security
26 TopicsNew audit requirement for Security specializations starts July 2026
Security specializations signal verified, high-caliber capability to customers and Microsoft field teams—and that signal holds up better when the bar is credible. To support that standard, starting July 2026, an independent audit will replace the Customer References requirement for four Security specializations: Cloud Security, Data Security, Identity & Access Management, and Threat Protection. Whether you’re enrolling for the first time or renewing, you’ll need to meet this audit requirement to earn or maintain your credential. Moving to an audit model for these specializations raises the bar, aligns Security with Azure specializations, and gives you a stronger, harder-to-copy advantage in competitive deals and co-sell conversations. When the change goes live, existing partners will be given a six-month extension to their anniversary date to allow time to prepare for the audit. What to do now Review the updated requirements so you know what the audit entails Check your specialization status and renewal date to understand when this applies Start preparing your documentation and evidence now—don’t wait for your renewal window Prepare early to stay in good standing, avoid disruption, and keep your business moving.160Views0likes0CommentsShow you’re a trusted leader in secure AI deployment with the Agentic Security specialization
Differentiate your expertise, build customer trust, and demonstrate readiness to deliver secure AI outcomes as customers move from experimentation to enterprise-wide AI adoption with the Agentic Security specialization, set to launch later in FY27. The Agentic Security specialization provides a clear, credible, and durable market signal that validates a partner's capabilities helping customers strengthen their security posture through AI-powered defense, threat protection, and operational resilience. Whether delivering services, software, or integrated security solutions, partners can earn the specialization to access badging and other key benefits while showcasing their ability to support customers as they strengthen security, improve operational resilience, and scale AI adoption responsibly.395Views0likes2CommentsBehind the Build with Gigamon: Enriching Microsoft Sentinel with Network-Derived Telemetry
Behind the Build is an ongoing series spotlighting standout Microsoft partner collaborations. Each edition dives into the technical and strategic decisions that shape real-world integrations—highlighting engineering excellence, innovation, and the shared customer value created through partnership. Security teams today operate across an expanding set of signals, spanning identity, endpoint, cloud and application environments. Yet many organizations still lack sufficient visibility into how systems communicate across their infrastructure, creating gaps in detection, investigation, and response. In this edition of Behind the Build, I spoke with Srinivas Chakravarty, vice president, cloud ecosystems at Gigamon, about how Microsoft and Gigamon collaborated to bring network-derived telemetry into Microsoft Sentinel, helping customers enrich security investigations with deeper runtime context and AI-driven insights. The Evolution of Network Intelligence and Why It Matters For more than twenty years, Gigamon has helped organizations access and operationalize network traffic across complex environments. Today, the Gigamon Deep Observability Pipeline, helps enable organizations to extract actionable network-derived telemetry across hybrid infrastructure, encrypted traffic, containers, and modern application environments. That foundation makes the Gigamon Deep Observability Pipeline a strong complement to Microsoft Sentinel. Microsoft Sentinel brings together security telemetry from across the enterprise—including identity, endpoint, cloud, application, and network data sources—while Gigamon contributes enriched network-derived telemetry that provides additional runtime context into how systems, applications, and services communicate. Together, these signals can help organizations gain deeper insight for threat detection, investigation, and response. As Srinivas put it: “You have logs, you have metrics, you have traces, but network telemetry completes the picture.” Together, these data sources provide deeper context for threat detection, investigation, and AI-driven analysis. Read the full announcement here: Behind the Build with Gigamon: Enriching Microsoft Sentinel with Network-Derived Telemetry Original Publication: Microsoft Sentinel Blog, June 30th, 202672Views0likes0CommentsExtending Sentinel Data Integration: Azure Blob Storage Support for CCF Connectors
As organizations scale their security operations, the ability to ingest, process, and analyze high volumes of data reliably becomes increasingly critical. Microsoft Sentinel continues to expand its ecosystem through the Codeless Connector Framework (CCF), enabling ISVs to build and deliver integrations with Sentinel faster while simplifying deployment for customers. Today, CCF extends even further with support for Azure Blob Storage, introducing a new pattern for how data can be delivered into Sentinel. Expanding Connector Patterns with Azure Blob Storage CCF has traditionally enabled connectors that integrate directly with partner APIs and data sources. With this latest enhancement, ISVs can now build connectors that read data from Azure Blob Storage—unlocking new flexibility in how security data is collected and delivered. In this model, an ISV writes data to an Azure Blob Storage account. The Sentinel connector then reads from that storage layer, using Azure-native components such as Event Grid and storage queues to process events and forward them through data collection rules (DCR) into Log Analytics workspace. This approach introduces a durable data layer between the data source and Sentinel, enabling more resilient and scalable ingestion scenarios. Read the full announcement here: Extending Sentinel Data Integration: Azure Blob Storage Support for CCF Connectors Original Publication: Microsoft Sentinel Blog, May 5th, 2026244Views0likes0CommentsSecuring and governing AI agents before deployment
April 30 | 2:00-3:00 PM (GTM +10) Join this live webinar to learn how to secure and govern AI agents before they go live. Explore how to provision agents with Entra Agent ID, manage identities and credentials, enforce least-privilege access, and prevent risks like Shadow AI and agent sprawl. Join to gain practical guidance on governing AI agents across their full lifecycle—so you can deploy with confidence. To view the session live, register here: Securing and Governing AI Agents Before They Go Live You can view previous Security for Software Development Company series sessions on demand here: Security for Software Development Company Series: Securing the Agentic Era