← Previous day

Today in Microsoft Defender

Every tracked change across Microsoft Defender documentation, in plain English. Browse the archive from 1 January 2026 → About this project →

Day in brief

Defender connectivity guidance adds Microsoft 365 Unified Domains allowlists

The period was dominated by documentation maintenance, with the most consequential update affecting Defender for Endpoint network configuration. Commercial connectivity guidance now says environments may also need Microsoft 365 Unified Domains URLs allowed, while separate guidance adds a clearer response path for automatic attack disruption that causes full isolation. Smaller updates correct an ABAP audit-log table name and explain where to find missing Threat Analytics reports.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

7 updates

1

Threat Analytics

Doc update

The documentation now directs users to check the Threat intelligence section when an emailed threat analytics report is missing from Threat analytics.

1

Custom Detection Rules

Doc update

The supported table list now spells `ABAPAuditLog_CL` correctly, fixing a missing “L.”

5

Standard Device Connectivity Urls Commercial

Doc update

The commercial device connectivity documentation now notes that, beyond the listed URLs, some environments might also need to allow URLs from the Microsoft 365 unified domains list.

Run Analyzer Linux

Doc update

The documentation fixes spelling errors in the descriptions for the minimum-requirement and external-dependency options.

Exploit Protection Reference

Doc update

The documentation corrects “memory manger” to “memory manager” and adjusts spacing before an ellipsis in the mitigation description.

Respond Machine Alerts

Doc update

The guidance now notes that the issue can occur when automatic attack disruption triggers full isolation. Administrators can define an isolation exclusion rule to use selective isolation instead.