<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Microsoft Security Community Blog articles</title>
    <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/bg-p/microsoft-security-blog</link>
    <description>Microsoft Security Community Blog articles</description>
    <pubDate>Sun, 02 Aug 2026 18:54:52 GMT</pubDate>
    <dc:creator>microsoft-security-blog</dc:creator>
    <dc:date>2026-08-02T18:54:52Z</dc:date>
    <item>
      <title>The Microsoft AI and Agent Platform — The Platform Behind Intelligent Agents</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/the-microsoft-ai-and-agent-platform-the-platform-behind/ba-p/4539060</link>
      <description>&lt;H1&gt;Why the platform around the model is the real enterprise differentiator&lt;/H1&gt;
&lt;P&gt;Enterprise AI has reached a turning point. Beyond answering questions, it can now reason over business context, retrieve knowledge, use tools, coordinate workflows, and act across enterprise systems. This shift raises a critical question: How can organizations build agents intelligent enough to transform work while ensuring they remain trusted, governed, and ready to operate at enterprise scale?&lt;/P&gt;
&lt;P&gt;The answer is not a single model, chatbot, or orchestration framework. Foundation models are advancing quickly and increasingly becoming a commodity input — Azure AI Foundry alone provides access to more than 11,000 models. What determines enterprise value is not the model alone, but the platform around the model: the data that grounds it, the tools it can use, the experiences where people engage it, the runtime where it operates, and the enterprise foundation that gives it identity, context, governance, and operational control.&lt;/P&gt;
&lt;P&gt;The Microsoft AI and Agent platform enables organizations to build, ground, govern, and operate AI apps and agents at scale, bringing together the full agent lifecycle with open development, built-in intelligence, and consistent security, compliance, and policy controls. One ecosystem, multiple experiences, shared intelligence, flexible build paths, multiple runtime choices, and an enterprise foundation that carries security, governance, compliance, and Responsible AI across the stack.&lt;/P&gt;
&lt;P&gt;The reference mental model below expresses this as a layered platform — Users → Experiences → Agents → Intelligence → Runtime → Foundation with security, governance, compliance, and Responsible AI applied across every layer.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;An agent that is brilliant but ungoverned never leaves the pilot stage. An agent that is locked down but context-blind never delivers real value. Impact compounds only when both dimensions advance together, on the same platform, so that intelligence and control share one identity model, one data plane, and one control plane.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Part 1 — Intelligence (this post): dives into how Microsoft's platform helps organizations build agents that understand work, reason over trusted context, and act through business systems to deliver real business value.&lt;/LI&gt;
&lt;LI&gt;Part 2 — Trust: will go deeper on how those agents are secured, governed, monitored, and managed across their lifecycle.&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV class="lia-align-center"&gt;
&lt;H1&gt;&lt;STRONG&gt;&amp;nbsp;Intelligence + Trust = Frontier Transformation&lt;/STRONG&gt;&lt;/H1&gt;
&lt;/DIV&gt;
&lt;H1 class="lia-clear-both"&gt;Part 1: Intelligence&lt;/H1&gt;
&lt;P&gt;Most enterprise AI programs begin with model experimentation - prompts, model comparisons, prototypes, accuracy evaluations. That is necessary but not sufficient. A model alone does not know your organization, your processes, your permissions, your systems of record, your compliance obligations, or your operating model.&lt;/P&gt;
&lt;H2&gt;Experience layer: meet users where work already happens&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Agents deliver value only when they reach people in the flow of work. &lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Enterprise AI adoption rarely happens through a single interface or experience. A sales leader, financial analyst, security operator, developer, field technician, and HR specialist do not need the same interface they need agents surfaced in the tools and workflows they already use.&lt;/P&gt;
&lt;P&gt;Microsoft's approach is not to force every agent into one portal. The platform supports multiple experiences over a shared foundation:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft 365 Copilot&lt;/STRONG&gt;&amp;nbsp;for productivity and business users.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Security Copilot&lt;/STRONG&gt;&amp;nbsp;for security operations.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Azure Copilot&lt;/STRONG&gt;&amp;nbsp;for IT operations, cloud, and infrastructure.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;GitHub Copilot&lt;/STRONG&gt;&amp;nbsp;for developers.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Dynamics 365 experiences&lt;/STRONG&gt;&amp;nbsp;for sales, service, finance, and supply chain workflows.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Power Platform and Copilot Studio experiences&lt;/STRONG&gt;&amp;nbsp;for business applications and low-code extensions.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Custom experiences&lt;/STRONG&gt;&amp;nbsp;for line-of-business apps, portals, websites, and industry-specific workflows.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Regardless of where users engage, the underlying intelligence, governance, and runtime capabilities remain consistent across experiences.&lt;/P&gt;
&lt;H2&gt;Agent layer: specialize by domain, tools, and autonomy&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Specialization with a shared substrate&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Generic agents often fail because enterprise work is domain specific. A security agent must understand incidents, alerts, identities, and threat intelligence. A finance agent must understand reconciliations, receivables, approvals, and controls. A developer agent must understand repositories, branches, pull requests, tests, and pipelines.&lt;/P&gt;
&lt;P&gt;Microsoft's platform supports both&amp;nbsp;prebuilt domain agents&amp;nbsp;and&amp;nbsp;custom agents. Organizations should leverage the domain specific agents where possible and focus custom development on capabilities that create unique business value. Whether an agent is out of the box or custom, it inherits the same governance, so built-in and custom are never two different compliance islands.&lt;/P&gt;
&lt;P&gt;Agent systems form an autonomy spectrum, allowing organizations to progressively increase capability while maintaining appropriate levels of human oversight.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Assistive: &lt;/STRONG&gt;The agent recommends; a human decides. Example - A finance agent drafts a reconciliation for review.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Supervised autonomy: &lt;/STRONG&gt;the agent acts within bounded authority and escalates exceptions. Example - An SRE agent auto-remediates known alert classes and escalates novel incidents.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Multi-agent orchestration: &lt;/STRONG&gt;A coordinating agent decomposes a goal and delegates to specialist agents. Example - One agent retrieves data, another analyzes it, another drafts a response, and another executes an approved action.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Intelligence layer: grounding as a first-class platform tier&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;An agent is only as good as the context it can reason over.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The hardest part of building a useful enterprise agent is not calling a model. It is giving the agent the right context. Without trusted context, agents produce generic answers. The IQ Platform is the intelligence fabric that separates enterprise-grade agents from generic AI assistants. A generic model can answer questions based on its training data or a narrow retrieval source. A Microsoft agent, by contrast, can be grounded in multiple dimensions of your organizational intelligence: how people work, what business data means, which knowledge is authoritative, and what external signals matter. With the right intelligence fabric, agents become role-aware, process-aware, data-aware, and policy-aware. Microsoft's IQ model treats grounding as a reusable platform capability rather than per-project plumbing.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 90.2778%; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;IQ layer&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;What it gives agents&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Why it matters&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Work IQ&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Collaboration context: people, skills, meetings, documents, decisions, workflows, and organizational relationships.&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Helps agents understand how work actually happens, not just what content exists.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Fabric IQ&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Governed business data, metrics, semantic models, and analytical context.&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Helps agents reason over trusted enterprise data with consistent business definitions.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Foundry IQ&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Models, curated knowledge, retrieval assets, memory, guardrails, and AI development capabilities delivered from Microsoft Foundry with plug-and-play memory, knowledge, and tool integrations.&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Helps teams build reliable, purpose-built agents with governed model and knowledge choices.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Web IQ&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Public web, current external signals, research, news, and external context.&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Helps agents augment internal context with timely external intelligence.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 16.1191%" /&gt;&lt;col style="width: 45.5904%" /&gt;&lt;col style="width: 38.2905%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;In a conventional application, data access is deterministic queries against known schemas. In an agentic system, the equivalent tier must serve retrieval for reasoning, semantically matching an ambiguous natural-language intent to the right passages, records, and metrics across unstructured collaboration content, structured business data, curated knowledge, and the live web. The four IQ sources correspond to those four retrieval modalities, and the IQ Platform gives agents a composable intelligence model. Each IQ layer adds a distinct signal, and together they allow agents to move from simple assistance to informed action. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Intelligence is more than model capability. It emerges from the combination of grounding, memory, model selection, orchestration, and guardrails working together as a coordinated system.&lt;/P&gt;
&lt;H4&gt;Grounding, fine-tuning, and adaptation&lt;/H4&gt;
&lt;P&gt;Microsoft gives teams multiple adaptation levers within a governed environment rather than forcing every use case into one technique. Grounding is not a sidecar retrieval capability; it is an enterprise intelligence layer. Because the model layer is a platform tier rather than a single endpoint, adaptation techniques fine-tuning, distillation into smaller task models, and retrieval-augmented grounding are first-class options selected per workload.&amp;nbsp; The common pattern: prefer grounding (RAG) for freshness and provenance, reserve fine-tuning for durable behavior, format, or domain-tone requirements, and distill to smaller models where latency and cost dominate.&lt;/P&gt;
&lt;H4&gt;Memory&lt;/H4&gt;
&lt;P&gt;In addition to retrieval and reasoning, enterprise agents increasingly rely on memory to preserve context across conversations, tasks, and workflows. Memory enables agents to maintain continuity, learn from prior interactions, and provide more personalized, adaptive, and goal-oriented experiences over time.&lt;/P&gt;
&lt;H4&gt;Multi-model choice&lt;/H4&gt;
&lt;P&gt;Agent workloads are not uniform. Some steps require simple classification. Others require complex reasoning, synthesis, code generation, or tool orchestration. Model choice is becoming a strategic architecture decision, balancing quality, latency, cost, sovereignty, and specialization requirements. &amp;nbsp;Microsoft Foundry supports model choice as part of the platform rather than forcing all workloads through one endpoint with a curated catalog of leading foundation, open-source, and partner models spanning capabilities, performance trade-offs, and use cases so teams can move from experimentation to production confidently.&lt;/P&gt;
&lt;H4&gt;Model routing&lt;/H4&gt;
&lt;P&gt;Microsoft Foundry's&amp;nbsp;Model Router&amp;nbsp;selects the optimal LLM for each agent request&amp;nbsp;per turn, not per session&amp;nbsp;— a simple greeting can route to a fast, inexpensive model, while a complex tool-calling chain can route to a frontier model, all through&amp;nbsp;one endpoint with zero routing logic. &amp;nbsp;Model selection becomes a runtime policy, not hard-coded application logic providing automatic failover when an upstream provider is unavailable, prompt caching across models for identical inputs, and consistent tool-use semantics regardless of which underlying model handles a call. Key routing capabilities include per-request optimization, complexity-aware model selection, tool-aware routing, multi-agent support, resiliency, and cost optimization.&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Orchestration&lt;/H4&gt;
&lt;P&gt;Orchestration transforms individual model interactions into coordinated agentic and multi-agent workflows. An LLM-driven planning layer that interprets user intent, breaks down complex requests, selects the right tools and knowledge, and executes multi-step plans and multi-agent workflows with guardrails for safety and compliance.&lt;/P&gt;
&lt;H4&gt;Guardrails&lt;/H4&gt;
&lt;P&gt;A guardrail is a named collection of controls; each control defines a risk to be detected, intervention points to scan the risk, and the response action to take when the risk is detected. Guardrails help ensure that agent behavior remains aligned with organizational policies, safety requirements, and business objectives.&lt;/P&gt;
&lt;H2&gt;How agents are built: one continuum from no-code to pro-code&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Different builders. Different depth. One platform.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The progression from no-code to low-code to pro-code is more than a tooling choice; it reflects increasing levels of customization, control, and organizational maturity. Different teams need different levels of control. A business user may need a simple knowledge agent. A process owner may need a workflow agent with connectors and approvals. An engineering team may need a custom multi-agent system with model routing, evaluation, tool use, and deployment automation. Organizations can start with simple productivity agents, evolve into governed workflow agents, and eventually build deeply integrated agentic systems.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;No-code - M365 Agent Builder: &lt;/STRONG&gt;create simple agents from natural language and your organizational data. This is useful for lightweight departmental workflows, knowledge assistants, and task-specific copilots.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Low-code - Copilot Studio: &lt;/STRONG&gt;design, extend, and orchestrate agents with connectors, workflows, and enterprise governance. This is where business technologists and app makers can build more sophisticated agents that integrate with systems, automate processes, and enforce organizational rules.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Pro-code - Microsoft Foundry: &lt;/STRONG&gt;enables developers to build custom AI systems with full control over models, orchestration, infrastructure, and code. This is where organizations can build highly specialized agents with advanced reasoning patterns, custom retrieval, tool use, evaluation pipelines, and deployment strategies.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The key principle is continuity; moving from no-code to low-code to pro-code should not require rethinking the architecture. Identity, grounding, governance, policy, and operational controls should carry forward including centralized identity and policy enforcement. &amp;nbsp;Regardless of the development approach, the same intelligence, runtime, governance, and operational capabilities can be reused across the platform.&lt;/P&gt;
&lt;H2&gt;Where agents run: one platform, multiple runtime choices&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Match the runtime to the requirement &lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;A mature enterprise platform must support more than one runtime pattern. Some agents need elastic cloud scale. Others need local execution because of latency, data sensitivity, offline operation, or regulated environments. Some need to interact with legacy applications that do not expose APIs. Runtime should be selected based on business, operational, and regulatory requirements rather than tooling limitations. Build path and runtime path should vary independently over a shared foundation.&lt;/P&gt;
&lt;P&gt;The ability to deploy the same agent architecture across multiple runtime environments helps organizations balance performance, compliance, and operational flexibility.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Local / edge (Foundry Local, Windows AI): &lt;/STRONG&gt;Local or edge execution supports scenarios where data sensitivity, latency, offline access, regulatory requirements, disconnected operation or device-specific context matter. Examples include on-device models, Windows AI capabilities, and local execution for regulated or disconnected environments.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Cloud runtime (Azure / Copilot stack): &lt;/STRONG&gt;supports scalable, API-driven agents with multi-agent orchestration running in Azure and Copilot with the default for enterprise workflows, multi-agent orchestration, connected systems, and data-connected scenarios that need elasticity.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Cloud PC (Windows 365 agents): &lt;/STRONG&gt;enables agents to operate in managed desktop environments. agents run on a Windows 365 Cloud PC using a check-out/check-in model, driving UI automation, browsers, and legacy apps as a human operator would in a managed and governed environment. This is the bridge to systems that expose no API, the agent operates the actual application UI in a governed, isolated desktop.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Foundation layer: shared trust fabric&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;The enterprise foundation for intelligence and trust&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The same enterprise services that secure, govern, and operate modern organizations now extend to agents, creating a shared foundation for both intelligence and trust. &amp;nbsp;This inheritance model allows organizations to extend existing investments in identity, governance, security, compliance, and operations directly to agent systems rather than introducing a separate control model for AI. Key foundation services include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft Graph&lt;/STRONG&gt; – Provides agents the context across users, groups, files, meetings, messages, relationships, and activity signals. It gives agents a permission-aware understanding of work, not just isolated documents.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft Entra&lt;/STRONG&gt; – Agents are governed using the same identity fabric that governs users, devices, apps, and resources enabling role-based and attribute-based access control plus risk-based Conditional Access policies.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft Fabric&lt;/STRONG&gt; - Governed data, analytics, semantic models, and business metrics. Foundry includes SharePoint and Microsoft Fabric among its built-in tools. Agents reason over trusted business definitions instead of disconnected raw tables.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft Purview&lt;/STRONG&gt; - Data protection, sensitivity labeling, DLP, compliance, and governance. Agent 365 uses Microsoft Purview for data protection and compliance controls on agent activity and data, complementing Microsoft Defender for threat detection and behavior monitoring. Agent interactions inherit enterprise compliance expectations.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Azure&amp;nbsp;&lt;/STRONG&gt;- Provides enterprise-grade cloud infrastructure and operational maturity. Foundry emphasizes centralized observability, traces, evaluated runs, and production performance monitoring with full traceability for enterprise-scale security, audit, and compliance requirements.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft 365&amp;nbsp;&lt;/STRONG&gt;- Brings agents into the tools where employees already work. Agents can be surfaced in the productivity tools users already leverage.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Dynamics 365 - &lt;/STRONG&gt;Business application context for sales, service, finance, supply chain, and operations. Grounds agents in business processes and systems of record.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Power Platform - &lt;/STRONG&gt;Low-code apps, automation, connectors, and business process integration — reachable via Foundry through Azure Logic Apps integration with more than 1,400 connectors. Business technologists can extend agent workflows without building everything in code.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;GitHub -&amp;nbsp;&lt;/STRONG&gt;Developer workflows, repositories, pull requests, code context, and DevOps integration. Extends agentic assistance into software development lifecycle.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Windows &amp;amp; Windows 365 - Endpoint&lt;/STRONG&gt; and Cloud PC environments for local, desktop, and legacy app scenarios. Extends agent reach beyond APIs into managed desktop execution patterns.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Alongside these services, &lt;STRONG&gt;Agent 365&lt;/STRONG&gt; and the F&lt;STRONG&gt;oundry Control Plane &lt;/STRONG&gt;provide the trust layer for enterprise agents, combining security, governance, compliance, and Responsible AI with centralized visibility, policy enforcement, lifecycle management, and secure AI operations from development through production.&lt;/P&gt;
&lt;H2&gt;End-to-end request journey: how the layers work together&lt;/H2&gt;
&lt;P&gt;The true value of the platform emerges when all the layers work together as a coordinated system. Intelligence emerges from the combined effect of experience, domain specialization, grounding, memory, models, orchestration, runtime, and foundation. An example request, from a user - “Reconcile last month's receivables and flag anomalies for my region."&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Experience&lt;/STRONG&gt; - The user asks from Microsoft 365 Copilot or a finance workflow surface, the agent is reached through the same stable endpoint used across Microsoft 365 and Teams.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Identity context&lt;/STRONG&gt; -&amp;nbsp;The platform attaches user identity, and, for the agent, its Microsoft Entra Agent ID assigned in Foundry.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Agent selection &lt;/STRONG&gt;- A finance agent interprets the goal. If the request spans domains, Copilot Studio generative orchestration decomposes it into a plan, choosing tools, topics, knowledge sources, or connected agents.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Grounding&lt;/STRONG&gt; -&amp;nbsp;Fabric IQ provides receivables data and metric definitions; Work IQ provides relevant approvals and prior decisions; Foundry IQ provides reconciliation rules and policy knowledge; Web IQ can add external signals when needed.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Model routing&lt;/STRONG&gt; - The Foundry Model Router selects the model per turn. A simple classification step goes to a nano-tier model; anomaly reasoning routes to a mid-tier model; multi-document synthesis routes to a frontier model, all through one endpoint with zero routing logic.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Guardrails &lt;/STRONG&gt;-&amp;nbsp;Foundry guardrails scan user input, tool calls, tool responses, and final output for defined risks and take the configured action (annotate or annotate-and-block).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Tool use&lt;/STRONG&gt; - The agent queries systems, invokes reconciliation logic, runs anomaly detection, or calls another specialist agent via Copilot Studio connected agents or Foundry's MCP integration.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Runtime execution&lt;/STRONG&gt; - The workflow runs in cloud, local, or Windows 365 Cloud PC environments depending on system access, data sensitivity, latency, and legacy application constraints.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Response&lt;/STRONG&gt; - The agent returns a reconciled view, flagged anomalies, rationale, and recommended next steps — with citations pulled from the knowledge layer for transparency.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Bridge to Trust&lt;/STRONG&gt; - Every action generated by the agent remains observable, governable, and auditable through the platform's trust capabilities, which are explored further in Part 2.&lt;/LI&gt;
&lt;/OL&gt;
&lt;H2&gt;Conclusion&lt;/H2&gt;
&lt;P&gt;The hard problem in enterprise AI was never obtaining a capable model; it was grounding that model in governed enterprise context, enabling it to act through governed tools, and doing so within the security, compliance, and operational controls organizations already rely on. Microsoft's answer is a platform approach: a dedicated grounding tier through the IQ Platform, a flexible intelligence layer spanning models, memory, routing, orchestration, and guardrails, specialized agent families aligned to business domains, a build-to-run continuum spanning no-code to pro-code, and a shared trust foundation that every agent inherits.&lt;/P&gt;
&lt;P&gt;Integrate once with this fabric, and the payoff compounds: one identity model, one grounding tier, and one governance spine become reusable across every persona surface, every agent family, every build-and-run target.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Coming next — Part 2: Trust&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Intelligence is only half the equation. In Part 2 we turn to the other axis: how Microsoft secures and governs every component of an agent - models, tools, MCP connectors, memory, and orchestration across the full lifecycle.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2026 18:05:42 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/the-microsoft-ai-and-agent-platform-the-platform-behind/ba-p/4539060</guid>
      <dc:creator>lmurthy</dc:creator>
      <dc:date>2026-07-29T18:05:42Z</dc:date>
    </item>
    <item>
      <title>Securing AI Agents at Runtime: Real-Time Protection and Threat Detection for Microsoft Agent 365</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/securing-ai-agents-at-runtime-real-time-protection-and-threat/ba-p/4541255</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Organizations are rapidly adopting AI agents to automate workflows, access enterprise data, invoke tools, and take actions on behalf of users. This autonomy creates a fundamentally new security challenge.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Unlike traditional AI applications, agents&amp;nbsp;operate&amp;nbsp;across dynamic execution flows, interacting with external content, calling tools, and accessing sensitive resources. These interactions create new attack paths that traditional security controls were not designed to address.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Today,&amp;nbsp;we're&amp;nbsp;announcing two major milestones for Security for AI in Microsoft Defender for Microsoft Agent 365:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Threat&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;d&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;etection for Microsoft Agent 365 agents —&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;now in&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;public preview&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Real-&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;t&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;ime&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;p&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;rotection for&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/microsoft-agent-365/developer/tooling?tabs=python" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Agent 365 tooling servers&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;—&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;now&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;generally available&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Together, these capabilities help security teams detect, investigate, and block attacks targeting AI agents, extending Microsoft Defender's threat protection capabilities into the&amp;nbsp;agent&amp;nbsp;runtime.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Threat&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;d&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;etection for&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Microsoft&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;A&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;gent&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;365&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;A&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;gents (Public Preview)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:480,&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Threat&amp;nbsp;detection provides SOC teams with&amp;nbsp;detailed&amp;nbsp;visibility into attacks and suspicious activity targeting AI agents.&amp;nbsp;By analyzing runtime signals across agent interactions, tool usage, and execution patterns, Microsoft Defender&amp;nbsp;identifies&amp;nbsp;suspicious and malicious behavior&amp;nbsp;throughout&amp;nbsp;the&amp;nbsp;agent&amp;nbsp;execution lifecycle and surfaces actionable security alerts for SOC teams.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Threat&amp;nbsp;detection supports cloud agent types that emit observability logs to&amp;nbsp;Microsoft&amp;nbsp;Agent&amp;nbsp;365, including:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Microsoft Copilot Studio&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="4" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Microsoft Foundry&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="5" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Microsoft 365 Copilot Agent Builder&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="6" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Agents integrated through the Microsoft Agent 365 SDK&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;This provides consistent&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;threat&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;visibility across supported Microsoft Agent 365 agent experiences, regardless of how the agent was built.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Fig. 1. Microsoft Security for AI alerts in Microsoft Defender XDR (Preview)&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559685&amp;quot;:720,&amp;quot;335559731&amp;quot;:720}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-center"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Defender&amp;nbsp;identifies&amp;nbsp;a broad range of AI-specific threats, including:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="7" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Indirect prompt injection (XPIA)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;— malicious instructions embedded in external content designed to manipulate agent behavior.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="8" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Evasion techniques&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;—&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;attempts&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;to bypass agent instructions or security controls.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="9" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Malicious content propagation&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;—&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;attempts&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;to use agents to generate or distribute malicious content.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="10" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Secret leakage&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt; — exposure&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;of&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;credentials, API keys, or other sensitive information through agent interactions.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="11" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;LLM reconnaissance&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;—&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;attempts&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;to probe agent capabilities, instructions, or security boundaries.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="12" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Suspicious IP access&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;— agent access originating from anonymized or suspicious IP addresses.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Alerts are surfaced directly in Microsoft Defender, enabling SOC analysts to investigate and respond using familiar workflows, Advanced Hunting queries, and the Defender XDR investigation experience.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Real-&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;t&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;ime&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;p&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;rotection for WorkIQ and Custom MCP servers&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;&amp;nbsp;(General Availability)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:480,&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Real-time protection moves beyond detection by blocking threats inline when AI agents interact with WorkIQ and custom MCP servers (see&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/microsoft-agent-365/developer/tooling?tabs=python" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Agent 365 tooling servers)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;When an agent invokes a registered tool or receives a tool response, Defender evaluates the interaction against configured security policies and&amp;nbsp;determines&amp;nbsp;whether to allow or block it directly within the agent's execution flow.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This helps prevent malicious actions and data leakage in real time, without requiring agent developers to implement custom security logic.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Fig. 2. Microsoft Security for AI Real-Time Protection policy in Defender&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559685&amp;quot;:720,&amp;quot;335559731&amp;quot;:720}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Real-time&amp;nbsp;protection&amp;nbsp;currently guards against high-impact threats, including:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="13" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Evasion techniques&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;—&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;attempts&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;to bypass agent guardrails or security controls.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="14" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Malicious content propagation&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;— preventing agents from spreading&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;malicious&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;content through tool actions.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="15" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Secret leakage&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;— blocking agents from inadvertently exposing credentials or sensitive data through tool calls.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="16" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Communication with untrusted domains&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;— preventing agents from sending email or data to high-risk or untrusted email domains.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Better Together: Detection&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;and&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;&amp;nbsp;Protection&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:480,&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Threat&amp;nbsp;detection and&amp;nbsp;real-time&amp;nbsp;protection address complementary parts of the&amp;nbsp;agent&amp;nbsp;security lifecycle.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Real-time&amp;nbsp;protection provides inline enforcement to block malicious interactions during execution, while&amp;nbsp;threat&amp;nbsp;detection gives SOC teams the visibility and investigation context needed to&amp;nbsp;identify&amp;nbsp;attack patterns, assess impact, and respond to suspicious activity.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Together, they provide a defense-in-depth approach that combines runtime enforcement with SOC-driven detection and investigation, purpose-built for AI agents.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Getting Started&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:480,&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Both capabilities are available through&amp;nbsp;Microsoft Defender,&amp;nbsp;using&amp;nbsp;a dedicated&amp;nbsp;Security for AI workload&amp;nbsp;experience that brings together AI threat detections, investigations, and runtime protection policies.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To learn more:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-xdr/security-for-ai/get-started-defender-security-for-ai" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Enable security for AI agents using Microsoft Defender&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-xdr/security-for-ai/ai-agent-detection-protection" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Detect and investigate threats to AI agents using Microsoft Defender (Preview)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="3" data-aria-level="1"&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-xdr/security-for-ai/ai-agent-real-time-protection" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Protect AI agents in real time using Microsoft Defender&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;As AI agents become more autonomous and gain access to enterprise data and tools, securing their runtime behavior becomes critical. With Threat Detection and Real-Time Protection, Microsoft Defender helps organizations adopt AI agents with security controls designed for how agents&amp;nbsp;actually operate—detecting attacks, enabling SOC investigation, and blocking malicious interactions at runtime.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2026 17:37:49 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/securing-ai-agents-at-runtime-real-time-protection-and-threat/ba-p/4541255</guid>
      <dc:creator>llevy</dc:creator>
      <dc:date>2026-07-27T17:37:49Z</dc:date>
    </item>
    <item>
      <title>Level Up Your Security Skills This August with the Microsoft Defender Challenge and Learn Live</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/level-up-your-security-skills-this-august-with-the-microsoft/ba-p/4541235</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Security teams face an increasingly complex landscape. Threats span identities, endpoints, email, cloud workloads, and emerging AI environments. The best defenders aren't just reacting to threats—they're continuously building the skills needed to stay ahead.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;That's why we're inviting security practitioners to build practical security operations expertise while working toward their next certification goal. Running from July 20 through August 21, 2026, and focused on skills across Microsoft Defender XDR, Microsoft Sentinel, and Microsoft Defender for Cloud, this hands-on learning experience is the &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/security/challenge/defender-challenge" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;Microsoft Defender Challenge.&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5 aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Build Skills That Matter to the Modern SOC&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:480,&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/security/challenge/defender-challenge" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;The Microsoft Defender Challenge&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; isn't about memorizing content for an exam. It's designed to help you develop real-world security skills you can apply immediately in your organization. Through curated Microsoft Learn content, you'll strengthen your ability to:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="994" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559683&amp;quot;:0,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Detect, investigate, and respond to threats across Microsoft Defender XDR&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="994" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559683&amp;quot;:0,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Manage incidents and automate workflows with Microsoft Sentinel&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="994" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559683&amp;quot;:0,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Triage and remediate security alerts in Microsoft Defender for Cloud&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="994" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559683&amp;quot;:0,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="4" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Secure cloud and AI workloads using modern security practices&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="994" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559683&amp;quot;:0,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="5" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Improve operational readiness for today's evolving threat landscape&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Whether you're a SOC analyst, security engineer, cloud security practitioner, or IT professional looking to expand your security expertise, the challenge is an opportunity to sharpen skills that map directly to modern security operations.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5 aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Complete the Challenge and Enter the Sweepstakes&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:480,&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Learning is the real reward, but there's an added incentive. Participants who complete the Microsoft Defender Challenge and submit the official sweepstakes entry form by August 21, 2026 will have the opportunity to win one of 500 certification exam vouchers worth 50% off one of the following Microsoft Certifications:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="993" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559683&amp;quot;:0,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;A href="https://learn.microsoft.com/en-us/credentials/certifications/security-operations-analyst/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;SC-200: Microsoft Security Operations Analyst&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="993" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559683&amp;quot;:0,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;A href="https://learn.microsoft.com/en-us/credentials/certifications/cloud-and-ai-security-engineer-associate/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;SC-500: Microsoft Cloud and AI Security Engineer&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;How to Enter&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:200,&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="992" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:720,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Complete the &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/security/challenge/defender-challenge" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Defender Challenge&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; on Microsoft Learn.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="992" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:720,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Before the entry period closes, submit the &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/security/challenge/defender-challenge" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;official sweepstakes entry form.&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="992" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:720,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;If selected, you'll receive instructions for redeeming your certification discount voucher.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Challenge window: July 20 – August 21, 2026. Sweepstakes entry deadline: August 21, 2026 at 11:59 PM UTC.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;No purchase necessary. See&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/credentials/support/microsoft-defender-challenge-sweepstakes-terms-and-conditions" target="_blank" rel="noopener"&gt; official rules&lt;/A&gt; for eligibility and sweepstakes details.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Join Learn Live: Remediating Threats Using Microsoft Defender&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:480,&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Want a guided walkthrough of the skills featured in the challenge? Join a live, interactive event where you can learn directly from Microsoft experts, ask questions in real time, and explore security operations scenarios together. Save your spot for our August &lt;/SPAN&gt;&lt;A href="https://aka.ms/LearnLive819/b" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;Learn Live session.&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Date: Wednesday, August 19, 2026&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp; Time: 12:00 PM PT / 3:00 PM ET&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;You'll be guided by Scott Landry, Microsoft Security Customer Experience Engineering, as you explore practical approaches to investigating security incidents, managing and remediating threats across the Microsoft Defender ecosystem, automating investigations and response actions, strengthening security operations processes, and applying Microsoft Defender capabilities to real-world scenarios.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5 aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Start Building Your Skills Today&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:480,&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Ready to level up? Sign up today to take the &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/security/challenge/defender-challenge" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Defender Challenge&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, then join us for the &lt;/SPAN&gt;&lt;A href="https://aka.ms/LearnLive819/b" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Learn Live session&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; on August 19. Your skilling journey doesn't end here—keep learning, keep growing, and keep building beyond August at the &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/security/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;Security Hub on Microsoft Learn.&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2026 16:47:02 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/level-up-your-security-skills-this-august-with-the-microsoft/ba-p/4541235</guid>
      <dc:creator>ShirleyseHaley</dc:creator>
      <dc:date>2026-07-27T16:47:02Z</dc:date>
    </item>
    <item>
      <title>How Nationwide stays ahead of attackers with Project Perception</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/how-nationwide-stays-ahead-of-attackers-with-project-perception/ba-p/4540534</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Nationwide, the world’s&amp;nbsp;largest&amp;nbsp;building&amp;nbsp;society,&amp;nbsp;is among the first&amp;nbsp;organizations&amp;nbsp;to&amp;nbsp;put Microsoft’s new agentic security system to work. Facing adversaries who now&amp;nbsp;regularly&amp;nbsp;weaponize AI, the society is using Project Perception’s coordinated multi-agent defense&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;—&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;red, blue, and green agents working alongside its analysts&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;—&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;to find and remediate threats faster, while its security experts stay firmly in command.&amp;nbsp;Their&amp;nbsp;team has already seen work that once took weeks compressed into hours.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;div data-video-id="https://youtu.be/ACx7NxQW9uo/1784922766209" data-video-remote-vid="https://youtu.be/ACx7NxQW9uo/1784922766209" class="lia-video-container lia-media-is-center lia-media-size-large"&gt;&lt;iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FACx7NxQW9uo%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DACx7NxQW9uo&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FACx7NxQW9uo%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" allowfullscreen="" style="max-width: 100%"&gt;&lt;/iframe&gt;&lt;/div&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Defending against AI-driven threats&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Nationwide Building Society is a member-owned mutual&amp;nbsp;serving&amp;nbsp;19&amp;nbsp;million&amp;nbsp;members&amp;nbsp;across the UK, and that responsibility is becoming increasingly complex as AI reshapes the threat landscape. Attackers can now scale campaigns faster&amp;nbsp;and&amp;nbsp;automate more of their operations. "AI is giving attackers a real advantage over defenders in&amp;nbsp;terms of pace and scale," says David Boda, Chief Security and Resilience Officer.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For its security teams, the mission is clear: protect the&amp;nbsp;customers&amp;nbsp;who trust the organization with some of the most important aspects of their lives. "The things that matter most are protecting their money, protecting their livelihoods." says Tim Russell, Cybersecurity Director.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For Nationwide Building Society, keeping pace means human-led, agent-driven defense that helps its team act faster,&amp;nbsp;together and stay ahead.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Coordinated multi-agent defense, built on Microsoft Security&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Nationwide&amp;nbsp;Building Society’s response is to&amp;nbsp;get ahead of&amp;nbsp;the change in the threat landscape&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;—&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;identifying&amp;nbsp;potential risks faster and accelerating response across its environment. Building on Microsoft Defender, which its teams have run for years, the society adopted Project Perception to bring coordinated multi-agent defense into its existing operations. "This solution for multi-agent defense allows us to move to a more proactive way of working," says Boda.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The system puts specialized agents to work as a team. "Red agents are offensive cyber agents used to explore the vulnerabilities and the attack paths in our environment. Blue agents are the defensive agents and&amp;nbsp;reflect&amp;nbsp;the work that a security operation center analyst might do," Boda explains, while green agents remediate and harden&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;—&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;with people in command throughout. "The power of the solution is it brings those agents together to achieve a better cybersecurity posture."&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For analysts, that coordination removes long-standing friction.&amp;nbsp;"We're able to use agentic workflows to identify threats and then track them through into remediation, which previously we would've had to have engaged with a number of different tools to achieve," says Russell.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Human-led,&amp;nbsp;agent-driven defense&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The&amp;nbsp;impact is already tangible. "My team came to me and said, look, we've just taken four weeks of threat intelligence analysis and collapsed that down into four hours&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;—&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;and for me, that was the moment that really brought this to life," Boda recalls. Just as important to Nationwide Building Society is what the technology does for its people. "This technology helps to amplify their skill sets, not&amp;nbsp;to replace&amp;nbsp;them," says Russell.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For&amp;nbsp;Nationwide&amp;nbsp;Building Society, the future is humans and agents working as one. "Agents can work twenty-four-seven, but as humans, we can't do that. So,&amp;nbsp;by harnessing humans and agents&amp;nbsp;operating&amp;nbsp;together, we can achieve so much more collectively," says Boda. And the ambition reaches further than the society itself: "Being able to develop this solution together with Microsoft allows us not just to protect Nationwide Building Society, but also to protect&amp;nbsp;wider&amp;nbsp;society&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;—&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;and&amp;nbsp;that feels really positive."&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2026 12:30:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/how-nationwide-stays-ahead-of-attackers-with-project-perception/ba-p/4540534</guid>
      <dc:creator>julievanloef</dc:creator>
      <dc:date>2026-07-27T12:30:00Z</dc:date>
    </item>
    <item>
      <title>Extend data security to the network with Microsoft Purview and Microsoft Entra</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/extend-data-security-to-the-network-with-microsoft-purview-and/ba-p/4531929</link>
      <description>&lt;H4 aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Protection that&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;keep&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;s&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;up&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;with how data moves&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;in the AI era&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:1,&amp;quot;335551620&amp;quot;:1,&amp;quot;335559685&amp;quot;:0,&amp;quot;335559737&amp;quot;:0,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Enterprise data used to be easier to contain.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;It lived in files, in apps you managed, within boundaries you controlled. Security teams could focus on endpoints and known systems, and that was often enough.&amp;nbsp;That’s&amp;nbsp;no longer the case.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Today, data&amp;nbsp;travels&amp;nbsp;constantly&amp;nbsp;between trusted endpoints and unmanaged&amp;nbsp;web apps, SaaS apps, and&amp;nbsp;most critically, generative AI tools&amp;nbsp;over the network. Employees&amp;nbsp;type and paste&amp;nbsp;sensitive information into prompts, upload&amp;nbsp;work-related&amp;nbsp;files to external services&amp;nbsp;or personal cloud storage, and interact with systems that sit entirely outside the traditional enterprise perimeter.&amp;nbsp;AI has expanded&amp;nbsp;the risk surface for&amp;nbsp;potential&amp;nbsp;enterprise data loss.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://aka.ms/networkdatasecurity" target="_blank"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;That’s&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;why Microsoft Purview and Microsoft Entra now integrate to extend data security to the network layer (available in public preview).&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Traditional&amp;nbsp;data loss prevention (DLP)&amp;nbsp;approaches lack real-time visibility and&amp;nbsp;enforcement,&amp;nbsp;flagging incidents after data has already left the organization.&amp;nbsp;In other cases,&amp;nbsp;vendors&amp;nbsp;rely&amp;nbsp;heavily on physical&amp;nbsp;network&amp;nbsp;appliances that are complex&amp;nbsp;and expensive&amp;nbsp;to deploy, or&amp;nbsp;compute&amp;nbsp;resources that can add significant latency.&amp;nbsp;In the era of AI, that model breaks down quickly.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:1,&amp;quot;335551620&amp;quot;:1,&amp;quot;335559685&amp;quot;:0,&amp;quot;335559737&amp;quot;:0,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;R&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;eal-time data protection for how work happens&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;today&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:1,&amp;quot;335551620&amp;quot;:1,&amp;quot;335559685&amp;quot;:0,&amp;quot;335559737&amp;quot;:0,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To adapt to how enterprise data moves in the AI era,&amp;nbsp;we’re&amp;nbsp;announcing the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;extension of data security to the network layer, powered by Microsoft Purview and Microsoft Entra&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;, now in public preview.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:1,&amp;quot;335551620&amp;quot;:1,&amp;quot;335559685&amp;quot;:0,&amp;quot;335559737&amp;quot;:0,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This integration brings together data context and identity-aware enforcement to help protect sensitive data in transit, in real time:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="10" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Detect how sensitive data is shared to&amp;nbsp;shadow AI tools,&amp;nbsp;unmanaged SaaS&amp;nbsp;apps, and personal cloud&amp;nbsp;repositories&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="10" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Help block&amp;nbsp;the sharing of sensitive data&amp;nbsp;in real time based on&amp;nbsp;identity,&amp;nbsp;user activity, and data context, before data leakage occurs&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="10" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="3" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Unify investigation workflows by correlating identity, data, and&amp;nbsp;insider risk&amp;nbsp;signals across Purview, Entra, and Defender&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;Figure 1: &lt;SPAN data-contrast="none"&gt;Prevent employees from sharing proprietary or sensitive organizational data to potentially risky locations such as consumer AI apps.&lt;/SPAN&gt;&lt;/img&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:2,&amp;quot;335551620&amp;quot;:2,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;By combining Purview data classification, DLP policies, and insider risk detection with identity-aware enforcement at the network layer through Entra, organizations can dynamically apply protections based on:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="12" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;The sensitivity of the data&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="11" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Who the user is&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="11" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;How that user has interacted with sensitive data over time&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Together, Purview and Entra enable&amp;nbsp;a modern&amp;nbsp;approach to data protection that follows the data&amp;nbsp;to prevent leakage&amp;nbsp;instead of relying on&amp;nbsp;at-rest controls alone.&amp;nbsp;Not only that, but the same Purview classification and policies that you already&amp;nbsp;leverage&amp;nbsp;for the rest of your&amp;nbsp;enterprise data&amp;nbsp;can now be applied&amp;nbsp;consistently across&amp;nbsp;data in motion, at rest, and in use.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:1,&amp;quot;335551620&amp;quot;:1,&amp;quot;335559685&amp;quot;:0,&amp;quot;335559737&amp;quot;:0,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="13" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559683&amp;quot;:0,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Learn more&amp;nbsp;in the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://aka.ms/networkdatasecurity" target="_blank"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;detailed blog&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="13" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559683&amp;quot;:0,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;See the&amp;nbsp;capabilities in action&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://aka.ms/NetworkDataSecurityDemo" target="_blank"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;here&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="13" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559683&amp;quot;:0,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Start your free trial of Purview Suite&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://signup.microsoft.com/get-started/signup?offerid=e816e8db-34c4-4dc0-bbee-6331c8e84029&amp;amp;products=e816e8db-34c4-4dc0-bbee-6331c8e84029&amp;amp;ali=1&amp;amp;bac=1&amp;amp;culture=en-us&amp;amp;country=us&amp;amp;bpr=1&amp;amp;mproducts=CFQ7TTC0LHR4%3a0004&amp;amp;fmproducts=CFQ7TTC0LHR4%3a0004" target="_blank"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;here&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 01 Jul 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/extend-data-security-to-the-network-with-microsoft-purview-and/ba-p/4531929</guid>
      <dc:creator>Vivian_Ma</dc:creator>
      <dc:date>2026-07-01T16:00:00Z</dc:date>
    </item>
    <item>
      <title>Introducing a unified alert experience for Microsoft Purview Insider Risk Management</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/introducing-a-unified-alert-experience-for-microsoft-purview/ba-p/4530714</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Modern insider risk investigations succeed or fail based on how quickly analysts can move from&amp;nbsp;signal to decision&amp;nbsp;with more context.&amp;nbsp;Too often, investigations&amp;nbsp;within Microsoft Purview&amp;nbsp;require&amp;nbsp;high switching costs&amp;nbsp;while analysts struggle with&amp;nbsp;disconnected&amp;nbsp;alert&amp;nbsp;views&amp;nbsp;and scattered case notes across workflows.&amp;nbsp;Every switch slows triage pulling&amp;nbsp;focus away from the risk&amp;nbsp;itself,&amp;nbsp;decreasing the&amp;nbsp;speed and confidence of investigations.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;That’s&amp;nbsp;why&amp;nbsp;we’re&amp;nbsp;unifying the&amp;nbsp;Microsoft Purview&amp;nbsp;Insider Risk Management investigation experience&amp;nbsp;with three connected&amp;nbsp;improvements&amp;nbsp;— a unified alert queue, expanded user profile details, and notes across alerts and cases.&amp;nbsp;Analysts can&amp;nbsp;now&amp;nbsp;triage, understand context, and capture their work in&amp;nbsp;a streamlined investigation flow&amp;nbsp;to help enable&amp;nbsp;faster investigations and increase confidence.&amp;nbsp;Here’s&amp;nbsp;what’s&amp;nbsp;coming to public preview in July 2026:&lt;/SPAN&gt; &lt;/P&gt;
&lt;P&gt;&lt;STRONG style="color: rgb(30, 30, 30); font-size: 24px;"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 10" data-ccp-parastyle-defn="{&amp;quot;ObjectId&amp;quot;:&amp;quot;81d40c56-e640-5cda-82bb-83448542e906|1&amp;quot;,&amp;quot;ClassId&amp;quot;:1073872969,&amp;quot;Properties&amp;quot;:[469777841,&amp;quot;Arial&amp;quot;,469777842,&amp;quot;Arial&amp;quot;,469777843,&amp;quot;Arial&amp;quot;,469777844,&amp;quot;Arial&amp;quot;,469769226,&amp;quot;Arial&amp;quot;,335551500,&amp;quot;12413967&amp;quot;,268442635,&amp;quot;28&amp;quot;,469775450,&amp;quot;heading 10&amp;quot;,201340122,&amp;quot;2&amp;quot;,134234082,&amp;quot;true&amp;quot;,134233614,&amp;quot;true&amp;quot;,469778129,&amp;quot;heading10&amp;quot;,335572020,&amp;quot;1&amp;quot;,134224900,&amp;quot;true&amp;quot;,335559739,&amp;quot;140&amp;quot;,335559738,&amp;quot;320&amp;quot;,335560102,&amp;quot;0&amp;quot;,469775498,&amp;quot;Normal&amp;quot;,469778324,&amp;quot;Normal&amp;quot;]}"&gt;1. One unified alert queue &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 10"&gt;inte&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 10"&gt;grati&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 10"&gt;ng &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 10"&gt;classic and agent workflows together&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:320,&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;The most disruptive part of triage happens before analysts dig into any single alert:&amp;nbsp;understanding&amp;nbsp;what&amp;nbsp;alerts&amp;nbsp;require the most attention. Today,&amp;nbsp;that means toggling between the classic alert queue and the&amp;nbsp;Data Security Triage&amp;nbsp;Agent’s&amp;nbsp;insights.&amp;nbsp;We’re&amp;nbsp;now&amp;nbsp;bringing them together into a single, unified alerts list.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Instead of switching between two experiences, analysts get one page where they can:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;Preview agent summaries, alert details, and user details directly&amp;nbsp;from&amp;nbsp;the alerts list,&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;reducing the need to&amp;nbsp;open each alert individually.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;Filter&amp;nbsp;all classic&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;and&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;agent attributes on one page, including a new agent&amp;nbsp;categorization column and the ability to surface agent-triaged alerts that&amp;nbsp;need&amp;nbsp;attention.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;View and manage the agent directly from the alerts list.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="4" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;Open or&amp;nbsp;act&amp;nbsp;on an alert&amp;nbsp;with the ability to stay within&amp;nbsp;the&amp;nbsp;queue.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;As part of this unification, alert spotlighting is being&amp;nbsp;retired,&amp;nbsp;and the toggle between agent and classic alerts is going away in favor of the single view. To give teams time to adjust, both the classic and new experiences will remain available for at least&amp;nbsp;60 days, with support for&amp;nbsp;both&amp;nbsp;currently planned&amp;nbsp;through&amp;nbsp;August 31, 2026.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;Explore the unified alert queue&amp;nbsp;here&amp;nbsp;→&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://aka.ms/NewIRMAlertExperienceInProduct" target="_blank"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;New&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;IRM Alert&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt; Experience.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Launch details:&amp;nbsp;Public preview: July 2026&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp; Roadmap ID:&amp;nbsp;&lt;A href="https://www.microsoft.com/en-us/microsoft-365/roadmap?filters=&amp;amp;searchterms=564621" target="_blank"&gt;564621&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:120,&amp;quot;335559739&amp;quot;:80,&amp;quot;335572083&amp;quot;:18,&amp;quot;335572084&amp;quot;:8,&amp;quot;335572085&amp;quot;:12413967,&amp;quot;469789810&amp;quot;:&amp;quot;single&amp;quot;}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;img&gt;&lt;SPAN data-contrast="none"&gt;Figure 1: The unified IRM alerts list, showing inline agent summaries, the new Categorization column, and combined classic and agent filtering on a single page.&lt;/SPAN&gt;&lt;/img&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 10" data-ccp-parastyle-defn="{&amp;quot;ObjectId&amp;quot;:&amp;quot;81d40c56-e640-5cda-82bb-83448542e906|1&amp;quot;,&amp;quot;ClassId&amp;quot;:1073872969,&amp;quot;Properties&amp;quot;:[469777841,&amp;quot;Arial&amp;quot;,469777842,&amp;quot;Arial&amp;quot;,469777843,&amp;quot;Arial&amp;quot;,469777844,&amp;quot;Arial&amp;quot;,469769226,&amp;quot;Arial&amp;quot;,335551500,&amp;quot;12413967&amp;quot;,268442635,&amp;quot;28&amp;quot;,469775450,&amp;quot;heading 10&amp;quot;,201340122,&amp;quot;2&amp;quot;,134234082,&amp;quot;true&amp;quot;,134233614,&amp;quot;true&amp;quot;,469778129,&amp;quot;heading10&amp;quot;,335572020,&amp;quot;1&amp;quot;,134224900,&amp;quot;true&amp;quot;,335559739,&amp;quot;140&amp;quot;,335559738,&amp;quot;320&amp;quot;,335560102,&amp;quot;0&amp;quot;,469775498,&amp;quot;Normal&amp;quot;,469778324,&amp;quot;Normal&amp;quot;]}"&gt;2. Expanded user profile details&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 10"&gt;to better understand&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 10"&gt;&amp;nbsp;user risk&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:320,&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Once an alert has&amp;nbsp;been raised, the next question is about the person behind it:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;Who are they, and how much risk does this really represent?&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;Answering that used to mean piecing context together from multiple places.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;The expanded user profile brings&amp;nbsp;context&amp;nbsp;into one unified view by:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="5" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;Adding new signals from the user’s Entra profile&amp;nbsp;including&amp;nbsp;office location, employee type, department, and last working date.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="6" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;Aggregating&amp;nbsp;key&amp;nbsp;insider&amp;nbsp;risk signals in one place&amp;nbsp;including&amp;nbsp;Entra profile details, past alert and case history, priority user group status, and policy inclusion.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;The result is a&amp;nbsp;fuller, more detailed&amp;nbsp;picture&amp;nbsp;of&amp;nbsp;users'&amp;nbsp;risk,&amp;nbsp;to&amp;nbsp;provide&amp;nbsp;investigators&amp;nbsp;with more context for&amp;nbsp;decisions&amp;nbsp;without leaving the alert.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;See expanded user profile details&amp;nbsp;here&amp;nbsp;→&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://aka.ms/NewIRMAlertExperienceInProduct" target="_blank"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;New IRM Alert Experience&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;&lt;STRONG&gt;Where to find it:&lt;/STRONG&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;On&amp;nbsp;the new&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;Alerts (preview)&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;tab — click&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;Alerts (preview)&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;in the left navigation, open an alert, scroll to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;User details&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;, and select&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;View user details&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;. Note: when pseudo-anonymization is enabled, user profile details will not appear, preserving privacy by design.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Launch details:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;Public preview: July 2026&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp; Roadmap ID:&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en-us/microsoft-365/roadmap?filters=&amp;amp;searchterms=564619" target="_blank"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;564619&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;img&gt;&lt;SPAN data-contrast="none"&gt;Figure 2: The unified user details view, combining Entra profile signals with aggregated Insider Risk history and status.&lt;/SPAN&gt;&lt;/img&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 10" data-ccp-parastyle-defn="{&amp;quot;ObjectId&amp;quot;:&amp;quot;81d40c56-e640-5cda-82bb-83448542e906|1&amp;quot;,&amp;quot;ClassId&amp;quot;:1073872969,&amp;quot;Properties&amp;quot;:[469777841,&amp;quot;Arial&amp;quot;,469777842,&amp;quot;Arial&amp;quot;,469777843,&amp;quot;Arial&amp;quot;,469777844,&amp;quot;Arial&amp;quot;,469769226,&amp;quot;Arial&amp;quot;,335551500,&amp;quot;12413967&amp;quot;,268442635,&amp;quot;28&amp;quot;,469775450,&amp;quot;heading 10&amp;quot;,201340122,&amp;quot;2&amp;quot;,134234082,&amp;quot;true&amp;quot;,134233614,&amp;quot;true&amp;quot;,469778129,&amp;quot;heading10&amp;quot;,335572020,&amp;quot;1&amp;quot;,134224900,&amp;quot;true&amp;quot;,335559739,&amp;quot;140&amp;quot;,335559738,&amp;quot;320&amp;quot;,335560102,&amp;quot;0&amp;quot;,469775498,&amp;quot;Normal&amp;quot;,469778324,&amp;quot;Normal&amp;quot;]}"&gt;3. Notes across alerts and cases keep context with the work&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Investigation context shouldn’t live in someone’s memory or a side document. Analysts and investigators can now add and view notes directly in alerts and cases within the Purview portal,&amp;nbsp;ensuring&amp;nbsp;the story of an investigation stays with the investigation.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Notes come in two forms:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="7" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;System-generated notes are applied automatically&amp;nbsp;on key changes&amp;nbsp;including&amp;nbsp;alert or case status, assigned user, alert or case closure, and case escalations.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="8" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;Analyst notes let investigators capture their own observations as they work&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;This gives teams continuity and a&amp;nbsp;clearer record of investigation activity&amp;nbsp;history without breaking stride.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;&lt;STRONG&gt;Where to find it:&lt;/STRONG&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;In&amp;nbsp;the Notes&amp;nbsp;tab within&amp;nbsp;the alert details&amp;nbsp;panel,&amp;nbsp;and within the Cases tab within a case.&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;Start capturing notes across alerts and cases here→&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://aka.ms/NewIRMAlertExperienceInProduct" target="_blank"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;New IRM Alert Experience&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Launch details:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;Public preview: July 2026&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp; Roadmap ID:&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en-us/microsoft-365/roadmap?filters=&amp;amp;searchterms=564620" target="_blank"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;564620&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:120,&amp;quot;335559739&amp;quot;:80,&amp;quot;335572083&amp;quot;:18,&amp;quot;335572084&amp;quot;:8,&amp;quot;335572085&amp;quot;:12413967,&amp;quot;469789810&amp;quot;:&amp;quot;single&amp;quot;}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;img&gt;&lt;SPAN data-contrast="none"&gt;Figure 3: The Notes tab in the alert detail panel, showing both system-generated and analyst-added notes.&lt;/SPAN&gt;&lt;/img&gt;
&lt;H5&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 10" data-ccp-parastyle-defn="{&amp;quot;ObjectId&amp;quot;:&amp;quot;81d40c56-e640-5cda-82bb-83448542e906|1&amp;quot;,&amp;quot;ClassId&amp;quot;:1073872969,&amp;quot;Properties&amp;quot;:[469777841,&amp;quot;Arial&amp;quot;,469777842,&amp;quot;Arial&amp;quot;,469777843,&amp;quot;Arial&amp;quot;,469777844,&amp;quot;Arial&amp;quot;,469769226,&amp;quot;Arial&amp;quot;,335551500,&amp;quot;12413967&amp;quot;,268442635,&amp;quot;28&amp;quot;,469775450,&amp;quot;heading 10&amp;quot;,201340122,&amp;quot;2&amp;quot;,134234082,&amp;quot;true&amp;quot;,134233614,&amp;quot;true&amp;quot;,469778129,&amp;quot;heading10&amp;quot;,335572020,&amp;quot;1&amp;quot;,134224900,&amp;quot;true&amp;quot;,335559739,&amp;quot;140&amp;quot;,335559738,&amp;quot;320&amp;quot;,335560102,&amp;quot;0&amp;quot;,469775498,&amp;quot;Normal&amp;quot;,469778324,&amp;quot;Normal&amp;quot;]}"&gt;Ready to get started?&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 10"&gt;Try the unified&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 10"&gt;Insider Risk Management&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 10"&gt;experience today&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 10"&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="https://aka.ms/NewIRMAlertExperienceInProduct" target="_blank"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Click here to get started&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 10"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:320,&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Privacy Statement:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt; &lt;BR /&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt;Microsoft Purview Insider Risk Management correlates various signals to identify potential malicious or inadvertent insider risks, such as IP theft, data leakage, and security violations. Insider Risk Management enables customers to create policies to manage security and compliance. Built with privacy by design, users are pseudonymized by default, and role-based access controls and audit logs are in place to help ensure user-level privacy.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335557856&amp;quot;:16777215}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 30 Jun 2026 19:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/introducing-a-unified-alert-experience-for-microsoft-purview/ba-p/4530714</guid>
      <dc:creator>MSlotwinski</dc:creator>
      <dc:date>2026-06-30T19:00:00Z</dc:date>
    </item>
    <item>
      <title>Understand your Sentinel tables at a glance: Monitor with table insights</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/understand-your-sentinel-tables-at-a-glance-monitor-with-table/ba-p/4530738</link>
      <description>&lt;H4&gt;&lt;STRONG&gt;What it is&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Table insights is a new panel on the Sentinel Tables page that gives you 30-day ingestion volume per tier, day-over-week fluctuations, the top 5 tables by volume, last-data-received per table, an estimated daily cost, and a volume anomaly indicator.&lt;/P&gt;
&lt;P&gt;Who benefits: SOC engineers chasing silent data connectors, platform owners chasing cost spikes, FinOps teams chasing chargeback clarity — all from the same screen.&lt;/P&gt;
&lt;H4 aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Why&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;these matter&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:280,&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Every Sentinel customer I talk to has the same two recurring incidents.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:320}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="Quote"&gt;"A third-party data connector stopped sending data three days ago and nobody noticed until a hunt came up empty."&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:360,&amp;quot;335559738&amp;quot;:120,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:320}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Both incidents share a root cause: until now, table-level health lived in a workbook you had to remember to open, a Usage KQL you had to remember to write, or a SentinelHealth alert someone had to remember to configure. In a workspace with 500+ tables and a mix of Microsoft 1st-party data connectors, third-party data connectors, custom logs, and data-lake tables, that's a lot of remembering.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:320}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Table insights flips the model. It puts the answer on the same page where you already manage tiers and retention, so the next time you open the Tables page to right-size a Lake-tier table, the data connector that went silent at 3 a.m. is already staring at you.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:320}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Try it today&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:280,&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Open the Defender portal → &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Sentinel → Configuration → Tables&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; and expand the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Table insights&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; panel.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:320}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img&gt;Figure 1: Table insights panel&lt;/img&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;What's&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt; new on the Tables page&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:280,&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="3" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Ingestion volume per tier&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;- Analytics vs. Lake split for the last 30 days. The first time you see Lake tier exceeding Analytics, you'll know the data-lake migration is working.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:100,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="4" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Table ingestion fluctuations&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; - tables whose last-24h volume differs from the same day last week beyond a threshold (default 10% and 1 MB).&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="5" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Top 5 tables by daily ingestion volume&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;- 30-day trend. The line that looks like a heart-rate monitor is the one your FinOps lead wants to talk about.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:100,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="6" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Last data received&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; column &lt;/STRONG&gt;– time of recency per table.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:100,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="7" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Volume anomaly&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; column&lt;/STRONG&gt; - signed percentage change versus baseline, right next to the table name.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:100,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="8" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Data sources&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; – Click on table details to open side panels for data sources.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Who wins, and how&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:280,&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Persona&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Pain today&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Win with Table insights&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;SOC engineer&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Detections silently degrade when a third-party data connector stops sending- you only notice when an incident is missed.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Spot the drop in "Last data received" or a -100% fluctuation before the next shift report.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Data Connector onboarding lead&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;"Did the new data connector light up?" takes a KQL query and a workbook hunt.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;One glance at the Tables page confirms the destination table, tier, and last-received timestamp.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H4 aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;How &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;I'd&lt;/SPAN&gt; &lt;SPAN data-ccp-parastyle="heading 1"&gt;actually use&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt; it&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="9" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Baseline- &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Open the Tables page, filter by Tier = Analytics, sort by Avg. daily ingestion descending.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="10" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Triage silent data connectors&lt;STRONG&gt;-&lt;/STRONG&gt; &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Sort by Last data received ascending.&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="11" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Tier review&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;- For every table above a few GB/day with low SOC query usage, evaluate moving it to Auxiliary or Lake tier. The Est. daily ingestion cost column makes the business case for you.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:100,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="12" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Wire up alerts- &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Convert the fluctuations card into a scheduled analytics rule on SentinelHealth, so the next "-100%" row pages someone instead of waiting for the morning standup.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:100,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="13" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Share the screenshot- &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Drop the ingestion volume per tier card into your monthly business review.&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Honest caveats&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:280,&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="14" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Fluctuations only compare the last 24h to the same day last week.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="15" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Cost numbers are estimates They're great for relative comparisons, not invoice forecasting.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:100,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="16" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Volume anomaly is most accurate on Analytics-tier tables today. Lake/Auxiliary anomalies will be catchup in features soon.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:100,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="17" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;The grid shows the table; for third-party data connectors you'll still cross-reference the Tables-to-connectors mapping page to find the upstream data connector.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:100,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="18" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Table insights is a visualization. If you want to be paged, build the SentinelHealth analytics rule.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:100,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H5 aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Resources&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:280,&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="19" data-aria-level="1"&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/sentinel/manage-data-overview" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Manage data tiers and retention in Microsoft Sentinel&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:100,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="20" data-aria-level="1"&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/sentinel/monitor-data-connector-health" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Monitor the health of your Microsoft Sentinel data connectors&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:100,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="21" data-aria-level="1"&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/sentinel/health-table-reference" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Sentinel health tables reference (SentinelHealth)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:100,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="22" data-aria-level="1"&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/sentinel/sentinel-tables-connectors-reference" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Sentinel tables and associated connectors&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:100,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="23" data-aria-level="1"&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/sentinel/configure-data-transformation" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Transform or customize data at ingestion time&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:100,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="24" data-aria-level="1"&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/sentinel/billing-reduce-costs" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Reduce costs for Microsoft Sentinel&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:100,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/sentinel/data-lake/sentinel-data-lake-overview" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Sentinel data lake (overview)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:100,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 29 Jun 2026 17:48:32 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/understand-your-sentinel-tables-at-a-glance-monitor-with-table/ba-p/4530738</guid>
      <dc:creator>NikitaChhabra</dc:creator>
      <dc:date>2026-06-29T17:48:32Z</dc:date>
    </item>
    <item>
      <title>The state of MCP security in 2026</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/the-state-of-mcp-security-in-2026/ba-p/4531327</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Co-Author: &lt;a href="javascript:void(0)" data-lia-user-mentions="" data-lia-user-uid="220710" data-lia-user-login="ShalabhPradhan" class="lia-mention lia-mention-user"&gt;ShalabhPradhan​&lt;/a&gt;&lt;BR /&gt;&lt;BR /&gt;A year&amp;nbsp;ago&amp;nbsp;we published&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoft-security-blog/understanding-and-mitigating-security-risks-in-mcp-implementations/4404667" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Understanding and mitigating security risks in MCP implementations&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The core idea still holds: the moment a model can choose and call tools, it stops being a question-and-answer box and becomes software that acts. Anything that acts has a trust boundary, and tool descriptions, schemas, outputs, and credentials all sit inside it.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;What has changed is scale. The Model Context Protocol has gone from a promising idea to the way agents connect to tools, data, and systems. Enterprises have stopped experimenting and started shipping into production. This post is a checkpoint: the main risks as they stand now, which of them have moved, and what good security looks like for each.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 20" data-ccp-parastyle-defn="{&amp;quot;ObjectId&amp;quot;:&amp;quot;741782aa-652f-563c-bdc7-8d2b1b3f555d|1&amp;quot;,&amp;quot;ClassId&amp;quot;:1073872969,&amp;quot;Properties&amp;quot;:[469775450,&amp;quot;heading 20&amp;quot;,201340122,&amp;quot;2&amp;quot;,134234082,&amp;quot;true&amp;quot;,134233614,&amp;quot;true&amp;quot;,469778129,&amp;quot;heading20&amp;quot;,335572020,&amp;quot;1&amp;quot;,134224900,&amp;quot;true&amp;quot;,335551500,&amp;quot;8870446&amp;quot;,268442635,&amp;quot;30&amp;quot;,335559739,&amp;quot;140&amp;quot;,335559738,&amp;quot;320&amp;quot;,335560102,&amp;quot;1&amp;quot;,469777841,&amp;quot;Segoe UI&amp;quot;,469777842,&amp;quot;Segoe UI&amp;quot;,469777843,&amp;quot;Segoe UI&amp;quot;,469777844,&amp;quot;Segoe UI&amp;quot;,469769226,&amp;quot;Segoe UI&amp;quot;]}"&gt;A specification that keeps moving&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;MCP is still evolving quickly, and the spec is revised on a regular&amp;nbsp;cadence. The latest&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://blog.modelcontextprotocol.io/posts/2026-07-28-release-candidate/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;release candidate&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; raises the security baseline in ways worth knowing. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Requests now carry what they need, so a gateway can inspect and&amp;nbsp;enforce on&amp;nbsp;every call rather than trust a hidden session. Identity checks between clients and servers are tighter. And a new MCP Apps capability lets a server ship&amp;nbsp;interactive&amp;nbsp;UI that the host&amp;nbsp;renders&amp;nbsp;inside a sandbox.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The protocol deliberately does not enforce security for you. It defines how clients and servers talk, and the rest is your responsibility. Treat "we reviewed MCP last year" as out of date, and revisit your assumptions with each release.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 20" data-ccp-parastyle-defn="{&amp;quot;ObjectId&amp;quot;:&amp;quot;741782aa-652f-563c-bdc7-8d2b1b3f555d|1&amp;quot;,&amp;quot;ClassId&amp;quot;:1073872969,&amp;quot;Properties&amp;quot;:[469775450,&amp;quot;heading 20&amp;quot;,201340122,&amp;quot;2&amp;quot;,134234082,&amp;quot;true&amp;quot;,134233614,&amp;quot;true&amp;quot;,469778129,&amp;quot;heading20&amp;quot;,335572020,&amp;quot;1&amp;quot;,134224900,&amp;quot;true&amp;quot;,335551500,&amp;quot;8870446&amp;quot;,268442635,&amp;quot;30&amp;quot;,335559739,&amp;quot;140&amp;quot;,335559738,&amp;quot;320&amp;quot;,335560102,&amp;quot;1&amp;quot;,469777841,&amp;quot;Segoe UI&amp;quot;,469777842,&amp;quot;Segoe UI&amp;quot;,469777843,&amp;quot;Segoe UI&amp;quot;,469777844,&amp;quot;Segoe UI&amp;quot;,469769226,&amp;quot;Segoe UI&amp;quot;]}"&gt;The main risks in 2026&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Some of these are the risks we flagged last year. Some have shifted, and authorization in particular has been reworked. Each entry below covers the same three things: what the risk is, what happens if it is exploited, and the controls that help most.&lt;/SPAN&gt;&lt;/P&gt;
&lt;img&gt;Figure 1: MCP Security Overview&lt;/img&gt;
&lt;H5&gt;&lt;STRONG&gt;1. Prompt injection and tool poisoning&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;What it is:&lt;/STRONG&gt; An agent treats everything in its context as trustworthy: tool descriptions, parameter schemas, and the data tools return. Anyone who can plant instructions in any of those can steer the agent. Tool poisoning is the sharp edge, malicious instructions hidden in a tool's description or schema that the model reads and the user usually does not.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;What could happen:&lt;/STRONG&gt; The agent follows the attacker's instructions instead of the user's. It might exfiltrate data through a tool call that looks legitimate, call the wrong tool, or take an action nobody approved.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:120,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Controls:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; Treat tool descriptions and outputs as untrusted input, and inspect the full schema before you approve a server. Put the tool list through a human approval step, and show the full tool call rather than a friendly summary. Keep sensitive servers isolated from general-purpose ones so a poisoned tool cannot reach across without further safeguards.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 30"&gt;2. Authorization and the confused deputy&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;What it is:&lt;/STRONG&gt; This is where the protocol moved most. MCP servers are now treated as OAuth 2.0 resource servers, and the guidance has settled on OAuth 2.1, PKCE, and tokens bound to a specific audience. The risk it targets is the confused deputy: a server acting with its own broad privileges on behalf of a user who does not have them, or a proxy that can be tricked into handing an attacker a valid authorization code.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;What could happen:&lt;/STRONG&gt; An attacker uses the server's privileges to reach data or actions the user was never entitled to, sometimes without the user approving anything.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Controls:&lt;/STRONG&gt; Adopt the current authorization model: OAuth 2.1 with PKCE, per-client consent, strict redirect-URI matching, and audience-bound tokens, so a token issued for one server cannot be replayed against another. Put an identity-aware gateway in front of every server and reject any call that does not carry a valid, audience-bound token&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/azure/api-management/validate-azure-ad-token-policy" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Azure API Management can validate Microsoft Entra tokens&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; and check issuer, audience, and expiry before the request reaches a tool.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;Figure 2: Confused Deputy Problem&lt;/img&gt;
&lt;H5&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 30"&gt;3. Over-broad access and credential aggregation&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;What it is:&lt;/STRONG&gt; A single MCP server often holds credentials for several systems at once, and asks for wider scopes than it needs, such as full mailbox access where read-only would do.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:120,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;What could happen:&lt;/STRONG&gt; One compromised server, or one leaked token, becomes a breach path of every system it touches. Wide scope means a wide blast radius.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Controls:&lt;/STRONG&gt; Apply least privilege, per resource: scoped, narrow OAuth scopes over wildcards; short-lived tokens over long-lived secrets. Give every agent an identity you can govern, like&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/entra/agent-id/what-is-microsoft-entra-agent-id" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Entra Agent ID&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; so you can apply policy to a whole class of agents or shut them down in one operation.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;4. Supply chain and rug pulls&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;What it is:&lt;/STRONG&gt; An MCP server is never just the server. It is the server, its dependencies, and the infrastructure it runs on, and each of those is a way in. A typo squatted package, a compromised dependency, or a change of ownership behind the same URL can all turn a trusted server hostile. Also, known as a 'rug pull' attack where a server behaves while it is being reviewed, earns approval, then changes once agents and workflows already depend on it.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:120,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;What could happen:&lt;/STRONG&gt; The server you approved is no longer the server you run. An ordinary tool call starts leaking its arguments, rewriting a response, or exfiltrating a token, and nothing about the request looks different from the thousands before it.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Controls:&lt;/STRONG&gt; Approval cannot be a one-time event. Build a &lt;A href="https://www.microsoft.com/en-us/securityengineering/sdl/practices/secure-by-design" target="_blank"&gt;Secure By Design&lt;/A&gt; Registry and register every server in a design-time catalog so you have a known-good baseline, pin tool definitions and alert on drift so you have a tripwire for rug pulls, and route everything through a gateway that re-checks identity and policy on every call.&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/azure/api-center/overview" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Azure API Center&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; inventories your APIs and MCP servers, and the &lt;/SPAN&gt;&lt;A href="https://microsoft.github.io/mcp-azure-security-guide/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;OWASP MCP Top 10 mapped to Azure controls&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; lines the risks up against what you already run.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-ccp-border-bottom="0.6666666666666666px solid #c9c9c9" data-ccp-padding-bottom="10.666666666666666px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;Figure 3: Supply Chain- Rug Pull. The approved dependency remains trusted even after ownership, version, or behavior changes.&lt;/img&gt;
&lt;DIV class="lia-align-left"&gt;
&lt;H5 data-ccp-border-top="0.6666666666666666px solid #c9c9c9" data-ccp-padding-top="10.666666666666666px"&gt;&lt;STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30); text-align: left;"&gt;5. Shadow MCP&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;What it is:&lt;/STRONG&gt; This is shadow IT for the AI era. A developer stands up a server to unblock a demo or get some work done quickly, a team wires an agent to whatever endpoint is handy, and nobody registers or verifies it.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;What could happen:&lt;/STRONG&gt; &amp;nbsp;You cannot govern, patch, or revoke what you cannot see, and ungoverned servers are where supply chain problems tend to hide.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Controls:&lt;/STRONG&gt; Start with visibility, of what exists, and a runtime gateway that everything routes through. The&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/entra/global-secure-access/how-to-view-model-context-protocol-logging" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;GSA AI Gateway&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;helps you surface the unregistered, shadow servers you&amp;nbsp;didn't&amp;nbsp;know were running.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;6. Command injection and sandbox escape&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;What it is:&lt;/STRONG&gt; Many MCP servers run locally and talk over standard input/output, spawning subprocesses and touching the file system. If a server passes unsanitized input into a shell or a file path, you have command injection or path traversal, and that has been one of the largest classes of MCP vulnerabilities reported this year.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;What could happen:&lt;/STRONG&gt; Arbitrary code runs on the host, or a server reaches files and credentials well outside what it should, in the worst cases with no user approval at all.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Controls:&lt;/STRONG&gt; Sandbox local servers in containers with only the file-system and network access they need, and block outbound traffic by default. Validate and sanitize every input and output, and never pass raw shell commands or unsanitized paths. Keep servers and SDKs patched, because this class of bug is being fixed in the field constantly.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 20" data-ccp-parastyle-defn="{&amp;quot;ObjectId&amp;quot;:&amp;quot;741782aa-652f-563c-bdc7-8d2b1b3f555d|1&amp;quot;,&amp;quot;ClassId&amp;quot;:1073872969,&amp;quot;Properties&amp;quot;:[469775450,&amp;quot;heading 20&amp;quot;,201340122,&amp;quot;2&amp;quot;,134234082,&amp;quot;true&amp;quot;,134233614,&amp;quot;true&amp;quot;,469778129,&amp;quot;heading20&amp;quot;,335572020,&amp;quot;1&amp;quot;,134224900,&amp;quot;true&amp;quot;,335551500,&amp;quot;8870446&amp;quot;,268442635,&amp;quot;30&amp;quot;,335559739,&amp;quot;140&amp;quot;,335559738,&amp;quot;320&amp;quot;,335560102,&amp;quot;1&amp;quot;,469777841,&amp;quot;Segoe UI&amp;quot;,469777842,&amp;quot;Segoe UI&amp;quot;,469777843,&amp;quot;Segoe UI&amp;quot;,469777844,&amp;quot;Segoe UI&amp;quot;,469769226,&amp;quot;Segoe UI&amp;quot;]}"&gt;Wrapping up&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:320,&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;MCP has not changed what good security looks like, only where you need to apply it. The risks that matter most now sit at the supply chain, in identity, and in servers nobody verified, and the controls that address them are ones you already know: strong identity, least privilege, a gateway in front of every server, sandboxing for local servers, and an alert when an approved tool changes. The spec continues to keep improving, but it still leaves the security decisions to you.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;If you would like to help improve the protocol, you can contribute to the specification&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://github.com/modelcontextprotocol/modelcontextprotocol/issues" target="_blank"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;here&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;In the next part, we'll get practical: a hands-on guide to implementing these controls in depth, with the patterns and configurations you can put to work.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;With thanks to &lt;a href="javascript:void(0)" data-lia-user-mentions="" data-lia-user-uid="538161" data-lia-user-login="Sarah_Young" class="lia-mention lia-mention-user"&gt;Sarah_Young​&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;for their inputs and collaboration on this post.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2026 16:43:45 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/the-state-of-mcp-security-in-2026/ba-p/4531327</guid>
      <dc:creator>JiteshThakur</dc:creator>
      <dc:date>2026-06-30T16:43:45Z</dc:date>
    </item>
    <item>
      <title>Security Community Spotlight: Sathish Veerapandian</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/security-community-spotlight-sathish-veerapandian/ba-p/4530697</link>
      <description>&lt;P&gt;&lt;SPAN class="lia-text-color-21"&gt;Meet Sathish Veerapandian: security architect, community collaborator, published author, and cycling enthusiast with a knack for turning real-world customer challenges into product-shaping feedback. From influencing phishing-resistant authentication and malware scanning improvements to helping organizations navigate Microsoft Purview, AI governance, and hybrid work, Sathish brings the best kind of energy to the Microsoft Security Community: curious, practical, generous, and always ready to help others move forward.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;&lt;SPAN class="lia-text-color-21"&gt;What do you find most rewarding about being a member of the Microsoft Security Community?&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;I find it most rewarding to be part of a community where knowledge sharing directly contributes to stronger, real world security outcomes. The Microsoft Security Community brings together practitioners, MVPs, engineers, and product teams, creating a space where collaboration leads to practical solutions, continuous learning, and meaningful impact. Being able to share experiences, learn from others, and help shape the direction of Microsoft Security technologies is what makes this community truly valuable to me.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;I have tested and provided feedback on a wide range of products via the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://aka.ms/SpotlightSecAdvisors" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Security Advisors&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; program. Some examples include extending FIDO support for on-premises environments; improving Microsoft Defender for Storage malware scanning with Sentinel integration, cost estimation, delta scanning, and scheduled scans; streamlining Microsoft Purview DSPM for AI onboarding and Insider Risk visibility; and strengthening Predictive Shielding by turning risk insights into preventive Conditional Access controls.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Overall, these examples reflect how I collaborate:&amp;nbsp;identifying&amp;nbsp;real-world gaps during implementation and operations, translating them into clear product feedback, and contributing in ways that help Microsoft engineering and the broader community.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Could you share something&amp;nbsp;you’re&amp;nbsp;proud of or a project&amp;nbsp;you’ve&amp;nbsp;completed?&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;One project I’m particularly proud of is co-authoring the book&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Reimagine Remote Working with Microsoft Teams&lt;/SPAN&gt;&lt;/EM&gt;&lt;SPAN data-contrast="auto"&gt; with my community colleagues during the COVID pandemic. At that time, we saw a significant increase in questions from organizations on how to effectively utilize Microsoft Teams to enable efficient and productive remote work. Recognizing this need, we took the initiative to bring together our collective experience and authored the book as a team. Our main goal was to help organizations improve their collaboration. We came together as a team and shared our real-world experience. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:1,&amp;quot;335551620&amp;quot;:1,&amp;quot;335557856&amp;quot;:16777215,&amp;quot;335559685&amp;quot;:0,&amp;quot;335559737&amp;quot;:0,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Authoring this book also motivated my colleagues to become more interested in the Microsoft MVP Program and contributing to the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-security" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Tech Community forums&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;which helped a lot of people.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:1,&amp;quot;335551620&amp;quot;:1,&amp;quot;335557856&amp;quot;:16777215,&amp;quot;335559685&amp;quot;:0,&amp;quot;335559737&amp;quot;:0,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.packtpub.com/en-us/product/reimagine-remote-working-with-microsoft-teams-9781801811019" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Reimagine Remote Working with Microsoft Teams&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;is&amp;nbsp;available for public purchase and has been used by IT professionals, team leaders, and organizations looking to strengthen their hybrid&amp;nbsp;work strategy. A copy of the book&amp;nbsp;was&amp;nbsp;also archived in the Microsoft Corporate Library in Redmond, which is a personal milestone and an honor as an MVP.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:1,&amp;quot;335551620&amp;quot;:1,&amp;quot;335557856&amp;quot;:16777215,&amp;quot;335559685&amp;quot;:0,&amp;quot;335559737&amp;quot;:0,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5&gt;&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;What does your ideal community experience look like?&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;My ideal community experience continues to be one where practitioners, MVPs, and product teams collaborate closely to share real- world insights, solve challenges together, and help shape the future of Microsoft Security. &lt;STRONG&gt;I value environments where knowledge flows openly, where hands- on learning is encouraged, and where community members can contribute through content, discussions, and events that have a meaningful impact on others.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5&gt;&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;How long have you been working with Microsoft Security Products?&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;My Microsoft Security journey began over a decade ago in the on- premises era, working with technologies such as Forefront, TMG, Exchange security, and Antispam solutions. Those early years gave me a deep foundation in securing Microsoft workloads at the infrastructure and perimeter level, long before cloud adoption became mainstream.&amp;nbsp;&amp;nbsp;As the industry shifted, I transitioned into the cloud security space, embracing Microsoft 365 and Azure security capabilities. This evolution led me to focus on data protection, identity, and modern collaboration security, eventually specializing in Microsoft Purview, Copilot DLP, Insider Risk, and Information Protection.&lt;/SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;What features or products have provided the most impact?&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The Microsoft Security products that have had the most impact&amp;nbsp;for&amp;nbsp;me are the ones that&lt;STRONG&gt; directly improve security outcomes while staying deployable at scale&lt;/STRONG&gt;. The most impactful areas have been:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;1)&amp;nbsp; &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/architecture/auth-passwordless" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Entra ID – FIDO / Passwordless&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;(including on-prem considerations)&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Impact:&lt;/STRONG&gt; Enabling phishing-resistant authentication in a way that works for real enterprise environments (including hybrid setups).&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Essential capability:&lt;/STRONG&gt; FIDO/passwordless&amp;nbsp;support that can extend into on-prem realities, so customers are not blocked by architecture constraints.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;2)&amp;nbsp; &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/defender-for-cloud/on-demand-malware-scanning" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Defender for Storage – On-demand Malware Scanning&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Impact: &lt;/STRONG&gt;Improving security assurance for storage data, especially during high-risk operational events like large-scale migrations.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN data-contrast="auto"&gt;Essential capabilities: More effective delta scanning and the ability to run scheduled or on-demand scans aligned to migration windows and operational needs.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;3) &amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/purview/dspm-for-ai?tabs=m365" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Purview – DSPM for AI&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Impact: &lt;/STRONG&gt;Supporting governance and security posture for AI-related data usage, with an experience that enables customers to adopt quickly.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Essential capability:&lt;/STRONG&gt; A smoother enablement/onboarding experience so the subscription/capability can be activated reliably and used without friction.&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;4)&amp;nbsp; &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-xdr/shield-predict-threats-manage" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Predictive Shielding + Conditional Access (preventive controls)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Impact: &lt;/STRONG&gt;Turning risk insight into preventive action by applying controls through Conditional Access.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Essential capability:&lt;/STRONG&gt; Preventive enforcement that helps stop risky access/behavior earlier rather than only&amp;nbsp;detecting after&amp;nbsp;the fact.&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5 class=""&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;What advice do you have for others who would like to get involved in the Microsoft Community?&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P class=""&gt;&lt;SPAN data-contrast="auto"&gt;My advice is to simply start by sharing what you know. You don’t need to be an expert to contribute just be willing to help others, document your learnings, and stay curious. The Microsoft Community grows through collaboration, and even small contributions like answering questions, writing a short post, or sharing a demo can make a real impact. Engage consistently, connect with others who share your interests, and focus on adding value. Over time, those small steps build into meaningful involvement, strong relationships, and opportunities you never expected.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559685&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Tell us more about you, including where to find you!&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559685&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Outside of technology,&amp;nbsp;I’m&amp;nbsp;very passionate&amp;nbsp;about cycling. I run a local cycling community in Almere called the Almere Cycling Club, where we focus on improving the health and fitness of people through regular group rides and community activities.&amp;nbsp;It’s&amp;nbsp;something I&amp;nbsp;truly enjoy&amp;nbsp;because it brings people together, encourages a healthier lifestyle, and creates a positive impact&amp;nbsp;in&amp;nbsp;the place where I live.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;Here’s where you can connect with me online:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559685&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{&amp;quot;134224900&amp;quot;:true,&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;YouTube: &lt;/SPAN&gt;&lt;A href="https://www.youtube.com/@devopsinfo391/video" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;DevOpsInfo 391&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{&amp;quot;134224900&amp;quot;:true,&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;LinkedIn:&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.linkedin.com/in/sathish-veerapandian-526a4226/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Sashtish Veerapandian&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{&amp;quot;134224900&amp;quot;:true,&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Website: https://ezcloudinfo.com&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{&amp;quot;134224900&amp;quot;:true,&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="4" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Purview Community Lightning Talk:&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://youtu.be/-SWX3R2ECPA?si=hUDnf0_-lWZOegoP" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;From Zero to First Signal: Insider Risk Management Prerequisites That Actually Matter&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-21"&gt;Sathish’s story is a reminder that strong communities are built by people who show up with curiosity, generosity, and a willingness to turn real-world experience into shared progress. Whether&amp;nbsp;he’s&amp;nbsp;helping shape Microsoft Security products, guiding organizations through modern security challenges, or bringing people together through cycling, Sathish leads with purpose and impact-&amp;nbsp;and the Microsoft Security Community is stronger because of it.&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;HR style="border: none; border-top: 2px solid #bfbfbf; margin: 20px 0;" /&gt;
&lt;H4&gt;Learn and Engage with the Microsoft Security Community&amp;nbsp;&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;Visit the&lt;A class="lia-external-url" href="https://aka.ms/securitycommunity" target="_blank" rel="noopener"&gt; Microsoft Security Community&lt;/A&gt; home.&lt;/LI&gt;
&lt;LI&gt;Log in and follow this &lt;A href="https://aka.ms/bpblog" target="_blank" rel="noopener"&gt;Microsoft Security Community Blog&lt;/A&gt;.&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;Follow = Click the heart in the upper right when you're logged in 🤍&lt;A href="https://aka.ms/MVPMDOvideo" target="_blank" rel="noopener"&gt;.&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI&gt;Subscribe to the &lt;A class="lia-external-url" href="https://forms.office.com/Pages/ResponsePage.aspx?id=v4j5cvGGr0GRqy180BHbRykv0w7KoL5Jj4AzbOLp7XxUQzBNR1lWOFFNR1lHTEhaQUlGTzZIUzY1RC4u" target="_blank" rel="noopener"&gt;Security Community Email List&lt;/A&gt;&amp;nbsp;and be notified of upcoming events, product feedback surveys, and more.&lt;/LI&gt;
&lt;LI&gt;Get early access to Microsoft Security products and provide feedback to engineers by joining the&amp;nbsp;&lt;A href="https://aka.ms/bpadvisors" target="_blank" rel="noopener"&gt;Microsoft Security Advisors.&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Join the &lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://aka.ms/pbseclinkedin" target="_blank" rel="noopener"&gt;Microsoft Security Community LinkedIn Group&amp;nbsp;&lt;/A&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;and follow the&amp;nbsp;&lt;/SPAN&gt;&lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://aka.ms/pbentralinkedin" target="_blank" rel="noopener"&gt;Microsoft Entra Community on LinkedIn&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 25 Jun 2026 15:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/security-community-spotlight-sathish-veerapandian/ba-p/4530697</guid>
      <dc:creator>RenWoods</dc:creator>
      <dc:date>2026-06-25T15:00:00Z</dc:date>
    </item>
    <item>
      <title>How Karambit.AI and Microsoft Bring Software Authenticity to 14 Billion Files Per Month</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/how-karambit-ai-and-microsoft-bring-software-authenticity-to-14/ba-p/4528606</link>
      <description>&lt;H3&gt;&lt;STRONG&gt;The Problem: Static Analysis Without Context&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;Traditional static analysis treats every file as an island. Scan a binary, match against known signatures, flag what you recognize. The approach is well-understood and increasingly insufficient against modern threats.&lt;/P&gt;
&lt;P&gt;The fundamental limitation is the absence of &lt;STRONG&gt;context&lt;/STRONG&gt;. Without it, a packer is just a packer. A network call is just a network call. An obfuscation routine is just an obfuscation routine. Whether that behavior is normal or anomalous, whether it belongs in &lt;EM&gt;this&lt;/EM&gt; software, in &lt;EM&gt;this&lt;/EM&gt; ecosystem, performing &lt;EM&gt;this&lt;/EM&gt; function, is invisible to tools that evaluate files in isolation.&lt;/P&gt;
&lt;P&gt;Attackers exploit this gap. They hide malicious behavior inside legitimate software patterns, evolve their techniques between versions, and distribute intent across multiple components so that no single artifact triggers a detection in a context-free scan.&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Context-Aware Behavior Analysis&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;Context-aware analysis inverts the model. Instead of asking "is this file bad?" it asks: &lt;STRONG&gt;"is this file behaving the way it should, given everything we know about this ecosystem?"&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;This requires building and maintaining behavioral context across multiple dimensions:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Ecosystem-level behavioral baselines&lt;/STRONG&gt;: Understanding what behaviors are normal across the entire corpus and which should never appear. In a trusted software ecosystem, obfuscated or packed content is itself an anomaly worth enforcing policy against, regardless of whether the underlying payload is known-malicious.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Behavioral chains with low false-positive rates&lt;/STRONG&gt;: Individual API calls and instructions are ambiguous in isolation. Context-aware analysis identifies &lt;EM&gt;chains&lt;/EM&gt; of behaviors, sequences where data staging feeds into exfiltration, or where privilege escalation is followed by persistence mechanisms, that reveal intent with high confidence.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Cross-file and cross-instance correlation&lt;/STRONG&gt;: Behaviors observed in one file are evaluated against patterns seen across millions of other files and scan instances. Shared behavioral fingerprints reveal family relationships, evolutionary lineage, and coordinated campaigns that single-file analysis cannot surface.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Historical behavioral deltas&lt;/STRONG&gt;: What changed between version N and version N+1? New behaviors in an update, especially behaviors that don't correspond to documented changes, are flagged not because they match a signature, but because they deviate from the established behavioral profile.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The result: dramatically higher detection confidence, lower false-positive rates, and the ability to enforce behavioral policy at the ecosystem level.&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Case Study: Packer_Dictator, Behavioral Detection Under Adversary Adaptation&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;Adversaries must change their Tactics, Techniques, and Procedures (TTPs) over time. When a detection capability catches them, they adapt to evade it. This is expected behavior and it is precisely why &lt;STRONG&gt;general detections at the behavior level&lt;/STRONG&gt; are more durable than signature-based approaches. Behavioral patterns are fundamentally harder for adversaries to change without breaking their own tooling.&lt;/P&gt;
&lt;P&gt;The packer family tracked as &lt;STRONG&gt;packer_dictator&lt;/STRONG&gt; illustrates this dynamic clearly.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Initial Detection: Obvious Indicators&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Early variants of packer_dictator used conspicuous binary section names: authoritarian and politically-themed strings that made identification straightforward for anyone examining the PE headers. These were low-hanging indicators, but Karambit.AI's detection wasn't built on them. The system flagged these samples based on their &lt;STRONG&gt;behavioral profile&lt;/STRONG&gt;: the entropy characteristics of their packed sections, the structure of their unpacker initialization routines, and the other patterns used to unpack and execute hidden payloads.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Adversary Adaptation: Surface Changes, Persistent Behavior&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;As detections rolled out, the users of this packer had to adapted. The obvious section names disappeared, replaced by more benign alternatives: .upx0, standard "unpacked" section names, and other strings designed to blend in with legitimate software.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But the underlying behavior didn't change because it &lt;EM&gt;couldn't&lt;/EM&gt;, not without fundamentally rearchitecting the packer itself.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Entropy Analysis: Seeing Through Surface Changes&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Sliding-window entropy analysis reveals why surface-level changes are insufficient to evade behavioral detection. The entropy profiles of packer_dictator samples, even after the section name changes, maintain a characteristic signature:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;Figure 1: fancontroller.sys sample entropy sliding window&lt;/img&gt;&lt;img&gt;Figure 2: packer_dictator sample entropy sliding window&lt;/img&gt;
&lt;P&gt;Both profiles exhibit the same structural pattern: a low-entropy region corresponding to the unpacker stub, followed by a sharp transition to a high-entropy plateau spanning the packed payload. This entropy profile is indicative of hidden behaviors, content that has been deliberately obscured, though not necessarily malicious content on its own. The profile shape, transition points, and entropy floor/ceiling ratios form a behavioral fingerprint that persists across variants regardless of metadata changes.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Unpacker Initialization: Common Structure Enables Generalized Detection&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;At the disassembly level, packer_dictator variants share a common unpacker initialization sequence that enables generalized analysis across the family. Examining the entry-point code of two samples reveals the structural similarity:&lt;/P&gt;
&lt;img&gt;Figure 3: Sample 1 disassembly&lt;/img&gt;&lt;img&gt;Figure 4: Sample 2 disassembly&lt;/img&gt;
&lt;P&gt;Both samples exhibit a characteristic pattern:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Register preservation&lt;/STRONG&gt;: PUSH R9/PUSH R11 followed by PUSHFQ to save register state and flags before the unpack routine modifies them.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Immediate constant loading&lt;/STRONG&gt;: Large immediate values loaded into registers (MOV R9, 0x689f8c87eebd998c / MOV R11, 0x6592b8afc22b0736) that serve as decryption keys or XOR masks for the unpacking routine.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Arithmetic flag manipulation&lt;/STRONG&gt;: Sequences of TEST, NEG, OR, CMP, NOT, and SETNS instructions that compute control flow decisions based on the loaded constants — a form of opaque predicate that obscures the true branch target.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Stack-based payload resolution&lt;/STRONG&gt;: MOV instructions referencing [RSP + local_120] / [RSP + 0x8] with additional immediate constants written to the stack, setting up parameters for the decompression/decryption loop.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;The structural template is consistent even as the specific constants, register assignments, and opaque predicate formulations change between variants. This is what makes behavioral detection durable: the adversary can rotate constants and rename sections, but the &lt;EM&gt;computational structure&lt;/EM&gt; required to unpack the payload is constrained by the packer's architecture.&lt;/P&gt;
&lt;P&gt;By generalizing detection to this structural level, Karambit.AI's engine identifies new packer_dictator variants, and structurally related packer families, without requiring signature updates for each iteration. And this is only one example of the resilience of Karambit.AI’s resilience in the face of constantly advancing adversaries.&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;From Karambyte to Karambiner: Engineering for Billions&lt;/STRONG&gt;&lt;/H3&gt;
&lt;H4&gt;&lt;STRONG&gt;Karambyte: Building the Context&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Karambyte was Karambit.AI's original analysis engine, purpose-built for deep behavioral extraction from compiled binaries. Its core function was to extract behavioral context, disassemble control flow, API call chains, entropy profiles, packer identification, behavioral intent classification, and store it for comparison and reference.&lt;/P&gt;
&lt;P&gt;Karambyte proved the model. It demonstrated that context-aware behavioral analysis could identify threats that traditional static analysis missed, by building rich behavioral profiles and comparing them across software versions and file populations. The system extracted context and maintained it internally, enabling the cross-file and cross-version correlation that drove detections like packer_dictator.&lt;/P&gt;
&lt;P&gt;But Karambyte's architecture, extracting &lt;EM&gt;and&lt;/EM&gt; storing context within the same system, created a scaling constraint. As adoption grew and the target moved from hundreds of thousands to billions of files per month, the tight coupling between analysis and context storage became the bottleneck.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Karambiner: Externalizing Context for Scale&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Karambiner re-architected the relationship between analysis and context. Rather than each analysis instance maintaining its own behavioral context store, Karambiner &lt;STRONG&gt;externalized the context layer&lt;/STRONG&gt; into a dedicated reference that can then be customized for the specific organizational context.&lt;/P&gt;
&lt;P&gt;This separation enabled three critical capabilities at scale:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Horizontal analysis throughput&lt;/STRONG&gt;: Analysis scales independently of the context store. Adding processing capacity doesn't require replicating the full behavioral knowledge base.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Context enrichment&lt;/STRONG&gt;: Behavioral context extracted from collective scans can be used in the massively scalable analysis engine.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Ecosystem-wide policy enforcement&lt;/STRONG&gt;: With externalized behavioral context, the system can enforce policies across a large-scale ecosystem, such as blocking all obfuscated or packed content.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;The move from Karambyte to Karambiner was the architectural shift that made scanning of 14 billion files per month possible: a configurable depth of behavioral analysis, with context that scales to the size of the ecosystem rather than the capacity of individual analysis nodes.&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;The Result: Software Behavior Analysis in Microsoft's Pipeline&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;Today, Karambiner is integrated into Microsoft's operational pipeline for build/release and plays a critical role in performing context-aware behavioral analysis across billions of files monthly.&lt;/P&gt;
&lt;P&gt;The operational impact:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Ecosystem-level behavioral policy enforcement&lt;/STRONG&gt;: Obfuscated and packed content that has no legitimate reason to exist in the ecosystem is blocked by policy, informed by the scaled behavioral analysis.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Durable detection under adversary adaptation&lt;/STRONG&gt;: The packer_dictator lineage demonstrates that behavioral detection survives TTP changes that defeat signature-based approaches. Adversaries can change section names, rotate constants, and vary metadata, but the structural behaviors required to execute their payloads remain detectable.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Low false-positive rates at scale&lt;/STRONG&gt;: Because detection decisions are driven by behavioral understanding and optimizing for scale, the system maintains precision even at 14 billion files per month.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Understanding AI capabilities&lt;/STRONG&gt;: Behavior analysis can include understanding of where and how AI is used in an ecosystem.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Deep understanding of the software going to production:&lt;/STRONG&gt; Developers don't always know what components and behaviors make it to the production software, behavior analysis has allowed us to catch unexpected components developers didn’t realize were going to deployment.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;&lt;STRONG&gt;What's Next&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;The partnership between Karambit.AI and Microsoft demonstrates that context-aware behavior analysis operates on a massive scale in production. As software supply chain attacks grow more sophisticated and adversaries continue evolving their TTPs and the use of AI agents to develop code, the ability to understand &lt;EM&gt;what software actually does&lt;/EM&gt;, in context, across billions of files, is foundational infrastructure.&lt;/P&gt;
&lt;P&gt;Software authenticity isn't about checking a signature or trusting a certificate. It's about confirming that every binary does what it should, and nothing more.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Karambit.AI is the software authenticity platform, ensuring software does only what the developer intended — nothing more. Learn more at &lt;/EM&gt;&lt;A href="https://karambit.ai/" target="_blank" rel="noopener"&gt;&lt;EM&gt;karambit.ai&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt;.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2026 20:30:26 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/how-karambit-ai-and-microsoft-bring-software-authenticity-to-14/ba-p/4528606</guid>
      <dc:creator>AlecCheung</dc:creator>
      <dc:date>2026-06-24T20:30:26Z</dc:date>
    </item>
    <item>
      <title>Microsoft Leads a New Era of Software Supply Chain Transparency</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/microsoft-leads-a-new-era-of-software-supply-chain-transparency/ba-p/4528369</link>
      <description>&lt;P&gt;Today, Microsoft announces the general availability of Microsoft’s Signing Transparency (MST)&amp;nbsp;– a first-of-its-kind capability that brings unprecedented visibility and trust to our software supply chain. With this release, Microsoft is&amp;nbsp;leading the industry&amp;nbsp;by recording the build of critical cloud services into a publicly readable and verifiable&amp;nbsp;&lt;A href="https://datatracker.ietf.org/group/scitt/documents/" target="_blank" rel="noopener"&gt;SCITT&lt;/A&gt; standard (Supply Chain Integrity, Transparency, and Trust) &lt;SPAN data-teams="true"&gt;compliant blockchain ledger&lt;/SPAN&gt;. This means every production software build for in scope services like Azure Attestation and Azure Managed HSM (Hardware Security Module), Azure confidential ledger, Microsoft Signing Transparency itself (and others over time) – is now logged in an immutable, tamper-evident record. Only builds that are in the MST ledger are deployed to production; this gives customers confidence that the supply chain for these critical services can be audited at anytime.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Notably, the MST ledger is fully&amp;nbsp;&lt;A href="https://github.com/microsoft/scitt-ccf-ledger" target="_blank" rel="noopener"&gt;open source&lt;/A&gt;&amp;nbsp;and built to align with the emerging IETF&amp;nbsp;&lt;A href="https://datatracker.ietf.org/group/scitt/documents/" target="_blank" rel="noopener"&gt;SCITT&lt;/A&gt;&amp;nbsp;standard. By embracing SCITT’s principles and open protocols, Microsoft ensures that MST not only secures our own ecosystem but also contributes to a broader industry movement toward standardized supply chain transparency. The open-source MST ledger serves as a&amp;nbsp;verifiable trust anchor&amp;nbsp;that any organization or researcher can inspect, audit, or even integrate with their own tooling. MST itself meets the highest levels of transparency, backed by a tamper-proof confidential ledger, open-source, and&amp;nbsp;&lt;A href="https://www.ioactive.com/wp-content/uploads/2025/10/Microsoft-Signing-Transparency-Service-Security-Assessment-IOActive-Public-Facing-Report.pdf" target="_blank" rel="noopener"&gt;independently verified&lt;/A&gt;. Specifically,&amp;nbsp;we are&amp;nbsp;making the foundation of our trust model transparent and accessible to everyone – reinforcing that&amp;nbsp;trust must be earned through proof, not just promises.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This launch marks a major milestone in our commitment to&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/security/zero-trust/zero-trust-overview" target="_blank" rel="noopener"&gt;Zero Trust&lt;/A&gt;&amp;nbsp;principles, extending “never trust, always verify” all the way into the build itself. Building on a public preview introduced late last&amp;nbsp;year,&amp;nbsp;MST’s general availability delivers verifiable transparency at the software level. It transforms traditional code signing with an additive trust layer that is accessible via an open verification model. Every new software update is accompanied by a publicly auditable proof of integrity, enabling security teams to proactively confirm that each update is authentic and unaltered.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To help organizations get the most out of this capability,&amp;nbsp;we are&amp;nbsp;also introducing a free tool to explore the contents –&amp;nbsp;&lt;A class="lia-external-url" href="http://aka.ms/ledgerexplorer" target="_blank" rel="noopener"&gt;Ledger Explorer&amp;nbsp;&lt;/A&gt;– an offline tool that allows security teams to examine MST ledger entries, verify cryptographic proofs, and even&amp;nbsp;validate&amp;nbsp;the ledger’s integrity independently. This tool, combined with MST’s open design, ensures that&amp;nbsp;every Microsoft customer – and the broader community – can hold us accountable&amp;nbsp;in real time for the software we run on their behalf.&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Key Benefits of Microsoft’s Signing Transparency (MST)&lt;/STRONG&gt;&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Verified Code Integrity&lt;/STRONG&gt;&amp;nbsp;– Every software release is cryptographically logged in MST’s ledgers. This makes each build&amp;nbsp;&lt;STRONG&gt;tamper-evident and traceable&lt;/STRONG&gt;. If an attacker&amp;nbsp;attempts&amp;nbsp;to inject malicious code or sign an unauthorized update, it will be evident through the well-defined validation step built into the SCITT standard. Organizations gain the&amp;nbsp;assurance that&amp;nbsp;code&amp;nbsp;integrity can be independently confirmed&amp;nbsp;at any time.&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Independent Verification &amp;amp; Zero Trust&lt;/STRONG&gt;&amp;nbsp;– MST enables customers and auditors to&amp;nbsp;verify software authenticity on their own, without having to solely rely on vendor attestations. For each update, Microsoft provides a transparency “receipt” (proof of logging) that you can use to prove the update was officially published and unaltered. This fosters a&amp;nbsp;&lt;EM&gt;“don’t just trust, verify”&lt;/EM&gt;&amp;nbsp;approach, empowering security teams to double-check everything running in their environment aligns with what Microsoft intended.&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Audit-Trail &amp;amp; Compliance&lt;/STRONG&gt;&amp;nbsp;– The transparency ledger creates a&amp;nbsp;permanent, auditable timeline&amp;nbsp;of code deployments. Every entry is a record of&amp;nbsp;&lt;EM&gt;what&lt;/EM&gt;&amp;nbsp;was released and&amp;nbsp;&lt;EM&gt;when&lt;/EM&gt;, backed by cryptographic&amp;nbsp;proofs. This simplifies compliance reporting and accelerates forensic analysis.&amp;nbsp;In the event of&amp;nbsp;an incident, you can quickly audit the ledger to see if any unexpected code was introduced. For highly regulated industries,&amp;nbsp;MST offers concrete evidence of software integrity&amp;nbsp;and policy compliance over time.&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Leadership &amp;amp; Open Standards&lt;/STRONG&gt;&amp;nbsp;– We are&amp;nbsp;delivering real transparency now, encouraging a future where all critical software is released with verifiable integrity. MST’s&amp;nbsp;open source&amp;nbsp;implementation and&amp;nbsp;SCITT-compliant&amp;nbsp;design exemplify our commitment to openness and collaboration. We believe widespread adoption of these standards will&amp;nbsp;strengthen supply chain security for everyone, making trust verification a universal practice.&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;&lt;STRONG&gt;Next Steps&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;Microsoft’s Signing Transparency is more than a new security feature and shapes the advances in trust technology. As threats grow more sophisticated, we must evolve the way we assure our customers about the software they depend on. With MST now generally available, we are leading by example: proving that it is possible to open up the traditionally opaque process of software deployment and turn it into a source of strength and trust, i.e., empowering each person with verifiable transparency.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We invite the industry to join us on this journey and get started by&amp;nbsp;&lt;A href="https://aka.ms/mst-docs" target="_blank" rel="noopener"&gt;reading the documentation&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A href="https://aka.ms/ledgerexplorer" target="_blank" rel="noopener"&gt;exploring Ledger Explorer today&lt;/A&gt;! Together, by embracing transparency and open standards, we can turn “trust but verify” from a slogan into an everyday reality for digital infrastructure.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jun 2026 18:01:03 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/microsoft-leads-a-new-era-of-software-supply-chain-transparency/ba-p/4528369</guid>
      <dc:creator>ShubhraS</dc:creator>
      <dc:date>2026-06-22T18:01:03Z</dc:date>
    </item>
    <item>
      <title>New Exchange Online Mailbox Auditing Signal: Visibility into IPM to Non-IPM Copy Activity</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/new-exchange-online-mailbox-auditing-signal-visibility-into-ipm/ba-p/4526914</link>
      <description>&lt;H4&gt;&lt;STRONG&gt;Background: IPM vs. Non-IPM Subtree&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Every Exchange Online mailbox is organized into two parts:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;IPM subtree (Interpersonal Message subtree)&lt;/STRONG&gt;&amp;nbsp;— the visible, user-facing part of a mailbox, designed for messages exchanged between human recipients. This includes Inbox, Sent Items, Deleted Items, Calendar, Contacts, Tasks, Notes, and any custom folders a user creates. Exchange mailbox auditing has always focused on activity within this area.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Non-IPM subtree&lt;/STRONG&gt;&amp;nbsp;— a hidden folder structure used by Exchange and Microsoft services for system-level storage, such as the Recoverable Items folder. Users cannot see or directly interact with this area from most mail clients (like Outlook).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;For more details, see&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/office/client-developer/outlook/mapi/ipm-subtree" target="_blank" rel="noopener"&gt;IPM Subtree | Microsoft Learn&lt;/A&gt;.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;The Audit Gap This Addresses&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;A known audit evasion technique involves copying mail items from a user's visible IPM folders into a hidden folder in the non-IPM subtree and then accessing the data from there for exfiltration. This technique has been observed in security investigations against Exchange Online.&lt;/P&gt;
&lt;P&gt;This worked as an evasion method because:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Copy operations are not enabled for auditing by default&lt;/LI&gt;
&lt;LI&gt;Activity in the non-IPM subtree was not audited&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;By staging data in the non-IPM subtree before exfiltration, this activity previously left no trace in the mailbox audit log.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;What's New&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Exchange Online now logs a&amp;nbsp;MailItemsAccessed&amp;nbsp;event whenever a mail item is copied from the IPM subtree to the non-IPM subtree.&lt;/P&gt;
&lt;P&gt;A new&amp;nbsp;AccessType&amp;nbsp;value —&amp;nbsp;CopyFromIPM&amp;nbsp;— has been introduced to distinguish these records from existing&amp;nbsp; MailItemsAccessed&amp;nbsp;events, making them straightforward to query for:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 45%; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;AccessType&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Description&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Bind&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Existing — individual item access&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Sync&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Existing — bulk sync access&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;CopyFromIPM&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;New&amp;nbsp;- &amp;nbsp;an item in the IPM subtree was accessed to copy its content to the non-IPM subtree&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 39.7665%" /&gt;&lt;col style="width: 60.1648%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;How to Query for These Records&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Use the following PowerShell command to search for&amp;nbsp;CopyFromIPM&amp;nbsp;activity in your tenant:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Search-UnifiedAuditLog -StartDate 4/1/2026 -EndDate 4/15/2026 -FreeText "CopyFromIPM"&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H4&gt;&lt;STRONG&gt;Understanding the CopyFromIPM Audit Record&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;When a CopyFromIPM event is logged, it is recorded as a MailItemsAccessed operation in the Unified Audit Log. Each record captures an individual mail item that was copied from the IPM subtree to the non-IPM subtree during the operation. When an entire folder is copied, the ItemId that is captured is the Id of the folder; individual records are not captured for each item in the folder.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Feedback&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;If you have any feedback about this change, you can reach out to &lt;A href="mailto:exchangemailboxaudit-support@microsoft.com" target="_blank" rel="noopener"&gt;ExchangeMailboxAudit-Support&lt;/A&gt; group. We are always happy to hear from you and assist in any way we can.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2026 15:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/new-exchange-online-mailbox-auditing-signal-visibility-into-ipm/ba-p/4526914</guid>
      <dc:creator>NehaArora1</dc:creator>
      <dc:date>2026-06-10T15:00:00Z</dc:date>
    </item>
    <item>
      <title>Level up your Azure Network Security Skills with our Upcoming Webinar Series</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/level-up-your-azure-network-security-skills-with-our-upcoming/ba-p/4525584</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;As network and application-layer threats continue to evolve, security and infrastructure teams need more than product knowledge. They need practical, scenario-driven guidance they can apply to real workloads. To support that, the Azure Network Security team is hosting a series of upcoming technical webinars covering the capabilities our customers rely on every day:&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-drs?tabs=drs21" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Azure Web Application Firewall (WAF),&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt; &lt;A href="https://learn.microsoft.com/en-us/azure/firewall/firewall-copilot" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Azure Firewall,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt; &lt;A href="https://learn.microsoft.com/en-us/azure/ddos-protection/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Azure DDoS Protection&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; and &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/bastion/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Azure Bastion&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Each session is focused on demos, the latest enhancements, and the design and operational decisions you face when securing modern Azure environments. Whether you are protecting customer-facing web applications, hardening east-west and egress traffic, or securing remote administrative access at scale, there is a session in this lineup for you.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;These webinars are ideal for Security Architects and Engineers, Network and Infrastructure teams, SOC Analysts, Cloud Platform Owners, Partner Technical Consultants, and any practitioner responsible for the security posture of workloads running on Azure.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Below is the schedule of the upcoming live deliveries.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Upcoming Events &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H3&gt;
&lt;H5&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Azure WAF Layer 7 DDoS defense in practice&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Date and time: Thursday, June 18, 2026, at 8am PST&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://securitycommunity.microsoft.com/VirtualEvents/Webinar-Details/?id=1776dc8f-c353-f111-bec7-000d3a58d82a" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;View event details and join&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;As web applications become primary targets for sophisticated application-layer attacks, Azure Web Application Firewall continues to evolve to meet the needs of modern application security teams facing volumetric and targeted application-layer threats. In this webinar, we will explore how Azure WAF enables a layered, adaptive approach to application-layer DDoS mitigation, helping organizations detect and block malicious request patterns through intelligent inspection, control traffic flow to prevent resource exhaustion from abusive sources, progressively challenge suspicious clients to verify legitimacy without disrupting real users, and combine multiple defense mechanisms into a cohesive mitigation strategy that adapts to evolving attack techniques. Whether you're securing customer-facing web apps or business-critical services, this session will equip you with practical approaches to building resilient application-layer defenses on Azure.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Azure Firewall IDPS Detections and Sentinel Integration&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Date and time: Thursday, July 9, 2026, at 8am PST&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://securitycommunity.microsoft.com/VirtualEvents/Webinar-Details/?id=125d3fb9-c653-f111-bec6-000d3a5bf7ee" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;View event details and join&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;As network threats grow in complexity, organizations need visibility that extends beyond simple traffic filtering into intelligent detection and unified investigation workflows. Azure Firewall's Intrusion Detection and Prevention capabilities continue to evolve to meet the needs of modern security operations teams facing advanced lateral movement, exploitation attempts, and command-and-control activity. In this webinar, we will explore how Azure Firewall identifies malicious network patterns in real time, how detection signals flow seamlessly into Microsoft Sentinel to enrich the broader security narrative, and how security teams can correlate firewall intelligence with other data sources to accelerate threat hunting, streamline incident response, and build a more connected and actionable view of their network security posture.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;What's New in Azure Bastion&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Date and time: Thursday, July 23, 2026, at 8am PST&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://securitycommunity.microsoft.com/VirtualEvents/Webinar-Details/?id=3a4e6d94-ca53-f111-bec6-6045bd06ff19" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;View event details and join&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Secure remote access to cloud workloads remains a critical requirement as organizations scale their Azure environments and adapt to evolving operational demands. Azure Bastion continues to evolve to meet the needs of modern infrastructure teams seeking seamless, browser-based connectivity without exposing virtual machines to the public internet. In this webinar, we'll explore the latest enhancements to Azure Bastion covering new capabilities that improve connectivity options, streamline the administrative experience, expand protocol and session support, and strengthen the overall security posture of remote access workflows. Whether you're managing a handful of VMs or operating at enterprise scale, this session will bring you up to speed on what's new and how these improvements can simplify and secure your day-to-day operations.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;What's New in Azure Firewall&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Date and time: Thursday, August 6, 2026, at 8am PST&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://securitycommunity.microsoft.com/VirtualEvents/Webinar-Details/?id=96d39a8e-bc5e-f111-a826-6045bd023cfc" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;View event details and join&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;As network architectures grow more distributed and threat landscapes more dynamic, organizations need a cloud-native firewall that keeps pace with both modern workload patterns and adversary techniques. Azure Firewall continues to evolve to meet the needs of network and security teams managing hybrid environments, multi-region deployments, and increasingly complex east-west and north-south traffic flows. In this webinar, we will explore the latest enhancements to Azure Firewall covering new policy and rule management capabilities, improvements that expand protocol and traffic inspection coverage, and deeper integrations across the Azure security ecosystem to streamline operations. Whether you are standardizing perimeter protection across a global Azure footprint or modernizing segmentation for business-critical workloads, this session will bring you up to speed on what is new and how these improvements can simplify and strengthen your day-to-day network security operations.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;What's New in Azure Web Application Firewall&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Date and time: Thursday, August 27, 2026, at 8am PST&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://securitycommunity.microsoft.com/VirtualEvents/Webinar-Details/?id=541a5162-4655-f111-bec7-000d3a5ad9f6" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;View event details and join&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Web applications remain primary entry points for attackers, and organizations need a Web Application Firewall that adapts as quickly as the threats targeting their workloads. Azure Web Application Firewall continues to evolve to meet the needs of modern application security teams defending against an expanding mix of OWASP-class attacks, automated abuse, and business logic threats across diverse hosting models. In this webinar, we will explore the latest enhancements to Azure WAF. We will cover new detection and rule capabilities that improve protection accuracy, tuning and exclusion improvements that reduce false positives without weakening coverage, and expanded visibility and analytics that accelerate investigation. Whether you are securing customer-facing web apps or managing WAF policies at scale, this session will bring you up to speed on what's new and how these improvements can simplify and strengthen your application protection strategy&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Past Recordings:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;View additional past webinars from &lt;/SPAN&gt;&lt;A href="https://www.youtube.com/playlist?list=PLmAptfqzxVEVh3-ecmlrdQJ3XAay97KNb" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Azure Network Security &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;on Microsoft Security Community&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt; YouTube&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;Stay connected with the Azure Network Security community&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Influence product feedback and join the &lt;/SPAN&gt;&lt;A href="https://www.youtube.com/playlist?list=PLmAptfqzxVEVh3-ecmlrdQJ3XAay97KNb" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Threat Protection Advisors Program&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Stay up-to-date and fo&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;llow the &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/category/azure-network-security/blog/azurenetworksecurityblog" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Azure Network Security Blog | Microsoft Community Hub&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Engage with &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;p&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;eers&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;, &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ask and answer questions &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;in the &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/category/azure-network-security/discussions/azurenetworksecurity" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Azure Network Security discussion board&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;---&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Learn and Engage with the Microsoft Security Community &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="o" data-font="Courier New" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Courier New&amp;quot;,&amp;quot;469769242&amp;quot;:[9675],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;o&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Log in and follow this &lt;/SPAN&gt;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/category/microsoft-security-product/blog/microsoft-security-blog?action=follow" target="_blank" rel="noopener" data-lia-auto-title="Microsoft Security Community Blog" data-lia-auto-title-active="0"&gt;Microsoft Security Community Blog&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; and post/ interact in the &lt;/SPAN&gt;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-category" href="https://techcommunity.microsoft.com/category/microsoft-security?action=follow" target="_blank" rel="noopener" data-lia-auto-title="Microsoft Security Community discussion spaces" data-lia-auto-title-active="0"&gt;Microsoft Security Community discussion spaces&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="o" data-font="Courier New" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Courier New&amp;quot;,&amp;quot;469769242&amp;quot;:[9675],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;o&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="2"&gt;&lt;SPAN style="font-style: var(--lia-blog-font-style); font-family: var(--lia-blog-font-family); font-size: var(--lia-bs-font-size-base);" data-contrast="auto"&gt;Follow = Click the heart in the upper right when you're logged in&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="font-style: var(--lia-blog-font-style); font-family: var(--lia-blog-font-family); font-size: var(--lia-bs-font-size-base);" data-contrast="auto"&gt;🤍&lt;/SPAN&gt;&lt;SPAN style="font-style: var(--lia-blog-font-style); font-family: var(--lia-blog-font-family); font-size: var(--lia-bs-font-size-base);" data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="o" data-font="Courier New" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Courier New&amp;quot;,&amp;quot;469769242&amp;quot;:[9675],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;o&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="3" data-aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Join the &lt;/SPAN&gt;&lt;A href="https://aka.ms/AAycdmn" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Security Community&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; and be notified of upcoming events, product feedback surveys, and more.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="o" data-font="Courier New" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Courier New&amp;quot;,&amp;quot;469769242&amp;quot;:[9675],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;o&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="4" data-aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Get early access to Microsoft Security products and provide feedback to engineers by joining the &lt;/SPAN&gt;&lt;A href="https://aka.ms/AAyclfq" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Security Advisors.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="o" data-font="Courier New" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Courier New&amp;quot;,&amp;quot;469769242&amp;quot;:[9675],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;o&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="5" data-aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Learn about the &lt;/SPAN&gt;&lt;A href="https://aka.ms/MVPMDOvideo" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft MVP Program.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="o" data-font="Courier New" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Courier New&amp;quot;,&amp;quot;469769242&amp;quot;:[9675],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;o&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="6" data-aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Join the &lt;/SPAN&gt;&lt;A href="https://aka.ms/AAyclgu" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Security Community LinkedIn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; and the &lt;/SPAN&gt;&lt;A href="https://www.linkedin.com/company/microsoft-entra/posts/?feedView=all" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Entra Community LinkedIn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 11 Jun 2026 18:09:16 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/level-up-your-azure-network-security-skills-with-our-upcoming/ba-p/4525584</guid>
      <dc:creator>andrewmathu</dc:creator>
      <dc:date>2026-06-11T18:09:16Z</dc:date>
    </item>
    <item>
      <title>Securing the new risk surface: local agents, claws, and open runtimes</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/securing-the-new-risk-surface-local-agents-claws-and-open/ba-p/4524602</link>
      <description>&lt;P&gt;The next wave of AI is more than just powerful models. We’re now seeing intelligent agents that run locally on our devices, interacting directly with sensitive data, apps, and systems. Some operate persistently: monitoring, planning, and executing tasks over time instead of just responding to one-off prompts. We call these more sustained, autonomous processes “claws.” Together, local agents and claws are changing how work gets done. They also introduce a new risk surface for organizations: these agents often run with deep access and minimal oversight on endpoints, meaning a single misstep or malicious input could lead to misuse of data, unintended system changes, or other real-world impacts.&lt;/P&gt;
&lt;H2&gt;A new class of risk: when agents run locally&lt;/H2&gt;
&lt;P&gt;Enterprise security teams already understand the risks introduced by AI agents in cloud services and managed platforms. Local agents introduce a different, and in many ways more acute, risk profile.&lt;/P&gt;
&lt;P&gt;When agents run locally on endpoints, &lt;STRONG&gt;&lt;EM&gt;they operate inside the user’s trust boundary&lt;/EM&gt;&lt;/STRONG&gt;. They inherit the device context, user credentials, local files, cached tokens, browser sessions, and developer tools already present on that machine. Unlike centrally managed cloud agents, local agents can be created, modified, and executed with little to no centralized oversight, often outside established onboarding and governance workflows.&lt;/P&gt;
&lt;P&gt;This creates a distinct risk scenario:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;High privilege by proximity&lt;/STRONG&gt; – Local agents often run under a user’s full identity and permissions, with direct access to sensitive data and systems the user can reach.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Reduced visibility &lt;/STRONG&gt;– Security teams may not know which agents are running locally, how they are configured, or what external services they communicate with.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Immediate impact&lt;/STRONG&gt; – A single malicious input, compromised dependency, or unsafe configuration can translate directly into data exposure, destructive system changes, or unauthorized external communication, at endpoint speed.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The risk is not theoretical. As recent incidents have shown, a locally running agent with overly broad permissions can issue destructive commands, leak sensitive data, or propagate errors faster than traditional software controls can react&lt;A href="#community--1-_ftn1" target="_blank" rel="noopener" name="_ftnref1"&gt;[1]&lt;/A&gt;. &lt;STRONG&gt;&lt;EM&gt;Existing endpoint and application security models were not designed for autonomous systems making decisions continuously on user devices.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;To reduce this risk, security must extend beyond application boundaries and into the agent operating environment. Organizations need visibility into local agents, control over where and how they run, and enforcement of policy as agents act, before unsafe behavior can cause harm.&lt;/P&gt;
&lt;H2&gt;A secure agent operating environment&lt;/H2&gt;
&lt;P&gt;Microsoft’s approach to agent security is already well established: secure agents&amp;nbsp;as systems, not individual tools, with consistent visibility, control, and enforcement across identity, data, network, and runtime.&amp;nbsp;&lt;STRONG&gt;Today’s announcements build on that foundation by extending the same agent security model to local agents running on endpoints.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Local agents introduce a different operating reality. They run on user devices, inherit local context, and act with direct proximity to sensitive data, credentials, and tools. Securing them requires bringing endpoint‑level agents into the same control framework CISOs already rely on, without fragmenting governance or creating new blind spots.&lt;/P&gt;
&lt;P&gt;To do this, Microsoft extends the Agent 365 control plane to local agents, delivering outcomes security leaders expect:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Observe&lt;/STRONG&gt;: Gain a unified view of known local agents across the enterprise to identify what is running, where, and with what access, reducing blind spots before risk materializes.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Secure&lt;/STRONG&gt;: Contain agent activity and help enforce controls in real time to block unsafe behavior, prevent unauthorized access, and stop sensitive data loss before impact.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Govern&lt;/STRONG&gt;: Apply consistent policy and audit across the agent lifecycle to help ensure accountability, enforce standards, and maintain control as agent behavior evolves over time.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;By extending Microsoft Agent 365 to the endpoint, local agents and claws can now operate under the same standards of oversight as cloud‑based agents. This reduces risk while enabling organizations to confidently adopt local, autonomous agents as part of their enterprise AI strategy.&lt;/P&gt;
&lt;H2&gt;Observe: discover and understand local agents&lt;/H2&gt;
&lt;P&gt;The first step in reducing risk is always visibility. Local agents often emerge and operate outside traditional IT oversight, what we call “shadow AI”. If security teams can’t see these agents, they can’t manage or protect them. Therefore, true observability into local agent presence and behavior is critical: organizations need an updated inventory of known local agents, where they’re running, and what they can access. With that knowledge, CISOs and their teams can assess exposure and take informed action.&lt;/P&gt;
&lt;P&gt;Today, Microsoft is introducing agent observability for &lt;A href="https://aka.ms/agenticendpointsecurity" target="_blank" rel="noopener"&gt;20+ local AI agents&lt;/A&gt; running on managed Windows and MacOS devices as first-class security assets. Together, these signals roll up into a unified agent inventory that is surfaced through the security and admin experiences teams already use, so IT, security, and identity teams can see and assess potential local agent risk in the context of their existing workflows.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Agent 365 Agent Registry (including Shadow AI)&lt;/STRONG&gt; provides a system of record for local agents that have been brought under governance, while also surfacing unmanaged or unsanctioned local agents detected on managed endpoints. Together, these capabilities give security teams visibility into both known local agents and previously unknown agent activity, using existing endpoint security signals. Teams can assess risk, decide whether to block execution, or bring local agents under governance as part of an end-to-end control workflow&lt;STRONG&gt;. &lt;/STRONG&gt;Public preview coming later in June. &lt;A href="https://www.microsoft.com/en-us/security/blog/2026/05/01/microsoft-agent-365-now-generally-available-expands-capabilities-and-integrations/" target="_blank" rel="noopener"&gt;Learn more&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;img /&gt;
&lt;P&gt;&lt;EM&gt;Shadow AI detection in the Microsoft 365 admin center, showing unmanaged agents and their publishers across the tenant.&lt;/EM&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft Defender &lt;/STRONG&gt;now&lt;STRONG&gt; &lt;/STRONG&gt;discovers and profiles supported local AI agents on eligible Microsoft Defender onboarded devices. It surfaces each agent’s configuration, such as any associated Model Context Protocol (MCP) servers, and maps it to the device and user identity under which it runs. This approach gives security teams a clear picture of potential exposure for supported agents: what it can reach and what it is entitled to access, making it easier to identify potentially risky combinations, such as auto-approval of agents running with elevated permissions on devices that contain sensitive data, and investigate using the same endpoint telemetry security teams already use in Defender. Now in public preview. &lt;A href="https://aka.ms/Build2026/SecuringLocalAgents" target="_blank" rel="noopener"&gt;Learn more&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft Purview &lt;/STRONG&gt;extends observability into the data layer by showing how agents interact with sensitive information across the environment. It helps identify potential exposure paths where data could be overshared, leaked, or used in ways that increase risk. This insight gives organizations the context they need to help reduce data security and compliance risk as part of broader agent governance. Now in public preview.&lt;STRONG&gt; &lt;/STRONG&gt;&lt;A href="https://aka.ms/PurviewforDevelopers" target="_blank" rel="noopener"&gt;Learn more&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft Entra &lt;/STRONG&gt;extends its Secure Access Service Edge (SASE) architecture to local agents, bringing identity‑aware, network‑level visibility to agents running on Windows and MacOS devices. By correlating network signals with Defender endpoint telemetry, security teams can see which local agents communicate externally, how they are configured, and which resources they are permitted to reach versus what they actually access. This elevates local agent network behavior into first‑class security insight, helping teams identify previously unknown or unmanaged agents and assess risk quickly. These insights surface through the Agent 365 experience, enabling faster, more confident decisions about local agent exposure. Now in public preview. &lt;A href="http://aka.ms/gsabuild2026" target="_blank" rel="noopener"&gt;Learn more&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Together, these capabilities help organizations with a unified, updated view of known local agent activity and potential risks, helping to minimize blind spots at the endpoint. But visibility alone does not reduce risk. To do that, organizations must also control how local agents behave—both where they run and what they do in real time.&lt;/P&gt;
&lt;H2&gt;Secure: contain and enforce local agent actions&lt;/H2&gt;
&lt;P&gt;As the earlier example illustrates, the risk is not just that local agents exist, but that they act autonomously. A single decision can translate directly into real‑world impact, accessing data, executing code, or modifying systems at machine speed.&lt;/P&gt;
&lt;P&gt;Reducing this risk requires two layers of protection. First, organizations must control where agents run and what they can access by design. Second, they must enforce controls as agents act, helping to stop unsafe behavior in real time. Microsoft delivers both through OS‑level containment and runtime enforcement.&lt;/P&gt;
&lt;H3&gt;Execution environment: control agent behavior by design&lt;/H3&gt;
&lt;P&gt;Containment helps organizations bound what agents can access and do, preventing dynamic behavior from turning into unintended impact. Today, we’re announcing execution‑environment controls that define where local agents run and what they can access, limiting exposure by design.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Windows 365 for Agents&lt;/STRONG&gt; provides Cloud PCs that enable AI agents to execute multi-step workflows across software, including opening apps, navigating interfaces, entering inputs, and processing data. Today, we are making Windows 365 for Agents generally available within Agent 365, enabling Agent builders to build computer-using agents for a variety of enterprise use cases. Now generally available within Agent 365. &lt;A href="https://learn.microsoft.com/en-us/windows-365/agents/" target="_blank" rel="noopener"&gt;Learn more.&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft Execution Containers (MXC)&lt;/STRONG&gt; helps to contain agent impact without limiting productivity gains. MXC is a cross-platform, policy-driven execution layer for agents across Windows and WSL. Developers declare what an agent can access — like files and networking related policies — and MXC enforces those boundaries at runtime. Windows delivers a composable sandbox through MXC—a single SDK and policy model that maps to the right isolation construct for any agent workload, from fast process isolation (adopted by GitHub Copilot CLI) to micro-VMs, Linux containers, and cloud instances via Windows 365. Session isolation separates the agent's execution from the user's desktop, clipboard, UI, and input devices, and critically, binds the agent to a strong user identity — mitigating UI spoofing, input injection, and cross-session data leakage. Agent 365 layers Entra and Intune policy on top so IT can govern containment centrally while developers choose the guardrail weight their workload demands. Now available in early preview. &lt;A href="https://blogs.windows.com/windowsdeveloper/?p=57808" target="_blank" rel="noopener"&gt;Learn more&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;OS-enforced Agent Identity and enterprise manageability on Windows&lt;/STRONG&gt;: beyond containment, every agent activity must be attributable and governed. Windows assigns agents a local ID or a cloud provisioned identity backed by Entra and attributes all activity from the container to that identity, so you can clearly differentiate human from agent. Native Windows integration with Agent 365 provides a common foundation for observability, security and governance, including native Intune integration to set policies that gate the agent runtime execution and control how agents run. Defender, Entra, Intune and Purview will provide runtime protections for evolving threats across access, sensitive data, malicious prompts, and risky behavior so security and IT teams can prevent enterprise risk. &lt;A href="https://blogs.windows.com/windowsdeveloper/?p=57808" target="_blank" rel="noopener"&gt;Learn more&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Runtime: enforce controls as agents act&lt;/H3&gt;
&lt;P&gt;If the execution environment defines where agents are allowed to operate, runtime enforcement governs what they are allowed to do. This is the moment an agent accesses sensitive data, invokes tools, or takes action under a user’s identity, and where real‑time controls matter most.&lt;/P&gt;
&lt;P&gt;Today, we are announcing runtime controls across identity, data, and threat protection for Claude Code and GitHub Copilot CLI, with OpenClaw and OpenAI Codex support coming in late June.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft Defender &lt;/STRONG&gt;adds runtime protection for supported local AI agents on Windows, helping to detect unsafe or malicious behavior inline across prompts, tool calls, and responses. Based on policy, Defender can help block or audit agent actions and raise alerts with agent context, enabling investigation using the same telemetry and hunting workflows security teams already use.&amp;nbsp; Now in public preview. &lt;A href="https://aka.ms/Build2026/SecuringLocalAgents" target="_blank" rel="noopener"&gt;Learn more&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;img /&gt;
&lt;P&gt;&lt;EM&gt;Microsoft Defender enforcement of policies during a local agent interaction with a potential threat&lt;/EM&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft Purview&lt;/STRONG&gt;&lt;STRONG&gt; &lt;/STRONG&gt;extends enforcement of Data Loss Prevention policies to local agent interactions, preventing sensitive data leakage and exfiltration as agents execute tasks, call tools, or generate outputs. These controls help reduce AI-driven data risks while maintaining productivity and providing visibility into recurring risky behaviors across agent sessions. Now in public preview.&lt;STRONG&gt; &lt;/STRONG&gt;&lt;A href="https://aka.ms/PurviewforDevelopers" target="_blank" rel="noopener"&gt;Learn more&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;img /&gt;
&lt;P&gt;&lt;EM&gt;Microsoft Purview enforcement of Data Loss Prevention policies during a local agent interaction with sensitive data&lt;/EM&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft Entra &lt;/STRONG&gt;extends the Secure Access Service Edge (SASE) model to local agents by enforcing network-based security controls at runtime, as agents act. Security teams can apply agent-specific network policies directly to agent traffic—separate from user traffic—to restrict web access to authorized destinations, control file transfers, and limit connections to trusted services. Enforced inline during execution, these controls help reduce the risk of data exfiltration, unauthorized access, and communication with untrusted systems, while maintaining consistent, policy‑driven control over local agent behavior. Now in public preview. &lt;A href="http://aka.ms/gsabuild2026" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Learn more&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Together with environment-level containment, these controls help to secure not just where agents run, but how they act.&lt;/P&gt;
&lt;H2&gt;Govern: sustain control with policy and audit&lt;/H2&gt;
&lt;P&gt;As agents become persistent systems operating over time, risk extends beyond individual actions to sustained and evolving behavior. Without governance, organizations lose visibility into how agents evolve, what they access, and whether their actions remain aligned with policy. Sustaining trust in local agents requires continuous oversight, accountability, and lifecycle control.&lt;/P&gt;
&lt;P&gt;Today, we’re announcing governance controls that keep local agent activity accountable over time through policy and audit.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft Intune&lt;/STRONG&gt; helps control how agents run on managed devices by applying endpoint policies that reduce device-level risk. It enables teams to help block OpenClaw on Windows and apply security policies for runtime protection, now in public preview. With MXC as well as &lt;A href="https://aka.ms/W365Build26Blog" target="_blank" rel="noopener"&gt;Windows 365 for Agents&lt;/A&gt;, administrators can use Intune to configure the environments for managed agents running locally and on Cloud PCs. This helps organizations apply controls across deployment models, prevent unauthorized agent activity, and maintain real-time governance over execution.&lt;/LI&gt;
&lt;/UL&gt;
&lt;img /&gt;
&lt;P&gt;&lt;EM&gt;In the Microsoft Intune admin center, an IT professional can apply policies to configure agents like OpenClaw to run in MXC and manage what they can access. &lt;/EM&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft Purview&lt;/STRONG&gt; provides a comprehensive audit record of agent activity over time, capturing how local agents access, use, and interact with sensitive data. These audit logs support investigation, compliance reporting, and accountability, helping to ensure agent actions are traceable and defensible long after execution. Now in public preview for supported agents. &lt;A href="https://aka.ms/PurviewforDevelopers" target="_blank" rel="noopener"&gt;Learn more.&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Together, these governance capabilities help to ensure that local agent activity is not only controlled in the moment, but&amp;nbsp;managed consistently over time, with visibility and accountability for every action. This enables organizations to move beyond limited AI pilots to&amp;nbsp;trusted, auditable, enterprise‑scale adoption&amp;nbsp;of agentic AI.&lt;/P&gt;
&lt;H2&gt;From unmanaged claws to secure and governed agents&lt;/H2&gt;
&lt;P&gt;The result of extending visibility, runtime enforcement, and governance across the agent operating environment is a shift from unmanaged local agents and claws to a secure, enterprise‑ready system. Each layer of Microsoft’s security stack plays a clear role:&lt;/P&gt;
&lt;P&gt;Agent 365 provides the unified control plane now for local agents that includes:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Microsoft Defender to detect and block unsafe actions&lt;/LI&gt;
&lt;LI&gt;Microsoft Purview to provide data protection and compliance&lt;/LI&gt;
&lt;LI&gt;Microsoft Entra to enforce network access controls&lt;/LI&gt;
&lt;LI&gt;Microsoft Intune governs execution through device policy&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;And Microsoft Windows enforces execution boundaries at the platform layer&lt;/P&gt;
&lt;P&gt;Together, these layers form a defense‑in‑depth model that helps to close gaps across the local agent lifecycle.&lt;/P&gt;
&lt;H2&gt;Enabling agentic AI with confidence&lt;/H2&gt;
&lt;P&gt;Local agents and claws introduce a new class of enterprise risk, as autonomous systems operate continuously across identities, data, and systems. They break assumptions that traditional security models rely on.&lt;/P&gt;
&lt;P&gt;Microsoft addresses this shift by securing the agent operating environment itself—helping organizations identify known agents through unified observability, help secure agent actions via real-time enforcement of policies, and govern agent interactions over time through consistent policy and audit.&lt;/P&gt;
&lt;P&gt;AI adoption is accelerating faster than the governance structures organizations have in place to manage it. Extending proven security principles to local agents and claws is how that gap gets closed.&lt;/P&gt;
&lt;P&gt;Learn more: &lt;A href="https://aka.ms/securityforAI" target="_blank" rel="noopener"&gt;aka.ms/securityforAI&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_ftnref1" target="_blank" rel="noopener" name="_ftn1"&gt;[1]&lt;/A&gt; &lt;A href="https://cybernews.com/ai-news/claude-ai-deletes-car-rental-database/" target="_blank" rel="noopener"&gt;Claude AI agent wipes firm’s database in 9 seconds | Cybernews&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2026 17:15:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/securing-the-new-risk-surface-local-agents-claws-and-open/ba-p/4524602</guid>
      <dc:creator>Herain_Oberoi</dc:creator>
      <dc:date>2026-06-02T17:15:00Z</dc:date>
    </item>
    <item>
      <title>Microsoft Purview enables developers with strong data security across AI apps and agents</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/microsoft-purview-enables-developers-with-strong-data-security/ba-p/4524626</link>
      <description>&lt;P&gt;Today, developers are at the center of a new wave of innovation—building AI applications and agents that are deeply connected to enterprise data. But with this opportunity comes a new and complex set of security challenges. AI systems operate across cloud platforms, third-party services, and even local and on-premises development environments, interacting dynamically with sensitive data such as customer records, financial information, and intellectual property. Traditional security approaches weren’t designed for this level of scale, autonomy, or fluid data movement—leaving developers to navigate fragmented tools, unclear policies, and the risk of unintentionally exposing sensitive information.&lt;/P&gt;
&lt;P&gt;At the same time, expectations are rising. Organizations need to ensure that AI applications and agents are compliant, auditable, and secure by default on an enterprise-level—not retrofitted after deployment. But for developers, adding security often means additional complexity, custom integrations, and slower time to market. This tension between speed and control has become one of the biggest barriers to moving AI from experimentation into production.&lt;/P&gt;
&lt;P&gt;Microsoft Purview is designed to help with this challenge by embedding data security and compliance controls across the development cycle. Purview provides a consistent way to govern how data is accessed, used, and shared—without requiring developers to become security experts. The result is a simpler path to building AI systems that are secure, compliant, and enterprise-ready by design.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Extending data security and compliance to local agents and claws&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Local and endpoint agents, built in platforms such as GitHub Copilot CLI and OpenClaw, introduce a new class of data security challenges as they operate outside traditional control planes and directly on user machines. Unlike cloud systems, these agents can access local files, credentials, terminals, and enterprise apps simultaneously—often moving data across tools and environments. This expands data risks, from sensitive data being unintentionally stored, copied, or shared, to API keys and tokens being exposed, and autonomous workflows triggering data movement without explicit user intent. At the same time, many existing security controls were designed for browser or cloud-based activity, leaving a growing blind spot at the endpoint where agents are increasingly running. The result is a widening gap between how developers build agents to operate locally in the users machines, and how organizations can detect, govern, and protect the data those agents interact with.&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://aka.ms/Build2026/SecureLocalAgents" target="_blank" rel="noopener"&gt;Microsoft Security and Windows&lt;/A&gt; are integrating management and security capabilities directly into the local agents’ development workflow, enabling security as an architectural guarantee rather than an implementation choice.&lt;/P&gt;
&lt;P&gt;At Build, we are thrilled to be &lt;STRONG&gt;extending Purview visibility and protection capabilities to local agents developed on GitHub Copilot CLI, Claude Code, OpenAI Codex, and OpenClaw &lt;/STRONG&gt;-&lt;STRONG&gt; &lt;/STRONG&gt;in Public Preview. Unlike traditional cloud applications, these agents operate closer to the data and often create new risks for data exposure. Purview addresses this challenge across all types of agent interactions with a clear, simplified set of scenarios:&lt;/P&gt;
&lt;P&gt;▪ &lt;U&gt;Observability&lt;/U&gt;: Visibility on Purview Data Security Posture Management (DSPM) across agent inventory, as well as into how local agents interact with sensitive data—across prompts, responses, and actions.&lt;/P&gt;
&lt;P&gt;▪ &lt;U&gt;Runtime data protection&lt;/U&gt;: Purview Data Loss Prevention (DLP) controls enforced directly into the agent execution flow, inspecting prompts and tool calls in real time to prevent sensitive data exfiltration.&lt;/P&gt;
&lt;P&gt;▪ &lt;U&gt;Agentic risk detection&lt;/U&gt;: Risky or anomalous agent behaviors detected through Insider Risk Management (IRM) signals, helping teams detect unsafe interactions early.&lt;/P&gt;
&lt;P&gt;▪ &lt;U&gt;Audit&lt;/U&gt;: Comprehensive, end-to-end logging of all local agent interactions—capturing prompts, responses, data access, and actions for data context.&lt;/P&gt;
&lt;P&gt;For example, a developer is using a local coding agent to generate code and accidentally includes sensitive credentials in a prompt. AI observability in DSPM surfaces the interaction and shows what data the agent accessed. DLP detects the sensitive data in real time and blocks it from being sent or processed (or sensitive files from being accessed and exfiltrated). At the same time, agentic risk detection flags the session as high risk based on the behavior pattern. All of this activity is captured in audit logs, enabling the security team to investigate and take action quickly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Data protection policy blocks agent interaction with sensitive data&lt;/EM&gt;&lt;/img&gt;
&lt;P&gt;Developers and security teams gain visibility into agent activity and data interactions, while policies prevent sensitive data leakage. This ensures consistent security outcomes across both cloud and endpoint environments, without disrupting developer workflows.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Strengthening visibility and controls for Foundry agents&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Foundry gives developers a central place to build and manage AI agents, but it also creates a need for data security context directly in that workflow—especially as prompts, model interactions, and downstream actions increasingly involve sensitive enterprise data.&lt;/P&gt;
&lt;P&gt;At Build, we are excited to announce the expansion of the Foundry integration with Purview. This includes&amp;nbsp;&lt;STRONG&gt;Purview DLP runtime controls for prompt processing in Foundry&lt;/STRONG&gt;,&lt;STRONG&gt; &lt;/STRONG&gt;in Public Preview. As agents and applications built on Foundry increasingly interact with sensitive data, Purview ensures those interactions are governed by trusted controls, identifying Sensitive Information Types (SITs) in real time to detect and protect confidential data embedded in prompts. For example, if a user includes customer PII or financial data in a prompt, Purview can automatically identify the sensitive content and block that prompt from being processed by the model. This ensures that all Foundry apps and agents, regardless of how they’re built or deployed, inherit consistent data protection – allowing organizations to reduce risk of inadvertent data exposure, centralize compliance enforcement across AI workloads, and confidently scale AI adoption knowing sensitive data is protected by design.&lt;/P&gt;
&lt;P&gt;We’re also building up on the &lt;A href="https://aka.ms/PurviewforAgents" target="_blank" rel="noopener"&gt;Purview coverage for Foundry shared at the last Microsoft Ignite&lt;/A&gt; by announcing &lt;STRONG&gt;Purview insights embedded directly into the Foundry Control Plane&lt;/STRONG&gt;,&lt;STRONG&gt; &lt;/STRONG&gt;in General Availability, bringing rich data security context to the plane where developers already work. Purview surfaces crucial signals—such as SITs detected in the agentic interactions, % of agentic interactions involving sensitive data, and spread of high-risk users — so Foundry admins can know how AI apps and agents are built in their environment. This shift enables developers to make faster, better decisions in the moment, reducing rework and closing security gaps early on.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Purview Audit embedded in the Foundry Control Plane&lt;/EM&gt;&lt;/img&gt;
&lt;P&gt;For customers, the value is clear: stronger security by design and at enterprise scale, accelerated development cycles, and reduced risk of data leaks or compliance issues—without slowing down innovation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Innovating for developers everywhere, at the pace of AI growth&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Microsoft is also expanding Purview’s reach across the broader developer ecosystem. New integrations help organizations apply consistent oversight to AI tools and platforms developers already use, without adding separate compliance workflows.&lt;BR /&gt;&lt;BR /&gt;GitHub Copilot is a critical productivity layer for developers, accelerating how code is written and shipped—making it equally important that developer interactions with GitHub Copilot are governed and secured with the same rigor as enterprise data. &lt;STRONG&gt;Microsoft Purview now extends data governance and compliance capabilities to GitHub Copilot interactions&lt;/STRONG&gt;, in Public Preview, enabling GitHub Enterprise customers with Entra SSO to stream audit logs directly into Purview. This brings centralized visibility for AI activity, allowing security and compliance teams to analyze GitHub Copilot agent session activity alongside other AI workloads. With this native integration into GitHub workflows, Purview audits Copilot activity across repositories, pull requests, and developer sessions—ensuring AI-generated code aligns with enterprise data policies, compliance requirements, and secure development standards.&lt;/P&gt;
&lt;P&gt;By integrating Purview into existing workflows, organizations can govern GitHub AI usage without building parallel pipelines—reducing complexity while ensuring consistent compliance coverage across their entire data estate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Purview capabilities configured directly into the GitHub Copilot experience&lt;/EM&gt;&lt;/img&gt;
&lt;P&gt;Today’s AI agents aren’t built in just one ecosystem—they span custom apps, third-party platforms, and open-source frameworks. Without consistent controls, this creates blind spots where sensitive data can be exposed outside enterprise guardrails. That’s why extending Purview protection beyond Microsoft environments is critical: it ensures developers can apply the same data security, DLP policies, and compliance controls to any agent, anywhere—so innovation can scale without increasing risk.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Developers already use Microsoft Purview APIs to embed data protection into enterprise workflows. Today, we’re&amp;nbsp;introducing the&lt;STRONG&gt; Microsoft Purview SDK for .NET — a simple, drop-in toolkit that brings Purview capabilities directly into any application&lt;/STRONG&gt;, in Public Preview. Instead of weeks spent wiring APIs, authentication, and error handling, developers can add content scanning, DLP checks, and sensitivity labeling in just a few lines of code. The SDK handles the heavy lifting — including auth, retries, caching, and telemetry — so teams can focus on building experiences.&lt;/P&gt;
&lt;P&gt;For AI apps and agents built outside of the Microsoft AI platforms, SDK adds built-in support and can evaluate prompts and responses in real time against DLP and content policies — helping prevent data exposure at runtime without custom logic.&lt;/P&gt;
&lt;P&gt;Designed for both real-time and asynchronous patterns, and for authenticated or anonymous flows, the SDK also feeds activity back into Purview to give security teams centralized visibility and control. The bottom line is- the Microsoft Purview SDK enables developers to build AI apps and agents that are secure and compliant by default — cutting integration time from weeks to days while ensuring data protection scales with AI. The SDK will be available in public preview within the next month.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Together, these announcements represent a significant step forward in how developers build secure AI systems. Microsoft Purview is no longer just a data security and compliance solution—it is a first-class layer of the development process by protecting data across AI applications and agents, and enables a bridge between developers and security teams. As AI becomes more agentic, distributed, and deeply connected to enterprise data, the need for built-in security will only grow. With Purview, developers no longer must choose between speed and security—they can build both into every application from the start&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Getting connected with Microsoft Purview and learn more&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Learn more about Microsoft Purview on our&amp;nbsp;&lt;A href="https://www.microsoft.com/en-us/security/business/microsoft-purview" target="_blank" rel="noopener"&gt;website&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/purview/" target="_blank" rel="noopener"&gt;Microsoft Learn&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Explore&lt;A class="lia-external-url" href="https://www.microsoft.com/en-us/microsoft-agent-365?msockid=0cae18635970673804700df9585d6659" target="_blank"&gt; Agent 365&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://aka.ms/PurviewTrial" target="_blank" rel="noopener"&gt;Try Microsoft Purview data security&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Learn more about &lt;A href="Microsoft%20Purview%20Developer%20Platform%20Documentation%20-%20purview-sdk%20|%20Microsoft%20Learn" target="_blank" rel="noopener"&gt;Microsoft Purview SDK&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2026 17:14:32 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/microsoft-purview-enables-developers-with-strong-data-security/ba-p/4524626</guid>
      <dc:creator>Nathalia_Borges</dc:creator>
      <dc:date>2026-06-02T17:14:32Z</dc:date>
    </item>
    <item>
      <title>New Windows Features to Secure Today’s Data in a Post-Quantum World</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/new-windows-features-to-secure-today-s-data-in-a-post-quantum/ba-p/4523370</link>
      <description>&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;***July 14 Update: &lt;SPAN data-olk-copy-source="MessageBody"&gt;TLS Hybrid Key Exchange using ML-KEM groups is now available on Windows 11 starting with update&amp;nbsp;&lt;A href="https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Ftopic%2Fmay-26-2026-kb5089573-os-builds-26200-8524-and-26100-8524-preview-f378c8ae-0170-47c9-a1e9-dfef978c8e17&amp;amp;data=05%7C02%7Ctrevor.rusher%40indigoslate.com%7C9b34c2c9d2904a36d4ea08dee1adcec9%7C73069f9390444331911838ad57b63fa8%7C0%7C0%7C639196333807768889%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=W66z2C9ssnqGd3z3SkOFXVATggvAffHpVT4IIiwTC%2Fg%3D&amp;amp;reserved=0" target="_blank" rel="noopener" data-auth="NotApplicable" data-linkindex="1" data-ogsc=""&gt;KB5089573&lt;/A&gt;&amp;nbsp;for 24H2 and 25H2 and&amp;nbsp;&lt;A href="https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Ftopic%2Fjune-23-2026-kb5095091-os-build-28000-2340-preview-255237ff-1236-4ad7-a087-251eb0cf8869&amp;amp;data=05%7C02%7Ctrevor.rusher%40indigoslate.com%7C9b34c2c9d2904a36d4ea08dee1adcec9%7C73069f9390444331911838ad57b63fa8%7C0%7C0%7C639196333807786117%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=NfS4%2FaICjFgcHtWvKxN6uPx3YMG9kEGPUFOD7lQQLn0%3D&amp;amp;reserved=0" target="_blank" rel="noopener" data-auth="NotApplicable" data-linkindex="2" data-ogsc=""&gt;KB5095091&lt;/A&gt;&amp;nbsp;for 26H1. Composite algorithms are now available on Windows 11 starting with update&amp;nbsp;&lt;A href="https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Ftopic%2Fjune-23-2026-kb5095093-os-builds-26200-8737-and-26100-8737-preview-0e2a20f2-cf9e-46f8-9f08-e6996220882d&amp;amp;data=05%7C02%7Ctrevor.rusher%40indigoslate.com%7C9b34c2c9d2904a36d4ea08dee1adcec9%7C73069f9390444331911838ad57b63fa8%7C0%7C0%7C639196333807803186%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=Mc7Sm7niedE3FnutuUxzA9NIREN2r2xHSjjdjkyFOFI%3D&amp;amp;reserved=0" target="_blank" rel="noopener" data-auth="NotApplicable" data-linkindex="3" data-ogsc=""&gt;KB5095093&lt;/A&gt;&amp;nbsp;for 24H2 and 25H2 and&amp;nbsp;&lt;A href="https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Ftopic%2Fjune-23-2026-kb5095091-os-build-28000-2340-preview-255237ff-1236-4ad7-a087-251eb0cf8869&amp;amp;data=05%7C02%7Ctrevor.rusher%40indigoslate.com%7C9b34c2c9d2904a36d4ea08dee1adcec9%7C73069f9390444331911838ad57b63fa8%7C0%7C0%7C639196333807819225%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=eB5ZgZ0dvYVkAt71ErB0CSJkMMwcp4VOPmd2HFSC%2BXU%3D&amp;amp;reserved=0" target="_blank" rel="noopener" data-auth="NotApplicable" data-linkindex="4" data-ogsc=""&gt;KB5095091&lt;/A&gt;&amp;nbsp;for 26H1. Both features are available for Windows Server 2025 with the July 14th patch -&lt;/SPAN&gt; &lt;A href="https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsupport.microsoft.com%2Fen-US%2Fservicing%2Fos%2Fwindows-server%2F2026%2F07%2Fjuly-14-2026-kb5099536-os-build-26100-33158&amp;amp;data=05%7C02%7CTrevor.Rusher%40indigoslate.com%7Cb34c7c5a285a4992fd9708dee1cd92fd%7C73069f9390444331911838ad57b63fa8%7C0%7C0%7C639196470257085955%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=FhSOepP0z8Ulp0FGRlMDn%2Bs5tvonWmPQGVVM3fTCi%2BA%3D&amp;amp;reserved=0" data-auth="NotApplicable" data-linkindex="0" data-ogsc="" data-olk-copy-source="MessageBody" target="_blank"&gt;July 14, 2026—KB5099536 (OS Build 26100.33158)&lt;/A&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Quantum safety is a staged transition across customer environments. Windows is enabling this progression by extending quantum-safe support beyond algorithms and APIs, into the protocols and platform components that organizations use the most. This foundation empowers customers to build, validate, pilot, and ultimately deploy quantum-safe applications, systems, and infrastructure at scale.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft’s earlier announcements introduced&amp;nbsp;PQC&amp;nbsp;support&amp;nbsp;in&amp;nbsp;the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoft-security-blog/microsofts-quantum-resistant-cryptography-is-here/4238780" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;core cryptographic building blocks&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;and&amp;nbsp;outlined&amp;nbsp;the broader&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2025/08/20/quantum-safe-security-progress-towards-next-generation-cryptography/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Quantum Safe Program&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;,&amp;nbsp;including the need for&amp;nbsp;crypto-agility, standards alignment, and a practical migration path.&amp;nbsp;Microsoft delivered&amp;nbsp;a key milestone&amp;nbsp;last November&amp;nbsp;by&amp;nbsp;making&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoft-security-blog/post-quantum-cryptography-apis-now-generally-available-on-microsoft-platforms/4469093" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;PQC algorithms generally available&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;on Windows 11 and Windows Server 2025.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Now,&amp;nbsp;we’re&amp;nbsp;bringing&amp;nbsp;quantum-safe capabilities to where&amp;nbsp;they&amp;nbsp;are used: adding&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://datatracker.ietf.org/doc/draft-ietf-tls-hybrid-design/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;PQ&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;TLS&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;hybrid key&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;exchange&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;to&amp;nbsp;the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/windows-server/security/tls/tls-ssl-schannel-ssp-overview" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows Transport Layer Security (TLS) stack&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, enabling composite PQC algorithms in&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/windows/win32/seccng/cng-portal" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows cryptography APIs&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;and&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/windows/win32/seccrypto/using-certificates" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;certificate functions&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;,&amp;nbsp;and bringing the ability to&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/windows-server/identity/ad-cs/post-quantum-cryptography-overview#pqc-algorithms-supported-in-ad-cs" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;generate PQ certificates via Active Directory Certificate Services (ADCS)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&amp;nbsp;Together, these advances help organizations address long-lived data risks now and begin preparing for the broader transition across authentication, certificates, device protection, and management workflows.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;These updates are part of a broader&amp;nbsp;transition: bringing quantum-safe security into the systems and workflows&amp;nbsp;on which&amp;nbsp;organizations already rely.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;PQ&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;TLS&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;hybrid key exchange&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;comes to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Windows&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The Windows TLS stack is a&amp;nbsp;core&amp;nbsp;component for secure&amp;nbsp;communication&amp;nbsp;across the platform. Adding&amp;nbsp;PQ&amp;nbsp;TLS&amp;nbsp;hybrid key exchange&amp;nbsp;brings&amp;nbsp;quantum-safe protection to&amp;nbsp;real&amp;nbsp;data-in-transit&amp;nbsp;scenarios that already run on&amp;nbsp;Windows.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Hybrid key exchange combines classical&amp;nbsp;and&amp;nbsp;post-quantum algorithms, allowing&amp;nbsp;organizations&amp;nbsp;to&amp;nbsp;begin mitigating&amp;nbsp;HNDL&amp;nbsp;risks. This is especially important for data that must remain confidential for years,&amp;nbsp;as&amp;nbsp;adversaries can capture encrypted traffic today and attempt to decrypt it in the future when quantum computing becomes practical.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This reflects Microsoft’s ongoing work in standards development and broader platform&amp;nbsp;investments,&amp;nbsp;including&amp;nbsp;the core cryptographic library&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://github.com/microsoft/SymCrypt" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;SymCrypt&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, Windows cryptography APIs,&amp;nbsp;and certificate handling.&amp;nbsp;TLS&amp;nbsp;PQ&amp;nbsp;hybrid key exchange&amp;nbsp;is&amp;nbsp;available&amp;nbsp;now in&amp;nbsp;preview&amp;nbsp;through&amp;nbsp;the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://blogs.windows.com/windows-insider/2026/05/14/announcing-new-release-preview-builds-for-14-may-2026/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows Insider Program&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;and will become generally available on Windows 11 and Windows Server 2025 in the coming months.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;These new&amp;nbsp;quantum safe key exchange options&amp;nbsp;can be configured the same way as&amp;nbsp;existing&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/windows-server/security/tls/manage-tls" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;TLS&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;curves&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;(&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;cla&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;ssical encryption groups already in&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;use today)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&amp;nbsp;IT administrators can enable them using familiar Windows management tools: Group Policy for domain-joined enterprise environments, Mobile Device Management (MDM) for modern device management platforms such as Intune, or&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/powershell/module/tls/?view=windowsserver2025-ps" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;TLS PowerShell cmdlets&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;(scripted configuration commands) for manual or automated setup. The following hybrid combinations — each pairing a classical algorithm with the post-quantum NIST&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://nvlpubs.nist.gov/nistpubs/fips/nist.fips.203.pdf" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;ML-KEM&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;algorithm to protect against both current and future threats — are available:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;X25519_MLKEM768 — combines the widely-used X25519 classical algorithm with ML-KEM&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;SecP256r1_MLKEM768 — combines the NIST P-256 elliptic curve with ML-KEM&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;SecP384r1_MLKEM1024 — combines the NIST P-384 elliptic curve with ML-KEM at a higher security level&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;In practical terms, bringing&amp;nbsp;this capability&amp;nbsp;to&amp;nbsp;Windows enables&amp;nbsp;security teams and application owners&amp;nbsp;to evaluate&amp;nbsp;real,&amp;nbsp;Windows-native deployments and begin planning&amp;nbsp;the&amp;nbsp;policy&amp;nbsp;and&amp;nbsp;configuration updates needed for quantum-safe readiness. It provides a direct path to start&amp;nbsp;testing&amp;nbsp;in familiar Windows environments, without&amp;nbsp;relying only on specialized preview stacks.&amp;nbsp;Our&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/windows/win32/secauthn/tls-supported-groups-in-windows-11-24h2-and-later" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;T&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LS&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;supported groups&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; page describes the PQ TLS hybrid key exchange groups available and how to enable them in your environment.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Composite PQC algorithms&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;in&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Windows cryptography APIs&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:360,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Windows cryptography APIs are&amp;nbsp;adding&amp;nbsp;support&amp;nbsp;for&amp;nbsp;composite&amp;nbsp;ML-KEM and composite&amp;nbsp;ML-DSA, where&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://nvlpubs.nist.gov/nistpubs/fips/nist.fips.203.pdf" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;ML&lt;/SPAN&gt;&lt;/SPAN&gt;‑&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;KEM&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;(Module-Lattice Key Encapsulation Mechanism)&amp;nbsp;and&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://nvlpubs.nist.gov/nistpubs/fips/nist.fips.204.pdf" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;ML&lt;/SPAN&gt;&lt;/SPAN&gt;‑&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;DSA&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; (Module-Lattice Digital Signature Algorithm) are NIST approved PQ algorithms for key exchange and digital signatures respectively. Composite approaches are important for transition because they allow cryptographic operations to incorporate both classical and post-quantum components.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Composite algorithms provide defense in depth by requiring an adversary to break all components to compromise protected data. When implemented natively, they abstract away the complexity of securely combining multiple algorithms, reducing the risk of incorrect integrations and strengthening resilience against weaknesses in individual schemes. This work follows the IETF drafts for &lt;/SPAN&gt;&lt;A href="https://datatracker.ietf.org/doc/draft-ietf-lamps-pq-composite-sigs/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;composite ML-DSA&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;and&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://datatracker.ietf.org/doc/draft-ietf-lamps-pq-composite-kem/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;composite ML-KEM&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, to&amp;nbsp;combine&amp;nbsp;the traditional digital signature algorithm&amp;nbsp;ECDSA with ML-DSA and&amp;nbsp;traditional key exchange algorithm&amp;nbsp;ECDHE with ML-KEM.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For developers, platform engineers, and security architects, this means Windows-native APIs are moving&amp;nbsp;beyond foundational primitives toward the real-world certificate and signing patterns required in production environments. Composite support&amp;nbsp;enables&amp;nbsp;organizations&amp;nbsp;to&amp;nbsp;prototype new certificate profiles, evaluate trust chain impacts, and&amp;nbsp;prepare for scenarios&amp;nbsp;as&amp;nbsp;relying parties,&amp;nbsp;issuing systems,&amp;nbsp;and&amp;nbsp;policy controls&amp;nbsp;adopt&amp;nbsp;post-quantum capabilities at different speeds.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;These capabilities are&amp;nbsp;in&amp;nbsp;Windows Insider Preview&amp;nbsp;for&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/windows/win32/seccng/cng-portal" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;C&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;ryptography&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;API Next Generation&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;and&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/windows/win32/seccrypto/using-certificates" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;certificate functions&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;and will become generally available on Windows 11 and Windows Server 2025 in the coming months.&amp;nbsp;Visit our&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/windows/win32/seccng/cng-algorithm-identifiers" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;crypto developers&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;page to&amp;nbsp;learn more and get started.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;PQ&amp;nbsp;Certificates&amp;nbsp;come to&amp;nbsp;ADCS&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Active Directory Certificate Services (ADCS) support for&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/windows-server/identity/ad-cs/ml-dsa-overview" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;issuance of ML&lt;/SPAN&gt;&lt;/SPAN&gt;‑&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;DSA certificates&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;in Windows Server 2025&amp;nbsp;is now generally available&amp;nbsp;as of May 2026,&amp;nbsp;bringing PQC support into enterprise&amp;nbsp;public key infrastructure (PKI). ML&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;DSA enables quantum&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;resistant signing operations across Certification Authorities (CAs) and Online Certificate Status Protocol (OCSP) Responders, providing a practical way to evaluate post&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;quantum certificate issuance and trust validation workflows.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;ADCS supports three ML&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;DSA parameter sets (ML&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;DSA&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;44, ML&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;DSA&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;65, ML&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;DSA&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;87), allowing organizations to balance security strength with key and signature size&amp;nbsp;for&amp;nbsp;scenarios&amp;nbsp;like&amp;nbsp;code signing and&amp;nbsp;TLS&amp;nbsp;certificates. PQC support requires&amp;nbsp;newly deployed CAs&amp;nbsp;(as existing CAs cannot be upgraded in place), so organizations can introduce a parallel CA hierarchy alongside existing infrastructure to test and validate deployments without disrupting production workloads.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Additional post&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;quantum capabilities, including ML&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;KEM and composite algorithm support, are planned later this year to expand beyond signing scenarios and enable broader certificate interoperability.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;What this means for security teams and developers&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For many organizations, these announcements&amp;nbsp;provide a&amp;nbsp;clear starting point&amp;nbsp;to adopt&amp;nbsp;quantum-safe cryptography.&amp;nbsp;The&amp;nbsp;Windows&amp;nbsp;platform now enables&amp;nbsp;early&amp;nbsp;validation and integration of PQC capabilities across applications&amp;nbsp;and infrastructure.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The most effective migrations will be phased.&amp;nbsp;Organizations should start by&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2026/04/16/building-your-cryptographic-inventory-a-customer-strategy-for-cryptographic-posture-management/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;inventorying where public-key cryptography&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;is used,&amp;nbsp;prioritizing systems that protect sensitive data with long confidentiality lifetimes, and testing hybrid and&amp;nbsp;composite approaches in non-production environments.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Security teams can&amp;nbsp;start by&amp;nbsp;identifying&amp;nbsp;where&amp;nbsp;long-lived data is&amp;nbsp;at&amp;nbsp;risk, such&amp;nbsp;as&amp;nbsp;document repositories (e.g.,&amp;nbsp;SharePoint),&amp;nbsp;email archives, database systems, and backup or archival storage (including device and cloud backups),&amp;nbsp;and&amp;nbsp;prioritizing the systems that depend on&amp;nbsp;TLS and certificate-based trust.&amp;nbsp;They can then&amp;nbsp;map which applications rely on Windows cryptographic interfaces. Developers can test new algorithm support in controlled environments.&amp;nbsp;IT administrators&amp;nbsp;can prepare for the operational changes&amp;nbsp;required&amp;nbsp;for&amp;nbsp;quantum-safe migration, including&amp;nbsp;across certificates, device policy, performance validation, interoperability testing, and cryptographic inventory management.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The goal is not only to adopt new algorithms, but to build crypto-agility into processes so future transitions are easier to manage.&amp;nbsp;These latest Windows capabilities&amp;nbsp;make it easier&amp;nbsp;for that work to begin in a more practical, standards-aligned way.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Looking ahead: the next wave of quantum-safe&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;&amp;nbsp;capabilities&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;in Windows&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:360,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;These announcements mark early but important steps in bringing&amp;nbsp;quantum-safe capabilities into the Windows scenarios organizations depend on most. Beyond foundational cryptography&amp;nbsp;and&amp;nbsp;PQ&amp;nbsp;hybrid key&amp;nbsp;exchange,&amp;nbsp;that&amp;nbsp;roadmap extends&amp;nbsp;across certificate lifecycle workflows,&amp;nbsp;networking&amp;nbsp;protections such as&amp;nbsp;IPsec and Wi-Fi,&amp;nbsp;authentication&amp;nbsp;scenarios including TLS and Kerberos, passwordless experiences&amp;nbsp;like&amp;nbsp;Windows Hello and passkeys,&amp;nbsp;and&amp;nbsp;platform protections&amp;nbsp;that&amp;nbsp;rely on trusted&amp;nbsp;keys, certificates, and recovery flows.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This future direction includes&amp;nbsp;additional capabilities&amp;nbsp;like composite&amp;nbsp;PQ support in&amp;nbsp;ADCS,&amp;nbsp;which will be central to enterprise certificate enrollment and issuance, as well as&amp;nbsp;BitLocker,&amp;nbsp;software signing, and firmware signing.&amp;nbsp;Customers&amp;nbsp;will&amp;nbsp;see progress in some of these areas&amp;nbsp;this year,&amp;nbsp;with additional advancements planned for&amp;nbsp;2027.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Across&amp;nbsp;these&amp;nbsp;investments, the&amp;nbsp;goal remains consistent: to help&amp;nbsp;customers move from algorithm availability&amp;nbsp;to&amp;nbsp;deployable, manageable, enterprise-ready,&amp;nbsp;and&amp;nbsp;quantum-safe solutions.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Preparing now for the transition ahead&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:360,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The transition to quantum&amp;nbsp;safety will&amp;nbsp;take time, testing, and close coordination across standards bodies, platform providers, software developers, and enterprise security teams. But momentum matters.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;By expanding Windows support from foundational post-quantum primitives to real protocol and certificate scenarios, Microsoft is helping make that transition more practical. TLS&amp;nbsp;PQ&amp;nbsp;hybrid key exchange in&amp;nbsp;the Windows TLS&amp;nbsp;stack, composite&amp;nbsp;PQC algorithms in Windows cryptography APIs, and PQC&amp;nbsp;capabilities in ADCS&amp;nbsp;represent important next steps in turning quantum-safe readiness into deployable capability.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;As the roadmap continues to unfold across certificates, authentication, and platform protection, the best time for organizations to begin preparing is now.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5 aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Securing&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;today. Preparing for what’s next.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Security in Windows is built into the platform -&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;continuously&amp;nbsp;maintained and&amp;nbsp;designed to&amp;nbsp;evolve as threats change&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;Learn more in the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/windows/security/book/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows Security book&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; and &lt;/SPAN&gt;&lt;A href="https://aka.ms/ws2025securitybook" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows Server Security book&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; or explore&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en-us/windows/business" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows 11&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;, &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/windows-server/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows Server&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;, and &lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en-us/windows/business/devices/copilot-plus-pcs" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Copilot+ PCs&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;For broader solutions, visit the&amp;nbsp; &lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en-us/security/business" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Security site&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, follow the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/security/blog/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Security blog&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, or connect with&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.linkedin.com/showcase/microsoft-security/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Security&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;on LinkedIn&amp;nbsp;and&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://twitter.com/@MSFTSecurity" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSFTSecurity&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;. &lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;  &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2026 18:24:17 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/new-windows-features-to-secure-today-s-data-in-a-post-quantum/ba-p/4523370</guid>
      <dc:creator>AabhaThipsay</dc:creator>
      <dc:date>2026-07-14T18:24:17Z</dc:date>
    </item>
    <item>
      <title>Share Your Use Case in a Lighting Talk</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/share-your-use-case-in-a-lighting-talk/ba-p/4524579</link>
      <description>&lt;H5&gt;&lt;SPAN class="lia-text-color-15"&gt;&lt;STRONG&gt;Microsoft Security Store Lightning Talks&amp;nbsp;&lt;/STRONG&gt;are high‑energy, community-led mini sessions&lt;/SPAN&gt; spotlighting real users like you who are putting &lt;A class="lia-external-url" href="https://securitystore.microsoft.com/" target="_blank" rel="noopener"&gt;Microsoft Security Store&lt;/A&gt; agents and solutions to work, driving measurable impact through faster workflows, smarter automation, and stronger security outcomes.&amp;nbsp;&lt;/H5&gt;
&lt;P&gt;Selected sessions will be recorded and curated into a single can’t‑miss public virtual event, with speakers live in chat to answer questions and help attendees translate ideas into action. After the event, each speaker receives a dedicated Microsoft Security Community YouTube link for their segment, ready to share and keep up the community momentum.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Any user of agents of solutions from the &lt;A class="lia-external-url" href="https://securitystore.microsoft.com/" target="_blank" rel="noopener"&gt;Microsoft Security Store&lt;/A&gt; are welcome to submit a session; multiple submissions are welcome:&amp;nbsp;&lt;A class="lia-external-url" href="https://aka.ms/MSScfp" target="_blank" rel="noopener"&gt;aka.ms/MSScfp&lt;/A&gt; | Due June 4&lt;SUP&gt;th&lt;BR /&gt;&lt;/SUP&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;See examples of Microsoft Security Community Lightning Talks&amp;nbsp;&lt;A class="lia-external-url" href="https://youtube.com/playlist?list=PLmAptfqzxVEX8BJp9n0ojZTM1pCCDJnOw&amp;amp;si=zZ_WYf6-wdl-FxEJ" target="_blank" rel="noopener"&gt;here&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Sessions must be no longer than 10 minutes long and session submissions/descriptions can be 1-3 sentences.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;More information on the requirements and timeline can be found within the&amp;nbsp;&lt;A class="lia-external-url" href="https://aka.ms/MSScfp" target="_blank" rel="noopener"&gt;submission form&lt;/A&gt;.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Event date: July 30th.
&lt;UL&gt;
&lt;LI&gt;Interested in registering for the event? Watch&amp;nbsp;&lt;A class="lia-external-url" href="https://securitycommunity.microsoft.com/VirtualEvents/" target="_blank" rel="noopener"&gt;this event space&lt;/A&gt; &lt;EM&gt;and&lt;/EM&gt; follow this blog post - yes, the one you're reading! Sign in (upper right corner) then click the heart to follow and be alerted on updates.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Have questions? Feel free to post in the comments below. Need help? Let us know by sending &lt;a href="javascript:void(0)" data-lia-user-mentions="" data-lia-user-uid="2764958" data-lia-user-login="RenWoods" class="lia-mention lia-mention-user"&gt;RenWoods​&lt;/a&gt; a direct message.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Professional speaking experience is not required in this community-focused event. Microsoft employees are not eligible to present.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A class="lia-external-url" href="https://aka.ms/MSScfp" target="_blank" rel="noopener"&gt;Submit &lt;/A&gt;your Microsoft Security Store Lightning Talk today!&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR style="border: none; border-top: 2px solid #bfbfbf; margin: 20px 0;" /&gt;
&lt;H6&gt;Learn and Engage with the Microsoft Security Community&lt;/H6&gt;
&lt;UL&gt;
&lt;LI&gt;Log in and follow this&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-security-product/blog/microsoft-security-blog" target="_blank" rel="noopener"&gt;Microsoft Security Community Blog&lt;/A&gt;&amp;nbsp;and post/ interact in the&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-security" target="_blank" rel="noopener" data-lia-auto-title="Microsoft Security Community discussion spaces" data-lia-auto-title-active="0"&gt;Microsoft Security Community discussion spaces&lt;/A&gt;.
&lt;UL&gt;
&lt;LI&gt;Follow = Click the heart in the upper right when you're logged in 🤍&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Join the &lt;A href="https://aka.ms/AAycdmn" target="_blank" rel="noopener"&gt;Microsoft Security Community&lt;/A&gt;&amp;nbsp;and be notified of upcoming events, product feedback surveys, and more.&lt;/LI&gt;
&lt;LI&gt;Get early access to Microsoft Security products and provide feedback to engineers by joining the&amp;nbsp;&lt;A href="https://aka.ms/AAyclfq" target="_blank" rel="noopener"&gt;Microsoft Security Advisors.&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;Learn about the&amp;nbsp;&lt;A href="https://aka.ms/MVPMDOvideo" target="_blank" rel="noopener"&gt;Microsoft MVP Program.&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Join the&amp;nbsp;&lt;A href="https://aka.ms/AAyclgu" target="_blank" rel="noopener"&gt;Microsoft Security Community LinkedIn&lt;/A&gt;&amp;nbsp;and the&amp;nbsp;&lt;A href="https://www.linkedin.com/company/microsoft-entra/posts/?feedView=all" target="_blank" rel="noopener"&gt;Microsoft Entra Community LinkedIn&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 01 Jun 2026 19:38:07 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/share-your-use-case-in-a-lighting-talk/ba-p/4524579</guid>
      <dc:creator>RenWoods</dc:creator>
      <dc:date>2026-06-01T19:38:07Z</dc:date>
    </item>
    <item>
      <title>Microsoft Security Community Spotlight: Marcel Graewer</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/microsoft-security-community-spotlight-marcel-graewer/ba-p/4523372</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Globally, Marcel shares practical detection engineering insights on Microsoft Sentinel and Microsoft Defender XDR through forums and blog posts.&lt;/STRONG&gt; Locally, he represents his employer in the IT-Security group of the Microsoft Business User Forum, where German companies using Microsoft technologies exchange real-world experience and expertise.&lt;/P&gt;
&lt;P&gt;The work Marcel values most is helping people enter the IT field. In Germany, "Fachinformatiker" is a recognized IT profession learned through a multi-year apprenticeship, and he is proud to have trained apprentices. He also serves as an examiner for the IHK (the German Chamber of Industry and Commerce), evaluating the final exams of these IT apprentices. &lt;BR /&gt;&lt;BR /&gt;This commitment also led him to support younger learners by teaching school cybersecurity classes and participating in Girls’ Day, where he introduced female students to the field. “I do this because most people don’t get an honest view of security work until much later in their education—if they see it at all. Showing someone early that this field is creative, varied, and genuinely interesting can change their path. Being part of that, even for a few people, means more to me than anything that fits neatly on a CV.”&lt;BR /&gt;&lt;BR /&gt;Let’s hear more from Marcel about his Microsoft Security Community and product paths.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;BR /&gt;&lt;EM&gt;All responses to questions are direct quotes from Marcel.&lt;/EM&gt;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN class="lia-text-color-21"&gt;&lt;STRONG&gt;What do you find most rewarding about being a member of the Microsoft Security Community?&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;The most rewarding part for me is how practical the exchange is. Microsoft security tooling moves fast -&amp;nbsp; &lt;A href="https://youtube.com/playlist?list=PLmAptfqzxVEUD7-w180kVApknWHJCXf0j&amp;amp;si=nhW-vxct0qnYSsCl" target="_blank" rel="noopener"&gt;Microsoft Sentinel&lt;/A&gt;, &lt;A href="https://youtube.com/playlist?list=PLmAptfqzxVEUEF0pNXGwAX97ci1keplfx&amp;amp;si=rkwa1WUVWnkduxyl" target="_blank" rel="noopener"&gt;Microsoft Defender XDR&lt;/A&gt; and &lt;A href="https://youtube.com/playlist?list=PLmAptfqzxVEU3XLdZ7TbwkmCaRmxP1uqN&amp;amp;si=WqIv-n3BxqmlrCUS" target="_blank" rel="noopener"&gt;Microsoft Security Copilot&lt;/A&gt; all change month to month- and no single person keeps up with all of it alone. &lt;STRONG&gt;The community is where that gap gets closed. When I read how someone else tuned a detection in their environment, or when someone responds to something I posted with a problem I hadn't considered, my own work gets better.&lt;/STRONG&gt; &lt;STRONG&gt;It's a feedback loop you don't get from documentation.&lt;/STRONG&gt; The other part I value is that it works in both directions: I started as a reader, learning from people more experienced than me, and now I'm at a point where I can give some of that back. Watching that shift happen has been genuinely motivating.&lt;/P&gt;
&lt;H5&gt;&lt;SPAN class="lia-text-color-21"&gt;&lt;STRONG&gt;How long have you been working with Microsoft Security Products?&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;Over ten years! My way into Microsoft security ran through infrastructure rather than security itself. I started out administering Active Directory and VMware environments, the on-premises world, and that is where I first understood identity, endpoints and the quiet attack surface they create. At the time, security was something layered on top of infrastructure. What changed everything was the shift to the cloud.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;As the environments I worked in moved into Microsoft Azure and Microsoft 365, the old separation between "running things" and "securing things" stopped making sense. In a cloud-first world, the identity is the perimeter, the sign-in log is the crime scene, and the telemetry that used to be scattered across servers suddenly lives in one place you could actually query. That was the moment Microsoft's security stack became less of a product set and more of a working environment for me.&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;As I moved from running infrastructure into roles centered on defending it, first leading IT infrastructure and security as a team lead, then as an IT Security Expert, and now as IT Security Manager focused on architecture and incident response in an Azure and M365 environment, Sentinel and Defender XDR went from tools I knew of to tools I work in every day. The infrastructure background turned out to be an advantage rather than a detour. Detection engineering makes far more sense once you have run the Active Directory and the endpoints that generate the very signals you are now writing detections against, and cloud security makes far more sense once you have felt the limits of the on-premises model it replaced. The part that keeps me engaged is that none of this stands still. The cloud security landscape changes constantly, the work is never quite finished, and that is exactly what I like about it.&lt;/P&gt;
&lt;H5&gt;&lt;SPAN class="lia-text-color-21"&gt;&lt;STRONG&gt;What Microsoft Security features or products have provided the most impact?&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;The single biggest impact for me comes from Microsoft Sentinel as a cloud-native SIEM and SOAR platform. The move away from a self-hosted SIEM matters more than it first appears. A traditional SIEM is itself a piece of infrastructure that has to be sized, hosted, patched, and scaled, and that effort constantly competes with the actual security work. Microsoft Sentinel removes that layer. There is no platform estate to keep alive and no capacity planning for the SIEM itself, which frees attention for what actually matters: getting the right telemetry in and getting detection and response right.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;What I value most is how naturally Sentinel fits into modern, cloud-first environments. When the landscape you are protecting already lives in Azure and Microsoft 365, a security platform that lives in the same place removes an entire class of integration friction. The other strength is the breadth of data onboarding. &lt;STRONG&gt;With a traditional SIEM, connecting a new log source was often a small project of its own, with connectors to build and parsers to maintain. With Sentinel, that friction is largely gone. Whether a source sits on-premises, in another cloud or in a third-party product, getting it in is straightforward, and the platform still provides the integration depth that genuinely matters rather than a shallow connection.&lt;/STRONG&gt; Microsoft Sentinel handles almost anything you point it at.&lt;/P&gt;
&lt;P&gt;Equally important is that SIEM and SOAR are not two separate platforms here. The orchestration and automation layer is built into the same solution, so response playbooks run on the same data that the detections are built on. For architecture, that is a real advantage: detection and response are designed as one system rather than stitched together afterwards. The central telemetry layer is one of the few decisions that is genuinely hard to reverse later, and Sentinel makes that an easy one to defend.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;H5&gt;&lt;STRONG&gt;&lt;SPAN class="lia-text-color-21"&gt;What advice do you have for others who would like to get involved in the Microsoft Community?&lt;/SPAN&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&lt;STRONG&gt;My advice is to start before you feel ready.&lt;/STRONG&gt; I read &lt;A href="https://techcommunity.microsoft.com/category/microsoft-security" target="_blank" rel="noopener"&gt;Microsoft Tech Community&lt;/A&gt; (forums) for years before I posted anything myself, always with the feeling that I needed more experience first, that I would just be adding noise. That was the wrong instinct. The moment I actually started contributing, the feedback I got back made my own work better, and I realised the bar for being useful is far lower than it looks from the outside. You do not need to be the leading expert on a topic. You need a real problem you have worked through and the willingness to write down how you solved it. Someone else is stuck on exactly that problem right now. Start small, stay consistent, and treat the community as an exchange rather than a stage. Consistency matters more than any single brilliant post.&lt;/P&gt;
&lt;H5&gt;&lt;SPAN class="lia-text-color-20"&gt;&lt;STRONG&gt;&lt;SPAN class="lia-text-color-21"&gt;Alles rund um sein Buch &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN class="lia-text-color-21"&gt;(&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="lia-text-color-19"&gt;&lt;EM style="color: rgb(30, 30, 30);"&gt;All About His Book)&lt;/EM&gt;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;Last year, I published "Die neue Realität der Cybersecurity" (2025). It tackles a question every security team is dealing with right now: “Where does AI genuinely strengthen security architecture and incident response, and where is it just noise?” Rather than staying abstract, the book takes the practitioner's side of that question, looking at how AI actually changes the work of designing defensible systems and responding to incidents, and where the limits and risks really are. It is written for the people doing the work, security architects, IR practitioners and the leaders who have to make decisions about AI without the marketing gloss. If that question is on your desk too, it is worth a look.&lt;/P&gt;
&lt;H5&gt;&lt;SPAN class="lia-text-color-21"&gt;&lt;STRONG&gt;Connect with Marcel&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;img /&gt;
&lt;UL&gt;
&lt;LI&gt;Microsoft Tech Community: &lt;A href="https://techcommunity.microsoft.com/users/marcel_graewer/3421956" target="_blank" rel="noopener"&gt;@marcel_graewer&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Linkedin:&amp;nbsp;&lt;A href="https://www.linkedin.com/in/mgraewer/" target="_blank" rel="noopener"&gt;https://www.linkedin.com/in/mgraewer/&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Github:&amp;nbsp;&lt;A href="https://github.com/bifrost0x" target="_blank" rel="noopener"&gt;https://github.com/bifrost0x&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Blogs:&amp;nbsp;&lt;A href="https://graewer.com/" target="_blank" rel="noopener"&gt;graewer.com&lt;/A&gt; and &lt;A href="https://magra-sec.de/" target="_blank" rel="noopener"&gt;magra-sec.de&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Book:&amp;nbsp;&lt;EM&gt;Die neue Realität der Cybersecurity &lt;/EM&gt;(ISBN: 9783695708833)&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Marcel Graewer is currently an IT-Sec&lt;/EM&gt;&lt;EM&gt;urity Manager at &lt;A href="https://www.festool.com/" target="_blank" rel="noopener"&gt;Festool Group&lt;/A&gt; and holds the &lt;A href="https://www.isc2.org/certifications/cissp?utm_source=google&amp;amp;utm_medium=cpc&amp;amp;utm_campaign=GBL-Ecomm-CISSP-cert&amp;amp;utm_term=search&amp;amp;utm_content=GBL-Ecomm-CISSP-cert&amp;amp;gad_source=1&amp;amp;gad_campaignid=23365755021&amp;amp;gbraid=0AAAAAD-S_-P5jgsryePoqJ52i0bkqcBkX&amp;amp;gclid=CjwKCAjwt7XQBhBkEiwAtStpp-0TjJpoQwcPR1jIxr7VMiQ_qUddvTYS11vBdwtntTx0ZIQUj4jzbhoC6VkQAvD_BwE" target="_blank" rel="noopener"&gt;CISSP&lt;/A&gt; certification. Outside of work, he is happiest when experimenting with&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt; technology on his own terms. He runs a Proxmox-based homelab with a range of self-hosted services and Docker containers, using it as both a playground and a testing ground. It gives him space to break things, learn, and explore without the constraints of formal change processes. He also spends time on Hack The Box and TryHackMe, believing that staying sharp on the offensive side makes him a stronger defender. Away from the keyboard, his life is refreshingly analog. He and his family, including two children, live in an old house that always seems to have one more project waiting. Between the homelab and the house, there is never a shortage of things to fix, and that suits him just fine.&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR style="border: none; border-top: 2px solid #bfbfbf; margin: 20px 0;" /&gt;
&lt;H5&gt;&lt;STRONG&gt;Learn and Engage with the Microsoft Security Community&amp;nbsp;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;UL&gt;
&lt;LI&gt;Log in and follow this&amp;nbsp;&lt;A href="https://aka.ms/bpblog" target="_blank" rel="noopener"&gt;Microsoft Security Community Blog&lt;/A&gt;.&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;Follow = Click the heart in the upper right when you're logged in 🤍&lt;A href="https://aka.ms/MVPMDOvideo" target="_blank" rel="noopener"&gt;.&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI&gt;Join the&amp;nbsp;&lt;A href="https://aka.ms/securitycommunity" target="_blank" rel="noopener"&gt;Microsoft Security Community&lt;/A&gt;&amp;nbsp;and be notified of upcoming events, product feedback surveys, and more.&lt;/LI&gt;
&lt;LI&gt;Get early access to Microsoft Security products and provide feedback to engineers by joining the&amp;nbsp;&lt;A href="https://aka.ms/bpadvisors" target="_blank" rel="noopener"&gt;Microsoft Security Advisors.&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Join the&amp;nbsp;&lt;A href="https://aka.ms/pbseclinkedin" target="_blank" rel="noopener"&gt;Microsoft Security Community LinkedIn Group&amp;nbsp;&lt;/A&gt;and follow the&amp;nbsp;&lt;A href="https://aka.ms/pbentralinkedin" target="_blank" rel="noopener"&gt;Microsoft Entra Community on LinkedIn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2026 19:17:27 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/microsoft-security-community-spotlight-marcel-graewer/ba-p/4523372</guid>
      <dc:creator>RenWoods</dc:creator>
      <dc:date>2026-05-27T19:17:27Z</dc:date>
    </item>
    <item>
      <title>Securing AI Agents End‑to‑End: Connecting Purview DSPM, Agent 365, and the AI Security Dashboard</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/securing-ai-agents-end-to-end-connecting-purview-dspm-agent-365/ba-p/4521155</link>
      <description>&lt;P&gt;&lt;STRONG&gt;The Challenge:&lt;/STRONG&gt;&lt;BR /&gt;Organizations deploying Microsoft Copilot and custom AI agents face a critical gap: &lt;STRONG&gt;security visibility is fragmented&lt;/STRONG&gt; across data protection, identity governance, and threat detection tools. While Microsoft provides powerful capabilities through Purview Data Security Posture Management (DSPM), Agent 365, and the AI Security Dashboard, practitioners often struggle to understand &lt;STRONG&gt;how these components work together&lt;/STRONG&gt; to deliver unified AI security posture management.&lt;/P&gt;
&lt;P&gt;This blog provides an architectural and operational blueprint for connecting these three pillars into a cohesive security framework that &lt;STRONG&gt;security architects can implement today&lt;/STRONG&gt;.&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;The Three Pillars: Capabilities Overview&lt;/STRONG&gt;&lt;/H3&gt;
&lt;H4&gt;&lt;STRONG&gt;Microsoft Purview DSPM for AI&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Purview DSPM extends data‑centric security controls to AI interactions. Its key capabilities include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Sensitivity labels with EXTRACT usage rights&lt;/STRONG&gt; that govern whether AI agents can read and process sensitive content&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Data Loss Prevention (DLP) policies&lt;/STRONG&gt; that block or audit AI interactions involving confidential data across Copilot, SharePoint, OneDrive, and Teams&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Comprehensive audit logging&lt;/STRONG&gt; that captures AI‑to‑data interactions, including user identity, agent identity, data classification, and the action taken&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Insider Risk Management integration&lt;/STRONG&gt; that detects anomalous agent behavior patterns, such as bulk or unusual data access&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;DSPM operates at the &lt;STRONG&gt;data layer&lt;/STRONG&gt;, answering a foundational question:&lt;BR /&gt;&lt;EM&gt;What sensitive information can this agent access, and what is it doing with that data?&lt;/EM&gt;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Microsoft Agent 365&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Agent 365 provides a unified control plane for governing AI agent identity, access, and lifecycle across the Microsoft 365 ecosystem. Core components include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Agent Registry&lt;/STRONG&gt;, backed by Entra Agent IDs, providing a unique identity for every Copilot Studio agent, custom agent, and supported third‑party AI integration&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Conditional Access policies&lt;/STRONG&gt; that enforce real‑time access controls based on agent identity, user context, device compliance, and risk signals&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Centralized observability&lt;/STRONG&gt;, with dashboards showing agent‑to‑agent interactions, agent‑to‑human conversations, and near real‑time telemetry&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Governance workflows&lt;/STRONG&gt; that support agent approval, lifecycle management, suspension, and decommissioning&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Agent 365 operates at the &lt;STRONG&gt;identity and control layer&lt;/STRONG&gt;, answering:&lt;BR /&gt;&lt;EM&gt;Which agents exist, who authorized them, and what access boundaries are enforced?&lt;/EM&gt;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;AI Security Dashboard&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;The AI Security Dashboard aggregates security signals from Entra, Purview, and Defender to provide a unified risk view across all AI assets. It delivers:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;AI asset inventory&lt;/STRONG&gt;, cataloging Copilot instances, custom agents, and third‑party models with associated risk context&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Misconfiguration detection&lt;/STRONG&gt;, identifying agents with excessive permissions, missing conditional access policies, or DLP coverage gaps&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Attack path visualization&lt;/STRONG&gt;, showing how compromised agents could pivot to sensitive data or escalate privileges&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Integration with Microsoft Security Copilot&lt;/STRONG&gt;, enabling natural‑language investigation of AI security risks and incidents&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The Dashboard operates at the &lt;STRONG&gt;aggregation and recommendation layer&lt;/STRONG&gt;, answering:&lt;BR /&gt;&lt;EM&gt;What is my overall AI security posture, and where should remediation be prioritized?&lt;/EM&gt;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;The Unified Architecture: How Signals Flow End-to-End&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;Understanding the technical integration requires mapping how&amp;nbsp;&lt;STRONG&gt;identity, data, and security signals&lt;/STRONG&gt; flow across these three systems.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Identity Foundation (Microsoft Entra):&lt;/STRONG&gt;&lt;BR /&gt;Every AI agent is assigned a unique Entra Agent ID at creation. This identity becomes the anchor for all security controls—conditional access policies in Agent 365, audit attribution in Purview, and risk correlation in the AI Security Dashboard. When a Copilot Studio agent is deployed, Entra automatically registers it with Agent 365 and propagates identity metadata to connected security services.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Data Interaction Telemetry (Microsoft Purview):&lt;/STRONG&gt;&lt;BR /&gt;When an agent accesses SharePoint files, reads emails, or queries structured data, Purview captures detailed audit events that include agent identity, user context, data classification labels, and enforcement outcomes. These events flow into Purview’s unified audit log and are accessible through the Compliance portal, Microsoft Graph, and SIEM integrations. Crucially, Purview enforces sensitivity labels with EXTRACT usage rights—if a document is labeled &lt;EM&gt;Confidential&lt;/EM&gt; without EXTRACT permission, the agent’s request is blocked &lt;STRONG&gt;before&lt;/STRONG&gt; content reaches the AI model.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Control Plane Enforcement (Agent 365):&lt;/STRONG&gt;&lt;BR /&gt;Agent 365 applies identity‑based governance by evaluating Entra signals and surfaced risk indicators. During policy evaluation, the control plane verifies whether the agent is registered, whether the invoking user satisfies authentication requirements, and whether recent signals (such as DLP violations) warrant blocking execution. Agent 365 also provides observability views that correlate agent activity with security events, helping administrators identify unmanaged or unauthorized (“shadow”) agents.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Aggregated Risk View (AI Security Dashboard):&lt;/STRONG&gt;&lt;BR /&gt;The AI Security Dashboard correlates telemetry from:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Entra&lt;/STRONG&gt; — conditional access decisions, authentication anomalies, and privileged identity usage&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Purview&lt;/STRONG&gt; — DLP violations, sensitivity label mismatches, and Insider Risk Management signals&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Defender&lt;/STRONG&gt; — threat detections, application posture assessments, and suspicious activity indicators&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;These signals are correlated by agent identity and time, then surfaced as risk cards with contextual severity and recommended remediation actions. The Dashboard does not replace the underlying tools; instead, it provides a consolidated view that helps teams focus on the most impactful risks.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;The diagram below illustrates how identity, data, and threat signals flow across the three AI security pillars.&lt;/EM&gt;&lt;/P&gt;
&lt;img&gt;&lt;BR /&gt;
&lt;P&gt;Figure 1: End‑to‑end AI security architecture. Enforcement happens at the data layer (Purview) and identity layer (Agent 365 via Entra). The AI Security Dashboard aggregates—rather than replaces—underlying security controls.&lt;/P&gt;
&lt;/img&gt;
&lt;H3&gt;&lt;STRONG&gt;From Architecture to Action: Telemetry &amp;amp; Enforcement Flow&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;Understanding architecture is essential—but practitioners need to know&amp;nbsp;&lt;STRONG&gt;when and where enforcement occurs&lt;/STRONG&gt; during a real agent invocation. The sequence below illustrates runtime interaction between a user, an AI agent, and the three security pillars.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The Critical Distinction: Two Enforcement Layers&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Enforcement occurs at &lt;STRONG&gt;two distinct points&lt;/STRONG&gt; in the request lifecycle.&lt;/P&gt;
&lt;P&gt;First, &lt;STRONG&gt;Microsoft Entra&lt;/STRONG&gt; validates agent identity and evaluates conditional access policies &lt;STRONG&gt;before execution begins&lt;/STRONG&gt;. If the agent is not registered, if the user fails authentication requirements, or if policy conditions require blocking, execution is denied immediately.&lt;/P&gt;
&lt;P&gt;Second, when execution is permitted, &lt;STRONG&gt;Purview DSPM&lt;/STRONG&gt; enforces data access controls inline. Every attempt to access documents, emails, or structured data is evaluated in real time. If a document is labeled &lt;EM&gt;Confidential&lt;/EM&gt; without EXTRACT rights, Purview blocks the request and returns no sensitive content to the agent.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Telemetry Generation Across the Stack&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Each step produces structured telemetry. Entra logs authentication attempts and policy decisions. Purview records AI interaction audit events, including enforcement outcomes. Agent 365 correlates identity and behavior signals to maintain agent posture and observability. These combined signals are surfaced in the AI Security Dashboard, which correlates activity across time and identity to present prioritized risk insights.&lt;/P&gt;
&lt;P&gt;Make the &lt;STRONG&gt;“where enforcement happens”&lt;/STRONG&gt; distinction explicit (data vs. identity).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;&lt;BR /&gt;
&lt;P&gt;Figure 2: Purview enforces data controls inline, Agent 365 enforces identity and execution controls, and the AI Security Dashboard correlates signals for prioritization.&lt;/P&gt;
&lt;/img&gt;
&lt;H3&gt;&lt;STRONG&gt;Practitioner Scenario: Detecting and Blocking Agent Data Exposure&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;&lt;STRONG&gt;Context:&lt;/STRONG&gt; Your organization deploys a custom Copilot Studio agent to summarize sales proposals stored in SharePoint. Several documents contain customer PII labeled "Highly Confidential" with no EXTRACT usage rights granted.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Incident Timeline: Agent Data Exposure Detection → Remediation&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Detection&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;The agent attempts to access SharePoint files through Microsoft Graph.&lt;/LI&gt;
&lt;LI&gt;Purview DSPM evaluates sensitivity labels and identifies restricted documents.&lt;/LI&gt;
&lt;LI&gt;A DLP policy blocks access and logs a violation with full context.&lt;/LI&gt;
&lt;LI&gt;The audit event appears in the Purview unified audit log within minutes.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;Visibility&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Agent 365 flags the blocked interaction in its observability dashboard.&lt;/LI&gt;
&lt;LI&gt;The AI Security Dashboard surfaces a &lt;EM&gt;High‑severity&lt;/EM&gt; risk card titled “Agent accessing restricted data.”&lt;/LI&gt;
&lt;LI&gt;Security teams investigate the agent using Security Copilot to determine scope and recurrence.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;Remediation&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;An administrator applies an Entra conditional access policy to suspend the agent.&lt;/LI&gt;
&lt;LI&gt;Data permissions are adjusted to restrict access or explicitly grant EXTRACT rights where justified.&lt;/LI&gt;
&lt;LI&gt;The AI Security Dashboard reflects a reduced risk score once controls are validated.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;Outcome:&lt;/STRONG&gt;&lt;BR /&gt;The incident is contained quickly, audit evidence is preserved, and the agent is restored with least‑privilege access—without disrupting legitimate business workflows.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;&lt;BR /&gt;
&lt;P&gt;Figure 3: A single DLP violation triggers coordinated detection, investigation, and remediation across Purview, Agent 365, and the AI Security Dashboard within 30 minutes.&lt;/P&gt;
&lt;/img&gt;
&lt;H3&gt;&lt;STRONG&gt;Division of Responsibility: What Each Tool Does&lt;/STRONG&gt;&lt;/H3&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;&lt;STRONG&gt;Tool&lt;/STRONG&gt;&lt;/th&gt;&lt;th&gt;&lt;STRONG&gt;Primary Function&lt;/STRONG&gt;&lt;/th&gt;&lt;th&gt;&lt;STRONG&gt;Key Signals&lt;/STRONG&gt;&lt;/th&gt;&lt;th&gt;&lt;STRONG&gt;Enforcement Capability&lt;/STRONG&gt;&lt;/th&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th&gt;&lt;STRONG&gt;Purview DSPM&lt;/STRONG&gt;&lt;/th&gt;&lt;td&gt;Data-layer protection and audit&lt;/td&gt;&lt;td&gt;Sensitivity labels, DLP violations, data access patterns&lt;/td&gt;&lt;td&gt;Blocks API calls violating DLP or label policies&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th&gt;&lt;STRONG&gt;Agent 365&lt;/STRONG&gt;&lt;/th&gt;&lt;td&gt;Identity and lifecycle governance&lt;/td&gt;&lt;td&gt;Agent registry, conditional access hits, observability telemetry&lt;/td&gt;&lt;td&gt;Denies agent invocation based on Entra policies&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th&gt;&lt;STRONG&gt;AI Security Dashboard&lt;/STRONG&gt;&lt;/th&gt;&lt;td&gt;Unified risk aggregation&lt;/td&gt;&lt;td&gt;Cross-product signals from Entra, Purview, Defender&lt;/td&gt;&lt;td&gt;No direct enforcement—provides recommendations and prioritization&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;STRONG&gt;Critical Distinction:&lt;/STRONG&gt; Enforcement happens at &lt;STRONG&gt;two layers&lt;/STRONG&gt;—Purview blocks data access violations, while Agent 365 (via Entra) blocks agent invocation. The Dashboard does not enforce policies but accelerates investigation and remediation by correlating signals that would otherwise require manual analysis across three separate consoles.&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Key Takeaways for Practitioners&lt;/STRONG&gt;&lt;/H3&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt; Agent identity is the integration anchor.&lt;/STRONG&gt; Every security control—DLP policies, conditional access, audit logs, risk scoring—relies on Entra Agent IDs. Ensure all agents are properly registered in Agent 365 before production deployment.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Purview enforces at the data layer, Agent 365 at the identity layer.&lt;/STRONG&gt; Use both—Purview prevents unauthorized data exfiltration, while Agent 365 prevents unauthorized agent execution. Neither is redundant.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; The AI Security Dashboard is for prioritization, not replacement.&lt;/STRONG&gt; Continue using Purview Compliance Portal for detailed DLP investigations and Agent 365 registry for operational monitoring. Use the Dashboard to identify which risks warrant immediate attention.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Audit logs are your ground truth.&lt;/STRONG&gt; All three tools consume Purview audit events. Integrate these logs with Microsoft Sentinel or your SIEM for long-term retention and advanced threat hunting.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Shadow agents are your blind spot.&lt;/STRONG&gt; Regularly audit the Agent 365 registry against actual AI deployments (Copilot Studio, Azure OpenAI, third-party integrations) to identify unregistered instances.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;As AI agents become embedded in everyday work, security teams must move beyond feature‑level understanding and adopt an &lt;STRONG&gt;end‑to‑end enforcement mindset&lt;/STRONG&gt;. The combination of Purview DSPM, Agent 365, and the AI Security Dashboard provides the building blocks—but value is realized only when they are implemented as a unified model.&lt;/P&gt;
&lt;P&gt;How are you governing AI agents in your environment today? Share your experiences and patterns in the comments—especially where identity, data, and security signals intersect.&lt;/P&gt;</description>
      <pubDate>Tue, 19 May 2026 18:08:13 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/securing-ai-agents-end-to-end-connecting-purview-dspm-agent-365/ba-p/4521155</guid>
      <dc:creator>SRay</dc:creator>
      <dc:date>2026-05-19T18:08:13Z</dc:date>
    </item>
    <item>
      <title>State Explosion Security Problem in AI-Era Software Supply Chains</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/state-explosion-security-problem-in-ai-era-software-supply/ba-p/4518255</link>
      <description>&lt;H4&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Introduction&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To see why this problem scales so quickly, start with the smallest possible change: a single line of code. In modern software, even a tiny edit is rarely just a local modification. It can change execution flow, introduce a new dependency, expose sensitive data, or quietly shift the purpose of the package itself. What looks trivial in a diff can create a materially different security outcome. That is why supply chain defenders cannot afford to treat small code changes as small security events.&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;How a Single Line Changes Package Intent&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Every software package exists in a particular state at a particular moment in time. Imagine a benign version — State X — that behaves exactly as intended. Now add one line of code. That small edit can shift the package into a new state with different behavior and, potentially, a very different risk profile.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The security issue is not the added line by itself. It is&amp;nbsp;the&amp;nbsp;fact that the package now has to be interpreted differently. A tiny diff can change the role of the entire component, which means defenders have to reason&amp;nbsp;about&amp;nbsp;the resulting behavior, not just the textual change.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;SPAN data-contrast="auto"&gt;That is why file-level scanning breaks down so quickly. A change in one file can alter the behavior of the entire package because software semantics emerge from how components interact. Security systems therefore need to analyze packages as composed systems, not as a series of isolated file edits.&lt;/SPAN&gt; &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Why the whole package matters&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This matters even more in modern supply chain attacks, where malicious intent is rarely concentrated in one obvious file. More often, the behavior is distributed across several files that look harmless when viewed independently.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="·" data-font="Symbol" data-listid="5" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;·&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;File A&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;defines an encoded string constant. Looks like a config value.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:36,&amp;quot;335559739&amp;quot;:36}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="·" data-font="Symbol" data-listid="5" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;·&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;File B&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;provides a decode function.&amp;nbsp;Looks&amp;nbsp;like a utility.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:36,&amp;quot;335559739&amp;quot;:36}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="·" data-font="Symbol" data-listid="5" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;·&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;File C&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;(setup.py / postinstall) imports both, decodes, and executes.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:36,&amp;quot;335559739&amp;quot;:36}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Viewed independently, each file may appear benign.&amp;nbsp;No single file has to trigger a clear signature, rule, or heuristic.&amp;nbsp;The malicious behavior only becomes visible when you reconstruct&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;how the files interact as a system&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;. Any scanner that evaluates files one by one without rebuilding that interaction is likely to miss the real behavior.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Why every change demands re-analysis&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&lt;SPAN data-contrast="auto"&gt;Every meaningful state change — a commit, pull request, version bump, or package&amp;nbsp;publish&amp;nbsp;— can alter the semantics of the software. That means defenders cannot stop at diff inspection or lightweight pattern matching. The real question is not only what changed, but what the software now does.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Quantifying the problem&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The scale of the problem becomes clearer when you look at how many software state changes occur across the ecosystem every day:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="·" data-font="Symbol" data-listid="5" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;·&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="4" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;GitHub alone&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;recorded nearly&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;1 billion commits in 2025&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;, merged an average of&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;43.2 million pull requests per month&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;, and now hosts roughly&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;630 million repositories&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;In 2026, GitHub was projected to reach roughly&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;38 million commits per day.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="·" data-font="Symbol" data-listid="5" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;·&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="5" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;npm&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;has grown to well over&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;2 million packages&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;, making JavaScript one of the largest public package ecosystems.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="·" data-font="Symbol" data-listid="5" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;·&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="6" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;PyPI&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;published more than&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;130,000 new projects in 2025&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;and more than&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;3.9 million new files&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;in the same year.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="·" data-font="Symbol" data-listid="5" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;·&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="7" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;NuGet&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;serves package downloads at&amp;nbsp;massive&amp;nbsp;operational scale, with recent weekly totals in the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;5 to 6 billion&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;range.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="·" data-font="Symbol" data-listid="5" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;·&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="8" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Maven Central&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;indexed more than&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;20 million packages&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;and published more than&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;3.2 million packages in 2025&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Taken together, these ecosystems are generating an enormous stream of new software states. Some numbers describe repositories, some describe publishes, and some describe downloads, but they all point to the same reality: the scale of software movement is already massive before you even account for the acceleration from AI-assisted development.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The number of state changes is already enormous, and AI-assisted development is&amp;nbsp;increasing it&amp;nbsp;even further. The result is not just more code, but more package states that may require meaningful security interpretation.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Why the math breaks traditional scanning&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{}"&gt;Assume a single semantic package analysis takes 30 seconds, which is a reasonable range for LLM-based inference. Scanning 50,000 packages would require roughly 1.5 million seconds of compute time per day — about 417 hours. But the ecosystem only gives defenders 24 hours before the next wave of packages arrives. Without aggressive parallelism and purpose-built infrastructure, backlog becomes inevitable.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;The scanning bottleneck&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This leaves modern scanning systems with a fundamental bottleneck:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Heuristic and signature-based scanners&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;are fast. They can match known patterns in milliseconds and work well for familiar malware families or repeated behaviors. Some systems also use emulation or detonation, but these approaches still struggle to deliver deep reasoning at ecosystem scale. That makes&amp;nbsp;them&amp;nbsp;easier&amp;nbsp;to bypass with novel, well-structured, or AI-generated code that behaves maliciously without resembling previously known samples.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;LLM-based semantic analysis&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;can reason&amp;nbsp;about&amp;nbsp;intent. It can follow behavior across files, recognize obfuscated exfiltration paths, and explain why a package is suspicious even when the code appears ordinary at first glance. The tradeoff is cost, latency, and trust: inference takes seconds rather than milliseconds, and a single package may require multiple reasoning passes. At&amp;nbsp;ecosystem&amp;nbsp;scale, that becomes a serious infrastructure challenge.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Neither approach is sufficient on its own.&amp;nbsp;Heuristics provide speed without deep understanding, while semantic models provide understanding without inherent scale.&amp;nbsp;Closing the gap requires systems that combine both: package-level reasoning with the latency and throughput needed for production supply chains.&lt;/SPAN&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;335559738&amp;quot;:180,&amp;quot;335559739&amp;quot;:180}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Heuristics often miss novel attacks, while LLM-based approaches remain too slow to apply inline at large scale. That gap between understanding and throughput is where supply chain malware can persist.&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;What needs to change&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Closing that gap will require a different class of supply chain security systems. Detonation can help in some cases, but it is too slow and expensive to apply inline to every&amp;nbsp;package&amp;nbsp;state change. What is needed is a system that can:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="Aptos" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Analyze entire packages as a unit&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;— not individual files. The intent lives in the interaction between files, not within any single one.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:36,&amp;quot;335559739&amp;quot;:36}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Run semantic analysis at data-plane speed&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;— every package, every version, on the hot path, with latency low enough for inline enforcement. Not async advisories. Not CI-time checks. Inline, before delivery.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="Aptos" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Handle the state explosion&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;— millions of state changes per day, each&amp;nbsp;requiring&amp;nbsp;full re-analysis. This is an infrastructure problem as much as a security problem: rate limiting, backpressure, connection pooling, regional failover, model versioning — the same hard distributed systems problems, with security stakes.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:36,&amp;quot;335559739&amp;quot;:36}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="4" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Maintain high accuracy under evasion&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;— attackers deliberately use encoding, string splitting, dynamic imports, polyglot files, and similar techniques to reduce detection quality. The scanner must continue to classify packages accurately even when the code is designed to obscure intent.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335551550&amp;quot;:3,&amp;quot;335551620&amp;quot;:3}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;The Latency-Accuracy Tradeoff: Malware Detection as an ML Problem&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;At cloud scale, malware detection is governed by a hard tradeoff between&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;latency, accuracy, throughput, and cost&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;. The fastest detectors are typically shallow: signatures, heuristics, and lightweight models can make decisions in milliseconds, but they often miss novel, compositional, or intent-level attacks. Deeper semantic analysis can improve recall and resilience against evasion, but it also increases inference time, compute cost, and operational complexity. As a result, defenders cannot&amp;nbsp;optimize for&amp;nbsp;accuracy in isolation; they must deliver strong detection quality within strict performance constraints.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This makes malware detection not just a cybersecurity problem, but a&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;machine learning and distributed systems&lt;/STRONG&gt; problem&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;. In modern software supply chains, AI-assisted development increases the number of package states and enables attackers to generate variants at high speed, expanding&amp;nbsp;the space defenders must reason over. The challenge is therefore to build detection architectures that preserve semantic depth while remaining fast enough for inline use at&amp;nbsp;global&amp;nbsp;scale.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The gap between the rate of software change and the capacity to analyze it is widening. That gap is the attack surface. If defenders cannot inspect software at the speed it is being produced and published, attackers will continue to exploit the delay. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;What the industry needs now is a cloud-scale malware analysis capability that can deliver l&lt;STRONG&gt;ow latency, low cost, high accuracy, and the flexibility to meet different operational requirements&lt;/STRONG&gt; , such as SLAs, false-positive tolerance, and enforcement policies , without compromising on package-level semantic analysis.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2026 20:41:50 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/state-explosion-security-problem-in-ai-era-software-supply/ba-p/4518255</guid>
      <dc:creator>nirwandogra</dc:creator>
      <dc:date>2026-05-18T20:41:50Z</dc:date>
    </item>
  </channel>
</rss>

