimagining-case-management-in-microsoft-defender/ba-p/4558044</guid>
      <dc:creator>Yaron_Abershitz</dc:creator>
      <dc:date>2026-09-23T15:35:09Z</dc:date>
    </item>
    <item>
      <title>Stop identity attacks before they start with Microsoft ISPM recommendations</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/stop-identity-attacks-before-they-start-with-microsoft-ispm/ba-p/4549692</link>
      <description>&lt;P&gt;Many major breaches involve compromised identities, excessive privileges, or misconfigured access. Long before ransomware detonates or data leaves the building, adversaries are quietly abusing valid accounts, excessive privileges or other misconfigurations to move deeper into the environment. Identity has become one of the most important attack surfaces you defend.&lt;/P&gt;
&lt;P&gt;That is why Microsoft has a dedicated team of researchers who study how identity attacks actually happen. Just as important, we turn what they learn into action. Real attacker behavior becomes concrete recommendations you can use to harden your environment before an attack begins. With Microsoft Defender, that research reaches you as Identity Security Posture Management (ISPM) recommendations: prioritized guidance that tells you what to fix, why it matters, and how to remediate it.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;What are identity security posture recommendations?&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Identity security posture recommendations are prioritized, attack-driven recommendations that address the weaknesses attackers exploit most, from overprivileged accounts to weak credentials and risky permissions. Rather than handing you a long hygiene checklist, ISPM recommendations tie each recommendation to a real attack technique. That shifts the question from "what setting do I need to change?" to "what attack am I going to prevent today?"&lt;/P&gt;
&lt;P&gt;That framing also changes how you prioritize. You can start with the fixes that close the most dangerous attack paths first, not just the ones that are quickest to clear. It gives identity admins and the SOC and others shared view of the same risk, and as our researchers uncover new techniques, the recommendations evolve, so your posture keeps pace with the threat.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;H4&gt;&lt;STRONG&gt;New recommendations&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;We are excited to announce five new ISPM recommendations geared toward emerging attack patterns you need to be aware of:&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;Ensure no privileged SaaS app accounts exist outside of IdP control&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;Most SaaS platforms let you create admin accounts directly inside the app, separate from your corporate identity provider (IdP). Those local admins are convenient, but they sit outside the protections every other identity relies on: No outside centrally managed identity controls as Conditional Access, and little to no monitoring. Attackers know it. We’ve seen a rise in SaaS data-exfiltration campaigns that specifically hunt for these app-native admin accounts, because once they find one they can sign in and operate without tripping any of your usual defenses.&lt;/P&gt;
&lt;P&gt;This recommendation surfaces those accounts so you can bring them under your identity provider, where you can manage them with single sign-on, multifactor authentication, Conditional Access, and lifecycle governance apply automatically and where your SOC can finally see them.&lt;/P&gt;
&lt;P&gt;This attack pattern aligns with MITRE ATT&amp;amp;CK techniques including Valid Cloud Accounts (T1078.004) and Account Manipulation (T1098).&lt;/P&gt;
&lt;img /&gt;
&lt;H5&gt;&lt;STRONG&gt;Ensure service accounts are not assigned Domain Admin or Global Admin roles&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;Service accounts run your apps and integrations, and because they are not tied to a person, they are easy to over-provision and easy to forget. When one is assigned Domain Admin or Global Admin, it becomes a quiet path to the top of your environment. Supply-chain intrusions like SolarWinds showed how attackers ride a trusted service identity straight into the highest levels of access, often without anyone noticing, because no one watches a service account the way they watch a user.&lt;/P&gt;
&lt;P&gt;This recommendation flags service accounts holding those top-tier roles so you can right-size them. It shrinks the blast radius if one is ever compromised and keeps a non-human account from becoming a hidden administrative backdoor.&lt;/P&gt;
&lt;P&gt;This attack pattern aligns with MITRE ATT&amp;amp;CK techniques including Valid Accounts: Domain Accounts (T1078.002) and Cloud Accounts (T1078.004)&lt;/P&gt;
&lt;img /&gt;
&lt;H5&gt;&lt;STRONG&gt;Ensure non-admin accounts cannot reset passwords for sensitive groups&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;Sometimes a standard user account quietly holds the ability to reset passwords for members of a sensitive group, a leftover of delegated permissions no one revisited. On paper that user is low privilege. In practice they are one password reset away from becoming an administrator. Attackers look for exactly this kind of shadow admin: compromise an unremarkable account, reset a privileged password, and walk in through the front door, no exploit required.&lt;/P&gt;
&lt;P&gt;This recommendation finds those unintended password-reset rights over sensitive groups and helps you remove them, closing a direct path from ordinary user to full administrator.&lt;/P&gt;
&lt;P&gt;This attack pattern aligns with MITRE ATT&amp;amp;CK techniques as Account Manipulation (T1098)&lt;/P&gt;
&lt;img /&gt;
&lt;H4&gt;&lt;STRONG&gt;Ensure non-admin identities cannot have WriteDACL permissions on sensitive groups&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Deep in Active Directory, some permissions can be abused to grant additional rights and gain control of a sensitive group. One of them, the right to modify an object's access control list (known as WriteDACL), is especially dangerous in the wrong hands. If a non-admin identity holds it over a sensitive group, that identity can simply rewrite the group's permissions and grant itself privileged control. It is one of the most reliable escalation paths attackers use.&lt;/P&gt;
&lt;P&gt;This recommendation identifies non-admin identities with that permission over sensitive groups so you can strip it, eliminating a well-worn route from a regular account to Domain Admin.&lt;/P&gt;
&lt;P&gt;This attack pattern aligns with MITRE ATT&amp;amp;CK techniques as Account Manipulation (T1098)&lt;/P&gt;
&lt;img /&gt;
&lt;H4&gt;&lt;STRONG&gt;Ensure external and guest accounts are not granted privileged roles&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Guest and external accounts make collaboration easy, but they live partly outside your control. Their security depends on another organization's hygiene, and they blend in, which makes them an attractive target. When one of these accounts is also granted a privileged role, a single compromise on the other side of that relationship becomes a privileged foothold inside your tenant.&lt;/P&gt;
&lt;P&gt;This recommendation highlights external and guest identities holding sensitive roles so you can remove that access, preventing an outside account from being used for persistence, escalation, or reaching your data.&lt;/P&gt;
&lt;P&gt;This attack pattern aligns with MITRE ATT&amp;amp;CK techniques as Valid Cloud Accounts (T1078.004) and Account Manipulation Cloud Roles (T1098.003)&lt;/P&gt;
&lt;img /&gt;
&lt;H4&gt;&lt;STRONG&gt;Additional high-impact identity posture recommendations&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;In addition to the five new recommendations, several existing ISPM recommendations remain especially important. We continue to see attackers exploit the weaknesses they address, which makes them high-value fixes for strengthening your identity posture.&lt;/P&gt;
&lt;P&gt;Here is why each one still earns priority.&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;Remove dormant accounts from sensitive groups&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;A privileged account no one uses is a gift to an attacker. It still carries powerful access, but because nobody signs into it, nobody notices when someone else does. Ransomware crews and intrusion groups seek out these forgotten admin accounts precisely because they can operate from one for weeks without raising suspicion. Removing dormant privileged accounts takes that stealthy, high-impact option off the table before it is ever used.&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;Reduce lateral movement path risk to sensitive entities&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;Reduce lateral movement path risk to sensitive entities helps close one of the most common ways identity attacks become domain-wide compromises: an attacker starts with a non-sensitive account, then follows permissions, group memberships, local admin rights, active sessions, or other identity relationships until they can reach highly sensitive credentials. This maps to well-known lateral movement and privilege escalation techniques, where adversaries abuse excessive permissions or exposed credential paths to move from an initial foothold toward Domain Admin or another high-value identity. This recommendation highlights exposed entities with risky lateral movement paths and provides remediation guidance to reduce the number of non-sensitive accounts on each path. By removing unnecessary privileges and memberships, teams can shrink the attack graph around sensitive entities and prevent a small compromise from becoming a privileged identity breach&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;Use least privileged administrative role&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;Use least privileged administrative roles in Microsoft Entra ID reduces the blast radius of a compromised admin account. In many identity attacks, adversaries first gain access through phishing, password spray, or stolen credentials, then abuse valid cloud accounts to escalate privileges, create persistence, or access sensitive data. This maps to the known attack technique Valid Accounts where an attacker uses a legitimate account’s assigned permissions instead of malware or exploits. Assigning narrow, task-specific admin roles instead of broad roles like Global Administrator limits what an attacker can do if that account is compromised and makes privilege escalation harder.&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;Ensure Sign-in frequency is enabled and browser sessions are not persistent for Administrative users&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;Ensure Sign-in frequency is enabled and browser sessions are not persistent for Administrative users reduces the window of opportunity after an admin session is stolen. This maps to known session-theft techniques such as Steal Web Session Cookie and Web Session Cookie, where adversaries use stolen authentication cookies to access cloud services as an already-authenticated user, sometimes bypassing MFA because the session was established before the theft. By requiring admins to reauthenticate more often and preventing persistent browser sessions, organizations make stolen sessions expire sooner and reduce the chance that a compromised admin browser session becomes long-lived access to sensitive systems.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Stay ahead of attackers&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Attackers keep evolving, so your identity posture has to evolve with them. The strongest defense is not a one-time cleanup, it is continuously closing the gaps attackers depend on, from stolen credentials to excessive privilege and lateral movement. That is exactly what ISPM recommendations are built to help you do, turning live attacker research into clear actions you can take today.&lt;/P&gt;
&lt;P&gt;In the Microsoft Defender portal, review your ISPM recommendations, start with the five new proactive exposures, and prioritize the highest-risk attack paths first. Every path you close is one an attacker cannot take.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Next steps&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Start by reviewing your identity security posture recommendations in the Microsoft Defender portal under&amp;nbsp;&lt;STRONG&gt;Exposure management &amp;gt; Recommendations&lt;/STRONG&gt;. Prioritize recommendations that expose privileged identities, sensitive groups, service accounts, or attack paths to critical assets, then remediate unnecessary privileges, delegated permissions, and unmanaged identity access.&lt;/P&gt;
&lt;P&gt;To explore your Microsoft Identity Security Posture Management (ISPM) recommendations, see: &lt;A href="https://security.microsoft.com/exposure-secure-scores" target="_blank"&gt;https://security.microsoft.com/exposure-secure-scores&lt;/A&gt;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Documentation&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;For more details as licensing and prerequisites, see:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/security-assessment" target="_blank"&gt;Microsoft Defender for Identity security posture assessments - Microsoft Defender for Identity | Microsoft Learn&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/stop-identity-attacks-before-they-start-with-microsoft-ispm/ba-p/4549692</guid>
      <dc:creator>adipavekatz</dc:creator>
      <dc:date>2026-09-01T16:00:00Z</dc:date>
    </item>
    <item>
      <title>Monthly News-August 2026</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/monthly-news-august-2026/ba-p/4544388</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Microsoft Defender&lt;/STRONG&gt;&lt;BR /&gt;Monthly news - August 2026 Edition&lt;/P&gt;
&lt;P&gt;This is our monthly "What's new" blog post, summarizing product updates and various new assets we released over the past month across our Defender products. In this edition, we are looking at all the goodness from July 2026. We are now including news related to Defender for Cloud in the Defender portal. For all other Defender for Cloud news, have a look at the dedicated Defender for Cloud Monthly News&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/microsoft-defender-for-cloud-customer-newsletter/4525656" target="_blank" rel="noopener"&gt;here&lt;/A&gt;&lt;STRONG&gt;.&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;🚀 New Virtual Ninja Show episode:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://youtu.be/17qtl8RSFKA?si=_O1CgQpNJtQgk_dY" target="_blank" rel="noopener"&gt;Redefining identity security for the modern enterprise&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://youtu.be/I24oxM6rL6E?si=rgXUPok9_jVu0SsQ" target="_blank" rel="noopener"&gt;One policy engine to govern them all: Securing agentic AI with Microsoft Purview&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://youtu.be/q_7IXnBwv8c?si=94-NKofzzGx-3HkG" target="_blank" rel="noopener"&gt;Building a modern detection pipeline with ContentOps&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://youtu.be/SzTEY3sY3lA?si=HJV1MKD8tJ63_EQT" target="_blank" rel="noopener"&gt;Securing local AI agents with Microsoft Defender&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://youtu.be/AnQiZZkZO0s?si=xOnPdLRegN-RHbyh" target="_blank" rel="noopener"&gt;Microsoft Defender: Extending critical protection for emerging threats in Team&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Actionable threat insights&lt;/STRONG&gt;&amp;nbsp;(find all of them&amp;nbsp;&lt;A href="https://www.microsoft.com/en-us/security/blog/content-type/research/?ep_filter_topic=actionable-threat-insights" target="_blank" rel="noopener"&gt;here&lt;/A&gt;)&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/" target="_blank" rel="noopener"&gt;Email threat landscape: Q2 2026 trends and insights&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2026/07/27/enhancing-ai-security-through-global-ai-red-teaming/" target="_blank" rel="noopener"&gt;Enhancing AI security through global AI red teaming&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2026/07/16/least-privilege-for-ai-agents-identity-access-and-tool-binding/" target="_blank" rel="noopener"&gt;Least privilege for AI agents: Identity, access, and tool binding&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Defender&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;(Public Preview) &lt;STRONG&gt;Microsoft Defender now assesses posture risk for AI agents&lt;/STRONG&gt;, including enterprise agents and local agents discovered on endpoint devices. Risk levels are based on active risk indicators, such as configuration, access, runtime activity, endpoint and user context, and active alerts. Security teams can use posture risk and recommendations to prioritize risky agents and improve agent security posture. For more information, &lt;A href="https://learn.microsoft.com/en-us/defender-xdr/security-for-ai/ai-agent-risk-assessment" target="_blank" rel="noopener"&gt;see AI agent posture risk in Microsoft Defender&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;(Generally available) The Domain investigation page allows you to investigate an Active Directory domain. It shows Active Directory domain security, including domain properties, deployment health, identity summary, service account breakdown, sensitive entities, active recommendations, group policies, and trust relationships. For more information, see &lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/investigate-domain" target="_blank" rel="noopener"&gt;Investigate a domain&lt;/A&gt; .&lt;/LI&gt;
&lt;LI&gt;(Generally available) &lt;STRONG&gt;With a Microsoft Agent 365 license, Microsoft Defender provides discovery, security posture, threat detection and investigation, and real-time protection for the AI agents in your tenant&lt;/STRONG&gt;. Onboarding includes enabling data collection, connecting the Microsoft 365 app connector, and connecting Copilot Studio for real-time protection of Copilot Studio agents. For more information, see &lt;A href="https://learn.microsoft.com/en-us/defender-xdr/security-for-ai/defender-security-for-ai#protect-ai-agents-using-microsoft-defender" target="_blank" rel="noopener"&gt;Protect AI agents using Microsoft Defender&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;(Generally available) &lt;STRONG&gt;Improved access to Playbook Generator&lt;/STRONG&gt;: Following the GA release of Playbook Generator May 31st, the team focused on streamlining the onboarding experience and reducing friction related to Security Copilot wallet provisioning. Playbook Generator remains included with Microsoft Sentinel and does not consume SCUs for generating, testing, or running playbooks, yet customer feedback highlighted friction around Security Copilot wallet provisioning and initial setup requirements. The team worked on simplifying access and reducing onboarding barriers so organizations can more quickly take advantage of AI-assisted playbook creation, testing, and automation capabilities.&lt;/LI&gt;
&lt;LI&gt;For all other Sentinel News, have a look at the "&lt;A href="https://techcommunity.microsoft.com/blog/microsoftsentinelblog/what%E2%80%99s-new-in-microsoft-sentinel-july-2026/4542130" target="_blank" rel="noopener"&gt;What's new in Microsoft Sentinel blog post - July edition&lt;/A&gt;"&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Identity Security&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;(Generally available) &lt;STRONG&gt;Migration&lt;/STRONG&gt; of Defender for Identity sensors from&lt;STRONG&gt; v2.x to v3.x is now generally available&lt;/STRONG&gt;. For more information, see &lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/deploy/migrate-to-sensor-v3" target="_blank" rel="noopener"&gt;Migrate to Defender for Identity sensor v3.x&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Migration readiness reasons on the Sensors page&lt;/STRONG&gt;: When a server is marked Not ready for migration on the Sensors page, you can now hover over the status to see a tooltip that lists the specific reasons the server doesn't meet the migration prerequisites. For more information, see &lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/deploy/migrate-to-sensor-v3#troubleshoot-not-ready-for-migration-status" target="_blank" rel="noopener"&gt;Troubleshoot "Not ready for migration" status&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;(Public Preview) &lt;STRONG&gt;Expanded SaaS app support in Password protection&lt;/STRONG&gt;. The Password protection page &lt;STRONG&gt;now includes password risks from SaaS apps&lt;/STRONG&gt; connected through Defender for Cloud Apps, in addition to Active Directory, Microsoft Entra ID, and Okta. SaaS apps that support SaaS Security Posture Management (SSPM), such as Salesforce and ServiceNow, appear on the Password Hygiene and Password Policies tabs. Each SaaS app requires a Defender for Cloud Apps app connector. For more information, see &lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/password-protection" target="_blank" rel="noopener"&gt;Investigate identity password protection&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;The Password Protection Page&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Automatic RPC auditing on domain controllers&lt;/STRONG&gt;: Defender for Identity now automatically enables RPC auditing on domain controllers when you upgrade to sensor version 3.0.8 or later. You no longer need to apply a tag manually to enable RPC auditing. For more information, see &lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/deploy/deploy-sensor-v3#configure-rpc-auditing" target="_blank" rel="noopener"&gt;Configure RPC auditing&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Defender Experts MDR&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;General Availability of Microsoft Defender Experts MDR P2&lt;/STRONG&gt;: Microsoft Defender Experts MDR (formerly Microsoft Defender Experts for XDR) is expanding with new third-party and multi-cloud coverage powered by Microsoft Sentinel, with the launch of Defender Experts MDR P2 service. Defender Experts MDR provides a 24/7 managed detection and response service that reduces noise, adds expert context, and drives action. In addition to the Microsoft Defender products, this new service supports key non-Microsoft sources across cloud (AWS), identity (Okta), email (Proofpoint), network (Palo Alto Networks, Cisco, Fortinet, ZScaler), and endpoint (CrowdStrike) that are ingested in Microsoft Sentinel, providing E2E visibility and protection for customers operating heterogenous environments. Defender Experts will continue expanding our scope to other non-Microsoft products to deliver on this promise. For more information, see the Microsoft Defender Experts MDR documentation.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Security Exposure Management / Defender Vulnerability Management&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;(Private Preview) &lt;STRONG&gt;Codename MDASH - Agentic code scanner is now available in private preview&lt;/STRONG&gt; in Microsoft Security Exposure Management. Codename MDASH uses a multi-model agentic AI system to detect code vulnerabilities with greater depth and accuracy than traditional static analysis. Security teams can run scans from Defender CLI or through a GitHub connector, review findings in the Defender portal, and use results to help prioritize code security risks. For more information, see &lt;A href="https://learn.microsoft.com/en-us/security-exposure-management/ai-code-security-overview" target="_blank" rel="noopener"&gt;Agentic code security overview&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;(Private Preview) &lt;STRONG&gt;Codename MDASH - MAI-Augmented scan profile private preview. &lt;/STRONG&gt;The MAI-Augmented scan profile is now available in preview as part of Codename MDASH. The MAI-Augmented profile can be used when triggering a scan through the Defender CLI. It includes MAI-Cyber-1-Flash, a new cyber-specialized model that extends the current agentic scanner in addition to the existing required models. Security teams can choose this profile when triggering a scan from Defender CLI or continue using a scan profile based on the existing models. For more information, see&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/security-exposure-management/defender-cli#scan-with-a-model-profile-preview" target="_blank" rel="noopener"&gt;Scan with a scan profile&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;OT data connectors in Microsoft Security Exposure Management&lt;/STRONG&gt;: Microsoft Security Exposure Management now supports operational technology (OT) data connectors for Armis, Dragos, and Forescout. OT data connectors bring OT asset and vulnerability data from supported third-party OT platforms into the Defender portal. This helps security teams view OT devices alongside other assets, enrich device inventory with OT context, and investigate vulnerabilities across IT and OT environments. For more information, see &lt;A href="https://learn.microsoft.com/en-us/security-exposure-management/ot-data-connectors" target="_blank" rel="noopener"&gt;OT data connectors&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Defender for Endpoint&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;(Public Preview)&amp;nbsp;&lt;STRONG&gt;AI agent runtime protection includes these enhancements&lt;/STRONG&gt;: - Vendor-supported agent event interfaces now work with standard platform and engine update channels, so no Beta channel configuration is required. Agent-native event inspection now supports Codex CLI and the GitHub Copilot app. - Network inspection is now supported for agents that don't expose vendor-supported event interfaces, including OpenClaw and similar Node.js-based Claw agents. For more information, see &lt;A href="https://learn.microsoft.com/en-us/defender-endpoint/ai-agent-runtime-protection-overview" target="_blank" rel="noopener"&gt;AI agent runtime protection with Defender for Endpoint&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;(Generally available) Available from Defender for Endpoint on Linux version 101.26042.0011 and later. The &lt;A href="https://learn.microsoft.com/en-us/defender-endpoint/linux-install-with-defender-deployment-tool" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Defender Deployment Tool for Linux&lt;/STRONG&gt;&lt;/A&gt; simplifies deployment by combining installation, onboarding, upgrades, and uninstallation into a single workflow. The tool automates prerequisite validation, supports custom installation paths, enables deployment of specific Defender versions from preferred update channels, and works seamlessly in environments that use local repositories. In addition to a simplified deployment experience, customers can now gain complete visibility into deployment progress through Device Timeline integration, providing step-by-step installation, upgrade, and onboarding status, Advanced Hunting queries for fleet-wide deployment monitoring, and detailed error reporting, including deployment stage, status, exit code, and failure reason to simplify troubleshooting. These capabilities help administrators quickly identify deployment issues, track onboarding progress, and understand deployment outcomes across their Linux estate.&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;The Defender for Endpoint Onboarding page&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Defender for Office 365&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Unified RBAC is the default permission model for new Defender for Office 365 Plan 2 organizations&lt;/STRONG&gt;. Starting July 2026, new Defender for Office 365 Plan 2 organizations use the Microsoft Defender unified role-based access control (Unified RBAC) model by default. For more information, see &lt;A href="https://learn.microsoft.com/en-us/defender-office-365/step-by-step-guides/configure-unified-rbac-defender-office-365" target="_blank" rel="noopener"&gt;Configure Unified RBAC for Defender for Office 365 and MC1246006&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft 365 E3 now includes Microsoft Defender for Office 365 Plan 1&lt;/STRONG&gt;. For more information about what's included in each plan, see &lt;A href="https://learn.microsoft.com/en-us/defender-office-365/mdo-about#defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank" rel="noopener"&gt;Microsoft Defender for Office 365 Plan 1 vs. Plan 2 cheat sheet&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;Prompt injection protection: &lt;STRONG&gt;Defender for Office 365 now detects prompt injection attacks&lt;/STRONG&gt; hidden in inbound email. For more information, see &lt;A href="https://learn.microsoft.com/en-us/defender-office-365/step-by-step-guides/prompt-injection-protection-defender-for-office-365" target="_blank" rel="noopener"&gt;Prompt injection protection in Defender for Office 365&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2026 22:15:47 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/monthly-news-august-2026/ba-p/4544388</guid>
      <dc:creator>EdFisher</dc:creator>
      <dc:date>2026-08-05T22:15:47Z</dc:date>
    </item>
    <item>
      <title>Detecting CVE-2026-54121 (Certighost) with Microsoft Defender</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/detecting-cve-2026-54121-certighost-with-microsoft-defender/ba-p/4542861</link>
      <description>&lt;H1&gt;What is CVE-2026-54121?&lt;/H1&gt;
&lt;P&gt;CVE-2026-54121 is an authentication-bypass vulnerability in Active Directory Certificate Services that allows an attacker to obtain certificates for arbitrary domain computer accounts, including Domain Controllers. A valid Domain Controller certificate enables escalation to full domain compromise: it can be used to obtain Kerberos tickets that authenticate the attacker as a Domain Controller. Those tickets can then be used to perform attacks such as DCSync, or to recover the Domain Controller's password hash for later use.&lt;/P&gt;
&lt;P&gt;The flaw lies in an AD CS enrollment fallback known as a chase, which occurs when the CA cannot resolve the requester. In such cases, the vulnerable CA contacts a client-supplied Domain Controller, specified in the cdc attribute, to retrieve fresher identity data and incorporates the response into the issued certificate, without verifying that it is communicating with a legitimate Domain Controller. The chase fallback occurs only for templates that require a DNS name, and only on CAs with the EDITF_ENABLECHASECLIENTDC flag enabled.&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;A public proof of concept was released on July 24, 2026. Microsoft has not observed confirmed threat-actor exploitation, and the activity seen so far appears consistent with security testing. Organizations with affected AD CS configurations should apply the July 14 security update. Organizations should identify exposed Certificate Services hosts, confirm whether the required environmental conditions exist, enable the recommended AD CS auditing, and monitor for the suspicious authentication and certificate-enrollment activity described below.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54121" target="_blank" rel="noopener"&gt;More details about VCE-2026-54121 can be found here&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;
&lt;H1&gt;What to do&lt;/H1&gt;
&lt;P&gt;The response follows a simple order: know your exposure, patch it, instrument it, and watch for the activity.&lt;/P&gt;
&lt;H3&gt;1. Identify affected systems&lt;/H3&gt;
&lt;P&gt;Certighost affects Windows Server 2012 through Windows Server 2025, including Server Core installations, but several conditions must all be present for a given environment to be exploitable:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;An Enterprise Certification Authority integrated with Active Directory&lt;/LI&gt;
&lt;LI&gt;Enrollment through the machine certificate template&lt;/LI&gt;
&lt;LI&gt;A default ms-DS-MachineAccountQuota value, or a machine account already controlled by the attacker&lt;/LI&gt;
&lt;LI&gt;Network reachability between the Certification Authority and the attacker's host over SMB and LDAP&lt;/LI&gt;
&lt;LI&gt;A valid domain account, with no administrative privileges required&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;2. Patch&lt;/H3&gt;
&lt;P&gt;The primary and durable remediation is the July 14, 2026 security update, applied to every AD CS host that runs an Enterprise Certification Authority. The update validates the lookup target before the Certification Authority contacts it, rejecting invalid or attacker-controlled targets before enrollment continues. Nothing else in this post replaces patching. The monitoring below gives you defense in depth and visibility, not an alternative to the fix.&lt;/P&gt;
&lt;H3&gt;3. Turn on AD CS auditing&lt;/H3&gt;
&lt;P&gt;The certificate request and issuance activity at the center of this attack is only useful to defenders if it is being recorded, and AD CS certificate services auditing is not enabled by default. With it on, the same events power detection and investigation across Microsoft Defender, and Kerberos authentication telemetry requires no additional configuration.&lt;/P&gt;
&lt;P&gt;Organizations that have Microsoft Defender for Identity sensors installed on their AD CS servers and have completed the required sensor configuration can typically skip this step, as the necessary Certificate Services auditing settings are already enabled as part of the deployment prerequisites.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Enabling AD CS auditing takes two settings:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Turn on the Certification Services audit subcategory.&lt;/STRONG&gt; Under Advanced Audit Policy, Object Access, enable success and failure for Certification Services. Set it through Group Policy, or with auditpol:&lt;/P&gt;
&lt;LI-CODE lang=""&gt;auditpol /set /subcategory:"Certification Services" /success:enable /failure:enable&lt;/LI-CODE&gt;
&lt;P&gt;&lt;STRONG&gt;Set the Certification Authority audit filter.&lt;/STRONG&gt;&amp;nbsp;In the Certification Authority console this is the Auditing tab; it can also be set with certutil, followed by a service restart:&lt;/P&gt;
&lt;LI-CODE lang=""&gt;certutil -setreg CA\AuditFilter 127
Restart-Service CertSvc -Force&lt;/LI-CODE&gt;
&lt;P&gt;With both in place, the Certification Authority records Security log events for certificate lifecycle operations, including event 4886 when a certificate request is received and event 4887 when a request is approved and a certificate is issued. Each event captures the requester, the template used, and the request disposition. For Certighost, this is the record that makes the abuse visible: a certificate issued for a Domain Controller identity, requested through a machine template by a low-privileged principal, is an issuance pattern that should never occur normally, and these events let defenders detect it, investigate it, and correlate it with the PKINIT authentication and DCSync activity that follow.&lt;/P&gt;
&lt;P&gt;For complete guidance, see &lt;A href="https://learn.microsoft.com/defender-for-identity/deploy/configure-windows-event-collection" target="_blank" rel="noopener"&gt;Configure Windows event auditing — Microsoft Defender for Identity&lt;/A&gt;.&lt;/P&gt;
&lt;H3&gt;4. Watch for alerts&lt;/H3&gt;
&lt;P&gt;Attempts to exploit this vulnerability are detected by Microsoft Defender for Identity with the alert :&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;"Potential Certighost (CVE-2026-54121) AD CS abuse."&lt;/STRONG&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;The alert fires on the malicious certificate requests crafted to exploit this flaw, the anomalous issuance pattern at the heart of the technique, so you do not need to author a custom rule to catch the core activity. Ensure Defender for Identity is deployed on your domain controllers and AD CS servers and treat this alert as high priority.&lt;/P&gt;
&lt;img&gt;Example of Potential Certighost (CVE-2026-54121) AD CS abuse alert within Microsoft Defender&lt;/img&gt;
&lt;P&gt;Because the exploitation chain touches several stages of an identity attack, you may also see supporting alerts that commonly appear alongside this activity, though on their own they do not confirm a Certighost attempt:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Security principal reconnaissance (LDAP)&lt;/LI&gt;
&lt;LI&gt;Suspicious Active Directory Certificate Services abuse tool activity&lt;/LI&gt;
&lt;LI&gt;Suspected suspicious Kerberos ticket request&lt;/LI&gt;
&lt;LI&gt;DCSync attack (replication of directory services)&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;Learn more&lt;/H1&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54121" target="_blank" rel="noopener"&gt;CVE-2026-54121 — Security Update Guide, Microsoft (Active Directory Certificate Services Elevation of Privilege Vulnerability)&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/defender-for-identity/deploy/configure-windows-event-collection" target="_blank" rel="noopener"&gt;Configure Windows event auditing — Microsoft Defender for Identity&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;To stay on top of the latest Defender for Identity capabilities, follow our &lt;A href="https://learn.microsoft.com/defender-for-identity/whats-new" target="_blank" rel="noopener"&gt;What's New&lt;/A&gt; documentation page.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jul 2026 17:41:07 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/detecting-cve-2026-54121-certighost-with-microsoft-defender/ba-p/4542861</guid>
      <dc:creator>EdanZwick</dc:creator>
      <dc:date>2026-07-31T17:41:07Z</dc:date>
    </item>
    <item>
      <title>MDTI convergence in Microsoft Sentinel and Defender XDR is complete</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/mdti-convergence-in-microsoft-sentinel-and-defender-xdr-is/ba-p/4541279</link>
      <description>&lt;P&gt;Beginning August 1, the final phase of Microsoft Defender Threat Intelligence (MDTI) convergence will be generally available in the Defender portal, giving customers real-time Microsoft threat intelligence across detection, investigation, response, hunting, and automation at no additional cost. Announced last year, &lt;A href="https://techcommunity.microsoft.com/blog/defenderthreatintelligence/mdti-is-converging-into-microsoft-sentinel-and-defender-xdr/4427991" target="_blank" rel="noopener"&gt;this unified SecOps experience&lt;/A&gt; reduces fragmented context and tool handoffs, creating a clearer path from threat signal to informed action.&lt;/P&gt;
&lt;H3&gt;Latest features converging&lt;/H3&gt;
&lt;H4&gt;Entity enrichments: all the intel, right where you need it&lt;/H4&gt;
&lt;P&gt;Defender entity pages surface threat intelligence enrichments in the Threat Intelligence Insights tab for IP addresses, domains, URLs, and files. This unified view combines reputation data and scores, attributed reports, infrastructure relationships, services, certificates, DNS and WHOIS records, trackers, cookies, and sandbox analysis, helping analysts assess risk and investigate incidents without switching tabs. For more information, see&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-xdr/entity-page-threat-intelligence" target="_blank" rel="noopener"&gt;View threat intelligence in entity pages&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Screenshot of the Threat Intelligence Insights tab under Threat Analytics in the Defender portal showing reputation risk.&lt;/EM&gt;&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Screenshot of the Threat Intelligence Insights tab under Threat Analytics in the Defender portal showing WHOIS records.&lt;/EM&gt;&lt;/img&gt;
&lt;H4&gt;MDTI Sentinel data connectors and APIs&lt;/H4&gt;
&lt;P&gt;Microsoft Threat Intelligence data that previously required the Premium MDTI connector is now available through the free Microsoft Threat Intelligence connector in Sentinel, enabling free and premium indicator feeds through one setup. MDTI APIs are also available by default to Microsoft Defender XDR and Microsoft Sentinel customers, without a separate MDTI license SKU, so teams can enrich investigations through Sentinel or external SIEM, SOAR, and automation tools.&lt;/P&gt;
&lt;P&gt;As a reminder, the API surface remains unchanged, and no customer migration is required. Customers do not need to perform endpoint mapping, code changes, tooling changes, or cutover activities.&lt;/P&gt;
&lt;H3&gt;Features previously released&lt;/H3&gt;
&lt;H4&gt;Threat Intelligence Library&lt;/H4&gt;
&lt;P&gt;Microsoft’s threat actor profiles, intelligence reports, OSINT articles, MSTIC and MTP research, and indicators of compromise (IoCs) are now available through &lt;A href="https://learn.microsoft.com/defender-xdr/threat-analytics" target="_blank" rel="noopener"&gt;Threat Analytics&lt;/A&gt; in the Defender portal, at no additional cost beyond the existing license.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Screenshot of the Threat Analytics dashbaord in the Defender portal.&lt;/EM&gt;&lt;/img&gt;
&lt;H4&gt;Threat Analytics Enhancements&lt;/H4&gt;
&lt;P&gt;Reports now bring together embedded IoCs, MITRE ATT&amp;amp;CK mappings, targeted industries, actor origins, and automatic incident correlation, so defenders can move from reading intelligence to applying it in investigations.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Screenshot of the Threat Analytics page in the Defender portal showing actor profile overview.&lt;/EM&gt;&lt;/img&gt;
&lt;H4&gt;Case Linking&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Security teams can link investigation cases directly to relevant IoCs, making it easier to document findings, collaborate across response workflows, and show how intelligence informed action.&lt;/P&gt;
&lt;P&gt;Reference the table below to see the full list of features available with the MDTI convergence into Microsoft Defender XDR and Sentinel.&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Chart showing full list of MDTI capabilities converged into Defender XDR and Sentinel&lt;/EM&gt;&lt;/img&gt;
&lt;H3&gt;Actions for existing MDTI customers&lt;/H3&gt;
&lt;P&gt;Starting August 1, the standalone MDTI pages (Intel Profiles, Intel Explorer &amp;amp; Intel Projects) will be retired. All MDTI capabilities will be accessible via the Threat Analytics tab in the Defender portal instead of the Threat Intelligence tab. &lt;STRONG&gt;No migration action is needed&lt;/STRONG&gt;. Customers will now access the MDTI value via the Threat Analytics tab in the Defender portal instead of the Threat Intelligence tab. &lt;A href="https://learn.microsoft.com/defender-xdr/defender-threat-intelligence" target="_blank" rel="noopener"&gt;Explore our documentation&lt;/A&gt; for more details and reach out to your account team or partner if you need have questions or need assistance on how to reduce your current license and transition to this new unified threat intelligence experience in Defender XDR or Sentinel at no additional cost.&lt;/P&gt;
&lt;H3&gt;Get started&lt;/H3&gt;
&lt;P&gt;To access threat intelligence in the Microsoft Defender portal:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Go to the&amp;nbsp;&lt;A href="https://security.microsoft.com/" target="_blank" rel="noopener"&gt;Microsoft Defender portal&lt;/A&gt;&amp;nbsp;and sign in.&lt;/LI&gt;
&lt;LI&gt;Use the&amp;nbsp;&lt;STRONG&gt;Threat intelligence&lt;/STRONG&gt;&amp;nbsp;navigation menu to access Intelligence explorer and Intel profiles.&lt;/LI&gt;
&lt;LI&gt;Investigate entities enriched with threat intelligence by selecting IP addresses, domains, URLs, or files from incidents, alerts, or search results.&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Wed, 29 Jul 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/mdti-convergence-in-microsoft-sentinel-and-defender-xdr-is/ba-p/4541279</guid>
      <dc:creator>AmelieDarchicourt</dc:creator>
      <dc:date>2026-07-29T16:00:00Z</dc:date>
    </item>
    <item>
      <title>Microsoft Defender now integrates with Dragos, Forescout, &amp; Armis for OT Security</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/microsoft-defender-now-integrates-with-dragos-forescout-armis/ba-p/4534936</link>
      <description>&lt;P&gt;Co-author(s): Amit Cohen and Hadar Shindler&lt;BR /&gt;&lt;BR /&gt;Operational technology (OT) environments are unlike anything else in cybersecurity. The systems that run our factories, power grids, water treatment plants, pipelines, and transportation networks weren’t built with modern threats in mind — and they can’t simply be patched, rebooted, or scanned the way IT systems can. A misstep doesn’t just create an alert backlog; it can stop a production line, disrupt critical services, or put physical safety at risk.&lt;/P&gt;
&lt;P&gt;To support customers in bringing their OT security solutions into their Security Operation (SOC) platform, we’re excited to announce an expansion of the Microsoft ecosystem with new OT security integrations from Dragos, Forescout, and Armis from ServiceNow. This gives customers greater flexibility to use the OT security solutions that best fit their environments.&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Expanding OT coverage in Defender with new partner integrations&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;We’ve built new connectors for Dragos, Forescout and Armis that are now ready for customers to start using.&lt;/P&gt;
&lt;H4&gt;Dragos&lt;/H4&gt;
&lt;H6&gt;&lt;EM&gt;"Strong OT defense starts with knowing what is running in your operational environment, the vulnerabilities those assets carry, the threats targeting your systems, and the data to determine root cause. That kind of intelligence comes from years of operating inside OT environments and tracking the groups behind those threats. As OT threats continue to grow and AI accelerates how quickly adversaries can approach the OT boundary, integrating Dragos into Microsoft Defender strengthens how organizations see, understand, and defend their OT environments."&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;EM&gt;-Robert M. Lee, CEO and Co-Founder, Dragos, Inc.&lt;/EM&gt;&lt;/H6&gt;
&lt;H4&gt;Forescout&lt;/H4&gt;
&lt;H6&gt;&lt;EM&gt;"Our integration with Microsoft Defender represents a significant step forward in helping organizations defend their most critical operations against today's rapidly evolving cyber threats. By combining Forescout's industry-leading visibility and protection for IoT, OT, and network-connected assets with Microsoft's leadership in endpoint, identity, cloud, and security operations, we're delivering a more unified approach to cyber defense. Together, we're enabling healthcare providers, government agencies, critical infrastructure operators, and enterprises comprehensive visibility across IT and OT environments while empowering security teams to detect, investigate, and respond to threats faster and with greater confidence."&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;EM&gt;-Robert McNutt, Chief Strategy Officer, Forescout&lt;/EM&gt;&lt;/H6&gt;
&lt;H4&gt;Armis&lt;/H4&gt;
&lt;P&gt;“&lt;EM&gt;Fragmented security is no longer an option as threats to critical infrastructure evolve at machine speed. By deepening our integration with Microsoft, we are unifying visibility and context in complex OT and IoT environments. Integrating Armis Centrix™ with Microsoft Defender equips security teams with real-time, actionable insights to identify and mitigate risks across their entire operational footprint.”&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;EM&gt;-Nadir Izrael, Group Vice President, Armis from ServiceNow&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Bringing OT and IT Security Together&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;With these new integrations, signals, asset inventory and vulnerabilities from Dragos, Forescout, and Armis from ServiceNow flow directly into Microsoft Defender — giving security operations teams a single, unified view across IT, OT, and IoT.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What this means for customers:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Unified visibility across IT and OT. &lt;/STRONG&gt;OT assets and vulnerabilities surface alongside IT signals in Defender, so the SOC can see and reason about them in one place.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Cross-domain correlation. &lt;/STRONG&gt;Identity, endpoint, cloud, and OT signals are correlated automatically.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Streamlined investigation and response. &lt;/STRONG&gt;Analysts can pivot from an OT detection to related IT activity (and back) without switching tools or losing context.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Specialized depth, unified breadth. &lt;/STRONG&gt;Customers keep the deep OT expertise of their chosen partner platform and gain the enterprise-wide coverage of Defender.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Let’s take a look at some of new the user experience updates that showcase these integrations.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Figure 1. Discovered devices by OT partner in device inventory&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Device Inventory now will show OT devices discovered through a new partner integration (see Figure 1). Industrial assets like substation relays and switches from vendors are automatically surfaced with rich context, criticality, vendor, model, firmware, and discovery source alongside built-in recommendations to classify critical assets and protect unmanaged OT devices. The result: unified visibility across IT and OT from a single view, so security teams can find, prioritize, and protect previously unseen devices faster.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Figure 2. Vulnerabilities and exposure across OT devices&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;The Vulnerabilities view now includes a dedicated OT Partner CVEs tab, surfacing thousands of vulnerabilities on operational technology devices discovered through partner integrations. Every CVE is enriched with severity, CVSS score, age, active threats, and exposed device count, and the list is sorted by exposure so the most widespread, highest-impact risks rise to the top. Most importantly, security teams can now see OT vulnerabilities alongside IT in a single, prioritized view, making it faster to focus remediation where it matters most.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Figure 3. Discovered devices exposed by OT integration&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Selecting a CVE opens a detail panel with a dedicated&amp;nbsp;&lt;STRONG&gt;Exposed devices discovered by OT partner&lt;/STRONG&gt; tab, listing every affected device along with its OS platform and last seen date. For CVE-2024-7264, that means a clear view of all 75 exposed devices in one place, from OT controllers to sales workstations. The benefit is that security teams can move from a single vulnerability straight to the exact devices at risk, making it easy to scope impact and drive targeted remediation without leaving the view.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Figure 4. Discovered vulnerabilities by OT integration&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Drilling into a specific device, like the &lt;STRONG&gt;Substation-North-HMI2&lt;/STRONG&gt;&amp;nbsp;shown here, reveals a dedicated&amp;nbsp;&lt;STRONG&gt;Discovered vulnerabilities by OT partner&lt;/STRONG&gt; tab alongside the standard device views such as incidents, timeline, and security recommendations. It lists every vulnerability found on that device by the OT partner, complete with severity, CVSS score, publication and detection dates, and active threats. The benefit is a complete, device-level picture of OT risk right where analysts investigate, so they can see exactly what a single asset is exposed to and prioritize remediation without switching tools or context.&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Built for customer choice and flexibility&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;We’re excited to expand our integration ecosystem, giving customers the flexibility to work with the OT solutions they already trust. These integrations help bring specialized OT context into broader security workflows, enabling SOC teams, risk managers, and security leaders to collaborate more effectively while using the tools that best fit their environment.&lt;/P&gt;
&lt;H1&gt;Get started&lt;/H1&gt;
&lt;P&gt;The Dragos, Forescout, and Armis integrations are available in public preview starting today. Customers can enable them through the Defender portal and begin ingesting OT signals from their partner platform of choice.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/security-exposure-management/ot-data-connectors" target="_blank" rel="noopener"&gt; Integrate the Dragos OT data connector in Microsoft Security Exposure Management - Microsoft Security Exposure Management | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/security-exposure-management/ot-data-connectors" target="_blank" rel="noopener"&gt; Integrate the Forescout OT data connector in Microsoft Security Exposure Management - Microsoft Security Exposure Management | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/security-exposure-management/armis-data-connector" target="_blank" rel="noopener"&gt;Integrate the Armis OT data connector in Microsoft Security Exposure Management - Microsoft Security Exposure Management | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 14 Jul 2026 13:46:58 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/microsoft-defender-now-integrates-with-dragos-forescout-armis/ba-p/4534936</guid>
      <dc:creator>Caroline_Lee</dc:creator>
      <dc:date>2026-07-14T13:46:58Z</dc:date>
    </item>
    <item>
      <title>Monthly news - July 2026</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/monthly-news-july-2026/ba-p/4532402</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Microsoft Defender&lt;/STRONG&gt;&lt;BR /&gt;Monthly news - July 2026 Edition&lt;/P&gt;
&lt;P&gt;This is our monthly "What's new" blog post, summarizing product updates and various new assets we released over the past month across our Defender products. In this edition, we are looking at all the goodness from June 2026. We are now including news related to Defender for Cloud in the Defender portal. For all other Defender for Cloud news, have a look at the dedicated Defender for Cloud Monthly News&amp;nbsp;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/microsoft-defender-for-cloud-customer-newsletter/4525656" target="_blank" rel="noopener" data-lia-auto-title="here" data-lia-auto-title-active="0"&gt;here&lt;/A&gt;&lt;STRONG&gt;.&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;🚀 New Virtual Ninja Show episode:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://youtu.be/17qtl8RSFKA?si=_O1CgQpNJtQgk_dY" target="_blank" rel="noopener"&gt; Redefining identity security for the modern enterprise&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://youtu.be/I24oxM6rL6E?si=rgXUPok9_jVu0SsQ" target="_blank" rel="noopener"&gt; One policy engine to govern them all: Securing agentic AI with Microsoft Purview&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://youtu.be/q_7IXnBwv8c?si=94-NKofzzGx-3HkG" target="_blank" rel="noopener"&gt; Building a modern detection pipeline with ContentOps&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://youtu.be/SzTEY3sY3lA?si=HJV1MKD8tJ63_EQT" target="_blank" rel="noopener"&gt;Securing local AI agents with Microsoft Defender&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://youtu.be/AnQiZZkZO0s?si=xOnPdLRegN-RHbyh" target="_blank" rel="noopener"&gt;Microsoft Defender: Extending critical protection for emerging threats in Team&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Weekly Security News:&amp;nbsp;&lt;/STRONG&gt;We publish a short 1ish minute video every week with updates across our Microsoft Security stack. Subscribe to our&amp;nbsp;&lt;A href="https://www.youtube.com/@MicrosoftSecurityCommunity/shorts" target="_blank" rel="noopener"&gt;YouTube channel&lt;/A&gt;, so you don't miss the next episode.&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Actionable threat insights&lt;/STRONG&gt; (find all of them &lt;A class="lia-external-url" href="https://www.microsoft.com/en-us/security/blog/content-type/research/?ep_filter_topic=actionable-threat-insights" target="_blank" rel="noopener"&gt;here&lt;/A&gt;)&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2026/06/30/securing-ai-agents-ai-tools-move-from-reading-acting/" target="_blank" rel="noopener"&gt;Securing AI agents: When AI tools move from reading to acting&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2026/06/29/chromium-extension-uses-airelated-branding-redirect-browser-search/" target="_blank" rel="noopener"&gt;Chromium extension uses AI‑related branding to redirect browser search&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2026/06/25/photo-zip-campaign-targeting-hospitality-industry-delivers-node-js-implant-persistent-access/" target="_blank" rel="noopener"&gt;Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Defender&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Two Workbooks capabilities in the unified Microsoft Defender portal moved to GA:
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Advanced Hunting connector &lt;/STRONG&gt;- build custom dashboards directly on top of Advanced Hunting (XDR) dat. Query XDR tables and visualize them in Workbooks for richer investigations and reports.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Workspace filter / multi-workspace experience&lt;/STRONG&gt; - scope and filter workbooks by workspace, with workspace selection integrated into the workbook itself rather than relying on the global selector.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;MTO Tenant Groups&lt;/STRONG&gt; let MSSPs and large enterprises organize their multitenant view in Microsoft Defender by grouping tenants logically (e.g., by region, business unit, or customer cohort). Learn more &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/organize-your-multitenant-view-with-tenant-groups-in-microsoft-defender/4522992" target="_blank" rel="noopener" data-lia-auto-title="here" data-lia-auto-title-active="0"&gt;here&lt;/A&gt;.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Custom Detections support in Microsoft Sentinel Repositories&lt;/STRONG&gt;. Custom Detections can now be managed as code in Microsoft Sentinel Repositories, the same way customers already manage analytic rules, playbooks, parsers and workbooks. Detection engineers connect a GitHub or Azure DevOps repo to their workspace; Custom Detections placed in the repo are reconciled on every commit. A standalone Bicep path via the Microsoft Security Bicep extension lets teams deploy from any CI/CD pipeline (ADO Pipelines, GitHub Actions, custom runners).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;(General Availability) The following advanced hunting schema tables are now generally available:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;The &lt;/SPAN&gt;&lt;EM style="color: rgb(30, 30, 30);"&gt;CloudAuditEvents&lt;/EM&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt; table contains information about cloud audit events for various cloud platforms protected by the organization's Defender for Cloud.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;The&amp;nbsp;&lt;EM&gt;CloudDnsEvents&lt;/EM&gt; table contains information about DNS activity events from cloud infrastructure environments.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;The&amp;nbsp;&lt;EM&gt;CloudProcessEvents&lt;/EM&gt; table contains information about process events in multicloud hosted environments.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;(Public Preview) The &lt;EM&gt;AgentsInfo &lt;/EM&gt;table in advanced hunting is now available in preview. The &lt;STRONG&gt;&lt;EM&gt;AIAgentsInfo &lt;/EM&gt;table is transitioning to this new table&lt;/STRONG&gt;, which provides a unified schema that supports agent inventory and governance for all agent types, including Copilot Studio, Microsoft Foundry, Microsoft 365 Copilot, third-party, and endpoint-discovered agents. &lt;STRONG&gt;Microsoft Agent 365 customers should use the AgentsInfo table today.&lt;/STRONG&gt; The &lt;EM&gt;AIAgentsInfo &lt;/EM&gt;table remains accessible until July 1, 2026. Update your queries to use AgentsInfo before this date. For more information, see &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-agentsinfo-table" target="_blank" rel="noopener"&gt;Advanced hunting schema - Naming changes&lt;/A&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;For all other Sentinel News, have a look at the "&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/microsoftsentinelblog/what%E2%80%99s-new-in-microsoft-sentinel-june-2026/4531902" target="_blank" rel="noopener" data-lia-auto-title="What's new in Microsoft Sentinel blog post - June edition" data-lia-auto-title-active="0"&gt;What's new in Microsoft Sentinel blog post - June edition&lt;/A&gt;"&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Identity Security&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;(Public Preview)&amp;nbsp;&lt;STRONG&gt;The Identity Security dashboard now includes a new Human identities card&lt;/STRONG&gt; that shows your human identities by source (Entra ID, SaaS, and on-premises), giving you a single view of where your human identities live. For more information, see &lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/dashboard" target="_blank" rel="noopener"&gt;Identity Security dashboard&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;img&gt;Identity Security dashboard overview&lt;/img&gt;
&lt;UL&gt;
&lt;LI&gt;(Public Preview) On the Coverage and maturity page, the &lt;STRONG&gt;Review and improve coverage side panel&lt;/STRONG&gt; for SaaS Identities now includes an &lt;STRONG&gt;Observed column &lt;/STRONG&gt;and a &lt;STRONG&gt;Show Only Observed Applications&lt;/STRONG&gt; toggle. By default, the panel shows only SaaS applications detected in your environment. Turn off the toggle to see other supported SaaS applications you can onboard to expand your identity coverage. For more information, see &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/defender-xdr/identity-security/coverage-maturity" target="_blank" rel="noopener"&gt;Coverage and maturity&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;New alerts were added to the Defender for Identity security alerts related to Microsoft Entra ID, Active Directory as well as other identity providers. For a full list of those new alerts, check out &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/defender-for-identity/whats-new#new-defender-for-identity-security-alerts" target="_blank" rel="noopener"&gt;our documentation&lt;/A&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Recent ShinyHunters attacks on Salesforce show how OAuth tokens and connected apps are being weaponized to bypass MFA at scale. &lt;STRONG&gt;The upgraded Salesforce connector for Defender for Cloud Apps&lt;/STRONG&gt; helps detect these attacks faster, with richer connected-app context and investigation-ready signals. Customers already using the connector are advised to enable the additional events in the Salesforce console for tighter protection, and eligible customers not yet using it are advised to connect Salesforce. &lt;A class="lia-external-url" href="https://learn.microsoft.com/defender-cloud-apps/release-notes#salesforce-connector-enhancements-preview" target="_blank"&gt;Learn more.&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Defender for Endpoint / Microsoft Defender Vulnerability Management&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;(Public Preview) &lt;STRONG&gt;Local AI agent discovery&lt;/STRONG&gt;: as part of the Defender AI agents experience, Microsoft Defender now automatically discovers supported local AI agents running on onboarded Windows &amp;amp; macOS devices. Discovered agents appear as assets in the AI agent inventory, exposure map, and advanced hunting, giving security teams visibility into local AI agent usage across the organization. For more information, see&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/defender-endpoint/local-agent-discovery-overview" target="_blank" rel="noopener"&gt;Discover local AI agents&lt;/A&gt;.&lt;/P&gt;
&lt;img&gt;AI Assets page&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;(Preview) &lt;STRONG&gt;Local AI agent runtime protection&lt;/STRONG&gt; on Windows endpoints is now available in public preview. Microsoft Defender inspects the agent loop (user prompts, tool calls, and tool responses) and can block risky activity before it executes, helping stop prompt injection and unsafe agent actions at the device level. Blocked and audited events appear as alerts in Microsoft Defender to support incident correlation and investigation workflows.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;The &lt;STRONG&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/defender-endpoint/defender-deployment-tool-windows" target="_blank" rel="noopener"&gt;new version of the Defender deployment tool&lt;/A&gt;&lt;/STRONG&gt; for Windows streamlines onboarding and enhances security by:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Bundling the onboarding package directly into the tool's executable.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Generating a key during deployment package creation that is required for running the tool.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Enabling users to configure an expiry date for the package to reduce the risk of unauthorized use. &lt;BR /&gt;In addition:&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;You have the option of downloading the package as either an .exe or a .zip file, whichever best suits your organization's needs.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;A new Deployment packages page in the Defender portal facilitates management of downloaded packages by providing centralized visibility into all the packages and their current status.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Now generally available: &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/defender-endpoint/restrict-response-actions-high-value-assets" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Selective Response Actions&lt;/STRONG&gt;&lt;/A&gt; enables organizations to tailor high-impact security operations on devices during onboarding. It provides precise control over how response actions are applied on Tier-0 systems and other high-value assets, helping maintain operational stability while delivering strong protection.&lt;/P&gt;
&lt;img&gt;Enable selective response actions&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;The &lt;STRONG&gt;new exposure score model &lt;/STRONG&gt;in Defender Vulnerability Management is now generally available. This model improves risk prioritization and recommendation impact accuracy by incorporating exploit prediction data (EPSS) and asset context factors such as internet-facing status and criticality. More details &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-exposure-score?tabs=preview-customers#exposure-score-model-updates-transition-overview" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Microsoft Secure Score now includes the &lt;STRONG&gt;Reduce unnecessary inbound internet exposure on internet-facing devices&lt;/STRONG&gt; recommendation, which helps identify devices that are accessible from the public internet and may represent unnecessary attack surface. This recommendation provides centralized visibility into internet-facing devices across the environment.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Many predefined SaaS application classification rules were added to the critical assets list. Have a look at &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/security-exposure-management/whats-new#new-predefined-classifications" target="_blank"&gt;our documentation&lt;/A&gt; for the full list. These classifications require onboarding to Microsoft Defender for Cloud Apps.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 01 Jul 2026 09:30:09 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/monthly-news-july-2026/ba-p/4532402</guid>
      <dc:creator>HeikeRitter</dc:creator>
      <dc:date>2026-07-01T09:30:09Z</dc:date>
    </item>
    <item>
      <title>Securing the invisible workforce</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/securing-the-invisible-workforce/ba-p/4528611</link>
      <description>&lt;P&gt;Non-human identities are now the majority of the identity estate in most enterprises. Service principals access organizational resources across SharePoint, Azure, and Microsoft 365, Service accounts run critical business processes on-premises, OAuth apps move data across SaaS boundaries, and AI agents increasingly operate autonomously at machine speed.&lt;/P&gt;
&lt;P&gt;As NHIs have grown in number and importance, so to have the threats targeting them. &lt;A href="https://www.microsoft.com/en-us/security/blog/2024/01/25/midnight-blizzard-guidance-for-responders-on-nation-state-attack/" target="_blank" rel="noopener"&gt;Midnight Blizzard&lt;/A&gt; showed how damaging compromised NHI can be. Attackers moved laterally across cloud resources and accessed sensitive data without ever triggering user-centric controls like MFA. The challenge many security teams are faced with however is that they simply do not have the visibility into what NHI’s even exist within their organization. Unlike their human counterparts, NHI can vary drastically in purpose, behaviour and risk profile. The one consistency is that most organizations lack a formal process for their creation, management and governance. For instance, while these identities often carry high and standing privileges, those permissions are typically granted at creation and never revisited. They authenticate programmatically so they cannot be enrolled in, or benefit from the protections of multi-factor authentication.&lt;/P&gt;
&lt;P&gt;As AI adoption accelerates, this issue has become even more urgent. Every AI agent needs an identity to function. That identity accesses data, invokes APIs, and takes action, autonomously, continuously, and at an unprecedented velocity. &amp;nbsp;But because AI tooling has moved faster than guidance, many agents were never given identities of their own, many riding on existing Service Principles. This means that those ordinary app registrations may in fact represent autonomous agents making decisions and taking action. This new reality further compresses the window between compromise and impact and makes securing non-human identities a prerequisite for safely deploying AI at enterprise scale.&lt;/P&gt;
&lt;P&gt;Today, I am excited to share more about the non-human identity protection available within Microsoft Defender. These capabilities bring NHIs into the same unified platform where security teams already work and protect human identities with purpose-built experiences for discovery, risk assessment, business context, governance, threat detection, and attack disruption.&lt;/P&gt;
&lt;H2&gt;The Challenge:&lt;/H2&gt;
&lt;P&gt;We hear consistently from customers that they cannot answer fundamental questions about their NHI estate:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;How many non-human identities exist? &lt;/STRONG&gt;Across Entra ID, Active Directory, and SaaS applications, the true count consistently exceeds expectations, often by an order of magnitude.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Which ones are still in use? &lt;/STRONG&gt;NHIs accumulate over time. Decommissioning is rare and dormant identities retain active permissions indefinitely.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Which ones hold more access than they need? &lt;/STRONG&gt;Permissions are granted broadly at provisioning and seldom revisited. Over-privilege is not the exception—it is the default state.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Who is responsible for them? &lt;/STRONG&gt;Without established ownership, remediating a risky NHI requires significant manual effort just to identify the right person to engage.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Which ones are powering AI agents? &lt;/STRONG&gt;Many agents ride on NHIs created long before the agent existed, making them indistinguishable from routine integrations.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;These are the questions that drive the capabilities we are delivering.&lt;/P&gt;
&lt;H2&gt;Raising the bar for NHI protection with Defender&lt;/H2&gt;
&lt;P&gt;Microsoft Defender helps protect non-human identities through six integrated focus areas:&amp;nbsp;Visibility, Risk analysis, relationships and access mapping, governance policies, AI Agent awareness and Detection and Disruption. Together, these areas help organizations discover NHI risk, understand relationships and permissions, enforce governance, identify AI-driven identity activity, and detect or disrupt threats before they escalate.&lt;/P&gt;
&lt;H4&gt;1. Visibility:&lt;/H4&gt;
&lt;P&gt;When Entra service principals, Active Directory service accounts, and SaaS-connected OAuth apps are managed in separate consoles with separate workflows, security teams cannot form a coherent picture of NHI exposure. These gaps in visibility translate directly into gaps in protection.&lt;/P&gt;
&lt;P&gt;Defender delivers a unified identity inventory for both human and non-human identities within a single view and investigation workflow. For non-human identities, coverage includes:&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; height: 131px; border-width: 1px;"&gt;&lt;colgroup&gt;&lt;col style="width: 50%" /&gt;&lt;col style="width: 50%" /&gt;&lt;/colgroup&gt;&lt;tbody&gt;&lt;tr style="height: 26px;"&gt;&lt;td class="lia-align-center" style="height: 26px;"&gt;
&lt;P&gt;&lt;STRONG&gt;Source&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-center" style="height: 26px;"&gt;&lt;STRONG&gt;Coverage&lt;/STRONG&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 35px;"&gt;&lt;td style="height: 35px;"&gt;&lt;STRONG&gt;Microsoft Entra ID&lt;/STRONG&gt;&lt;/td&gt;&lt;td style="height: 35px;"&gt;All service principals&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 35px;"&gt;&lt;td style="height: 35px;"&gt;&lt;STRONG&gt;Active Directory&lt;/STRONG&gt;&lt;/td&gt;&lt;td style="height: 35px;"&gt;All service accounts&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 35px;"&gt;&lt;td style="height: 35px;"&gt;&lt;STRONG&gt;SaaS Apps&lt;/STRONG&gt;&lt;/td&gt;&lt;td style="height: 35px;"&gt;All OAuth-connected apps&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;img&gt;&lt;U&gt;Unified visibility across all non-human identities in a single pane of glass&lt;/U&gt;&lt;/img&gt;
&lt;P&gt;This consolidated inventory is the foundation that security insights, risk scoring, business context, governance, and threat detection all build on. Security teams work from one place, using the same investigation workflows they already use for human identities, across the entire NHI population.&lt;/P&gt;
&lt;H3&gt;2. Risk insights and analysis:&lt;/H3&gt;
&lt;P&gt;Visibility into what exists is the starting point. What security teams need next is a clear understanding of which identities carry risk, what kind of risk, and how they should prioritize. Similar to how we review risk signals for human identities, Defender continuously evaluates the NHI estate and surfaces findings across key risk pivots:&lt;/P&gt;
&lt;img&gt;Actionable insights into your unique NHI footprint&lt;/img&gt;
&lt;H6&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;SPAN class="lia-text-color-15"&gt;Unused Identities&lt;/SPAN&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/H6&gt;
&lt;P&gt;NHIs that have not authenticated over extended periods but retain active permissions. These identities serve no current business purpose while remaining fully available for misuse if compromised.&lt;/P&gt;
&lt;H6&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;SPAN class="lia-text-color-15"&gt;Over-Privileged Identities&lt;/SPAN&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/H6&gt;
&lt;P&gt;NHIs whose granted permissions significantly exceed their observed usage. Defender analyses the gap between what an identity &lt;EM&gt;can&lt;/EM&gt; do and what it &lt;EM&gt;actually does&lt;/EM&gt;, identifying where privilege can be safely reduced without impacting operations.&lt;/P&gt;
&lt;H6&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;SPAN class="lia-text-color-15"&gt;High-Privileged Identities&lt;/SPAN&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/H6&gt;
&lt;P&gt;Some NHI’s however require elevated roles or broad permissions to perform their intended use. These NHIs pose the highest lateral movement risk if compromised. For context, these privileges can sometimes exceed the access held by admins in the organization.&lt;/P&gt;
&lt;H6&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;SPAN class="lia-text-color-15"&gt;Identity Risk Score for NHIs&lt;/SPAN&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/H6&gt;
&lt;P&gt;The new Identity Risk Score within Defender also extends to NHI. Ever NHI now has a dynamic risk score , informed by Microsoft’s global threat intelligence, exposure indicators, and observed activity patterns.&lt;/P&gt;
&lt;P&gt;The score is fully explainable. For every NHI, Defender shows the specific factors that contributed—what combination of privilege, exposure, and activity drove the assessment, and why. Analysts see the reasoning directly: an identity scored high because it is unused, holds broad directory permissions, and is published by an unverified publisher. This means analysts can act on the score with confidence, without needing to conduct a separate investigation to understand what it means.&lt;/P&gt;
&lt;P&gt;These insights allow teams to rank their entire NHI estate by risk and systematically focus investigation where it matters most.&lt;/P&gt;
&lt;img&gt;Risk insights for NHI for effective prioritization&lt;/img&gt;
&lt;H3&gt;3. Relationship mapping:&lt;/H3&gt;
&lt;P&gt;Knowing that an NHI is risky is necessary but not sufficient for remediation. Security teams need business context: what application depends on this identity, who owns it, what resources can it access, and with what permissions.&lt;/P&gt;
&lt;P&gt;Without this information, even a critical finding stalls. Can we disable this identity, or will it break a production workflow? Who do we contact to coordinate? What is the scope of exposure if this identity is compromised?&lt;/P&gt;
&lt;P&gt;Defender introduces a Graph for NHIs that visually maps these relationships directly.&lt;/P&gt;
&lt;img&gt;Graph connecting risk to business context for faster remediation&lt;/img&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;What application depends on this NHI?&amp;nbsp;&lt;/STRONG&gt;Understanding downstream dependencies before taking remediation action.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Who owns it? &lt;/STRONG&gt;Identifying the owner for coordinated response.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;What resources or crown jewels does it access, and with what permissions? &lt;/STRONG&gt;Determining the sensitivity of accessed resources to assess actual severity.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;With this context directly available in the investigation experience, security teams can assess risk, evaluate business impact, and coordinate remediation without switching tools or conducting manual discovery.&lt;/P&gt;
&lt;H3&gt;4. Governance policies&lt;/H3&gt;
&lt;P&gt;When we extrapolate this out to enterprise scale, with thousands to tens of thousands of NHIs, manual remediation simply cannot keep pace with the rate at which risk accumulates. Organizations need governance policies that enforce decisions automatically and consistently.&lt;/P&gt;
&lt;P&gt;Defender enables this through governance policies. Organizations can define policies that leverage the insights Defender surfaces like unused timeframe, privilege level, risk score, over-privilege status, AI agent association and then map them to automated disablement of identities that exceed acceptable risk.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Example: &lt;/EM&gt;&lt;/STRONG&gt;&lt;EM&gt;An NHI that has been unused for 90+ days, holds high-privilege roles, and carries a risk score above 70 exceeds the organization’s risk tolerance → disable the identity.&lt;/EM&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;img /&gt;&lt;img&gt;Automated governance policies that turn risk insights into enforcement at scale&lt;/img&gt;
&lt;P&gt;This shifts NHI security from periodic audit cycles to continuous posture management. The NHI estate stays within organizational risk tolerance because policy enforces the standard automatically, at the scale the environment demands.&lt;/P&gt;
&lt;H3&gt;5. AI Agent awareness&lt;/H3&gt;
&lt;P&gt;Agents built on platforms like Copilot Studio, Azure AI Foundry, and third-party frameworks require identities to authenticate, access data, and take action. In practice, many agents operate using traditional NHI that were provisioned for other workloads, making them indistinguishable from routine integrations at the identity layer.&lt;/P&gt;
&lt;P&gt;The risk profile, however, is materially different:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Agents are autonomous. &lt;/STRONG&gt;They make decisions and execute actions without human approval at each step.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Agents are high-velocity. &lt;/STRONG&gt;They perform hundreds of operations per minute across multiple systems.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Agents interact with sensitive data. &lt;/STRONG&gt;They access documents, query databases, read communications, and invoke APIs, often with broad permissions to support flexible workflows.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;When a misconfigured identity backs an AI agent, the risk compounds significantly because the agent continues to operate autonomously, with legitimate access, at machine speed, across whatever resources it can reach.&lt;/P&gt;
&lt;P&gt;Defender infers which NHIs are used by AI agents and surfaces this signal directly in the inventory, risk insights, and assessment. This enables security teams to prioritize investigation of agent-backed NHIs and apply differentiated governance like stricter controls, shorter review cycles, and tighter privilege boundaries for identities backing&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;Visibility into service principals powering AI agents and their associated risk&lt;/img&gt;
&lt;H3&gt;6. Detection and disruption&lt;/H3&gt;
&lt;P&gt;Posture and governance reduce the attack surface. But when an attacker compromises a non-human identity, detection speed and response automation determine whether the attack is contained or succeeds.&lt;/P&gt;
&lt;P&gt;Microsoft Defender brings the same detection and disruption capabilities that protect human identities to the non-human estate.&lt;/P&gt;
&lt;H6&gt;&lt;STRONG&gt;&lt;SPAN class="lia-text-color-15"&gt;&lt;EM&gt;Threat Detection for NHIs&lt;/EM&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H6&gt;
&lt;P&gt;Defender detects anomalous and malicious activity involving non-human identities using behavioral analytics and Microsoft’s global threat intelligence. Detections are purpose-built for how NHIs operate because the signals indicating compromise in a NHI is fundamentally different from those in a human account, and our detection models reflect that.&lt;/P&gt;
&lt;img&gt;Detecting anomalous and suspicious activities on non-human identities&lt;/img&gt;
&lt;P&gt;Every alert is enriched with full context from the identity inventory, risk insights, and graph. Analysts see not just what happened, but which identity was involved, what it can reach, who owns it, and how critical it is immediately, without manual correlation.&lt;/P&gt;
&lt;H6&gt;&lt;STRONG&gt;&lt;SPAN class="lia-text-color-15"&gt;&lt;EM&gt;Disrupting Attacker Persistence&lt;/EM&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H6&gt;
&lt;P&gt;We are introducing new disruption capabilities designed to address the persistence techniques attackers use against non-human identities. These capabilities focus on the specific actions that turn a legitimate non-human Identity &amp;nbsp;into an attack path, such as adding credentials for off-tenant use or modifying permissions and role assignments to expand access.&lt;/P&gt;
&lt;P&gt;Rather than broad remediation, the approach targets the exact moves attackers use to establish and maintain control. By directly addressing actions like unauthorized credential additions and privilege expansion, these capabilities help remove attacker access while preserving legitimate application functionality.&lt;/P&gt;
&lt;H2&gt;Why This Maters&lt;/H2&gt;
&lt;P&gt;Every AI agent requires an identity. As organizations scale agent deployments, the NHI estate grows with them and inherits every existing gap: over-privilege, absent ownership, insufficient monitoring.&lt;/P&gt;
&lt;P&gt;What has changed is speed. An AI agent with a compromised identity operates autonomously and never sleeps. The window between compromise and impact has compressed to the point where periodic manual review is no longer adequate. Automated visibility, continuous risk assessment, policy-driven governance, and real-time detection and disruption are now requirements.&lt;/P&gt;
&lt;P&gt;The organizations investing in NHI protection today are building the security foundation their AI strategy depends on.&lt;/P&gt;
&lt;H2&gt;Getting Started&lt;/H2&gt;
&lt;P&gt;Non-human identity protection is available in Microsoft Defender today:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Visit the unified identity inventory &lt;/STRONG&gt;in Defender to see all NHIs across Entra ID, Active Directory, and SaaS.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Review risk insights &lt;/STRONG&gt;to identify unused, over-privileged, high-risk NHIs, and NHIs used by agents.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Explore the identity graph &lt;/STRONG&gt;to understand business context, ownership, and resource access.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Configure risk-based governance policies &lt;/STRONG&gt;to enforce organizational risk tolerance at scale.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;These capabilities are integrated into the same platform and workflows security teams already use for human identity protection—no separate tools, no additional deployment. Learn more about the NHI protections provided by Defender within our &lt;A href="https://learn.microsoft.com/en-us/defender-xdr/investigate-non-human-identities" target="_blank" rel="noopener"&gt;docs here&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jun 2026 12:35:52 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/securing-the-invisible-workforce/ba-p/4528611</guid>
      <dc:creator>Nagaraj Venkatesh</dc:creator>
      <dc:date>2026-06-17T12:35:52Z</dc:date>
    </item>
    <item>
      <title>The next frontier in endpoint security: Securing local AI agents with Microsoft Defender</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/the-next-frontier-in-endpoint-security-securing-local-ai-agents/ba-p/4524651</link>
      <description>&lt;P&gt;AI agents are now doing real work on the endpoint — reading files, running commands, browsing the web, and acting on behalf of the users they run under. That same power is also what makes them dangerous: agents act on whatever content they take in, and much of it comes from outside the user's control — a web page, a repository, a command's output. A single malicious instruction hidden in that content can turn an agent against the very environment it's trusted to work in. With access to source code, secrets, and the corporate resources, its identity can reach — from cloud infrastructure to SharePoint, email, and internal apps — a compromised agent becomes a path to everything that identity is trusted with.&lt;/P&gt;
&lt;P&gt;Yet most security teams can't see this activity at all. Local AI agents run as ordinary processes, with little of the visibility or context SOC teams need to understand — let alone investigate — what an agent actually did.&lt;/P&gt;
&lt;P&gt;That’s why today, we're extending Microsoft Defender to secure AI agents running locally on devices. Security teams now have the visibility, context, and control needed to manage this new frontier of endpoint risk without slowing down the developers driving innovation forward. This includes:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Discover 20+ types of local AI agents running on managed Windows and macOS devices&lt;/LI&gt;
&lt;LI&gt;Block malicious AI agent activity on the device in real time&lt;/LI&gt;
&lt;LI&gt;Assess local agent exposure across identities and reachable resources&lt;/LI&gt;
&lt;LI&gt;Investigate local AI agent activity in Advanced Hunting&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;In preview, Defender now discovers these agents across the endpoint — AI coding agents, AI assistants, local AI runtimes, agentic IDE extensions, and Model Context Protocol (MCP) servers — and adds runtime protection for popular coding agents, with coverage expanding over time. Just as important, it brings them into the same security platform teams already use for endpoints, identities, email, and cloud, so local agents are no longer running unseen alongside the tools security teams already protect, but part of one coordinated defense.&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;&lt;STRONG&gt;Watch this episode of the Ninja Show to see how Microsoft Defender brings visibility, context, and control to local AI agents, helping security teams securely adopt AI and stay ahead of emerging threats.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;div data-video-id="https://www.youtube.com/watch?v=SzTEY3sY3lA/1782496140882" data-video-remote-vid="https://www.youtube.com/watch?v=SzTEY3sY3lA/1782496140882" class="lia-video-container lia-media-is-center lia-media-size-large"&gt;&lt;iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FSzTEY3sY3lA%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DSzTEY3sY3lA&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FSzTEY3sY3lA%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" allowfullscreen="" style="max-width: 100%"&gt;&lt;/iframe&gt;&lt;/div&gt;
&lt;H4&gt;&lt;STRONG&gt;Discover local AI agents on managed devices&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Security Operation Center (SOC) teams can now identify AI agents running locally as first-class assets, not just operating system (OS) processes. In the Defender portal, security teams can view a dedicated inventory of AI agents across their environment, spanning categories such as:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Coding CLIs and terminal agents: GitHub Copilot CLI, Codex CLI, Claude Code CLI, Gemini CLI, Antigravity CLI, OpenCode&lt;/LI&gt;
&lt;LI&gt;Agentic IDEs and VS Code extensions: Cursor, Windsurf, Antigravity, Claude Code, Codex, Cline, Gemini, GitHub Copilot, Roo Code&lt;/LI&gt;
&lt;LI&gt;Desktop AI assistants: ChatGPT Desktop, Claude Desktop, Codex Desktop, Poe Desktop, Antigravity Desktop, GitHub Copilot App&lt;/LI&gt;
&lt;LI&gt;Local AI runtimes and autonomous platforms: OpenClaw, Nanobot, ZeroClaw, Ollama Desktop&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Each agent is surfaced as a security asset, with runtime context including user identity, device and process relationships, trust indicators, and integrity level. Security teams can also see configuration signals, such as “auto-approve” settings and connected services via MCP servers. Defender discovers more than 20 supported local AI agents across Windows and macOS, with coverage continuing to expand.&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Figure 1: The AI Assets (preview) inventory and an agent detail record in the Microsoft Defender portal.&lt;/EM&gt;&lt;/img&gt;
&lt;H4&gt;&lt;STRONG&gt;Block malicious AI agent activity in real time&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Discovery is the starting point. Once SOC teams know which agents are present, they need confidence that malicious behavior will be stopped to reduce impact to their organization’s environment.&lt;/P&gt;
&lt;P&gt;For popular coding agents, Defender now provides runtime protection that helps block malicious behavior inline and in real time. This capability starts with Claude Code and GitHub Copilot CLI, with OpenClaw and OpenAI Codex coming soon. When Defender identifies that an agent activity is malicious, it can automatically block it. As with other threats, the user can be notified, and the activity is logged in the protection history.&lt;/P&gt;
&lt;P&gt;The SOC analyst receives a detailed alert with agent and session context for investigation, including details on the detected threat. At the same time, the user sees a notification on the device that the activity was blocked.&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Figure 2: Runtime protection blocking malicious instructions in a post-tool response&lt;/EM&gt;&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Figure 3: The matching Windows Security notification, blocking the detected threat&lt;/EM&gt;&lt;/img&gt;&lt;img&gt;&lt;EM&gt;Figure 4: &lt;/EM&gt; &lt;EM&gt;The corresponding security alert in the Defender portal, with the process tree and session context for investigation&lt;/EM&gt;&lt;/img&gt;
&lt;H4&gt;&lt;STRONG&gt;Assess local agent exposure&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Knowing an agent exists is only half the picture. The next step is mapping the potential blast radius: the resources the agent touches, the identities it can use, and the assets exposed to its next moves. That’s why every agent discovered is automatically mapped to the device it runs on, the identity associated with that device, the MCP servers it’s connected to, and the cloud resources the identity can reach. The exposure graph turns "this agent exists" into “this agent can do these things” by providing an understanding of the agent’s connectivity across your environment.&lt;/P&gt;
&lt;P&gt;As an example, in the map below, the SOC analyst can see that a ChatGPT Desktop agent is tied to a single AWS account, and from that identity its reach extends to S3 buckets, an AWS KMS key, EC2 instances, and an AWS Bedrock agent. The agent has no cloud permissions of its own, but it inherits the account's — so if it were compromised or misused, that reach becomes a path to encrypted data and key material. This view gives security teams a clear picture of the agent's blast radius, so they can decide how to contain it before it's abused.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Figure 5: Exposure map of a local AI agent, showing its identity and the resources that identity can reach.&lt;/EM&gt;&lt;/img&gt;
&lt;H4&gt;&lt;STRONG&gt;Investigate local AI agent activity in Advanced Hunting&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Beyond the inventory and exposure views, security teams often need to hunt across the environment — to ask which agents are behaving unusually, and what else they touch. Every AI agent discovery event, MCP server connection, and configuration signal is queryable in Advanced Hunting, alongside the endpoint, identity, email, and cloud security telemetry your team already uses every day.&lt;/P&gt;
&lt;P&gt;This capability unlocks two use cases that security teams have been asking for:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Correlate agent activity&lt;/STRONG&gt; with process, file, network, identity, and cloud telemetry to see the full picture of what the agent did&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Hunt for risky configurations – &lt;/STRONG&gt;for example, agents running in auto-approve mode under an identity with privileged access to production, source code, or CI/CD systems&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Security teams can turn any of these queries into a custom detection rule — for instance, raising an alert whenever a newly discovered agent appears with a risky configuration on a device tied to a privileged identity.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Figure 6: A KQL query in Advanced Hunting tracing which critical resources a local AI agent can reach.&lt;/EM&gt;&lt;/img&gt;
&lt;H4&gt;&lt;STRONG&gt;Securing the next frontier of endpoint activity&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;The risk that opened this post — an agent acting on a malicious instruction and reaching everything its identity can touch — is exactly what this protection is built to contain.&lt;/P&gt;
&lt;P&gt;By bringing local AI agents into the same platform teams already use for endpoints, identities, and cloud, Defender turns that blind spot into something security teams can see, investigate, and stop — without getting in the developer's way.&lt;/P&gt;
&lt;P&gt;Developers keep the AI tools accelerating their work. Defenders get the visibility and real-time protection to stay ahead of attackers as they turn to this new surface. That balance — speed for builders, control for defenders — is what securing the AI era actually requires.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Learn more&lt;/STRONG&gt;&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/Build2026/SecuringLocalAgents/Discovery" target="_blank" rel="noopener"&gt;Discover local AI agents with Microsoft Defender&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/Build2026/SecuringLocalAgents/RuntimeProtection" target="_blank" rel="noopener"&gt;Block malicious AI agent behavior with runtime protection&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/microsoft-agent-365" target="_blank" rel="noopener"&gt;Manage and secure your agents with Microsoft Agent 365&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 30 Jun 2026 03:19:36 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/the-next-frontier-in-endpoint-security-securing-local-ai-agents/ba-p/4524651</guid>
      <dc:creator>Eitan_Shteinberg</dc:creator>
      <dc:date>2026-06-30T03:19:36Z</dc:date>
    </item>
    <item>
      <title>Organize your multitenant view with Tenant Groups in Microsoft Defender</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/organize-your-multitenant-view-with-tenant-groups-in-microsoft/ba-p/4522992</link>
      <description>&lt;P&gt;Managing security across many tenants shouldn’t mean drowning in a single, flat list. We’re excited to share a new capability, now in public preview in the Microsoft Defender multitenant (MTO) porta&lt;STRONG&gt;l&lt;/STRONG&gt;: &lt;STRONG&gt;Tenant Groups&lt;/STRONG&gt;—a flexible way to organize the tenants you manage and switch your view between them with a single click.&lt;/P&gt;
&lt;P&gt;If you’re a managed security service provider (MSSP), a cloud service provider (CSP), or a security team operating across multiple Entra ID tenants, this one’s for you.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;What’s new&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;STRONG&gt;Tenant Groups&lt;/STRONG&gt; let you create logical groupings of tenants (by customer segment, geography, criticality, onboarding stage—whatever fits how you work) and seamlessly switch the Defender MTO view to show data from only the tenants in that group.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;NOTICE: &lt;/STRONG&gt;The feature previously called &lt;EM&gt;Tenant groups&lt;/EM&gt;—used for content distribution—has been renamed to &lt;STRONG&gt;Deployment profiles&lt;/STRONG&gt;. The name “Tenant Groups” now refers to this new grouping experience.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H4&gt;&lt;STRONG&gt;Why it matters&lt;/STRONG&gt;&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Focus, faster&lt;/STRONG&gt; – Investigate incidents, hunt threats, and review posture against just the tenants you care about right now—without noise from the rest.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Operational clarity &lt;/STRONG&gt;– Group tenants the way your team actually works (e.g., Tier 1 customers, EMEA, Pilot rollout).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Permissions-aware &lt;/STRONG&gt;– Even if a Tenant Group contains more tenants, you’ll only see the ones where you have B2B/GDAP (granular delegated admin privileges) access. Your existing access controls stay in charge.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;&lt;STRONG&gt;Permissions you’ll need&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;To work with Tenant Groups, your account needs one of the following:&lt;/P&gt;
&lt;H5&gt;Entra ID roles&lt;/H5&gt;
&lt;UL&gt;
&lt;LI&gt;Security Administrator&lt;/LI&gt;
&lt;LI&gt;Security Operator&lt;/LI&gt;
&lt;LI&gt;Global Administrator&lt;/LI&gt;
&lt;/UL&gt;
&lt;H5&gt;Product-specific (MDE, MDI, etc.) role-based access control (RBAC)&lt;/H5&gt;
&lt;UL&gt;
&lt;LI&gt;Global Administrator&lt;/LI&gt;
&lt;LI&gt;Security Administrator&lt;/LI&gt;
&lt;LI&gt;Plus, any custom RBAC roles required to see data across products&lt;/LI&gt;
&lt;/UL&gt;
&lt;H5&gt;Unified RBAC (URBAC)&lt;/H5&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Security/read&lt;/STRONG&gt;—to view Tenant Groups&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Security/manage&lt;/STRONG&gt;—to create Tenant Groups&lt;/LI&gt;
&lt;/UL&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;Remember:&lt;/STRONG&gt; A Tenant Group can include tenants you don’t have access to. You’ll only ever see the ones your permissions allow.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H4&gt;&lt;STRONG&gt;Getting started&lt;/STRONG&gt;&lt;/H4&gt;
&lt;H5&gt;1. Open Tenant Groups&lt;/H5&gt;
&lt;P&gt;Sign in to the &lt;STRONG&gt;Microsoft Defender portal&lt;/STRONG&gt; with administrative credentials, then navigate to &lt;STRONG&gt;Multitenant Management &amp;gt; Tenant Groups&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;You’ll find a built-in group called &lt;STRONG&gt;My private group&lt;/STRONG&gt; that contains all the tenants from your previous setup. You can add or remove tenants from it, but it can’t be deleted.&lt;/P&gt;
&lt;H5&gt;2. Create a Tenant Group&lt;/H5&gt;
&lt;OL&gt;
&lt;LI&gt;Select &lt;STRONG&gt;+ Create tenant group&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;Give it a descriptive name (e.g., Healthcare customers, EMEA Tier 1).&lt;/LI&gt;
&lt;LI&gt;Optionally, add a description so teammates know the group’s intent.&lt;/LI&gt;
&lt;LI&gt;Select the tenants you want to include.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;That’s it—your group is ready.&lt;/P&gt;
&lt;H5&gt;3. Switch between Tenant Groups&lt;/H5&gt;
&lt;OL start="5"&gt;
&lt;LI&gt;In the top-left corner of the portal, select &lt;STRONG&gt;Open multitenant management&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;Choose the group you just created.&lt;/LI&gt;
&lt;/OL&gt;
&lt;img /&gt;
&lt;P&gt;Navigate around the Defender MTO portal—incidents, alerts, devices, hunting—and you’ll see only data from the tenants in that group. Switch groups anytime to refocus.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;Live change detection: &lt;/STRONG&gt;If a teammate edits a Tenant Group (adds or removes tenants) while you’re viewing it, the portal surfaces a notification so you know the underlying scope has changed. No stale views, no surprises.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;img /&gt;
&lt;H5&gt;4. Edit a Tenant Group&lt;/H5&gt;
&lt;OL start="7"&gt;
&lt;LI&gt;Go back to &lt;STRONG&gt;Multitenant Management &amp;gt; Tenant Groups&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;Select the group and choose &lt;STRONG&gt;Edit&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;Add or remove tenants as your environment evolves, then re-test your views.&lt;/LI&gt;
&lt;/OL&gt;
&lt;H4&gt;&lt;STRONG&gt;Tips for getting the most out of Tenant Groups&lt;/STRONG&gt;&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Start with how your team triages&lt;/STRONG&gt; – Name groups after the workflows you actually run (On-call queue, Customer A—production).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Keep groups small and purposeful &lt;/STRONG&gt;– Overlapping, focused groups beat one giant catch-all.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Pair with Deployment profiles &lt;/STRONG&gt;–&lt;STRONG&gt; &lt;/STRONG&gt;Use Tenant Groups for viewing, and Deployment profiles for distributing content—two clean, complementary concepts.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Audit access regularly &lt;/STRONG&gt;–&lt;STRONG&gt; &lt;/STRONG&gt;Because group membership is independent of B2B/GDAP access, periodic reviews keep expectations aligned.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;&lt;STRONG&gt;We want your feedback&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Tenant Groups are designed around real multitenant operations work—and we’d love to hear how you’re using them. Try it out in your environment, share what’s working (and what isn’t), and let us know what you’d like to see next.&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/organize-your-multitenant-view-with-tenant-groups-in-microsoft/ba-p/4522992</guid>
      <dc:creator>Simaya_Ouli</dc:creator>
      <dc:date>2026-05-27T16:00:00Z</dc:date>
    </item>
    <item>
      <title>Monthly news -  May 2026</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/monthly-news-may-2026/ba-p/4516764</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Microsoft Defender&lt;/STRONG&gt;&lt;BR /&gt;Monthly news - May 2026 Edition&lt;/P&gt;
&lt;P&gt;This is our monthly "What's new" blog post, summarizing product updates and various new assets we released over the past month across our Defender products. In this edition, we are looking at all the goodness from April 2026. We are now including news related to Defender for Cloud in the Defender portal. For all other Defender for Cloud news, have a look at the dedicated Defender for Cloud Monthly News&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/microsoft-defender-for-cloud-customer-newsletter/4491637" target="_blank" rel="noopener" data-lia-auto-title="here" data-lia-auto-title-active="0"&gt;here&lt;/A&gt;&lt;STRONG&gt;.&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;🚀 New Virtual Ninja Show episode:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.youtube.com/watch?v=u9nXRABIw1k&amp;amp;list=PLmAptfqzxVEVeZJO1kj4wiUVhCPfCa0Fm&amp;amp;index=2" target="_blank" rel="noopener"&gt;The future of identity protection with Predictive Shielding&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.youtube.com/watch?v=rujGb8CEmN0&amp;amp;list=PLmAptfqzxVEVeZJO1kj4wiUVhCPfCa0Fm&amp;amp;index=3&amp;amp;t=5s" target="_blank" rel="noopener"&gt;Network-layer data protection with Microsoft Entra GSA and Purview DLP&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.youtube.com/watch?v=pDA80Gr-0xc&amp;amp;list=PLmAptfqzxVEVeZJO1kj4wiUVhCPfCa0Fm&amp;amp;index=4" target="_blank" rel="noopener"&gt;Data lake federation: hunt across external data without ingesting it&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Weekly Security News: &lt;/STRONG&gt;We publish a short 1ish minute video every week with updates across our Microsoft Security stack. Subscribe to our&amp;nbsp;&lt;A class="lia-external-url" href="https://www.youtube.com/@MicrosoftSecurityCommunity/shorts" target="_blank" rel="noopener"&gt;YouTube channel&lt;/A&gt;, so you don't miss the next episode.&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;Actionable threat insights&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2026/05/01/cve-2026-31431-copy-fail-vulnerability-enables-linux-root-privilege-escalation/" target="_blank" rel="noopener"&gt;CVE-2026-31431: Copy Fail vulnerability enables Linux root privilege escalation across cloud environments&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2026/04/30/email-threat-landscape-q1-2026-trends-and-insights/" target="_blank" rel="noopener"&gt;Email threat landscape: Q1 2026 trends and insights&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2026/04/18/crosstenant-helpdesk-impersonation-data-exfiltration-human-operated-intrusion-playbook/" target="_blank" rel="noopener"&gt;Cross‑tenant helpdesk impersonation to data exfiltration: A human-operated intrusion playbook&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2026/04/21/detection-strategies-cloud-identities-against-infiltrating-it-workers/" target="_blank" rel="noopener"&gt;Detection strategies across cloud and identities against infiltrating IT workers&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2026/04/16/dissecting-sapphire-sleets-macos-intrusion-from-lure-to-compromise/" target="_blank" rel="noopener"&gt;Dissecting Sapphire Sleet’s macOS intrusion from lure to compromise&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Defender&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Blog post:&amp;nbsp;&lt;A href="https://www.microsoft.com/en-us/security/blog/2026/04/17/domain-compromise-predictive-shielding-shut-down-lateral-movement/" target="_blank" rel="noopener"&gt;Containing a domain compromise: How predictive shielding shut down lateral movement&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;(Public Preview) You can now view the current status of automatic attack disruption and predictive shielding actions related to a specific incident. You view this data in the&amp;nbsp;&lt;STRONG&gt;Activities&lt;/STRONG&gt;&amp;nbsp;tab of the incident page.&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-xdr/autoad-results#track-the-action-status-in-the-activities-tab-preview" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Learn more&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;We made several enhancements across the Advanced hunting experience, read &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/microsoft-defender-new-advanced-hunting-enhancements/4514654" target="_blank" rel="noopener" data-lia-auto-title="this blog post" data-lia-auto-title-active="0"&gt;this blog post&lt;/A&gt; for all the details.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;(Public Preview) &lt;STRONG&gt;The&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-aiagentsinfo-table" target="_blank" rel="noopener" data-linktype="relative-path"&gt;AIAgentsInfo&lt;/A&gt;&amp;nbsp;table in advanced hunting&lt;/STRONG&gt; now includes additional columns that provide deeper visibility into AI agents operating in your Microsoft 365 environment. These fields expand coverage beyond Copilot Studio to all agent types, including Microsoft Foundry, third-party marketplace, and custom line-of-business agents.&lt;/LI&gt;
&lt;LI&gt;(Generally Available) &lt;A href="https://learn.microsoft.com/en-us/defender-xdr/investigate-alerts#built-in-alert-tuning-rules" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Built-in alert tuning rules&lt;/A&gt;&amp;nbsp;are now generally available. Built-in alert tuning rules suppress alerts from common benign activity in Defender for Endpoint and Defender for Office 365 without affecting Automated Investigation and Response (AIR) investigations and email notifications.&lt;/LI&gt;
&lt;LI&gt;Microsoft Defender Experts for XDR customers can now see&amp;nbsp;&lt;STRONG&gt;Defender Experts&lt;/STRONG&gt;&amp;nbsp;as a distinct entry in the Microsoft Defender portal navigation menu. This feature adds to the existing home page status card as in-portal experiences that provide consistent and predictable access to the service.&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-xdr/start-using-mdex-xdr" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Learn more&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Blog post: &lt;A href="https://www.microsoft.com/en-us/security/blog/2026/04/28/simplifying-aws-defense-microsoft-sentinel-ueba/" target="_blank" rel="noopener"&gt;Simplifying AWS defense with Microsoft Sentinel UEBA&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Call to action: update automation by July 1, 2026 - Account Name is now consistently the UPN prefix for analytics rule alerts! Microsoft Sentinel is updating how the account entity's&amp;nbsp;&lt;STRONG&gt;Account Name&lt;/STRONG&gt; value is populated for analytics rule alerts when the full UPN is mapped into Account Name. This change improves consistency for downstream automation rules and Logic Apps playbooks. For more information, including before and after examples, read the blog article&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/blog/microsoftsentinelblog/update-changing-the-account-name-entity-mapping-in-microsoft-sentinel/4489040" target="_blank" rel="noopener" data-linktype="external"&gt;Update: Changing the Account Name Entity Mapping in Microsoft Sentinel&lt;/A&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;For all other Sentinel News, have a look at the "&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/microsoftsentinelblog/what%E2%80%99s-new-in-microsoft-sentinel-april-2026/4516354" target="_blank" rel="noopener" data-lia-auto-title="What's new in Microsoft Sentinel blog post - April edition" data-lia-auto-title-active="0"&gt;What's new in Microsoft Sentinel blog post - April edition&lt;/A&gt;"&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Defender for Endpoint / Microsoft Defender Vulnerability Management&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;(Public Preview) You can now view the current status of automatic attack disruption and predictive shielding actions related to a specific incident. You view this data in the&amp;nbsp;&lt;STRONG&gt;Activities&lt;/STRONG&gt;&amp;nbsp;tab of the incident page.&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-xdr/autoad-results#track-the-action-status-in-the-activities-tab-preview" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Learn more&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Microsoft Secure Score now includes the&amp;nbsp;&lt;STRONG&gt;Ensure devices are updated to Secure Boot 2023 certificates and boot manager&lt;/STRONG&gt;, which helps identify devices that haven't yet transitioned to the new Secure Boot 2023 certificates required ahead of the June 2026 expiration. To learn more about the recommendation, see&amp;nbsp;&lt;A href="https://aka.ms/secureboot-mde" target="_blank" rel="noopener" data-linktype="external"&gt;Assess Secure Boot status with Microsoft Defender (blog)&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Defender for Identity&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;(Public Preview) Custom account correlation rules. Custom account correlation rules let you link accounts that belong to the same identity, such as privileged accounts with unique naming conventions. You can correlate accounts that don't share strong identifiers such as account ID, SID, object ID, or UPN by defining rules based on UPN prefix, UPN suffix, domain UPN, or employee ID. For more information, see&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/custom-account-correlation-rules" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Create custom account correlation rules&lt;/A&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;(Generally Available) The&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/deploy/configure-windows-event-collection#configure-defender-for-identity-to-collect-windows-events-automatically" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Automatic Windows event-auditing configuration for sensors v3.x&lt;/A&gt; is now generally available. Automatic Windows event-auditing streamlines deployment by automatically applying the required auditing settings to new sensors and correcting misconfigurations on existing ones.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 04 May 2026 15:24:34 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/monthly-news-may-2026/ba-p/4516764</guid>
      <dc:creator>HeikeRitter</dc:creator>
      <dc:date>2026-05-04T15:24:34Z</dc:date>
    </item>
    <item>
      <title>Microsoft Defender: New Advanced hunting enhancements</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/microsoft-defender-new-advanced-hunting-enhancements/ba-p/4514654</link>
      <description>&lt;H5&gt;&lt;STRONG&gt;Co-author: Jeremy Tan&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;As a security analyst who actively hunts for critical threats, one of the most frustrating things that can happen is hitting a limit mid-query or encounter an experience that doesn’t behave as expected. The resulting friction and time spent troubleshooting or navigating takes valuable focus away from the investigation itself.&lt;/P&gt;
&lt;P&gt;To address this, we’ve made several enhancements across the experience to ensure investigations can scale seamlessly so analysts can stay focused on finding and stopping threats without interruption. These updates are based on your feedback and our commitment to continually improve the experience for analysts and customers alike.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Scaling Investigations with Expanded Limits&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;We’ve made several enhancements across the experience to expand limits and better support large-scale investigations so analysts can query, explore, and act on more data with fewer constraints.&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;Results limitation increase (Preview)&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;We have heard your feedback on the need for larger data sets and are excited to announce that the results limitation in advanced hunting has been raised from 30,000 to &lt;STRONG&gt;100,000 records&lt;/STRONG&gt;. Now, queries returning up to 100,000 results will display all available data. If a query exceeds this threshold, results are truncated as before, but the increase allows for more comprehensive analysis and improved incident response.&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;Records limitation picker (Preview)&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;One common challenge in advanced hunting has been the risk of running queries that return overwhelming result sets, consuming excessive resources and potentially hitting system limits. The new &lt;STRONG&gt;records limitation picker&lt;/STRONG&gt; addresses this by allowing you to explicitly set how many rows a query should return, directly from the editor toolbar.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Choose from predefined limits: 1,000, 5,000, or 10,000, 30,000 and 100,000 rows.&lt;/LI&gt;
&lt;LI&gt;Select the maximum system limit (currently 100,000 records).&lt;/LI&gt;
&lt;LI&gt;Define a custom value as needed.&lt;/LI&gt;
&lt;LI&gt;The selected limit applies alongside any KQL-defined row limitations, with the lower value always taking precedence.&lt;/LI&gt;
&lt;LI&gt;Your choice persists across page refreshes, navigation, and browser restarts.&lt;/LI&gt;
&lt;LI&gt;By default, tenants start at the maximum row limit, but you can tailor your selection via page preferences.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This enhancement greatly improves performance and prevents unexpected limitations, making hunting safer and more efficient.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Partial results on size limit (GA)&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Previously, queries that exceeded the 64 mb results size limit would fail outright, forcing analysts to modify their queries and rerun them. With the latest update, &lt;STRONG&gt;partial results&lt;/STRONG&gt; are now provided when the size limit is reached:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Queries return the maximum records that fit within the 64 MB cap.&lt;/LI&gt;
&lt;LI&gt;A clear message bar indicates when results are partial due to size constraints.&lt;/LI&gt;
&lt;LI&gt;This allows you to act on available data immediately, without repeating query adjustments.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This improvement speeds up investigations and provides valuable data even in scenarios where limits are reached.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Enhanced UI for Faster, More Intuitive Investigations&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;We’ve made significant enhancements to the user experience delivering a more streamlined interface that helps analysts move through incidents with greater clarity, act with confidence, and spend less time searching and more time responding. &lt;BR /&gt;&lt;BR /&gt;Hear from one of our customers:&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;“&lt;EM&gt;The recent updates to the Defender Advanced Hunting experience have gone a long way toward decluttering the interface and lowering the barrier for analysts and engineers who were previously more comfortable working exclusively in Microsoft Sentinel in the Azure portal.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;By simplifying navigation, reducing unnecessary visual noise, and adding pinnable tabs, the XDR portal now feels more familiar. This usability improvement has helped shift long-standing Sentinel users toward the XDR experience without forcing a change in how teams think about their data or workflows.”&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;-Matt McCullogh, Senior SIEM Engineer, Best Buy&lt;/STRONG&gt;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Query details side pane: enhanced visibility and troubleshooting (GA)&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Understanding query execution and troubleshooting errors has often required tedious trial and error. The new &lt;STRONG&gt;query execution details side pane&lt;/STRONG&gt; surfaces rich, actionable metadata for every query—successful or failed. With this feature, you can:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;View execution time breakdowns, data sources, scopes, and resource utilization.&lt;/LI&gt;
&lt;LI&gt;Examine response characteristics and detailed error information.&lt;/LI&gt;
&lt;LI&gt;Navigate tabs such as overview, raw statistics, and errors for comprehensive diagnostics.&lt;/LI&gt;
&lt;LI&gt;Access the side pane easily after running a query, or even from error messages in failure scenarios.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This transparency makes it far easier to investigate issues and optimize your hunting experience.&lt;/P&gt;
&lt;img /&gt;&lt;img /&gt;
&lt;H4&gt;&lt;STRONG&gt;Improved error-handling for Advanced hunting queries (GA)&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Advanced hunting now provides improved output messages, including clearer error messages that explain query failures and actionable suggestions for common issues. This update simplifies troubleshooting and helps reduce downtime with complex queries.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Simpler Navigation, More Powerful Hunting&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Alongside these updates, the Advanced hunting UI has received several enhancements focused on usability and streamlined workflows. Users can now easily filter results with a single click, making data exploration more efficient and responsive and enhanced configuration of the schema tree now allows for collapsing or expanding all nodes with ease. Additionally, the page layout has been thoughtfully restructured, organizing components in a more intuitive manner for a modern, cohesive experience that makes advanced hunting both powerful and easy to use.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Rename tabs (GA)&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Another notable usability enhancement is the ability for users to rename their working tabs within advanced hunting. This feature enables users to organize their work sessions more efficiently, allowing for clear identification of ongoing investigations and queries without requiring them to save their work as long-term functions or queries. By simply renaming tabs, users can quickly switch between tasks and keep their workspace well-structured, further improving workflow and productivity.&lt;/P&gt;
&lt;img /&gt;
&lt;H4&gt;&lt;STRONG&gt;Saving KQL functions to log analytics workspace (GA)&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;In addition to the above enhancements, we are delighted to introduce the ability to save KQL functions directly from the advanced hunting page into your log analytics workspace. To utilize this feature:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Pick a folder under &lt;STRONG&gt;shared functions → Sentinel workspace functions&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;Functions saved in this folder are available for use in workbooks, analytics rules, and for execution in advanced hunting.&lt;/LI&gt;
&lt;LI&gt;Note: functions saved here are &lt;STRONG&gt;not&lt;/STRONG&gt; available in custom detection rules.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This new capability empowers you to build reusable logic and streamline your security workflows across Microsoft Sentinel and advanced hunting.&lt;/P&gt;
&lt;img /&gt;
&lt;H4&gt;&lt;STRONG&gt;Conclusion&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;These enhancements represent our continued commitment to supporting your security investigations with robust, flexible, and efficient tools. We look forward to your feedback and to bringing even more improvements in the future. Learn more about the new advanced hunting enhancements in our &lt;A href="https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-overview" target="_blank" rel="noopener"&gt;documentation&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2026 16:45:15 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/microsoft-defender-new-advanced-hunting-enhancements/ba-p/4514654</guid>
      <dc:creator>Noa_Nutkevitch</dc:creator>
      <dc:date>2026-04-28T16:45:15Z</dc:date>
    </item>
    <item>
      <title>Monthly news -  April 2026</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/monthly-news-april-2026/ba-p/4508050</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Microsoft Defender&lt;/STRONG&gt;&lt;BR /&gt;Monthly news - April 2026 Edition&lt;/P&gt;
&lt;P&gt;This is our monthly "What's new" blog post, summarizing product updates and various new assets we released over the past month across our Defender products. In this edition, we are looking at all the goodness from March 2026. We are now including news related to Defender for Cloud in the Defender portal. For all other Defender for Cloud news, have a look at the dedicated Defender for Cloud Monthly News&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/microsoft-defender-for-cloud-customer-newsletter/4491637" target="_blank" rel="noopener" data-lia-auto-title="here" data-lia-auto-title-active="0"&gt;here&lt;/A&gt;&lt;STRONG&gt;.&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;🚀 New Virtual Ninja Show episode:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.youtube.com/live/sCv_iPAxMBY?si=PvnM_k5dZ6JMQb-J" target="_blank" rel="noopener"&gt;New skills in Microsoft Defender&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.youtube.com/live/Uf1bMc4vVKY?si=Tfs07p3YLeQOo6AE" target="_blank" rel="noopener"&gt;Autonomous AI Agents in Microsoft Defender&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://youtu.be/xJTw_Q2WVD8?si=5x9fbSZ2zW16jJ1h" target="_blank" rel="noopener"&gt; Beyond KQL: Unlocking SOC Insights with Sentinel data lake Jupyter Notebooks&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://youtu.be/-Mi-Rw3zCE0?si=p7lKt-rTxcggplW5" target="_blank" rel="noopener"&gt; Extending Attack Disruption beyond Microsoft: third‑party signals in action&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://youtu.be/5ZrrhPgzLn0?si=IqNidWLE-vfK0htV" target="_blank" rel="noopener"&gt; A new home for Microsoft Defender for Cloud&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;RSA blog posts:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/security-copilot-in-defender-empowering-the-soc-with-assistive-and-autonomous-ai/4503047" target="_blank" rel="noopener"&gt;Security Copilot in Defender: empowering the SOC with assistive and autonomous AI&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/rsa-2026-what%E2%80%99s-new-in-microsoft-defender/4503046" target="_blank" rel="noopener"&gt;RSA 2026: What’s new in Microsoft Defender?&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Actionable threat insights&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2026/04/06/ai-enabled-device-code-phishing-campaign-april-2026/" target="_blank"&gt;Inside an AI‑enabled device code phishing campaign&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2026/04/06/storm-1175-focuses-gaze-on-vulnerable-web-facing-assets-in-high-tempo-medusa-ransomware-operations/" target="_blank"&gt;Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2026/04/02/cookie-controlled-php-webshells-tradecraft-linux-hosting-environments/" target="_blank"&gt;Cookie-controlled PHP webshells: A stealthy tradecraft in Linux hosting environments&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2026/04/01/mitigating-the-axios-npm-supply-chain-compromise/" target="_blank"&gt;Mitigating the Axios npm supply chain compromise&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Defender&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;We’re introducing &lt;STRONG&gt;a chat experience for Security Copilot directly within Microsoft Defender&lt;/STRONG&gt;. Copilot is already embedded across Microsoft Defender experiences today, but now you can interact with it through an ongoing, two-way conversation. Ask questions, explore hypotheses, and follow your investigation threads across incidents, alerts, identities, devices, IPs, and other evidence. Read more about it in this &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/security-copilot-in-defender-empowering-the-soc-with-assistive-and-autonomous-ai/4503047" target="_blank" rel="noopener" data-lia-auto-title="blog post" data-lia-auto-title-active="0"&gt;blog post&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;We are &lt;STRONG&gt;expanding agentic triage to identity and cloud alerts&lt;/STRONG&gt; - bringing triage for phish, identity and cloud together within a single agent. &lt;STRONG&gt;The Security Alert Triage Agent &lt;/STRONG&gt;helps you autonomously determine whether these alerts represent real threats or false alarms, delivering natural language findings and transparent, step-by-step decision analysis.&amp;nbsp;Read more about it in this &lt;A href="https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/security-copilot-in-defender-empowering-the-soc-with-assistive-and-autonomous-ai/4503047" target="_blank" rel="noopener" data-lia-auto-title="blog post" data-lia-auto-title-active="0"&gt;blog post&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Identity security enhancements&lt;/STRONG&gt;: New identity security capabilities help you monitor and manage identity security for human and non-human identities:
&lt;UL&gt;
&lt;LI&gt;(Public Preview) Identity Security dashboard: The&amp;nbsp;&lt;STRONG&gt;Identity Security&lt;/STRONG&gt;&amp;nbsp;dashboard provides summary cards for identity providers, on-premises identities, SaaS identities, PAM and IGA integrations, and non-human identities. For more information, see&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/dashboard" target="_blank" rel="noopener" data-linktype="absolute-path"&gt;The Identity Security dashboard&lt;/A&gt;. The&amp;nbsp;&lt;STRONG&gt;Identity Security&lt;/STRONG&gt;&amp;nbsp;dashboard is being rolled out gradually to customers, and might not yet be available in your organization.&lt;/LI&gt;
&lt;LI&gt;(Public Preview) Coverage and maturity page: The&amp;nbsp;&lt;STRONG&gt;Coverage and maturity&lt;/STRONG&gt;&amp;nbsp;page shows your organization's identity security coverage with maturity levels, including Connected, Protected, Fortified, and Resilient, and prioritized setup tasks. For more information, see&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-xdr/identity-security/coverage-maturity" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Coverage and maturity&lt;/A&gt;. The&amp;nbsp;&lt;STRONG&gt;Coverage and maturity&lt;/STRONG&gt;&amp;nbsp;page is being rolled out gradually to customers, and might not yet be available in your organization. If you don't see this feature in your environment yet, check back soon.&lt;/LI&gt;
&lt;LI&gt;Identity inventory: The&amp;nbsp;&lt;STRONG&gt;Identity inventory&lt;/STRONG&gt;&amp;nbsp;page now shows human and non-human identities in separate tabs. Insight cards help you classify critical assets, view highly privileged identities, identify critical Active Directory service accounts, and view cloud application accounts. For more information, see&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/identity-inventory" target="_blank" rel="noopener" data-linktype="absolute-path"&gt;View the Identity inventory&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;(Preview) Non-human identities: The&amp;nbsp;&lt;STRONG&gt;Non-human identities&lt;/STRONG&gt;&amp;nbsp;tab shows non-human identities, including Microsoft Entra ID apps, Active Directory service accounts, Google Workspace apps, and Salesforce apps. For more information, see&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/identity-inventory" target="_blank" rel="noopener" data-linktype="absolute-path"&gt;Identity inventory&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-xdr/investigate-non-human-identities" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Investigate non-human identities&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;(Public Preview) Identity risk score: A new risk score for identities, ranging from 0 to 100, that indicates the likelihood of compromise and the potential impact based on criticality and privileged roles. The risk score is available in Microsoft Entra ID, where it can be used to inform conditional access policies and identity protection workflows. A new&amp;nbsp;&lt;STRONG&gt;Risk score&lt;/STRONG&gt;&amp;nbsp;tab on the&amp;nbsp;&lt;STRONG&gt;Identity&lt;/STRONG&gt;&amp;nbsp;page provides a detailed breakdown of the risk factors, including percentile comparison and risk trends. For more information, see&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-xdr/investigate-users" target="_blank" rel="noopener" data-linktype="absolute-path"&gt;Investigate an identity&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;(Public Preview) Domain investigation page: The&amp;nbsp;&lt;STRONG&gt;Domain investigation&lt;/STRONG&gt;&amp;nbsp;page shows Active Directory domain security, including domain properties, deployment health, identity summary, service account breakdown, sensitive entities, active recommendations, group policies, and trust relationships. For more information, see&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/investigate-domain" target="_blank" rel="noopener" data-linktype="absolute-path"&gt;Investigate a domain&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;(Public Preview)Identity security recommendations: View recommendations from Active Directory, Microsoft Entra ID, SaaS applications, and supported non-Microsoft identity providers. For more information, see&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-xdr/identity-security/identity-security-recommendations" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Identity security recommendations&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/sentinel/whats-new?tabs=defender-portal#call-to-action-update-older-microsoft-sentinel-content-as-code-sentinel-repositories-api-versions-before-june-15-2026" target="_blank" rel="noopener" data-linktype="self-bookmark"&gt;Call to action: update older Microsoft Sentinel content as code (Sentinel repositories) API versions before June 15, 2026&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;(Public Preview) The following advanced hunting schema tables are now available for preview:
&lt;UL&gt;
&lt;LI&gt;The&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-clouddnsevents-table" target="_blank" rel="noopener" data-linktype="relative-path"&gt;CloudDnsEvents&lt;/A&gt;&amp;nbsp;table contains information about DNS activity events from cloud infrastructure environments.&lt;/LI&gt;
&lt;LI&gt;The&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-cloudpolicyenforcementevents-table" target="_blank" rel="noopener" data-linktype="relative-path"&gt;CloudPolicyEnforcementEvents&lt;/A&gt;&amp;nbsp;table contains policy enforcement evaluation decisions and metadata of security gating events for various cloud platforms protected by the organization's Microsoft Defender for Cloud.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;To improve accuracy and better protect organizational identities, we've made &lt;STRONG&gt;updates to the Secure Score category calculations&lt;/STRONG&gt;. Some security recommendations categorized as&amp;nbsp;&lt;STRONG&gt;Cloud apps&lt;/STRONG&gt;&amp;nbsp;recommendations are now considered identity‑related and grouped under the&amp;nbsp;&lt;STRONG&gt;Identity&lt;/STRONG&gt;&amp;nbsp;category. While the total Secure Score remains unchanged, individual identity and app scores may change.&lt;/LI&gt;
&lt;LI&gt;(Public Preview) Customers can now use filters on very large incidents with many alerts and entities or hide specific entities to simplify complex incident graphs. By simplifying the graphs, they can focus their investigations on what matters most.&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-xdr/investigate-incidents#filter-and-focus-the-incident-graph-preview" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Learn more&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;The&amp;nbsp;&lt;STRONG&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-endpoint/respond-machine-alerts#contain-user-from-the-network" target="_blank" rel="noopener" data-linktype="absolute-path"&gt;proactive user containment (contain user)&lt;/A&gt;&lt;/STRONG&gt;&amp;nbsp;action as part of the predictive shielding feature is &lt;STRONG&gt;now generally available&lt;/STRONG&gt;. This action infuses activity data with exposure data to identify exposed credentials at risk of being compromised and reused to conduct malicious activity.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Defender for Endpoint / Microsoft Defender Vulnerability Management&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Library management for live response is now generally available&lt;/STRONG&gt;. This feature provides a centralized view for managing files and scripts used during live response sessions.&lt;/LI&gt;
&lt;LI&gt;Microsoft&amp;nbsp;&lt;STRONG&gt;Secure Score now includes new recommendations:&lt;/STRONG&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Block outbound network connections from Microsoft HTML Application Host (mshta.exe):&lt;/STRONG&gt; Helps mitigate attacks that leverage mshta.exe (a trusted Windows binary) to execute malicious scripts and communicate with external command-and-control (C2) infrastructure. Blocking outbound connections from mshta.exe disrupts common attack chains, prevents payload download and data exfiltration, and reduces the risk of living-off-the-land attacks. This is relevant for emerging attack campaigns, for example, ClickFix campaigns, where attackers abuse legitimate tools like mshta.exe to execute malicious content delivered through user interaction.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Block file transfer over RDP&lt;/STRONG&gt;: Restricts file transfer capabilities in Remote Desktop Protocol (RDP) sessions. This helps prevent attackers from using RDP sessions to transfer malicious files into the environment or exfiltrate sensitive data.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;SMB server security hardening against authentication relay attacks&lt;/STRONG&gt;: Helps protect servers from credential relay attacks by strengthening Server Message Block (SMB) authentication protections, including enforcing Extended Protection for Authentication (EPA), SMB signing, and SMB encryption to ensure authentication integrity and protect SMB traffic from tampering or interception.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;The&amp;nbsp;&lt;STRONG&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-endpoint/respond-machine-alerts#contain-user-from-the-network" target="_blank" rel="noopener" data-linktype="absolute-path"&gt;proactive user containment (contain user)&lt;/A&gt;&lt;/STRONG&gt;&amp;nbsp;action as part of the predictive shielding feature is &lt;STRONG&gt;now generally available&lt;/STRONG&gt;. This action infuses activity data with exposure data to identify exposed credentials at risk of being compromised and reused to conduct malicious activity.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Defender for Identity&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;New identity security capabilities help you monitor and manage identity security for human and non-human identities:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;(Public Preview) Identity Security dashboard&lt;/STRONG&gt;: The&amp;nbsp;&lt;STRONG&gt;Identity Security&lt;/STRONG&gt;&amp;nbsp;dashboard provides summary cards for identity providers, on-premises identities, SaaS identities, PAM and IGA integrations, and non-human identities. Widgets show deployment status, highly privileged identities, users at risk, and domains with unsecured configurations. For more information, see&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/dashboard" target="_blank" rel="noopener" data-linktype="relative-path"&gt;The Identity Security dashboard&lt;/A&gt;.&amp;nbsp;The&amp;nbsp;&lt;STRONG&gt;Identity Security&lt;/STRONG&gt;&amp;nbsp;dashboard is being rolled out gradually to customers, and might not yet be available in your organization.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;(Public Preview) &lt;/STRONG&gt;The&amp;nbsp;&lt;STRONG&gt;Coverage and maturity&lt;/STRONG&gt;&amp;nbsp;page shows your organization's identity security coverage for identity providers, on-premises identities, SaaS identities, and PAM and IGA integrations. Each source displays a maturity level, including Connected, Protected, Fortified, and Resilient, with identity counts, coverage scores, and prioritized setup tasks. For more information, see&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-xdr/identity-security/coverage-maturity" target="_blank" rel="noopener" data-linktype="absolute-path"&gt;Coverage and maturity&lt;/A&gt;.&amp;nbsp;The&amp;nbsp;&lt;STRONG&gt;Coverage and maturity&lt;/STRONG&gt;&amp;nbsp;page is being rolled out gradually to customers, and might not yet be available in your organization. If you don't see this feature in your environment yet, check back soon.&lt;/LI&gt;
&lt;LI&gt;The&amp;nbsp;&lt;STRONG&gt;Identity inventory&lt;/STRONG&gt;&amp;nbsp;page now shows human and non-human identities in separate tabs. Insight cards help you classify critical assets, view highly privileged identities, identify critical Active Directory service accounts, and view cloud application accounts. For more information, see&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/identity-inventory" target="_blank" rel="noopener" data-linktype="relative-path"&gt;View the Identity inventory&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;(Public Preview) &lt;/STRONG&gt;The&amp;nbsp;&lt;STRONG&gt;Non-human identities&lt;/STRONG&gt;&amp;nbsp;tab on the&amp;nbsp;&lt;STRONG&gt;Identity inventory&lt;/STRONG&gt;&amp;nbsp;page shows non-human identities, including Microsoft Entra ID apps, Active Directory service accounts, Google Workspace apps, and Salesforce apps. The tab includes statistics for risky, highly privileged, overprivileged, unused, and externally published identities. A separate investigation page lets you view details for each identity. For more information, see&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/identity-inventory" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Identity inventory&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-xdr/investigate-non-human-identities" target="_blank" rel="noopener" data-linktype="absolute-path"&gt;Investigate non-human identities&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;(Public Preview) A new risk score for identities&lt;/STRONG&gt;, ranging from 0 to 100, that indicates the likelihood of compromise and the potential impact based on criticality and privileged roles. The risk score is available in Microsoft Entra ID, where it can be used to inform conditional access policies and identity protection workflows. A new&amp;nbsp;&lt;STRONG&gt;Risk score&lt;/STRONG&gt;&amp;nbsp;tab on the&amp;nbsp;&lt;STRONG&gt;Identity&lt;/STRONG&gt;&amp;nbsp;page provides a detailed breakdown of the risk factors, including percentile comparison and risk trends. For more information, see&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-xdr/investigate-users" target="_blank" rel="noopener" data-linktype="absolute-path"&gt;Investigate an identity&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;(Public Preview) Identity security recommendations&lt;/STRONG&gt;: View recommendations for Active Directory, Microsoft Entra ID, and SaaS applications such as Microsoft, Atlassian, GitHub, Google Workspace, Salesforce, and ServiceNow. Recommendations are also available for non-Microsoft identity providers such as Okta, PingOne, CyberArk, and SailPoint. For more information, see&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-xdr/identity-security/identity-security-recommendations" target="_blank" rel="noopener" data-linktype="absolute-path"&gt;Identity security recommendations&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;(Public Preview) Domain investigation page&lt;/STRONG&gt;: The&amp;nbsp;&lt;STRONG&gt;Domain investigation&lt;/STRONG&gt;&amp;nbsp;page shows Active Directory domain security, including domain properties, deployment health, identity summary, service account breakdown, sensitive entities, active recommendations, group policies, and trust relationships. For more information, see&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/investigate-domain" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Investigate a domain&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;(Public Preview) Password protection page&lt;/STRONG&gt;: The&amp;nbsp;&lt;STRONG&gt;Password protection&lt;/STRONG&gt;&amp;nbsp;page shows identity password risk from Active Directory, Microsoft Entra ID, and Okta, with tabs for password hygiene, password policies, leaked credentials, and exposed passwords. For more information, see&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/password-protection" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Password protection&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;To improve accuracy and better protect organizational identities, we've made &lt;STRONG&gt;updates to the Secure Score category calculations&lt;/STRONG&gt;. Some security recommendations categorized as&amp;nbsp;&lt;STRONG&gt;Cloud apps&lt;/STRONG&gt;&amp;nbsp;recommendations are now considered identity‑related and grouped under the&amp;nbsp;&lt;STRONG&gt;Identity&lt;/STRONG&gt;&amp;nbsp;category. While the total Secure Score remains unchanged, individual identity and app scores may change.&lt;/LI&gt;
&lt;LI&gt;The&amp;nbsp;&lt;STRONG&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/alerts-xdr#suspected-pass-the-ticket-attack" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Suspected pass-the-ticket attack&lt;/A&gt;&lt;/STRONG&gt;&amp;nbsp;alert is now &lt;STRONG&gt;generally available&lt;/STRONG&gt;. This alert was previously available in public preview as&amp;nbsp;&lt;EM&gt;Pass-the-Ticket (PtT) attack&lt;/EM&gt;. For more information, see&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/alerts-xdr" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Lateral movement alerts&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;These new alerts were added to the Defender for Identity security alerts:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;New alerts related to Entra ID&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/alerts-xdr#attempt-to-disable-defender-for-identity-service-principal-observed" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Attempt to disable Defender for Identity service principal observed&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/alerts-xdr#suspicious-entra-account-enablement-after-disruption" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Suspicious Entra account enablement after disruption&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/alerts-xdr#suspicious-intune-device-registration-activity" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Suspicious Intune device registration activity&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/alerts-xdr#suspicious-os-switch-sign-in" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Suspicious OS switch sign-in&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/alerts-xdr#suspicious-shared-client-infrastructure-activity" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Suspicious shared client infrastructure activity&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/alerts-xdr#suspicious-sign-in-from-unusual-user-agent-and-ip-address-using-powershell" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Suspicious sign-in from unusual user agent and IP address using PowerShell&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/alerts-xdr#suspicious-sign-in-from-unusual-user-agent-and-ip-address-using-device-code-flow" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Suspicious sign-in from unusual user agent and IP address using device code flow&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;New alerts related to Active Directory&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/alerts-xdr#suspicious-on-prem-account-enablement-after-disruption" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Suspicious on-premises account enablement after disruption&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/alerts-xdr#suspicious-resource-based-constrained-delegation-rbcd-attribute-change" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Suspicious resource-based constrained delegation (RBCD) attribute change&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/alerts-xdr#suspicious-resource-based-constrained-delegation-rbcd-authentication" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Suspicious resource-based constrained delegation (RBCD) authentication&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Defender for Office 365&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Expanding User reporting in Teams to include Calls&lt;/STRONG&gt;: Users can reported completed or missed one-to-one&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-office-365/submissions-teams" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Microsoft Teams calls&lt;/A&gt;&amp;nbsp;from the call history as malicious (scam) or non malicious (non-scam) to the specified reporting mailbox, or Microsoft and the reporting mailbox via&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-office-365/submissions-user-reported-messages-custom-mailbox" target="_blank" rel="noopener" data-linktype="relative-path"&gt;user reported settings&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Added support for contextual Teams messages in User reported Teams Messages&lt;/STRONG&gt;: When Users report&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-office-365/submissions-teams" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Microsoft Teams messages&lt;/A&gt;&amp;nbsp;from chats, channels (standard, shared, and private), and meeting conversations to Microsoft as malicious (security risk), up to fifteen messages before and after the reported message are shared for analysis.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Defender for Cloud Apps&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;To improve accuracy and better protect organizational identities, some security recommendations categorized as&amp;nbsp;&lt;STRONG&gt;Cloud apps&lt;/STRONG&gt;&amp;nbsp;recommendations are now considered identity‑related and grouped under the&amp;nbsp;&lt;STRONG&gt;Identity&lt;/STRONG&gt; category. While the total Secure Score remains unchanged, individual identity and app scores may change.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 08 Apr 2026 08:18:07 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/monthly-news-april-2026/ba-p/4508050</guid>
      <dc:creator>HeikeRitter</dc:creator>
      <dc:date>2026-04-08T08:18:07Z</dc:date>
    </item>
    <item>
      <title>Redefining identity security for the modern enterprise</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/redefining-identity-security-for-the-modern-enterprise/ba-p/4503129</link>
      <description>&lt;P&gt;Every breach has one thing in common: an identity was exploited. Attackers have learned that identity is the fastest path to lateral movement and escalation. The challenge for defenders is that today's identity landscape is vast and fragmented — spanning hybrid environments, SaaS apps, cloud platforms, and autonomous agents. Protecting it demands more than point solutions. It requires continuous visibility, proactive posture reduction, and the ability to detect and disrupt identity threats across the full attack lifecycle.&lt;/P&gt;
&lt;P&gt;Leveraging our expertise as a leader in both Identity and Access Management (IAM) and Security, our focus has been to deliver a fast, comprehensive, and increasingly autonomous approach to identity security. It is designed to continuously strengthen identity posture and help SOC teams act faster with less manual effort. Today, I am excited to announce the next set of innovations including:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Reimagined Identity Security dashboard and experiences to surface identity insights&lt;/LI&gt;
&lt;LI&gt;Expanded protection for more elements of modern identity fabrics including non-human identities.&lt;/LI&gt;
&lt;LI&gt;Streamlined detections including a new identity-level risk score that can be applied directly within risk-based conditional access policies.&lt;/LI&gt;
&lt;LI&gt;Unified identity view &amp;amp; protection across Active Directory, Entra ID, IAM solutions, SaaS and Cloud – with improved at-scale identity correlations&lt;/LI&gt;
&lt;LI&gt;New autonomous response capabilities to further speed identity threat triage, disruption and response.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Below is a deeper look at what’s new.&lt;/P&gt;
&lt;H4&gt;Turning identity sprawl into clarity&lt;/H4&gt;
&lt;P&gt;Security teams don’t suffer from a lack of identity data — they suffer from a lack of insight across that data. Without context, the flood of activity from various directories, SaaS platforms, cloud services, and on‑premises infrastructure simply becomes noise.&amp;nbsp; Disconnected alerts, isolated accounts, and fragmented investigations make it harder, not easier, to determine what actually matters.&lt;/P&gt;
&lt;P&gt;The updated Identity security dashboard is one of the new experiences designed to help with just that. It serves as the starting point for the SOC to gain a birds eye view of their entire identity security status, surfacing critical information on the human and non-human identities from across on-premises, SaaS and cloud environments.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;Fueling this, and other identity security experiences within Defender, are the advancements we have made in unifying the identity inventories. First, for human users we have expanded the &lt;A href="https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/enhancing-visibility-into-your-identity-fabric-with-microsoft-defender/4470662" target="_blank" rel="noopener"&gt;account correlation&lt;/A&gt;&amp;nbsp; capabilities we released at Ignite to include SaaS and cloud accounts. This means that security professionals will have an even more comprehensive view of related accounts, their holistic posture and identity risk. Additionally, we are also introducing new, policy-based linkage to help organizations customize these connections at scale.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But modern identity fabrics extend far beyond human users. To address this shift, we are also expanding identity security coverage to include a greater focus on non‑human identities. The new non‑human identity inventory helps security teams to discover, understand, and protect these critical identities within the same identity‑centric view as human accounts.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;Defender helps teams see the full identity fabric — not as disconnected components, but as an interconnected system — so they can reduce blind spots, prioritize exposure, and apply consistent protection across the identities attackers increasingly rely on.&lt;/P&gt;
&lt;H4&gt;Expanded coverage across the modern identity fabric&lt;/H4&gt;
&lt;P&gt;Staying one step ahead of attackers starts with having a better understanding of what makes you vulnerable and closing those gaps before they can be exploited. With this mission in mind, I am excited to announce a &lt;STRONG&gt;new coverage and &lt;/STRONG&gt;&lt;STRONG&gt;maturity &lt;/STRONG&gt;&lt;STRONG&gt;view&lt;/STRONG&gt; that shows how identity infrastructure, protections, and risk actually connect across your environment. This view serves as a snapshot revealing which access paths are protected, which are exposed, and what to fix next to meaningfully reduce blast radius.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;Rather than treating coverage as a static checklist, this experience surfaces actionable insights that show both current status and prioritized next steps, helping teams understand not only what needs to be protected, but also how to systematically improve identity security posture over time. With this clear guidance Defender empowers SOC teams to move from fragmented awareness to confident, identity‑centric protection.&lt;/P&gt;
&lt;P&gt;This new view is powered by the native integration available out-of-the-box with Microsoft Entra ID and the dedicated sensors and connectors available for other identity components like Privilege Access Management (PAM) solutions and other identity providers. Given this, I am pleased to share that we are adding new integrations with solutions like SailPoint and CyberArk that further our commitment to bringing additional depth and coverage for more elements of modern identity landscapes within Defender.&lt;/P&gt;
&lt;P&gt;In this same vein, we're making it easier for customers to activate protections across their on-premises identity infrastructure. Today we are excited to share that the &lt;A href="https://aka.ms/unified-sensor-ga-community-blog" target="_blank" rel="noopener"&gt;unified identity and endpoint agent&lt;/A&gt; is extending support for more identity infrastructure and releasing a streamlined experience for existing customers looking to &lt;A href="https://aka.ms/defender-sensor-migration" target="_blank" rel="noopener"&gt;migrate to the new sensor.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;In addition to all this we are also adding a new identity explorer experience that is designed to help security professionals uncover identity-based exposures and lateral movement paths within their organization. Leveraging the graph capabilities within Defender and a robust set of pre-defined queries, SOC teams gain new visibility into potential exposure scenarios and end-to-end attack paths.&lt;/P&gt;
&lt;img /&gt;
&lt;H4&gt;Streamlined protections and workflows across Defender and Entra&lt;/H4&gt;
&lt;P&gt;Security teams need to understand how the individual role, privilege, activity and alerts for each individual account relate to the risk of the identity as a whole. To address this, we’re introducing a new &lt;STRONG&gt;unified risk score&lt;/STRONG&gt; that aggregates signals across all linked accounts to calculate a single risk score for the identity.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;As you can see in the image above the score considers the observed activity, criticality, privilege and likelihood of compromise for each linked account and produces a single, actionable view of risk. This means analysts no longer need to decipher various alerts themselves, they can quickly prioritize investigations based on the potential impact and urgency of identity‑driven threats.&lt;/P&gt;
&lt;P&gt;But the value of this new unified risk score doesn’t stop at investigation. Entra ID customers can now leverage these new risk signals directly within their risk-based conditional access policies. This gives admins a stronger signal for access decisions, resulting in earlier prevention, detection, and response across the identity control plane. This powers the feedback loop between identity and SOC teams, ensuring that insights gained in the SOC can immediately reduce exposure across the identity fabric.&lt;/P&gt;
&lt;P&gt;Together, these advances transform identity sprawl into clarity. By automatically connecting the dots and surfacing insights instead of raw data Defender is elevating what matters most, helping security teams cut through noise, focus on true risk, and respond to identity‑based threats with greater speed and confidence.&lt;/P&gt;
&lt;H4&gt;New Identity detections using novel and unique sensor capabilities&lt;/H4&gt;
&lt;P&gt;Detection opportunities start with visibility and sensor capabilities and we are excited to share a new capability that significantly improves how we see identity-based attacks on Domain Controllers. We work closely with the Windows team within Microsoft and are introducing a new Event Tracking for Windows (ETW) that gives us richer insight into Kerberos activity. This allows us to safely access important ticket details that were previously hidden while the ticket was in use, without needing to break or decrypt the ticket itself.&lt;/P&gt;
&lt;P&gt;With this additional context, we can spot unusual behavior that points to forged or tampered Kerberos tickets more accurately than before. By connecting this new operating system signal directly into our identity threat detection capabilities, we unlock a unique level of protection. It also opens up new investigation and hunting scenarios for SOC analysts who want deeper visibility into Kerberos related activity.&lt;/P&gt;
&lt;P&gt;Our first detection using this new sensor capability (&lt;EM&gt;“&lt;/EM&gt;&lt;EM&gt;Possible golden ticket attack (suspicious ticket)”&lt;/EM&gt;) is now generally available, and further exemplifies why our strategy is so revolutionary. Previously detecting these types of attacks would require decrypting the ticket/token itself, introducing even more potential for exposure. With this ETW however we have the same visibility without the risk.&lt;/P&gt;
&lt;P&gt;We know that Identity attacks no longer stop at the perimeter. Recognizing that modern adversaries target on‑premises, hybrid, and cloud identities alike, we invested heavily in expanding also our detection capabilities across this full spectrum. In particular, we introduced new detections for emerging attack techniques targeting Entra ID as a platform. While Entra ID Protection continues to deliver broad, native protection for Entra users and identities, the core mission of Identity Threat Protection products is to go further— detecting also sophisticated post‑breach activity and lateral movements where attackers directly target the identity provider itself, often by exploiting the hybrid trust and linkage between on‑premises and cloud environments. We are excited to announce the availability of the following new detections:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;4 new detections for anomalies and attacks targeting Entra ID sync application in hybrid environments&lt;/LI&gt;
&lt;LI&gt;2 new detections for suspicious device registration/join across Entra and Intune&lt;/LI&gt;
&lt;LI&gt;1 new detection for techniques abusing Oauth Authorization Flow for browser-based attacks, as observed in-the-wild recently (“ConsentFix”)&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;Powering autonomous Identity Threat Protection&lt;/H4&gt;
&lt;P&gt;When a security incident is unfolding, every second matters. Attackers are already operating at machine speed, and human response alone can’t keep up, which is why AI-powered capabilities are essential for detecting, triaging and remediating identity threats in time.&lt;/P&gt;
&lt;P&gt;As part of our push toward autonomous Identity Threat Protection, we’re extending Security Copilot’s agentic triage capabilities to identity. We’ve already seen the impact of outcome-driven autonomous workflows in phishing, where our agent identifies 6.5 times more malicious alerts than human analysts working alone. Today, that same capability is extending beyond phishing to include identity alerts.&lt;/P&gt;
&lt;P&gt;The new Security Alert Triage Agent autonomously evaluates high‑volume identity alerts, distinguishing true threats from noise, and surfacing clear, explainable verdicts so analysts can focus immediately on what requires action. At Public Preview, it supports triage of alert types involving password spray attempts, suspicious inbox rules associated with business email compromise (BEC), and accounts potentially compromised following a password spray attack. Learn more about Security Copilot in Defender announcements &lt;A href="https://aka.ms/CiD-RSAC26" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;In parallel, we’re expanding identity takeover predictive shielding, using real‑time exposure and attack path insights to proactively harden the identity attack surface during an active incident—blocking attacker progression before high‑value identities can be compromised. Together, these capabilities shift identity defense from reactive investigation to real‑time disruption, helping security teams contain attacks faster, reduce blast radius, and stay ahead of adversaries when it matters most.&lt;/P&gt;
&lt;P&gt;At Ignite, we introduced &lt;A href="https://aka.ms/predictiveshielding" target="_blank" rel="noopener"&gt;predictive shielding,&lt;/A&gt; an AI-powered capability in automatic attack disruption that predicts an attacker’s next move in an active attack and applies targeted, just-in-time hardening to block them before they can pivot. Today, predictive shielding proactively hardens many of the controls attackers most often rely on to regain access, such as SafeBoot abuse and Group Policy Objects. We’ve already seen tremendous impact across our customers, including &lt;STRONG&gt;a large public university&lt;/STRONG&gt;:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;EM&gt;“During a ransomware incident, Microsoft Defender’s attack disruption stopped the attack before it could progress. In parallel, predictive shielding applied Safe Boot hardening across key devices, helping protect against a common evasion tactic—rebooting endpoints into Safe Mode to try and bypass protections like disruption. Together, these layers increased our confidence and resilience during the incident.”&lt;/EM&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;This speed and accuracy matter because identity-based attacks now operate at massive scale, with each user tied to many accounts across the environment, making it increasingly difficult to protect every identity.&lt;/P&gt;
&lt;P&gt;We are excited to share that we’re expanding this set of just-in-time hardening actions tailored for identity-based attacks. This includes:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;RemoteOps hardening: &lt;/STRONG&gt;restricts high-risk remote administrative operations such as RPC-based actions that attackers rely on for lateral movement and hands-on-keyboard control. &lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Remote Registry hardening&lt;/STRONG&gt;: prevents attackers from remotely modifying sensitive registry settings often used to weaken security controls or enable credential theft.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;What makes these controls unique is their precision: Defender shields only the specific assets at risk, rather than applying broad, organization-wide restrictions, maximizing security while minimizing business impact.&lt;/P&gt;
&lt;H4&gt;Looking ahead&lt;/H4&gt;
&lt;P&gt;Identity has become the foundation of access, trust, and control in modern enterprises—and the primary target for attackers. The announcements detailed throughout this blog reflect our continued commitment to advancing identity security and to helping customers stay ahead of rapidly evolving identity-based threats.&lt;/P&gt;
&lt;P&gt;We’re excited to share more throughout the week at RSA, and we look forward to partnering with customers as they continue their journey toward comprehensive, identity centric security.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/redefining-identity-security-for-the-modern-enterprise/ba-p/4503129</guid>
      <dc:creator>YaronParyanty</dc:creator>
      <dc:date>2026-03-20T16:00:00Z</dc:date>
    </item>
    <item>
      <title>RSA 2026: What’s new in Microsoft Defender?</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/rsa-2026-what-s-new-in-microsoft-defender/ba-p/4503046</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Modern attacks increasingly exploit the sprawl of today’s digital environments.&lt;/STRONG&gt; In the identity space alone, over half of today’s organizations say each person now has more than 21 distinct accounts. Each one of these accounts is a potential entry point that an attacker can exploit. As organizations adopt cloud, SaaS, AI, and autonomous agents, the rapid growth of non‑human identities accelerates sprawl, expanding the attack surface and increasing gaps in protection. At the same time, agents help accelerate the SOC by automating high‑volume tasks, reducing noise, and enabling analysts to act faster and more consistently.&lt;/P&gt;
&lt;P&gt;This shift demands a new approach: comprehensive identity security paired with agentic AI to help the SOC better reason across signals, predict risk, and act earlier, while augmenting human analysts to keep pace with increasingly fast and complex attacks.&lt;/P&gt;
&lt;P&gt;At RSA, we’re excited to announce innovations in Microsoft Defender and Security Copilot to help customers defend against the latest threats. These include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Identity Security&lt;/STRONG&gt;: expanded capabilities and enhanced experiences to help the SOC better prepare for, detect and autonomously respond to identity-related threats.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Collaboration Security&lt;/STRONG&gt;: protect&lt;STRONG&gt; &lt;/STRONG&gt;against voice‑based attacks in Teams with real‑time user warnings, SOC‑ready investigation, and new threat &amp;amp; posture insights reporting.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Accelerate the SOC with Security Copilot&lt;/STRONG&gt;: expansion of the Security Triage Agent to identity and cloud alerts, a new Security Analyst agent to uncover risk and a new chat experience directly in Microsoft Defender.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Cloud Security&lt;/STRONG&gt;: expansion of multi-cloud visibility to new AWS and GCP services, near real-time container runtime protection to eliminate binary drift, and introducing AI model scanning. Learn more &lt;A href="https://aka.ms/MDCblog_RSA" target="_blank"&gt;here&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;Reshaping Identity Security&lt;/H4&gt;
&lt;P&gt;Today’s identity landscape is no longer defined by a single directory and a single set of users. It’s a fast-changing fabric of human, non-human, and emerging agentic identities spread across cloud services, SaaS apps, and on-premises infrastructure—that attackers actively target. To meet this new reality, we’re reshaping identity security in Microsoft Defender to move beyond point defenses and reactive investigation to an autonomous, end-to-end approach that continuously strengthens identity posture, stops active threats while they’re happening, and helps the SOC act faster with less manual effort.&lt;/P&gt;
&lt;P&gt;To start, we’re broadening our coverage across modern identity fabrics, making posture and activity easier to understand quickly, and tightening the operational loop between identity and the SOC. To do this were delivering new detections, a unified risk score that assesses risk across all accounts and identity types, and updated experiences like the new identity security dashboard that brings your most important posture gaps, active exposures, and identity risk into one place - so security teams can move from fragmented signals to shared context and coordinated action. &lt;BR /&gt;&lt;BR /&gt;On top of this improved foundation we are also unveiling autonomous ITDR in two complementary ways. First, &lt;STRONG&gt;we’re extending Security Copilot’s agentic triage capabilities to identity&lt;/STRONG&gt;. With the new Security Alert Triage Agent, Defender can autonomously evaluate high‑volume identity alerts, distinguish true threats from noise, and surface clear, explainable verdicts so analysts can focus immediately on what requires action. Second, we’re bringing the AI-powered just-in-time hardening of &lt;STRONG&gt;predictive shielding&lt;/STRONG&gt; to identity allowing Defender to not only disrupt threats but also anticipate an attacker’s next move and automatically enforces targeted controls to block credential- and token-driven pivots before they succeed.&lt;/P&gt;
&lt;P&gt;Together, these innovations empower security teams to understand their identity footprint, prioritize what matters most, and stop identity-driven attacks earlier:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Expanded coverage across modern identity fabrics&lt;/STRONG&gt; with new identity-specific detections&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Identity-level insights that turn sprawl into clarity&lt;/STRONG&gt; via an updated dashboard that provides a unified inventory and improved correlation across SaaS apps and identity types—elevating the SOC view from accounts to the identity.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Streamlined protections and aligned workflows across Defender and Entra&lt;/STRONG&gt;, including a new identity-level risk score to help identity and SOC teams prioritize and act from shared signals.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Predictive shielding &lt;/STRONG&gt;applies precise, just-in-time hardening actions used during identity attacks including RemoteOps hardening and Remote Registry hardening —helping prevent lateral movement.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Autonomous triage for identity alerts with Security Copilot&lt;/STRONG&gt;, expanding the Security Triage Agent so identity alerts can be investigated consistently and at scale, with clear verdicts and explainable reasoning to speed up response.&lt;/LI&gt;
&lt;/UL&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Learn more about these innovations &lt;A href="https://aka.ms/IDSecurity-Defender-RSA" target="_blank"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H4&gt;Protect collaboration threats and prove security outcomes&lt;/H4&gt;
&lt;P&gt;As collaboration platforms become a new front door for attackers, Microsoft Defender extends protection beyond email to detect and respond to voice‑based social engineering in Microsoft Teams. New Teams calling protection surfaces suspicious and malicious calls, enables SOC teams to investigate and correlate call activity using Advanced Hunting, and delivers real‑time in‑call warnings when a call appears to impersonate a trusted contact, closing the gap between what users experience and what analysts can investigate.&lt;/P&gt;
&lt;P&gt;To help organizations clearly measure and communicate the impact of these protections, Microsoft Defender is introducing the&amp;nbsp;&lt;STRONG&gt;Protection &amp;amp; Posture Insights report&lt;/STRONG&gt;. It gives customers a tenant‑specific view of the threats targeting their environment, highlighting spam, phishing, and malware campaigns observed against users. The report delivers personalized insights and policy recommendations to reduce exposure, while enabling teams to validate results, and share credible, executive‑ready security outcomes—without manual data assembly.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Read more &lt;A href="https://aka.ms/EmailRSA26" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H4&gt;Accelerate your security operations at scale with Security Copilot&lt;/H4&gt;
&lt;P&gt;Adversaries are using AI to accelerate attacks and increase sophistication. At RSA Conference 2026, we’re expanding our innovation around autonomous and assistive AI in Microsoft Defender with Security Copilot—helping defenders operate with the speed, scale, and intelligence required to stay ahead of modern threats across the entire SOC lifecycle.&lt;/P&gt;
&lt;P&gt;In addition to expanding agentic triage to identity alerts, we’re extending that same capability to cloud—bringing phish, identity and cloud triage together within a single agent. The Security Alert Triage Agent helps analysts autonomously determine whether these alerts represent real threats or false alarms, delivering natural language verdicts and transparent, step-by-step decision reasoning.&lt;/P&gt;
&lt;P&gt;We’re also announcing the Security Analyst Agent, designed to help security teams uncover hidden risk. This agent performs deep, multi-step investigations across Microsoft Defender and Sentinel telemetry to surface high-impact threats, cut through the noise, and deliver prioritized insights in minutes. Every finding is accompanied by transparent reasoning and supporting evidence.&lt;/P&gt;
&lt;P&gt;Lastly, we’re bringing a chat experience for Security Copilot directly within Microsoft Defender. Analysts can ask questions, explore hypotheses, and follow investigative threads across incidents, alerts, identities, devices, IPs, and other evidence without switching tools or manually piecing together context.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;You can learn more about Microsoft Security Copilot news at RSA Conference 2026 &lt;A href="https://aka.ms/CiD-RSAC26" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H4&gt;Looking ahead&lt;/H4&gt;
&lt;P&gt;The Microsoft Defender announcements at RSA 2026 reflect a clear shift toward agentic and autonomous security, while augmenting the SOC with Security Copilot–driven workflows. Together, these capabilities give defenders clearer context, tighter control, and the ability to stop attacks earlier, before adversaries can escalate privileges or move laterally. Microsoft’s continued investment signals a longer-term evolution toward agentic security operations that anticipate attacker behavior, adapt in real time, and steadily reduce risk as environments and threats continue to evolve.&lt;/P&gt;
&lt;H4&gt;Learn more at RSA Conference 2026!&lt;/H4&gt;
&lt;P&gt;To learn more about Microsoft Defender and Security Copilot, visit us at booth # at RSA Conference 2026. Our team will be demonstrating how autonomous agents and assistive AI experiences are helping SOC teams move faster through alert triage, investigation, and response.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;You can join our booth sessions:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Empowering the SOC with assistive and autonomous AI with Yuval Derman | March 23rd at 5.15PM&lt;/LI&gt;
&lt;LI&gt;Predictive Shielding: Protecting identities before attackers pivot | March 24th at 4.30PM&lt;/LI&gt;
&lt;LI&gt;Identity Security with Microsoft | March 25 at 3:30PM&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;For a full list of all the ways to connect with us at RSA, check out our dedicated RSAC 2026 &lt;A href="https://microsoftsecurityevents.eventbuilder.com/RSACMicrosoftEvents26?ref=blog_techcomm" target="_blank" rel="noopener"&gt;page&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2026 15:45:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/rsa-2026-what-s-new-in-microsoft-defender/ba-p/4503046</guid>
      <dc:creator>Caroline_Lee</dc:creator>
      <dc:date>2026-03-20T15:45:00Z</dc:date>
    </item>
    <item>
      <title>Security Copilot in Defender: empowering the SOC with assistive and autonomous AI</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/security-copilot-in-defender-empowering-the-soc-with-assistive/ba-p/4503047</link>
      <description>&lt;P&gt;Security operations centers are increasingly overwhelmed. Analysts must triage large volumes of alerts, investigate complex signals across multiple environments, and determine which threats require immediate action. Much of this work still involves manually gathering context, reconstructing timelines, and making decisions under time pressure.&lt;/P&gt;
&lt;P&gt;As Microsoft Ignite 2025, we introduced how Security Copilot is bringing agentic AI directly into Microsoft Defender to transform how SOC teams detect, triage, and investigate threats. Building on that vision, Copilot continues to expand its capabilities with two complementary forms of AI: &lt;STRONG&gt;autonomous &lt;/STRONG&gt;agents that reason dynamically to execute complex security tasks, and &lt;STRONG&gt;assistive&lt;/STRONG&gt; experiences that help analysts complete their daily workflows faster and with greater scale.&lt;/P&gt;
&lt;P&gt;Together, these innovations are designed to reduce operational burden while enabling analysts to focus on the decisions that matter most.&lt;/P&gt;
&lt;H4&gt;Autonomous AI: agents that triage alerts and investigate risk&lt;/H4&gt;
&lt;P&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/security-copilot-for-soc-bringing-agentic-ai-to-every-defender/4470187" target="_blank" rel="noopener"&gt;Our vision is to bring autonomous AI across the SOC lifecycle&lt;/A&gt;, moving from isolated AI-enabled tasks to outcome-driven agentic transformation that elevates SOC teams across all experience levels. By applying frontier LLM reasoning to security telemetry and threat intelligence, Security Copilot is uniquely positioned to embed specialized agents at every stage—from anticipating risk and preventing attacks, to detecting, triaging, investigating, and responding. The result is a SOC that operates at machine speed while keeping humans firmly in control.&lt;/P&gt;
&lt;P&gt;During RSA Conference 2026, we’re expanding that vision within the triage and investigation stage of the SOC lifecycle with the launch of one expanded agent and one new agent.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;We’ve already demonstrated the impact of outcome-driven autonomous workflows with agentic phishing triage: our agent identifies &lt;A class="lia-external-url" href="https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/bade/documents/products-and-services/en-us/security/randomized-controlled-trial-for-phishing-triage-agent-accessible.pdf" target="_blank" rel="noopener"&gt;6.5 times more malicious alerts than human analysts working alone&lt;/A&gt;. Today, that same capability is extending beyond phishing to identity and cloud alerts.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;STRONG&gt;The Security Alert Triage Agent helps analysts autonomously determine whether phishing, identity and cloud alerts represent real threats or just false alarms.&lt;/STRONG&gt; The agent provides natural language verdicts and transparent, step-by-step reasoning that explains how it reached each decision. At Public Preview, for identity, it supports triage of alert types involving password spray attempts, suspicious inbox rules associated with business email compromise (BEC), and accounts potentially compromised following a password spray attack. For cloud, it supports more than 30 alert types related to &lt;A href="https://learn.microsoft.com/en-us/azure/defender-for-cloud/alerts-containers" target="_blank" rel="noopener"&gt;cloud container activity&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;This agent is designed to handle alerts that are both high risk and high noise. Identity and cloud alerts often require longer and more complex investigations, and missing them has important implications. For &lt;STRONG&gt;identity alerts&lt;/STRONG&gt;, the challenge is scale—high-volume signals such as password spray generate noise, making it difficult to quickly isolate real compromise. The agent helps by rapidly triaging these alerts and filtering out false positives, allowing analysts to focus on identity activity that truly indicates risk. &lt;STRONG&gt;For cloud alerts&lt;/STRONG&gt;, the challenge is different: alert volume may be lower, but investigations are inherently more complex and require deep expertise. In these cases, the agent applies advanced analysis across multiple signals to investigate alerts that would otherwise be burdensome and difficult to analyze manually, helping ensure critical cloud threats are surfaced quickly and not overlooked.&lt;/P&gt;
&lt;P&gt;By providing natural language verdicts and transparent decision logic, the agent walks teams step-by-step through investigations that would typically require senior-level expertise. Clear explanations and visual decision graphs show how each conclusion was reached, reducing investigation effort and increasing confidence in outcomes. This transparency frees teams to focus on responding to real threats, while giving junior analysts visibility into the reasoning behind each verdict. The result is specialized expertise embedded directly into daily SOC workflows, raising the floor for the entire team.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;STRONG&gt;At RSA Conference 2026, we’re also announcing the Security Analyst Agent in Microsoft Defender&lt;/STRONG&gt;&lt;STRONG&gt;. &lt;/STRONG&gt;This agent performs deep, multi-step investigations across Microsoft Defender and Sentinel telemetry to surface high-impact risks and deliver prioritized insights in minutes. Each finding includes clear reasoning and supporting evidence, enabling analysts to quickly understand and act on the results.&lt;/P&gt;
&lt;P&gt;Today, teams often rely on advanced hunting to investigate potential threats by writing queries, iteratively refining hypotheses, and correlating results across multiple datasets. While powerful, this process typically requires manually piecing together context across tools, reconstructing timelines, and sifting through large volumes of telemetry to determine whether suspicious activity represents real risk. Given the breadth and complexity of modern threats, these investigations can take days or even weeks.&lt;/P&gt;
&lt;P&gt;The Security Analyst Agent builds on the power of advanced hunting by autonomously orchestrating parts of that investigative process. The agent retrieves and analyzes large volumes of security data (up to ~100MB), correlates signals across telemetry sources, and iteratively explores hypotheses to surface patterns and threats that might otherwise go unnoticed. The results are synthesized into clear, risk-relevant findings with supporting evidence trails, helping analysts quickly understand what matters most. In doing so, the agent performs the kind of deep analytical work typically carried out by experienced security analysts.&lt;/P&gt;
&lt;H4&gt;Assistive AI: Chat experience in the analyst’s flow of work&lt;/H4&gt;
&lt;P&gt;While autonomous agents help execute complex security tasks with dynamic reasoning, Security Copilot also brings assistive AI directly into analysts’ daily workflows. These capabilities are designed to accelerate manual tasks, helping analysts gather context, and make decisions faster.&lt;/P&gt;
&lt;P&gt;Today, Copilot is already embedded across Microsoft Defender experiences. Analysts can generate natural language summaries of incidents, receive guided response recommendations, draft incident reports, generate KQL queries with natural language, and more. These capabilities help accelerate specific tasks, but interactions with Copilot typically occur as individual actions within a side panel or embedded experience.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;STRONG&gt;We’re now taking the next step by introducing a chat experience for Security Copilot directly within Microsoft Defender,&lt;/STRONG&gt; enabling teams to interact with AI through an ongoing, two-way conversation. Analysts can ask questions, explore hypotheses, and follow investigative threads across incidents, alerts, identities, devices, IPs, and other evidence—without switching tools or manually piecing together context. Copilot understands the analyst’s investigation context, grounding each response in the relevant signals and telemetry already available in Defender.&lt;/P&gt;
&lt;P&gt;Throughout the interaction, Copilot does more than respond. It actively advances the investigation by initiating step-by-step analysis, such as examining a specific entity, while continuously incorporating new signals as they emerge. Analysts can follow up in real time, refining their line of inquiry and digging deeper as the conversation evolves. This creates a more fluid, iterative workflow that lowers the barrier to AI adoption and enables SOC teams to operate with the speed and scale needed to stay ahead of modern threats.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;STRONG&gt;Alongside this new embedded chat experience for Security Copilot, we are also extending conversational capabilities to third-party agents&lt;/STRONG&gt;&lt;STRONG&gt;. &lt;/STRONG&gt;From the Agents library in Defender, teams can start a chat with any eligible agent to validate findings, gather additional context, and accelerate response. For example, users can interact with &lt;A href="https://securitystore.microsoft.com/solutions/xbowinc.xbow-pentest-analysis-agent" target="_blank" rel="noopener"&gt;XBOW’s Pentest Analysis Agent&lt;/A&gt; to determine whether vulnerabilities flagged by Microsoft Defender for Cloud are truly exploitable. The agent can initiate a pentest, explain the results, and recommend next steps—such as improving detection coverage in Microsoft Sentinel—to strengthen defenses.&lt;/P&gt;
&lt;H4&gt;Learn more at RSA Conference 2026!&lt;/H4&gt;
&lt;P&gt;To learn more about Security Copilot in Microsoft Defender, visit us at booth #5744. Our team will be demonstrating how AI is helping SOC teams move faster through alert triage, investigation, and response.&lt;/P&gt;
&lt;P&gt;You can join our booth sessions:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Empowering the SOC with assistive and autonomous AI with Yuval Derman | March 23&lt;SUP&gt;rd&lt;/SUP&gt; at 5.15PM&lt;/LI&gt;
&lt;LI&gt;Security Copilot agents: Insight. Action. Impact. with Lizzie Heinze and Donna Lee | March 24th at 3.00PM&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;You can also register for &lt;EM&gt;Security Copilot in action: An agentic approach to modern security&lt;/EM&gt; on March 24&lt;SUP&gt;th&lt;/SUP&gt; at 8.30AM &lt;A href="https://microsoftsecurityevents.eventbuilder.com/events/11f0faf0203562b0af62159fbd1fe445?ref=blog_RSACpreevent" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2026 15:30:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/security-copilot-in-defender-empowering-the-soc-with-assistive/ba-p/4503047</guid>
      <dc:creator>cristinadagamah</dc:creator>
      <dc:date>2026-03-20T15:30:00Z</dc:date>
    </item>
    <item>
      <title>Monthly news -  March 2026</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/monthly-news-march-2026/ba-p/4498458</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Microsoft Defender&lt;/STRONG&gt;&lt;BR /&gt;Monthly news - March 2026 Edition&lt;/P&gt;
&lt;P&gt;This is our monthly "What's new" blog post, summarizing product updates and various new assets we released over the past month across our Defender products. In this edition, we are looking at all the goodness from February 2026. We are now including news related to Defender for Cloud in the Defender portal. For all other Defender for Cloud news, have a look at the dedicated Defender for Cloud Monthly News&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/microsoft-defender-for-cloud-customer-newsletter/4491637" target="_blank" rel="noopener" data-lia-auto-title="here" data-lia-auto-title-active="0"&gt;here&lt;/A&gt;&lt;STRONG&gt;.&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;🚀 New Virtual Ninja Show episode:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.youtube.com/watch?v=30e-LU-z5Xg&amp;amp;list=PLmAptfqzxVEVeZJO1kj4wiUVhCPfCa0Fm&amp;amp;index=1" target="_blank" rel="noopener"&gt; New AI-powered SIEM migration experience&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Defender&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;(Public Preview) &lt;STRONG&gt;Microsoft Defender for Cloud is expanding to the Defender portal to provide a unified security experience across cloud and code environments&lt;/STRONG&gt;. As part of this expansion, some features are now available in the Microsoft Defender Portal, and additional capabilities will be added to the Defender portal over time. Follow instructions provided here to enable Defender for Cloud experience in XDR. Learn more on how to &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-portal/enable-preview-features" target="_blank" rel="noopener"&gt;enable preview features in the Defender portal&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;(Public Preview) &lt;STRONG&gt;Generate playbooks using AI in Microsoft Sentinel&lt;/STRONG&gt;: The SOAR &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/azure/sentinel/automation/generate-playbook" target="_blank" rel="noopener"&gt;playbook generator&lt;/A&gt; creates python based automation workflows coauthored through a conversational experience with Cline, an AI coding agent. For more information, see &lt;A class="lia-external-url" href="https://aka.ms/PlaybookGenBlog" target="_blank" rel="noopener"&gt;the Playbook Generation blog post&lt;/A&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;(Public Preview) &lt;STRONG&gt;The Microsoft Copilot Data Connector for Microsoft Sentinel&lt;/STRONG&gt;. This new connector allows for audit logs and activities generated by Copilot to be ingested into Microsoft Sentinel and Microsoft Sentinel data lake. The data can be used in analytic rules/custom detections, Workbooks, automation, and more.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Update: We are &lt;STRONG&gt;extending the sunset date for managing Microsoft Sentinel in the Azure portal to March 31, 2027&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;The upcoming Sentinel update &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/microsoftsentinelblog/update-changing-the-account-name-entity-mapping-in-microsoft-sentinel/4489040" target="_blank" rel="noopener" data-lia-auto-title="standardizes Account Name in analytics, incidents, and automation" data-lia-auto-title-active="0"&gt;standardizes Account Name in analytics, incidents, and automation&lt;/A&gt;. Starting July 1, 2026 for UPN-based mappings, Account Name will show only the UPN prefix, with new fields for full UPN and UPN suffix.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;Microsoft Defender Experts for Hunting &lt;STRONG&gt;customers can now set up Notification contacts&lt;/STRONG&gt;. These contacts are the individuals or groups that Microsoft needs to notify if there are critical incidents or service updates. Learn more &lt;A href="https://learn.microsoft.com/en-us/defender-xdr/onboarding-defender-experts-for-hunting#tell-us-who-to-contact-for-important-matters" target="_blank" rel="noopener"&gt;on our docs&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;The following &lt;STRONG&gt;advanced hunting schema tables are now generally available&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;IdentityAccountInfo&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;EntraIdSignInEvents&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;EntraIdSpnSignInEvents&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;GraphApiAuditEvents&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Lake only ingestion for Microsoft Defender Advanced Hunting tables is now General Available&lt;/STRONG&gt;. You can &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/MicrosoftSentinelBlog/lake-only-ingestion-for-microsoft-defender-advanced-hunting-tables-is-now-genera/4494206" target="_blank" rel="noopener" data-lia-auto-title="now ingest Advanced Hunting data into Sentinel Data lake" data-lia-auto-title-active="0"&gt;now ingest Advanced Hunting data into Sentinel Data lake&lt;/A&gt; without the need to ingest into the Microsoft Sentinel Analytics tier.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Custom Guidebooks (SOP) for Copilot Guided Response is now Generally Available! &lt;/STRONG&gt;Custom Guidebooks enable organizations to bring their own Standard Operating Procedures (SOPs) directly into the Copilot Guided Response experience, helping ensure investigations and remediation steps align with internal processes and best practices. Please find more information in &lt;U&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/defender-xdr/security-upload-guide" target="_blank" rel="noopener" data-outlook-id="ccb386e0-2bc7-4365-b7f9-122fcb418beb"&gt;our documentation&lt;/A&gt;&lt;/U&gt;&lt;STRONG&gt;.&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;img&gt;On the new &lt;STRONG&gt;Custom Guidebooks&lt;/STRONG&gt;settings page in the portal, users can &lt;STRONG&gt;upload guidebooks&lt;/STRONG&gt; and review the parsed tasks generated from their SOP files.&lt;/img&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;(Public Preview) &lt;STRONG&gt;The Sentinel Codeless Connector Framework (CCF) Push feature&lt;/STRONG&gt;. CCF addresses a critical need: enabling seamless, automated, and immediate delivery of security data to Microsoft Sentinel, so teams can respond to threats as they happen.&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;The UEBA behaviors layer in Microsoft Sentinel is now generally available&lt;/STRONG&gt;, summarizing clear, human‑readable behavioral insights from high-volume, raw security logs. The behaviors layer aggregates and sequences related events into normalized behaviors, helping analysts more quickly understand who did what to whom without manually correlating raw logs. For more information, see&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/azure/sentinel/entity-behaviors-layer" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Translate raw security logs to behavioral insights using UEBA behaviors in Microsoft Sentinel&lt;/A&gt;. &lt;BR /&gt;Watch the &lt;A href="https://www.youtube.com/watch?v=SqbxmGdMP7c" target="_blank" rel="noopener" data-linktype="external"&gt;UEBA behaviors webinar&lt;/A&gt; for a full overview and demo of the UEBA behaviors layer.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;To help SOC teams get value from behaviors from day one, &lt;STRONG&gt;Microsoft Sentinel now provides the&amp;nbsp;behaviors workbook&lt;/STRONG&gt; as part of the UEBA essentials solution. The workbook offers guided views and prebuilt, customizable analytics that turn rich behavioral data into actionable insights across three core SOC workflows. For more information about the workbook, see the&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/blog/microsoftsentinelblog/introducing-the-microsoft-sentinel-ueba-behaviors-workbook/4448398" target="_blank" rel="noopener" data-linktype="external"&gt;Microsoft Sentinel Behaviors Workbook blog post&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Defender for Endpoint / Microsoft Defender Vulnerability Management&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;(Public Preview) &lt;STRONG&gt;Microsoft Defender now has a Library Management for live response!&lt;/STRONG&gt; This is addressing a long standing pain point. You can now centrally manage Live Response scripts and files directly in the Defender portal, not just during a live response session. Read more details in &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/microsoftdefenderatpblog/introducing-library-management-in-microsoft-defender/4494434" target="_blank" rel="noopener" data-lia-auto-title="this blog post" data-lia-auto-title-active="0"&gt;this blog post&lt;/A&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;(General Availability) &lt;STRONG&gt;Effective Settings:&lt;/STRONG&gt; Effective Settings Reporting for device security settings is now available in GA! &lt;STRONG&gt;This report presents the actual security settings enforced on a specific device, capturing the real configuration&lt;/STRONG&gt; rather than just the admin’s intent. &lt;BR /&gt;This visibility empowers admins to easily track applied configurations and swiftly identify discrepancies.&lt;/P&gt;
&lt;P&gt;A new tab, named "Effective Settings", is now enabled on the device page, under the "Configuration Management" section. This tab displays:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;The actual value of each security setting&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;The configuring source for each setting&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Configuration attempts from other sources that were not effectively applied&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;(General Availability) To reflect Defender Vulnerability Management's visibility into all software components identified in your organization, the&amp;nbsp;&lt;STRONG&gt;Vulnerable components&lt;/STRONG&gt;&amp;nbsp;page is now named&amp;nbsp;&lt;STRONG&gt;Software components&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;(General Availability) To provide comprehensive vulnerability management capabilities across all supported Windows versions,&amp;nbsp;&lt;STRONG&gt;Microsoft Defender Vulnerability Management now gathers software product vulnerability data on Windows 7 devices&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;The &lt;STRONG&gt;what's new and OS-specific release notes pages are now updated&lt;/STRONG&gt; to provide better visibility and access to new features, improvements, and fixes:
&lt;UL&gt;
&lt;LI&gt;The &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/defender-endpoint/whats-new-in-microsoft-defender-endpoint" target="_blank" rel="noopener"&gt;what's new page&lt;/A&gt; is now named &lt;STRONG&gt;New features in Microsoft Defender for Endpoint&lt;/STRONG&gt; and includes both features and links to latest release notes.&lt;/LI&gt;
&lt;LI&gt;The&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-endpoint-releases" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Release notes page&lt;/A&gt; now consolidates release details for all supported operating systems, including Windows Antivirus. The new page groups updates by platform and date, making it easier to find specific information.&lt;/LI&gt;
&lt;LI&gt;All previous release notes pages redirect to the consolidated release notes page.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Defender for Identity&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Webinar recording:&amp;nbsp;&lt;A class="lia-external-url" href="https://www.youtube.com/watch?v=6MoV7SEEkJg" target="_blank" rel="noopener"&gt;Identity Control Plane Under Attack: Consent Abuse and Hybrid Sync Risks&lt;/A&gt; (YouTube)&lt;/STRONG&gt;&lt;BR /&gt;
&lt;P&gt;A new wave of identity attacks abuses legitimate authentication flows, allowing attackers to gain access without stealing passwords or breaking MFA. In this webinar recording the team breaks down how attackers trick users into approving malicious apps, how this leads to silent account takeover, and why traditional phishing defenses often miss it. &lt;SPAN style="color: rgb(30, 30, 30);"&gt;They also dive into the identity sync layer at the heart of hybrid environments. You’ll learn how Entra Connect Sync and Cloud Sync are protected as Tier-0 assets, how Microsoft Defender for Identity secures synchronization flows, and how the new application-based authentication model strengthens Entra Connect Sync against modern threats.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Defender for Office 365&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Expanding User reporting in Teams to Defender for Office 365 Plan 1&lt;/STRONG&gt;: Users can report external and intra-org&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-office-365/submissions-teams" data-linktype="relative-path" target="_blank"&gt;Microsoft Teams messages&lt;/A&gt;&amp;nbsp;from chats, standard, shared, and private channels, meeting conversations to Microsoft as malicious (security risk) the specified reporting mailbox, or both via&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-office-365/submissions-user-reported-messages-custom-mailbox" data-linktype="relative-path" target="_blank"&gt;user reported settings&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Defender for Cloud Apps&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;As part of Microsoft's ongoing efforts to increase accuracy in Secure Score, &lt;STRONG&gt;security recommendation categories will be updated in March 2026&lt;/STRONG&gt;. As a result, identity and app Secure Scores may be impacted.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 02 Mar 2026 12:13:48 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/monthly-news-march-2026/ba-p/4498458</guid>
      <dc:creator>HeikeRitter</dc:creator>
      <dc:date>2026-03-02T12:13:48Z</dc:date>
    </item>
    <item>
      <title>From signal to strategy: Closing attack paths with identity intelligence</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/from-signal-to-strategy-closing-attack-paths-with-identity/ba-p/4491856</link>
      <description>&lt;P&gt;Compromised credentials remain one of the most common entry points for attackers. In the first half of 2025 alone, &lt;A href="https://blogs.microsoft.com/on-the-issues/2025/10/16/mddr-2025/#:~:text=Adversaries%20aren't%20breaking%20in,based%20attacks%20surged%20by%2032%25." target="_blank" rel="noopener"&gt;identity-based attacks surged more than 32% and its estimated that 97% of them are password focused&lt;/A&gt;. While that scale is overwhelming, it only takes a single exposed account to give an attacker a foothold from which they can move laterally towards the critical assets they are after. At today’s attack scale, identity signals need to be connected with broader context to stop attacks earlier in the kill chain.&lt;/P&gt;
&lt;P&gt;Today we are excited to share more about how Microsoft Defender can help security professionals proactively understand how identity-related risks, like leaked credentials, relate back to critical assets, helping security professionals proactively close potential entry points before they can be exploited.&lt;/P&gt;
&lt;H2&gt;Understanding leaked credentials and attack paths:&lt;/H2&gt;
&lt;P&gt;Leaked credentials refer to valid usernames and passwords that have been exposed beyond their intended scope. Whether this exposure occurs as part of a data breach, phishing attack, or postings on dark web forums, the result is the same: an attacker may be using legitimate credentials to access your organization.&lt;/P&gt;
&lt;P&gt;Similarly, attack paths describe the sequence of misconfigurations, permissions, and trust relationships that an attacker can chain together to move from an initial foothold to high‑value resources. Rather than relying on a single vulnerability, attackers tend to think in graphs, following paths of least resistance to systematically escalate privileges and expand access. This makes identities the primary control plane they target and leaked credentials as an extremely common entry point. The recent Microsoft digital defense report put this into focus, stating that more than &lt;A href="https://www.microsoft.com/en-us/corporate-responsibility/cybersecurity/microsoft-digital-defense-report-2025/?msockid=045bd99662826f600aa4caf166826d6e" target="_blank" rel="noopener"&gt;61% of attack paths lead to a sensitive user&lt;/A&gt;. These user accounts have elevated privileges or access to critical resources meaning that if they were to be attacked or misused it would significantly impact the organization.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Microsoft’s differentiated approach&lt;/H2&gt;
&lt;P&gt;Most solutions stop at the alert and can only tell you that a password was exposed, found, or leaked. That information matters, but it is incomplete, it describes an event, not the risk.&lt;/P&gt;
&lt;P&gt;The real differentiation starts with the next question: &lt;STRONG&gt;what does this exposure mean for my environment right now&lt;/STRONG&gt;. Not every exposed password creates the same level of risk. Context is what determines impact. Which identity does the password belong to? What assets can that identity access? Does that access still exists? And are those assets truly sensitive?&lt;/P&gt;
&lt;P&gt;That is why exposed password detection is a starting point, not an end state. Effective protection begins when organizations move beyond technical alerts and toward an identity-aware understanding. This shift from detection to context is where better decisions are made and where meaningful security value is created. This is why we took our identity alerts a step further, connecting these risks with broader security context to reveal how an initial identity signal can lead to sensitive users, critical assets, and core business operations.&lt;/P&gt;
&lt;P&gt;This perspective moves security beyond isolated alerts to prioritized, actionable insight that shows not just &lt;EM&gt;if&lt;/EM&gt; risk exists, but &lt;EM&gt;how&lt;/EM&gt; identity‑based threats could unfold and &lt;EM&gt;where to intervene&lt;/EM&gt; to stop them before they have impact.&lt;/P&gt;
&lt;P&gt;In the case of leaked credentials, Microsoft continuously scans for exposed accounts across public and private breach sources. If a match is found, Microsoft’s Advanced Correlation Engine (MACE) automatically identifies the affected user within your organization and surfaces the exposure with clear severity and context. By bringing this powerful detection into Defender, teams can investigate and respond with better context, allowing leaked credentials to be evaluated alongside endpoint, email, and app activity, giving teams additional context needed to prioritize response. Additionally, for &lt;A href="https://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-risks#leaked-credentials" target="_blank" rel="noopener"&gt;Microsoft Entra ID accounts&lt;/A&gt; we can go a step further validating whether the discovered credentials actually corresponds to a real, usable password for an identity in the tenant. This confirmation further reduces unnecessary noise and gives defenders an early signal - often before any malicious activity begins. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Next, Microsoft Defender steps in to correlate these signals with your organization’s unique security context. Connecting the alert and associated account with other signals and like unusual authentications, lateral movement attempts, or privilege escalations, elevating the isolated alert into a complete story about any potential incidents related to that vulnerability.&lt;/P&gt;
&lt;P&gt;At the same time, Microsoft Exposure management is analyzing the same data to create a potential &lt;A href="https://learn.microsoft.com/en-us/security-exposure-management/work-attack-paths-overview?source=recommendations" target="_blank" rel="noopener"&gt;attack path&lt;/A&gt; related to the exposed credentials. By tracing permissions, consents, and access relationships, Attack Paths show exactly which routes an attacker could take and what controls will break that path.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;When these capabilities work together, visibility becomes action. MACE identifies who is exposed, Defender connects other signals into an incident level view and Attack Paths reveal where the attacker could go next. The result is a single, connected workflow that transforms early exposure data into prioritized, measurable risk reduction.&lt;/P&gt;
&lt;H2&gt;Conclusion&lt;/H2&gt;
&lt;P&gt;Leaked credentials should be treated as the beginning of a story, not an isolated event. Microsoft Defender is uniquely able to enrich security teams visibility and understanding of Identity-related threats from initial exposure to detection, risk prioritization, and remediation. This connected visibility fundamentally changes how defenders manage identity risk, shifting the focus from reacting to individual alerts to continuously reducing exposure and limiting blast radius. One leaked password doesn’t have to become a breach. With Microsoft’s identity security capabilities, it becomes a closed path, and a measurable step toward greater resilience.&lt;/P&gt;
&lt;P&gt;Learn more about &lt;STRONG&gt;&lt;A href="https://learn.microsoft.com/en-us/security-exposure-management/work-attack-paths-overview?source=recommendations" target="_blank" rel="noopener"&gt;attack paths&lt;/A&gt;&lt;/STRONG&gt; and the new leaked credentials capabilities in Defender.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Feb 2026 15:54:38 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/from-signal-to-strategy-closing-attack-paths-with-identity/ba-p/4491856</guid>
      <dc:creator>Tal_Guetta</dc:creator>
      <dc:date>2026-02-09T15:54:38Z</dc:date>
    </item>
    <item>
      <title>Monthly news -  February 2026</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/monthly-news-february-2026/ba-p/4491826</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Microsoft Defender&lt;/STRONG&gt;&lt;BR /&gt;Monthly news - February 2026 Edition&lt;/P&gt;
&lt;P&gt;This is our monthly "What's new" blog post, summarizing product updates and various new assets we released over the past month across our Defender products. In this edition, we are looking at all the goodness from January 2026. Defender for Cloud has its own Monthly News post, have a look &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/microsoft-defender-for-cloud-customer-newsletter/4491637" data-lia-auto-title="here" data-lia-auto-title-active="0" target="_blank"&gt;here&lt;/A&gt;&lt;STRONG&gt;.&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;🚀 New Virtual Ninja Show episode:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A style="background-color: rgb(255, 255, 255); font-style: normal; font-weight: 400;" href="https://www.youtube.com/watch?v=Ei02Yr1rE18&amp;amp;list=PLmAptfqzxVEVeZJO1kj4wiUVhCPfCa0Fm&amp;amp;index=5" target="_blank" rel="noopener"&gt;Discovering Microsoft Sentinel MCP server&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.youtube.com/watch?v=gbzMB3KnmvM&amp;amp;list=PLmAptfqzxVEVeZJO1kj4wiUVhCPfCa0Fm&amp;amp;index=4" target="_blank" rel="noopener"&gt;Microsoft Sentinel for SAP: What's New, What's Gone, and What's Next&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.youtube.com/watch?v=MVyHJR6TJjU&amp;amp;list=PLmAptfqzxVEVeZJO1kj4wiUVhCPfCa0Fm&amp;amp;index=3" target="_blank" rel="noopener"&gt;Unlocking Security Context with Microsoft Sentinel Graph&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.youtube.com/watch?v=d6eEklWCxXw&amp;amp;list=PLmAptfqzxVEVeZJO1kj4wiUVhCPfCa0Fm&amp;amp;index=2" target="_blank" rel="noopener"&gt;Inside OAuth App: Risks, Real Attacks, and How Microsoft Defender Shuts Them Down&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.youtube.com/watch?v=bZpUhOzxYbA&amp;amp;list=PLmAptfqzxVEVeZJO1kj4wiUVhCPfCa0Fm&amp;amp;index=1" target="_blank" rel="noopener"&gt;Technical AI Agent foundations and Microsoft Entra Agent ID&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Defender&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;(Public Preview) &lt;STRONG&gt;Microsoft Defender now supports Entra Agent IDs!&lt;/STRONG&gt; Microsoft Entra Agent ID extends the comprehensive security capabilities of Microsoft Entra to agents, enabling organizations to build, discover, govern, and protect agent identities. Until now agents use User OBO (User on behalf of), but now you can specify an Entra agent ID, a dedicated identity for your agents. Learn more about Entra Agent IDs &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/agent-id/identity-professional/microsoft-entra-agent-identities-for-ai-agents" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;(Public Preview) The&amp;nbsp;&lt;/SPAN&gt;&lt;A style="background-color: rgb(255, 255, 255); font-style: normal; font-weight: 400;" href="https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-behaviorinfo-table" target="_blank" rel="noopener" data-linktype="relative-path"&gt;BehaviorInfo&lt;/A&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;&amp;nbsp;and&amp;nbsp;&lt;/SPAN&gt;&lt;A style="background-color: rgb(255, 255, 255); font-style: normal; font-weight: 400;" href="https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-behaviorentities-table" target="_blank" rel="noopener" data-linktype="relative-path"&gt;BehaviorEntities&lt;/A&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;&amp;nbsp;tables in advanced hunting now include additional columns and information about behavior data types and alerts from User and Entity Behavior Analytics (UEBA), providing more insights on the relationships between identified behaviors and entities.&amp;nbsp;&lt;/SPAN&gt;&lt;A style="background-color: rgb(255, 255, 255); font-style: normal; font-weight: 400;" href="https://learn.microsoft.com/en-us/azure/sentinel/entity-behaviors-layer" target="_blank" rel="noopener" data-linktype="absolute-path"&gt;Learn more about UEBA behaviors&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;(Public Preview)&amp;nbsp;&lt;STRONG&gt;Streamline Incident Management with Microsoft Defender’s New Built-In Alert Tuning Rules&lt;/STRONG&gt;. Built‑in alert tuning rules help SOC teams focus on high‑quality, actionable incidents that reflect real threats - while automatically handling informational and low‑severity alerts in the background.&lt;/LI&gt;
&lt;LI&gt;At Microsoft Ignite last November, we&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/ignite-2025-whats-new-in-microsoft-defender/4469996" target="_blank"&gt;announced&lt;/A&gt;&amp;nbsp;a new capability in Microsoft Defender designed to solve exactly this problem: AI-powered incident prioritization. Today, we’re excited to share that&amp;nbsp;&lt;STRONG&gt;AI-powered incident prioritization is now available in public preview for all Microsoft Defender customers&lt;/STRONG&gt;! This is about helping SOC teams cut through noise, focus on what matters most, and move faster with confidence. Read more details in &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/introducing-ai-powered-incident-prioritization-in-microsoft-defender/4483834" data-lia-auto-title="this blog post" data-lia-auto-title-active="0" target="_blank"&gt;this blog post&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;(Public Preview) In advanced hunting, if the query result exceeds the 64-MB size limit, the portal now returns the maximum number of records it can within this limit and displays a message indicating that the displayed results are partial due to size constraints.&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-overview#quotas-and-usage-parameters" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Learn more&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;(Public Preview) &lt;STRONG&gt;Alert tuning set as behavior&lt;/STRONG&gt; - reclassifies certain alerts as behaviors so they don’t appear in the open alerts queue or generate incidents - yet remain available for investigation and hunting when needed.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Recording: &lt;STRONG&gt;Spotlight the latest innovations and enhancements&lt;/STRONG&gt;, including improvements to the Microsoft Defender portal that deepen its integration with Microsoft Sentinel.&amp;nbsp;&lt;A class="lia-external-url" href="https://www.youtube.com/watch?v=7Gf-QWcsWi4" target="_blank" rel="noopener"&gt;Watch it on YouTube&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Updated date: Microsoft Sentinel in the Azure portal to be retired March 2027&lt;/STRONG&gt;. Microsoft Sentinel is&amp;nbsp;generally available in the Microsoft Defender portal, including for customers without Microsoft Defender XDR or an E5 license. This means that you can use Microsoft Sentinel in the Defender portal even if you aren't using other Microsoft Defender services. After&amp;nbsp;&lt;STRONG&gt;March 31, 2027&lt;/STRONG&gt;, Microsoft Sentinel will no longer be supported in the Azure portal and will be available only in the Microsoft Defender portal. Learn more in &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/microsoftsentinelblog/update-new-timeline-for-transitioning-sentinel-experience-to-defender-portal/4490464" data-lia-auto-title="this blog post" data-lia-auto-title-active="0" target="_blank"&gt;this blog post&lt;/A&gt; and get useful resources.&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;2 Part Webinar: walk through a day in the life of a SOC, showing how integration and simplicity make security operations smoother in the unified portal&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Part 1: &lt;A class="lia-external-url" href="https://www.youtube.com/watch?v=I5dhz_0LDCI" target="_blank" rel="noopener"&gt;Stop Waiting, Start Onboarding: Get Sentinel Defender‑Ready Today&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Part 2: &lt;A class="lia-external-url" href="https://www.youtube.com/watch?v=0GAxsbzGirw" target="_blank" rel="noopener"&gt;Don’t Get Left Behind: Complete Your Sentinel Move to Defender&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;(General Availability) The option to disable incident correlation for analytics rules is now general available. Learn more about it &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/defender-xdr/exclude-analytics-rules-correlation" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;(Public Preview) &lt;STRONG&gt;Content distribution in Defender's multi-tenant management now supports the distribution of Analytics Rules, Automation Rules, and Workbooks&lt;/STRONG&gt;. This allows multi-tenant customers to quickly onboard new tenants and maintain a consistent security baseline. Read &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/microsoftsentinelblog/new-content-types-supported-in-multi-tenant-content-distribution/4457948" data-lia-auto-title="the blog to learn more" data-lia-auto-title-active="0" target="_blank"&gt;the blog to learn more&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;Blog post: &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/microsoftsentinelblog/accelerate-your-move-to-microsoft-sentinel-with-the-new-ai-powered-siem-migratio/4488505" data-lia-auto-title="Accelerate your move to Microsoft Sentinel with the new AI Powered SIEM migration experience" data-lia-auto-title-active="0" target="_blank"&gt;Accelerate your move to Microsoft Sentinel with the new AI Powered SIEM migration experience&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;(Public Preview) You can now enable UEBA for supported data sources directly from the data connector configuration page, reducing management time and preventing coverage gaps.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;(Public Preview) &lt;STRONG&gt;UEBA behaviors layer aggregates actionable insights from raw logs in near-real time&lt;/STRONG&gt;. Microsoft Sentinel introduces a UEBA behaviors layer that transforms high-volume, low-level security logs into clear, human-readable behavioral insights in the Defender portal. This AI-powered capability aggregates and sequences raw events from supported data sources into normalized behaviors that explain "who did what to whom" with MITRE ATT&amp;amp;CK context. Learn more &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/azure/sentinel/whats-new?tabs=defender-portal#ueba-behaviors-layer-aggregates-actionable-insights-from-raw-logs-in-near-real-time-preview" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;(Public Preview) &lt;STRONG&gt;The Triage MCP is a collection (server) on the Sentinel MCP platform and provides access to a set of APIs &lt;/STRONG&gt;that enable incident and alert triage. You can use these tools to carry out autonomous triage and investigation, or build your own agentic workflows, on top of Microsoft Defender and Microsoft Sentinel alerts and incidents.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;New detections for Sentinel solution for SAP BTP&lt;/STRONG&gt;. This update expands&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/azure/sentinel/sap/sap-btp-security-content#built-in-analytics-rules" target="_blank" rel="noopener" data-linktype="relative-path"&gt;detection coverage for SAP BTP&lt;/A&gt;, strengthening visibility into high‑risk control plane, integration, and identity activities.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Defender Vulnerability Management&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;(General Availability) New Microsoft Secure Score recommendations:
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Disable Remote Registry service on Windows&lt;/STRONG&gt;: Prevents remote access to the Windows registry, reducing attack surface and blocking unauthorized configuration changes, privilege escalation, and lateral movement.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Disable NTLM authentication for Windows workstations&lt;/STRONG&gt;: Helps prevent credential theft and lateral movement attacks by removing support for an outdated and insecure protocol. New Technology LAN Manager (NTLM) can be exploited with techniques like Pass-the-Hash and NTLM relay, allowing attackers to bypass password complexity and compromise domains.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;(Public Preview) To simplify and streamline the&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-vulnerable-devices-report" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Device vulnerabilities report&lt;/A&gt; experience, &lt;STRONG&gt;the Vulnerable devices report now includes the following changes and enhancements&lt;/STRONG&gt; (These changes are not yet visible to government cloud customers. The changes will be visible in late January 2026):&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The&amp;nbsp;&lt;STRONG&gt;Vulnerable devices by Windows 10/11 version over time&lt;/STRONG&gt;&amp;nbsp;section has been removed.&lt;/LI&gt;
&lt;LI&gt;The report’s filters have been simplified to only include the&amp;nbsp;&lt;STRONG&gt;Device group&lt;/STRONG&gt;&amp;nbsp;filter.&lt;/LI&gt;
&lt;LI&gt;The report’s history is now limited to the last 30 days.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Defender for Office 365&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Blog post: &lt;STRONG&gt;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/secure-collaboration-in-microsoft-teams-with-efficient-and-automated-threat-prot/4484479" data-lia-auto-title="Secure collaboration in Microsoft Teams with efficient and automated Threat Protection and response" data-lia-auto-title-active="0" target="_blank"&gt;Secure collaboration in Microsoft Teams with efficient and automated Threat Protection and response&lt;/A&gt;.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Block communication from sender email address and domains in Teams&lt;/STRONG&gt;: Admins can directly block&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-office-365/tenant-allow-block-list-teams-domains-configure" target="_blank" rel="noopener" data-linktype="relative-path"&gt;malicious domains and email addresses&lt;/A&gt;&amp;nbsp;from within the Microsoft Defender portal, seamlessly adding targeted entries to the Teams Admin Center (TAC) blocked domains and users list. This capability enables near real-time protection. When suspicious or abusive external organizations are identified, SOC teams can immediately block them, effectively halting new external chat messages, invites, and channel communications from those domains and senders while deleting existing ones.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Expanding ZAP and Teams Admin quarantine to Plan 1&lt;/STRONG&gt;:&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-office-365/zero-hour-auto-purge#zero-hour-auto-purge-zap-in-microsoft-teams" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Zero-hour-auto-purge (ZAP)&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-office-365/quarantine-admin-manage-messages-files#use-the-microsoft-defender-portal-to-manage-microsoft-teams-quarantined-messages" target="_blank" rel="noopener" data-linktype="relative-path"&gt;admin management of quarantined Teams messages&lt;/A&gt;&amp;nbsp;is available to Microsoft Defender for Plan 1 by default, bringing a post-delivery protection layer.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Defender for Cloud Apps&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;The Workday connector now requires only “View” permissions to function&lt;/STRONG&gt;. We have removed the “Modify” permission requirement to better align with the principle of least privilege. While existing configurations will continue to work, admins are encouraged to update the Workday account settings to remove these unnecessary rights as a security best practice. For more information see:&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-cloud-apps/protect-workday" target="_blank" rel="noopener" data-linktype="absolute-path"&gt;How Defender for Cloud Apps helps protect your Workday environment&lt;/A&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Defender for Identity&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;(General Availability) &lt;STRONG&gt;The following&amp;nbsp;Identity inventory enhancements &lt;/STRONG&gt;are now generally available:
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Accounts tab in Identity Inventory&lt;/STRONG&gt;: The new&amp;nbsp;&lt;STRONG&gt;Accounts&lt;/STRONG&gt;&amp;nbsp;tab provides a consolidated view of all accounts associated with an identity, including accounts from Active Directory, Microsoft Entra ID, and supported non-Microsoft identity providers. For more information, see&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/manage-related-identities-accounts" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Manage related identities and accounts&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Manually link and unlink accounts&lt;/STRONG&gt;: Manually link or unlink accounts from an identity directly in the&amp;nbsp;&lt;STRONG&gt;Accounts&lt;/STRONG&gt;&amp;nbsp;tab. This capability helps you correlate identity components from different directory sources and provides a complete identity context during investigations. For more information, see&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/manage-related-identities-accounts" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Manage related identities and accounts&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Identity-level remediation actions&lt;/STRONG&gt;: You can now perform remediation actions such as disabling accounts or resetting passwords on one or more accounts linked to an identity. For more information, see&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/remediation-actions#roles-and-permissions" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Remediation actions&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;New advanced hunting table&lt;/STRONG&gt;: Advanced hunting in Microsoft Defender now includes the&amp;nbsp;&lt;STRONG&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-identityaccountinfo-table" target="_blank" rel="noopener" data-linktype="absolute-path"&gt;IdentityAccountInfo&lt;/A&gt;&lt;/STRONG&gt;&amp;nbsp;table. This table provides account information from various sources, including Microsoft Entra ID, and links to the identity that owns the account.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;As part of the ongoing transition to a unified alerting experience across Microsoft Defender products, some &lt;STRONG&gt;alerts were converted from the Microsoft Defender for Identity classic format to the Microsoft Defender XDR alert format&lt;/STRONG&gt;. Keep in mind that all alerts are based on detections from Defender for Identity sensors. See&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/alerts-xdr" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Microsoft Defender for Identity XDR security alerts&lt;/A&gt; for the full list of XDR alerts. Alert names in the XDR structure are different than the alert names in the classic structure, but alert IDs stay consistent between the two alert structures.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Enhanced RPC auditing&lt;/STRONG&gt; is required for some Microsoft Defender for Identity advanced identity detections. &lt;STRONG&gt;A new health alert helps identify v3.x sensors where this configuration is either missing or incorrectly applied&lt;/STRONG&gt;. The alert is being rolled out gradually to customers. For more information, see&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/deploy/prerequisites-sensor-version-3#configure-rpc-auditing" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Configure RPC on sensors v3.x&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;(Public Preview) We’re gradually rolling out &lt;STRONG&gt;automatic Windows event-auditing configuration for sensors v3.x, along with related health alerts&lt;/STRONG&gt;. This update streamlines deployment by automatically applying the required auditing settings to new sensors and correcting misconfigurations on existing ones. For more information, see&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/deploy/configure-windows-event-collection#configure-defender-for-identity-to-collect-windows-events-automatically-preview" target="_blank" rel="noopener" data-linktype="relative-path"&gt;Configure automatic windows auditing&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 03 Feb 2026 11:36:55 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/monthly-news-february-2026/ba-p/4491826</guid>
      <dc:creator>HeikeRitter</dc:creator>
      <dc:date>2026-02-03T11:36:55Z</dc:date>
    </item>
  </channel>
</rss>

