Threat Analytics
Doc updateThe documentation now directs users to check the Threat intelligence section when an emailed threat analytics report is missing from Threat analytics.
Daily Defender NewsEvery tracked change across Microsoft Defender documentation, in plain English. Browse the archive from 1 January 2026 → About this project →
The period was dominated by documentation maintenance, with the most consequential update affecting Defender for Endpoint network configuration. Commercial connectivity guidance now says environments may also need Microsoft 365 Unified Domains URLs allowed, while separate guidance adds a clearer response path for automatic attack disruption that causes full isolation. Smaller updates correct an ABAP audit-log table name and explain where to find missing Threat Analytics reports.
Both commercial connectivity topics now say that, beyond the URLs in their existing tables, some environments may also need URLs from the Microsoft 365 Unified Domains list. Administrators configuring or validating Defender for Endpoint access should review that linked list.
The machine-alert guidance now identifies automatic attack disruption triggering full isolation as a possible cause. It also points administrators to an isolation exclusion rule when selective isolation is preferred.
If an emailed threat analytics report is absent from the expected Threat analytics section, administrators are now directed to check the Threat intelligence section instead.
The supported-table list now spells the table as `ABAPAuditLog_CL`, restoring the missing final “L.” Detection authors using ABAP audit-log data should use this corrected name.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
The documentation now directs users to check the Threat intelligence section when an emailed threat analytics report is missing from Threat analytics.
The supported table list now spells `ABAPAuditLog_CL` correctly, fixing a missing “L.”
The commercial device connectivity documentation now notes that, beyond the listed URLs, some environments might also need to allow URLs from the Microsoft 365 unified domains list.
The documentation now notes that access may also be needed for URLs listed under Microsoft 365 Unified Domains, in addition to the URLs in the existing table.
The documentation fixes spelling errors in the descriptions for the minimum-requirement and external-dependency options.
The documentation corrects “memory manger” to “memory manager” and adjusts spacing before an ellipsis in the mitigation description.
The guidance now notes that the issue can occur when automatic attack disruption triggers full isolation. Administrators can define an isolation exclusion rule to use selective isolation instead.