← Previous day

Today in Microsoft Defender

Every tracked change across Microsoft Defender documentation, in plain English. Browse the archive from 1 January 2026 → About this project →

Day in brief

Sentinel table migration and Linux enforcement changes sharpen administrator action

The period was dominated by documentation maintenance, but several updates carry direct operational weight. Sentinel guidance now points administrators from the legacy ThreatIntelligenceIndicator table to ThreatIntelIndicators and ThreatIntelObjects, while Defender for Endpoint documents four Linux antivirus enforcement levels, a passive default, and Preview audit mode. Other consequential changes include SIEM-agent deprecation guidance for the Cloud Apps integration, manual Preview activation limits for Defender for Identity v3.x sensors on non-domain controllers, and material changes to the documented Defender XDR DataSecurityEvents schema.

  • The STIX guidance directs content to the ThreatIntelIndicators and ThreatIntelObjects schemas and states that ingestion into the legacy ThreatIntelligenceIndicator table stops after July 31, 2025. Custom queries, analytics and detection rules, workbooks, and automation using the old table should be updated.

  • The Linux configuration article lists four antivirus enforcement levels, identifies passive as the default, and marks audit mode as Preview. It adds verification guidance for the active level; audit mode requires Defender for Endpoint version 101.26062.0007 or later.

  • The Sentinel integration page states that SIEM agents are deprecated while the Microsoft Sentinel integration (Preview) remains supported, and adds a dedicated integration section. Organizations still using SIEM agents should review their integration strategy against the supported Sentinel option.

  • The v3.x sensor deployment guidance now covers non-domain-controller AD FS, AD CS, and Microsoft Entra Connect servers. Activation on those servers is in Preview and requires manual activation; automatic activation and migration are unsupported. Deployments limited to these servers should include at least one v3.x sensor on a domain controller.

  • The Defender XDR table reference removes its Preview and prerelease notices, adds physical access, removable media, and risky AI usage fields, and removes several URL, email, file-path, workload, and Cloud App Alert fields. Query and integration owners should review dependencies on the removed columns.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

1307 updates

67

DataSecurityEvents

Doc update

The table no longer includes the Preview label or prerelease notice. It adds physical access, removable media, and risky AI usage fields, while removing several URL, email, file-path, workload, and Cloud App Alert fields.

What's new in Microsoft Defender XDR

Generally available

The page now lists Agent 365 agent threat detection as Preview, tooling-server real-time protection as GA, and the Security Copilot Threat Hunting Assistant as GA under its updated name.

OAuthAppInfo (Preview)

Doc update

The documentation now lists the `RiskScore` and `AssignedRoles` columns, and clarifies that data for Entra managed identities is excluded. The article date was also updated.

DataSecurityBehaviors

Doc update

The table documentation removes the Preview label and prerelease notice and adds the `PolicyInfo` and `Policies` columns.

EntraIdSignInEvents

Feature update

The replacement of AADSignInEventsBeta is now scheduled for October 19, 2026, with queries migrated automatically. Custom detections require no changes, and several field definitions and schema fields were updated.

EntraIdSpnSignInEvents

Feature update

The replacement date for AADSpnSignInEventsBeta moved to October 19, 2026. Queries will migrate automatically, custom detections need no changes, and several fields are now documented.

Integrate your SIEM tools with Microsoft Defender XDR

Doc update

The article now explains pulling incidents through REST APIs and streaming event data through Azure Event Hubs to supported SIEM platforms. It also clarifies terminology for Splunk CIM mapping and the ArcSight SmartConnector, which replaces the retired FlexConnector.

Protect AI assets from emerging threats and vulnerabilities using Microsoft Defender

Feature update

The documentation now states that real-time protection evaluates tool invocations and responses from Agent 365 agents using Work IQ MCP or customer MCP tools onboarded to Agent 365. The default rule audits activity, while custom rules can block matching actions. It also lists expanded threat-detection examples, including prompt injection, secret leakage, and suspicious IP access.

Microsoft 365 Security Center Mdo

Doc update

The page now refers to Microsoft Defender instead of Microsoft Defender XDR in links and labels for the overview, threat analytics, learning paths, and unified RBAC.

Security Copilot Agents Defender

Doc update

The page’s table of contents, section heading, description, and linked article now use “Threat Hunting Assistant” and point to the corresponding assistant documentation.

Playbook Responding Ransomware M365 Defender

Doc update

The playbook now refers to Microsoft Defender instead of Microsoft Defender XDR when describing consolidated visibility into impacted or at-risk assets, and updates the linked article title accordingly.

Configure Attack Disruption

New feature

The page now describes automatic device isolation for Microsoft Defender for Endpoint-managed end-user workstations and identifies it as in preview. It adds prerequisites, safeguards, exclusion guidance, and clearer Sense Agent and connector setup instructions.

Ai Agent Real Time Protection

New feature

The documentation now labels Copilot Studio agent protection as Preview and describes protection for Foundry agents, covering user requests, agent responses, tool invocations, and tool responses.

Compare Rbac Roles

Doc update

The page now clarifies that activating Defender unified RBAC for Email & collaboration imports only actively assigned source roles and role groups. Unassigned built-in roles and groups are not imported, and the permission mapping tables were revised.

Investigate and respond to incidents in Microsoft Defender

Doc update

The article title, headings, descriptions, and deployment references were updated from Microsoft Defender XDR to Microsoft Defender. Threat intelligence wording and tutorial links were also revised, along with metadata and the publication date.

Scoping

New feature

The scoping guide now documents applying scope tags through Azure Monitor data collection rules (DCRs), including CI/CD workflows. It also updates prerequisites, requires Data Operations (Manage) and Alerts (Manage) for Table Management, and clarifies subscription requirements and rule timing.

Configure Event Hub

Doc update

The article clarifies resource provider registration, app and service principal creation, client-secret handling, namespace settings, resource ID retrieval, and event hub choices.

Before you begin using Defender Experts MDR

Feature updateAction required

The documentation adds Plan 2 prerequisites covering endpoint, email, identity, cloud workload protection, Sentinel ingestion and connectivity, access permissions, 90-day retention, and UEBA. It also updates data storage, retention, deletion, and GCC availability details.

Defender Threat Intelligence

New feature

The documentation now explains how to use Copilot in Defender on the Threat analytics, Intel profiles, and Intel explorer pages, including prompts, built-in actions, and saved chat sessions.

Edit Delete Rbac Roles

Doc update

The article now provides clearer steps and prerequisites for editing, deleting, and exporting roles. It also highlights that deleting an active workload role removes its assigned user permissions and clarifies export behavior for newer tenants.

Microsoft Xdr Auditing

Doc update

The page broadens references from Microsoft Defender XDR to Microsoft Defender, clarifies that audit logs can be searched in the Defender or Purview portals, updates navigation and retention guidance, and removes the PowerShell query example.

Investigate Alerts

Doc update

The page updates headings, anchors, wording, and tag-color descriptions. It also notes that alert suppression is incompatible with custom detections and recommends fine-tuning them to avoid false positives.

DeviceInfo

Doc update

The DeviceInfo table reference now documents the DeviceRoles string column, including JSON-formatted roles, confidence levels, and last-seen times. It also includes minor formatting and wording updates.

Exclude assets from automated response in attack disruption

Doc update

The article now explains exclusion policies, adds permission requirements for device and identity exclusions, clarifies policy application and IP exclusion steps, and recommends excluding specific assets rather than opting out entirely.

Entity Page Threat Intelligence

Doc update

The documentation now explains the 0–100 reputation score, its Malicious, Suspicious, Neutral, and Unknown ranges, scoring inputs, and infrastructure data sources including passive DNS, port scans, web crawling, and reverse DNS.

Threat Intel Briefing Agent Defender

Doc update

The documentation now labels required products explicitly, clarifies that the recommended agent identity is a service principal, and adds more detail on obtaining a Microsoft Graph token, registering the service principal, and verifying it.

Detecting human-operated ransomware attacks with Microsoft Defender

Doc update

The playbook now uses Microsoft Defender branding, updates its date, and revises the ransomware signal table to include Defender for Cloud Apps for email or cloud-app exfiltration and Defender for Endpoint for endpoint file encryption. Related API, Sentinel integration, and queue references were also renamed.

Investigate data loss prevention alerts with Microsoft Defender XDR

Feature update

The documentation now states that a built-in alert tuning rule will take effect in early October 2026. In Microsoft Defender XDR, affected DLP signals will appear as behaviors instead of alerts, so they will not generate alerts or enter the incident queue, but will remain available for advanced hunting.

Threat Analytics Indicators

Doc update

The documentation now consistently refers to the Indicators tab, clarifies that access is available to verified customers, simplifies the verification steps, and updates related-content formatting.

Configure Asset Rules

Doc update

The guidance now explains that administrators can select an existing tag or create a new one, and warns that deleting a dynamic rule removes it and may affect tag or device value assignments. Turning off the rule stops it from applying while retaining it.

Microsoft 365 Defender

Doc update

The page now uses “Microsoft Defender” instead of “Microsoft Defender XDR” throughout and replaces the automatic response description with a linked explanation of automatic attack disruption, including signal correlation and containment actions.

General information on Defender Experts MDR service

Doc update

The FAQ now distinguishes Plan 1 from Plan 2, including Sentinel requirements, supported third-party sources, Sentinel deployment responsibilities, and incident coverage. Plan 2 extends coverage to supported third-party sources but does not manage the customer’s Sentinel deployment.

Microsoft 365 Defender Portal

Doc update

The page replaces “Microsoft Defender XDR” with “Microsoft Defender” in integration links, feature descriptions, headings, and learning-path text. The documented settings path remains **Settings > Microsoft Defender XDR**.

Phishing Triage Agent

Doc update

The documentation now links directly to agent identity, role, feedback, and removal tasks, and presents a warning that removing the agent deletes stored feedback and stops triage of new incidents while retaining incident history.

Prerequisites

Doc update

The page now refers to Microsoft Defender instead of Microsoft Defender XDR across licensing, access, browser, government-customer, integration, and overview references.

Ai Agent Detection Protection

Feature update

The documentation now states that unpublished Foundry agents, including playground-only agents, aren't supported for threat detection and links to publishing guidance. It also updates terminology and metadata.

Import Rbac Roles

Doc update

The page refreshes metadata and clarifies permission prerequisites, Defender unified RBAC role terminology, activation instructions, and the relationship between imported roles and their source roles.

M365d Autoir Actions

Doc update

The page now links to the Microsoft Defender Action center and clarifies that **Apply to X more instances of the selected quarantined file** is used before selecting **Undo**. The documentation date was also updated.

M365d Configure Auto Investigation Response

Doc update

The page date and wording were refreshed, and the settings section was renamed to “Change automated investigation settings” with an updated anchor and additional learning link.

M365d Notifications Incidents

Doc update

The documentation now consistently refers to email notifications, clarifies that severity filters can be set for each service or detection source, and refines the instructions for creating rules and opening incidents from notification emails.

Manage Rbac

Doc update

The page replaces Microsoft Defender XDR with Microsoft Defender in its descriptions, licensing notes, role guidance, and workload activation instructions. The page date was also updated.

Microsoft Secure Score

Doc update

References to Microsoft Defender XDR Unified RBAC were updated to Microsoft Defender Unified RBAC throughout the Secure Score permissions guidance.

Step 5. Develop and test use cases

Doc update

The article’s metadata and several passages were updated, including clarification of the SOC Oversight team’s role and streamlined wording for use-case workflow and testing guidance.

Hunt for ransomware

Doc update

The article was updated with a new introductory description and additional explanations for the taskkill.exe process-stop and cipher.exe multi-drive data-deletion queries. The publication date was also updated.

Manage Incidents

Doc update

The article was updated with a new date, clearer incident-lifecycle wording, a Microsoft Defender portal access note, expanded KQL terminology, and more precise instructions for exporting an Incident report as a PDF from the Copilot side panel.

Protect Against Iot Ot Threats

Doc update

The article now uses “Defender” instead of “Defender XDR” in relevant introductory and enterprise IoT text, and adds a named anchor to the section heading.

Work with results containing Microsoft Sentinel data

Doc update

The article now explains how to explore and act on query results containing Microsoft Sentinel data, including linking results to incidents and taking response actions. It also adds inline inspection guidance and updates wording and formatting.

AlertEvidence

Doc update

The documentation now lists alerts from Defender for Endpoint, Office 365, Cloud Apps, Identity, and onboarded Microsoft Sentinel sources. It also clarifies that data availability depends on deployed services and accessible Sentinel workspaces, and recommends joining AlertEvidence with AlertInfo by AlertId for alert metadata.

AlertInfo

Doc update

The documentation now states that AlertInfo can contain Microsoft Sentinel alerts associated with incidents when Sentinel is onboarded to the Defender portal. Data availability depends on deployed Defender services and accessible Sentinel workspaces.

Merge Incidents Manually

Doc update

The article’s metadata was updated, and the instruction about providing feedback when merging incidents was reworded to emphasize its value for improving alert correlation.

Create Custom Rbac Roles

Doc update

The article now documents selecting GDAP remote tenant groups for a custom role assignment. Members of selected groups inherit the configured permissions, data-source access, and applicable scopes.

Entity Page Device

Doc update

The documentation clarifies that custom activity data from Microsoft Sentinel must include a strong identifier combination for the host to be mapped and displayed in the Device Timeline.

M365d Response Actions Notifications

Doc update

The documentation now refers to these capabilities as being in Microsoft Defender instead of Microsoft Defender XDR and uses the complete link for automated investigation and response.

Supported Event Types

Doc update

The documentation now says streaming data is available only for columns or fields that are generally available in Microsoft Defender, replacing “Microsoft Defender XDR.”

44

Advanced Hunting Security Copilot

Feature update

The documentation now describes Rich insights and Query only modes, with Rich insights as the default. It updates mode-switching steps, notes that modes aren't available on non-primary workspaces, and explains that switching starts a new chat and clears the current conversation. It also documents support for queries spanning multiple tables.

Microsoft Security Copilot advanced hunting query assistant

Doc update

The page now refers to Security Copilot’s Threat Hunting Assistant and explains how to run a generated query, add it to the editor for review, and view its logic. Screenshots, image descriptions, feedback wording, and the page date were also updated.

Advanced Hunting Migrate From Mde

Doc update

The documentation now clarifies migration queries from Microsoft Defender for Endpoint, including PowerShell technique filtering, AlertInfo and AlertEvidence joins, and entity filtering. It also updates the Microsoft Defender XDR setup link and publication date.

Advanced Hunting Extend Data

Doc update

The page wording was revised to emphasize correct settings across data sources, and section headings now clearly describe enabling Windows advanced security auditing and installing the Defender for Identity sensor. Section anchors and the page date were also updated.

Microsoft Defender XDR Advanced hunting API

RetirementAction required

The documentation states that the Defender XDR advanced hunting API is transitioning to the Microsoft Graph security API, with retirement beginning in January 2026.

Advanced Hunting Emailevents Table

Doc update

The Advanced Hunting EmailEvents page updated its ownership metadata and date, and changed the documented column reference for sender, recipient, delivery, threat, authentication, and policy fields.

DeviceLogonEvents table in the advanced hunting schema

Doc update

The page now explains that token creation events initiated by lsass.exe can include access-token privilege context in AdditionalFields. It also refines guidance for investigating authentication activity and privileged logons.

CallActivityEvents table in the advanced hunting schema

New feature

The new table documents Microsoft Teams call activity details, including timestamps, call and participant identifiers, activity types, scheduling information, and join links. It is populated by Microsoft Defender for Office 365.

Custom Detection Rules

New feature

The documentation adds support for governance actions on supported SaaS identities returned by CloudAppEvents queries. Queries must include AccountObjectId, InstanceId, ApplicationId, AppInstanceId, and other required fields; unsupported actions or services produce no action.

Advanced Hunting Defender Use Custom Rules

Doc update

The article now warns that deleting functions and saved queries is permanent, clarifies guidance for the `adx()`, `arg()`, and `workspace()` operators, updates menu image descriptions, and renames analytics rule section headings.

Advanced Hunting Query Builder

Doc update

Updated the publication date, clarified wording for the Run query and All filters controls, improved screenshot descriptions, and renamed the Related content section with an anchor.

Advanced Hunting Query Results

Doc update

The article adds stable anchors and clearer “Example chart” headings, refines query descriptions, identifies the newly added filter, and documents when the timeline appears: results must contain more than 40 events and a `Timestamp` or `timeGenerated` column.

Advanced Hunting Overview

Feature update

The documentation now distinguishes 30-day native Defender XDR data retention from Microsoft Sentinel analytics-tier retention. It explains that onboarding a Sentinel workspace and configuring table retention can support longer retention, while streaming to external services remains another option.

Advanced Hunting Link To Incident

Doc update

The article date and wording were updated, with shorter instructions for running queries, confirming prerequisites, troubleshooting, creating alerts, viewing linked incidents, and filtering manually detected alerts.

Defender Experts Hunting Ask Experts

Doc update

The documentation now includes screenshots showing the Ask Defender Experts option on the Defender Experts overview page and in the message center. The page metadata and authoring identifier were also updated.

Advanced Hunting Query Builder Details

Doc update

The page updates its date, clarifies when the EventType filter is available, and improves descriptions of EventType, sample-size, Edit in KQL, and generated KQL screenshots. It also specifies the file-name and SHA256 example when describing narrowed Emails & collaboration queries.

Advanced Hunting Shared Queries

Doc update

The page date moved to July 2, 2026. Wording now describes query sections as lists or groups, simplifies rename and delete instructions, updates the GitHub contribution link, and directs readers to threat analytics reports in the Defender portal.

Advanced Hunting Query History

Doc update

The Query history section was reworded for clarity, with an updated date and new section anchor. It continues to describe rerunning past queries, retaining up to 30 queries from the last 28 days, and using or editing queries.

Defender Experts Hunting Prerequisites

Feature update

The prerequisites now document storage locations for hunting, reporting, and operational data; retention of up to 90 days after subscription expiry and deletion within 30 days after termination; and availability for eligible GCC customers through Defender Experts Hunting for Gov.

Manage custom detection rules in Microsoft Defender XDR

Doc update

The article now explicitly covers viewing, editing, running, enabling, disabling, and deleting custom detection rules, along with reviewing triggered alerts and response actions. Headings, an anchor, and the publication date were also updated.

Advanced Hunting Modes

Doc update

The article now includes an updated section heading, refreshed screenshots and image descriptions, clearer guided-tour wording, and a new publication date.

Advanced Hunting Query Language

Doc update

The article now uses clearer terms for the advanced hunting schema and time zone settings, identifies the Get started pane on the Advanced hunting page in the Microsoft Defender portal, and fixes link wording. The article date was updated to July 2, 2026.

Advanced Hunting Query Emails Devices

Doc update

The article date was updated, and explanatory text was revised to clarify extracting the account name from recipient email addresses and checking logon activity on a recipient's device after ZAP processing.

Advanced Hunting Clouddnsevents Table

Doc update

The table documentation now describes ImageDigest, Region, and HostName, including their meanings for container image, cluster region, and node hostname data.

Advanced Hunting Go Hunt

Doc update

The documentation date changed to July 2, 2026, and the wording now specifies that the associated incident includes the entity.

Advanced Hunting Limits

Doc update

The explanation now explicitly describes the difference between average daily use and top daily use; the example values remain 75% and 100%. The document date was updated to July 2, 2026.

Advanced Hunting Microsoft Defender

Doc update

The documentation now states that a newly created Microsoft Sentinel function in Log Analytics can take up to 20 minutes to appear in advanced hunting.

18

Security Alert Triage Agent

Doc update

The article now labels supported alert types more clearly, separates prerequisite guidance by alert category, updates RBAC terminology and links, and renames feedback guidance links. It also clarifies that existing Phishing Triage Agent users can enable additional alert types through configuration.

Alert Classification Password Spray Attack

Doc update

The article now explains MFA fatigue, clarifies query descriptions and alert references, and adds a Kusto query to check whether MFA strong authentication requirements were removed from Microsoft Entra ID accounts.

Alert Classification Malicious Exchange Connectors

Doc update

The page updates wording, metadata, and investigation guidance. Sample queries are now described as covering new connector creation, connector-to-mail-flow correlation, and external domain detection, with added admin logon checks.

Alert Grading Playbook Email Forwarding

Doc update

The playbook now presents alert-review steps as a numbered sequence, clarifies terminology for the forwarding user and recipient lists, and refines investigation and remediation wording. Metadata and the documentation date were also updated.

Alert policies in the Microsoft Defender portal

Doc update

The article now notes that some default alert policies contain filters not shown in the Microsoft Defender portal. These filters can affect whether activities match conditions and trigger alerts, and the article provides a PowerShell command to view them.

Manually Create Incident

Doc update

The article now clarifies the Related incident step, adds navigation support, updates the date and metadata, and provides additional incident-management references.

Alert classification for suspicious inbox manipulation rules

Doc update

The playbook now more explicitly covers true and false positives, compromised accounts, rules without filters, activity before suspicious rules were created, and related alerts. Metadata and the publication date were also updated.

Session Cookie Theft Alert

Doc update

The article’s date was updated, wording was refined, an investigation-steps introduction was added, and references to Advanced hunting and business email compromise were made clearer.

Alert Classification Suspicious Ip Password Spray

Doc update

The article updates its date and wording, and adds clearer instructions for the investigation queries. Administrators are told to set the `ip_address` variable, use an eight-hour lookback, and review legacy-protocol indicators, successful sign-ins, and related cloud app activity.

M365d Action Center

Doc update

The page adds introductory steps for opening and using Action center, updates the source-details heading and anchor, reformats the remediation-actions link, and refreshes the publication date.

Alert Grading Playbook Inbox Forwarding Rules

Doc update

The article now uses clearer terminology for investigating suspicious rule parameters, identifying the IP involved in inbox rule creation, and remediating account compromise. Its metadata and publication date were also updated.

Api Incident

Doc update

The documentation explains that lastUpdateTime identifies incidents changed after creation. It also states that severity may change when alerts are added or removed, and that the incident resource does not provide severity-change history.

Incident Queue

Feature update

The documentation now states that the incident list defaults to incidents from the last week instead of the last six months. The listed 30-day option was removed.

7

Pilot and deploy Microsoft Defender for Cloud Apps

Doc update

The article now uses Microsoft Defender instead of Microsoft Defender XDR in its deployment workflow, headings, integration instructions, and descriptions of signal correlation and Sentinel integration.

Pilot and deploy Microsoft Defender for Endpoint

Doc update

The article replaces several references to Microsoft Defender XDR with Microsoft Defender in its introduction, deployment workflow, signal-correlation guidance, management location, and next-step heading.

Pilot and deploy Defender for Office 365

Doc update

The article now refers to “Microsoft Defender” instead of “Microsoft Defender XDR” in its introduction, headings, deployment table, signal-sharing description, and next-step section.

Set up your Microsoft Defender XDR trial lab or pilot environment

Doc update

The article now describes dedicated Microsoft Defender XDR trial lab or pilot setup, including tenant provisioning and subscription activation. References to the pilot guide and configuration phases were updated to use “Microsoft Defender,” and metadata was refreshed.

5

View your identity coverage and maturity (Preview)

Doc update

The page now explains coverage task ranking fields, observed-application filtering, and the On-premises identities panel, including sensor onboarding, activation, migration metrics, and related actions. SaaS panel guidance was also updated.

Investigate an identity

Feature update

The page now documents connector-dependent remediation actions, including that Confirm safe resets both the identity risk score and Microsoft Entra risk level. It also expands the identity timeline to include sign-ins, audit events, risk signals, Conditional Access evaluations, correlated accounts, and additional data tables.

Sop Documentation Template

Doc update

The template was revised with clearer wording and added guidance for prerequisites, user validation, containment, MFA review, impact assessment, remediation, recovery, and prevention of recurrence.

Enable attack disruption actions in Okta with Microsoft Defender XDR

Doc update

The article updates its title and terminology, clarifies Okta and Microsoft prerequisites, and specifies that the saved token is used when creating an integration profile in the Defender portal. The prerequisite link text and documentation metadata were also updated.

Manage predictive shielding in Microsoft Defender

Doc update

The page now highlights Defender for Identity data enrichment, advanced hunting for policy changes, and undoing shielding actions. It also clarifies alert investigation steps and refines the example scenario.

4

Streaming Api Storage

Doc update

The documentation now refers specifically to user accounts and service principals for Contributor role assignments, clarifies the trusted Microsoft services setting, and adds guidance for interpreting blob event records and querying their schema.

Api List Incidents

Doc update

The documentation now explains that incident properties, including severity, may change after creation. Applications should poll `lastUpdateTime` and compare current values with retained values; severity cannot be filtered server-side.

Streaming Api

Doc update

The streaming API documentation now refers to configuring Microsoft Defender, instead of Microsoft Defender XDR, to stream Advanced Hunting events to Azure Event Hubs or Azure storage.

3

Microsoft Security Copilot Security Analyst Agent overview

Doc update

The article now explains how to switch to and from the Security Analyst Agent through the More actions menu, notes that switching resets the conversation, adds a Sentinel Log Analytics investigation prompt, and reorganizes report interpretation guidance.

What is Microsoft Defender Experts MDR?

Doc update

The page now explains that Plan 1 covers Microsoft Defender workloads, while Plan 2 includes Plan 1 and extends expert-led detection, investigation, response, and threat hunting to selected non-Microsoft telemetry collected in Microsoft Sentinel.

Defender Experts Overview

Doc update

The overview now states that Plan 2 extends expert triage and investigation to supported third-party sources ingested through Microsoft Sentinel, in addition to Microsoft Defender workloads.

2

Activate Defender Rbac

Doc update

The documentation now provides direct navigation and toggle-based steps for deactivating workloads, including confirmation and the resulting **Not Active** status.

1
1

Microsoft 365 Security Center Mde

Doc update

The documentation now says the alerts API works across all Defender products, replacing “all Defender XDR products.” The migration link is unchanged.

1

Troubleshoot

Doc update

The troubleshooting page now links to prerequisites and clearer Azure portal destinations, corrects the Option 3 wording, and documents required URL parameters. It also warns that removing the application configuration temporarily prevents file submission until consent is restored.

208

Discover local AI agents with Microsoft Defender for Endpoint (Preview)

Feature update

The documentation now covers Windows and macOS, adds agent risk and configuration details, and clarifies licensing: Defender for Endpoint Plan 2 supports discovery and hunting, while risk insights and recommendations require Microsoft 365 E7 or Microsoft Agent 365 with Defender for Endpoint Plan 2.

Whats New In Microsoft Defender Endpoint

New feature

The page now lists Linux memory scanning, WSL container plug-in support, Linux audit modes, Linux offboarding API support, Store application vulnerability assessment, the Linux Deployment Tool, and macOS releases, with Preview or GA status.

Configure Microsoft Defender Antivirus using Microsoft Intune

Feature update

The documentation now describes creating antivirus policies in Intune, adds Windows Server devices managed through Defender for Endpoint security settings management, and notes that Windows 10 support is not guaranteed after October 14, 2025.

Configure Microsoft Defender for Endpoint on Android

Doc update

The guide was retitled and restructured. It now covers protection, privacy, file scanning, device tagging, vulnerability assessment, sign-out controls, custom indicators, and web protection through Microsoft Intune, with updated licensing and platform-limit details.

Enable exploit protection in Windows

Retirement

The page now documents configuration through multiple management methods, default mitigations, audit mode, XML export, and staged testing. It also states that EAF and IAF are deprecated and incompatible with .NET Framework 2.0 and 3.5 applications.

Evaluate Microsoft Defender Antivirus with security policies

Doc update

The article was retitled and restructured to cover evaluating Microsoft Defender Antivirus and Windows protection features through endpoint security policies in the Defender portal. It now provides clearer prerequisites, including onboarding and security settings management requirements, and notes that Intune enrollment is not required.

Migrate servers to Microsoft Defender for Endpoint by using Configuration Manager

Doc update

The article now covers migrating Windows Server 2012 R2 and 2016 from MMA to the unified Defender for Endpoint solution. It clarifies that manual steps apply to Configuration Manager versions earlier than 2207, while version 2207 and later can automate deployment and upgrades, and it updates prerequisites and download instructions.

Schedule Microsoft Defender Antivirus protection updates

Doc update

The article now provides detailed steps for configuring security intelligence update day, interval, and time settings through Group Policy, including current and legacy policy paths and local Group Policy guidance.

Assign Microsoft Defender for Endpoint basic permissions

Feature update

The article now states that basic permissions are for existing Defender for Endpoint customers, with full access assigned through Security Administrator and read-only access through Security Reader. It also adds Microsoft Graph PowerShell role and delegated-permission prerequisites and notes that new customers use unified RBAC.

Exploit Protection Reference

Doc update

The page clarifies per-program registry settings, XML deployment through PowerShell, Group Policy, and MDM, policy-removal behavior, and resetting settings with the Windows Security Baselines XML. It also adds links and mitigation-specific introductory sections.

Evaluate exploit protection

Doc update

The article adds clearer audit-mode guidance, default mitigation tables, deprecated program-setting details, compatibility notes, configuration instructions, and updated PowerShell examples.

Customize exploit protection

Doc update

The article updates Windows Security and PowerShell instructions, clarifies the `-System` scope and `-Remove` behavior, and explains that audit-only ACG monitoring logs policy violations without blocking execution.

Prevent malware infection

Doc update

The page now uses current Microsoft Support links for Windows Update, User Account Control, user accounts, Microsoft account security, and Microsoft Defender.

Web Content Filtering

Doc update

The documentation now notes up to two hours of policy-enforcement latency, audit-only policies, possible delays during policy or group changes, and risks of blocking the “Uncategorized” category. It also names dashboard cards and updates the SmartScreen link.

Microsoft Defender Antivirus Exclusions Configure

Doc update

The article adds clearer GPMC navigation steps, updates the GPMC and Windows Security links, and refreshes its publication date. The note about legacy Windows Defender Antivirus policy names remains included.

Set up Microsoft Defender for Endpoint during migration

Doc update

The Phase 2 migration page was retitled, its date and metadata were updated, migration diagram labels were clarified, Step 3 was renamed to cover onboarding and protection settings, and a Group Policy link was corrected. Additional anchors and clearer exclusion wording were added.

Manage tamper protection on an individual device

Doc update

The page adds explicit Windows Security steps for turning tamper protection on or off, corrects a permissions typo, and clarifies the Security intelligence version 1.287.60.0 or later guidance for non-Microsoft security products and enterprise scripts.

Tamper Resiliency

Doc update

Updated links now point to revised Zero Trust, Group Policy, WDAC, and vulnerable driver block-list documentation locations.

Endpoint Security Policies Configure

Feature update

The documentation now states that Endpoint security policy management cannot be used on devices with an MMA-delivered sensor. On Windows 7 SP1 and Windows Server 2008 R2 SP1, only Microsoft Defender Antivirus policy is supported.

Indicators Overview

Doc update

The article now points to updated Windows Defender Application Control and Windows Security app settings URLs, with minor accompanying text synchronization.

Controlled Folder Access Overview

Doc update

The article now points to an updated Windows Security Protection History URL and removes the Microsoft Volume Licensing Reference Guide link.

Respond File Alerts

Doc update

The page now uses repository-relative links for Defender Antivirus compatibility and cloud-delivered protection guidance, and points sample submissions to the Microsoft Security Intelligence submission portal.

Get Vulnerability By Id

Doc update

The documented `status` example remains `RemediationRequired`; only the documentation line was synchronized.

Migration Guides

Doc update

The migration guide now links Microsoft Defender for Endpoint to the relative `microsoft-defender-endpoint.md` page instead of `/windows/security/threat-protection`.

Guidance Pen Testing Bas Linux

Doc update

The guide now more clearly describes the managed JSON configuration, preview protections, diagnostic-log resources, and the information to submit through the MDSI or Microsoft Defender portal.

Schedule antivirus scans on Linux

Doc update

The page title no longer includes “preview.” The command-line section gained an anchor, clearer heading, updated metadata, and identifies `mdatp` as the Microsoft Defender for Endpoint command-line tool.

Address false positives/negatives in Microsoft Defender for Endpoint

Doc update

The article now provides workflows for identifying detection sources, classifying and suppressing alerts, reviewing remediation, configuring exclusions, submitting files, and investigating suspected false negatives. Definitions, response guidance, links, and metadata were also updated.

Android Mobile Threat Defense (MTD) Role for Microsoft Defender for Endpoint

New feature

The new documentation explains how Intune can assign Microsoft Defender for Endpoint as the Android Enterprise Mobile Threat Defense application. The role helps block force-stop and app-data clearing, and automatically exempts Defender from battery optimization on Android 14 and later. It lists prerequisites and supports COBO and COPE enrollment scenarios.

Configure block at first sight in Microsoft Defender Antivirus

Doc update

The article now explains how block at first sight works, lists its required conditions—cloud protection, automatic sample submission, and current Defender updates—and documents coverage for downloaded executable and nonportable files. It also adds Configuration Manager to the supported management tools and includes updated links and visuals.

Controlled configuration in Microsoft Defender for Endpoint

Private preview

The new article describes cloud-managed Defender Antivirus policy as the authoritative configuration source, overriding Group Policy, scripts, Configuration Manager, and local changes. It lists prerequisites, supported platforms, covered settings, exclusions, and enforcement behavior.

Microsoft Defender Endpoint Releases

Doc update

The page now lists July and August 2026 releases for Windows Antivirus, Android, iOS, macOS, and Linux. It also refreshes Windows update-history links and removes the displayed Windows KB links.

Release Notes Mde Archive

Doc update

The archive metadata date was updated to August 25, 2026. Release tables were reformatted, KB5005292 links were updated, and the “What’s new” heading was adjusted.

Schedule antivirus scans using Microsoft Intune

Doc update

The article now documents daily quick-scan states, valid times from 0 to 1380 minutes, the 120-minute default, and a noon example. It also updates weekly scan guidance, supported OS wording, and configuration links.

Turn on network protection

Feature updateAction required

The article now specifies supported Windows versions, Microsoft Defender Antivirus requirements, Windows Server management options, licensing considerations, and recommends testing audit mode before block mode.

Create a custom gradual rollout process for Microsoft Defender updates

Feature updateAction required

The documentation now specifies Windows devices and Microsoft Defender Antivirus platform version 4.18.2106.6 or later, revises the rollout channel descriptions and policy paths, and warns that MDM and Group Policy settings can conflict for Defender settings.

Configure Conditional Access

Doc update

The article now explicitly describes enabling Conditional Access for Microsoft Defender for Endpoint with Microsoft Intune and Microsoft Entra ID, and refers to the Microsoft Defender for Endpoint compliance policy evaluation integration. The page date and authoring metadata were also updated.

Take response actions on a device

Doc update

The article adds a note that live response may be restricted on high-value assets according to their selective response actions. It also refreshes investigation, live response, package-content, and metadata wording.

Behavior monitoring in Microsoft Defender Antivirus

Doc update

The article now explains real-time detection, dynamic analysis, response and remediation, and identifies Antimalware and Network protection features that depend on behavior monitoring. It also updates configuration-tool guidance and adds verification and performance-troubleshooting context.

Set up the Microsoft Defender for Endpoint on macOS policies in Jamf Pro

Doc update

The article now provides expanded guidance for onboarding, antivirus and EDR settings, notifications, Microsoft AutoUpdate, permissions, system extensions, network extensions, and deployment profiles. It also clarifies GUI and legacy configuration methods, schema usage, and required bundle and socket-filter values.

Controlled Folder Access Configure

Doc update

The article now lists the Intune navigation path, policy type, platform, profile, CFA settings, and Add/Import examples for protected folders and allowed applications.

Configure Microsoft Defender Antivirus scanning options

Doc update

The article now links to newer Windows 10 and Windows 11 Group Policy reference spreadsheets, provides expanded GPMC navigation and setting-edit steps, and adds guidance for Local Group Policy and legacy policy names.

Ios Configure Features

Doc update

The article clarifies local VPN behavior, open-network alert changes, privacy controls, jailbreak compliance, sign-out settings, and device tagging. It also separates instructions for enrolled and unenrolled devices and improves section headings and links.

Set preferences for Microsoft Defender for Endpoint on macOS

Doc update

The article now provides clearer guidance for enterprise administrators using JAMF or Intune, including plist structure, scan-exclusion fields, threat actions, device tags, and recommended profiles. Section anchors and metadata were also updated.

Detect and block potentially unwanted applications

Doc update

The article now includes current links, clearer GPMC navigation and editing steps, a note about updating Administrative Templates when the setting is unavailable, legacy policy-path naming guidance, and Local Group Policy instructions.

Specify the cloud protection level

Doc update

The article now provides revised GPMC navigation steps, clearer protection-level descriptions, an RSOP caution, and instructions for configuring the setting locally with gpedit.msc.

Investigate entities on devices using live response

Feature update

Background file downloads now use `getfile`; the US Government `library` limit is documented as 5 MB by default, with higher limits available through support. Command guidance and links were also clarified.

Manage system extensions using Jamf

Doc update

The article now explicitly covers approving system extensions, granting Full Disk Access through Privacy Preferences Policy Control, and configuring network extensions. It also clarifies code requirements and commands for validating and signing configuration profiles.

Endpoint detection and response in block mode

Doc update

The article now provides expanded steps for locating and editing the setting in Group Policy Management Console, including the full navigation path and alternative edit methods. It also documents configuring the setting locally with the Local Group Policy Editor.

Phishing trends and techniques

Doc update

The article adds examples of calendar invitations, attached emails, nested attachments, QR code phishing, and CAPTCHA-gated phishing, and updates its reference links and wording.

Assess Devices

Doc update

The page now lists licensing, onboarding, and portal-permission prerequisites. It also updates queries for identifying unmanaged devices, their discovering onboarded devices, and recent network connections.

Create indicators for IPs and URLs/domains

Doc update

The documentation now uses a local link, updates the URL precedence example, clarifies network protection logging, and restates that policy changes can take up to 48 hours to apply, usually under two hours.

Defender Endpoint Demonstration Controlled Folder Access Ransomware

Doc update

The instructions now explain that the setup script excludes c:\demo from Microsoft Defender Antivirus. They direct users to run the test file from a nonexcluded folder when testing for a CFA block or detection, and clarify where to run and delete copies afterward.

Mac Schedule Scan

Doc update

The article now links directly to parameter tables and Intune/Jamf examples, clarifies the sample configurations, and adds clearer guidance for using mdatp commands to configure and list scheduled scans.

Microsoft Defender Offline

Doc update

The page updates protection-download links, clarifies firmware and rootkit coverage, revises offline-scan instructions, and adds a warning that initiating a scan immediately restarts the endpoint.

Production Deployment

Doc update

Updated section titles, anchors, wording, metadata, and publication date in the Microsoft Configuration Manager deployment guide.

Microsoft Defender Antivirus Compatibility

Feature update

The compatibility table now separates Smart App Control from Defender Antivirus state and documents additional combinations, including hybrid mode and revised passive or disabled states with third-party antivirus. The page also updates catch-up quick scan guidance, Smart App Control wording, and Endpoint DLP links.

Network protection demonstrations

Doc update

The guidance now explicitly describes block mode, expected verification values, browser test behavior, and cleanup steps on Windows, macOS, and Linux.

Edr Detection

Doc update

The page adds prerequisite guidance and platform-specific procedures, clarifies the Windows test command and completion message, updates the Linux test-script link text, and refines exclusion guidance.

Defender Deployment Tool Windows

Feature update

The Windows deployment-tool page now includes the streamlined connectivity SSL inspection requirement and replaces DefenderDTconfig.txt with MdeConfig.txt/MDEConfig.txt in its instructions. Prerequisite links were also refreshed.

Grant Mssp Access

Doc update

The article clarifies RBAC role and Microsoft Entra ID group terminology, updates the role-assignment reference, and adds guidance for reviewing and managing MSSP access requests in My Access.

Investigate devices in Microsoft Defender for Endpoint

Doc update

The investigation guidance now notes that some response actions may be unavailable or grayed out for high-value assets because permissions are set during onboarding. Firewall audit links were also updated, and the document date was refreshed.

Onboarding Notification

Doc update

The article now clarifies how to create the notification flow, filter by the `lastSeen` property, prevent duplicate alerts, and apply the one-hour offboarding interval from seven days ago.

Create indicators for certificates in Microsoft Defender for Endpoint

Doc update

The article now explicitly explains creating certificate-based indicators to allow or block signed applications, adds steps from the Settings page, updates the cloud protection link, identifies the Microsoft Defender for Endpoint evaluation pipeline, and expands the IoC wording.

Gov

Doc update

The Defender for Endpoint government documentation updates KB reference URLs for supported Windows versions and Windows Server 2019 entries.

Manage Tamper Protection Intune

Doc update

The page now cautions that registry keys are for viewing only and that changing them does not affect whether tamper protection applies to exclusions. It also adds a related-content link.

Test controlled folder access with an untrusted app

Doc updateAction required

The documentation warns that the setup script excludes `c:\demo` from Microsoft Defender Antivirus. Testers must copy and run `CFAtool.exe` from a folder that is not excluded so the expected CFA block or detection occurs.

Address Unwanted Behaviors Mde

Doc update

The page now emphasizes identifying the capability causing unwanted behavior and uses clearer links for viewing ASR detections and configuring exclusions. Documentation metadata was also updated.

Device Health Reports

Doc update

The page updates metadata, clarifies that the Device Health report corresponds to the Device health and compliance dashboard in the Microsoft Defender portal, and adds a See also section.

Manage Sys Extensions Manual Deployment

Doc update

The instructions now identify the Virus & threat protection screen, file selection dialog, and Accessibility list, and add an anchor to the mdatp health output section. Page metadata was also updated.

Mde Demonstration Amsi

Doc update

The article now includes a prerequisite reminder and clarifies that the sample protection-history output confirms AMSI detected and blocked the test payload. Minor wording and metadata were also updated.

Microsoft Defender Antivirus Updates

Doc update

Updated links for broad-channel releases, Endpoint DLP, Windows lifecycle information, installation-image updates, and EDR Sensor updates. The platform-update postponement wording was also revised.

Microsoft Defender for Endpoint - Mobile Threat Defense

Doc update

The overview now describes protection against web, network, and app-based threats, notes the separate Android Mobile Threat Defense role, and documents scanning for non-APK files such as documents, archives, and scripts.

Run Live Response

Feature update

The documented response changed from HTTP 200 OK to HTTP 201 Created. Several Windows update links were also updated to current support URLs.

Get Live Response Result

Doc update

The documentation now uses updated Microsoft Support URLs for KB4515384, KB4537818, KB4537795, and KB4537816 in Windows version and prerequisite references.

Manage Tamper Protection Microsoft 365 Defender

Doc update

The article now explicitly explains how to turn tamper protection on or off tenant-wide in the Microsoft Defender portal. It also updates the supported operating systems link, renames the considerations section, and refreshes metadata.

Rootkits Malware

Doc update

The page now uses WDSI threat-description URLs for five malware entries and updates the Microsoft Defender Offline support link.

Automated Investigations

Doc update

The page now uses updated Microsoft Support URLs for the Windows 10 KB4493441 and KB4493464 references and a local link for PUA protection.

Configure Device Discovery

Doc update

The page updates wording for customizing standard discovery and monitoring networks, and adds a direct link to the Monitored networks section for the advanced hunting query.

Defender Endpoint Trial User Guide

Doc update

The guide’s date and custom metadata were updated, and wording for configuring capabilities and running detection tests was revised.

Explore devices in the device inventory

Doc update

Updated the publication date and authoring metadata, renamed the device discovery link, clarified the Plan 2 wording, and expanded “AH” to “Advanced Hunting.”

Microsoft Defender Endpoint

Doc update

The Defender for Endpoint documentation now includes guidance that organizations using Defender for Endpoint on servers may qualify for discounts when also using Microsoft Defender for Servers. The page date was updated.

Microsoft Safety Scanner Download

Doc update

The page now describes using Microsoft Safety Scanner for manual malware scans and reversing changes made by identified threats. It also updates the SHA-2 requirements, troubleshooting, and malware-removal links.

Evaluate Network Protection

Doc update

The article now says to use Event Viewer and filter for Event ID 1125 to review blocked apps, and specifies that the prerequisite guidance applies when malicious sites are not detected. The publication date and custom metadata were also updated.

Exploit Protection

Doc update

The exploit protection article now links to a revised EMET guidance page and updated previous-version Windows mitigation documentation.

Machine Tags

Doc update

The article now directs admins to select devices from file and IP address views and delete tags from the device page.

Manage Suppression Rules

Doc update

The suppression rules article now includes instructions for viewing a suppression rule’s details. Its publication date and custom metadata were also updated.

Mde P1 Setup Configuration

Doc update

The setup guide now points to revised Microsoft Learn URLs for Windows Defender Firewall best practices and three Application Control topics.

Offboard Machines

Doc update

The page date was updated to August 11, 2026, and navigation entries were added for Linux devices and API-based offboarding.

Protect your organization against web threats

Doc update

The article now explicitly states that web threat protection is enabled when network protection or Microsoft Defender SmartScreen is enabled, with direct links to both settings.

Run Analyzer Linux

Doc update

The documentation now lists new SHA-256 checksums for the analyzer ZIP files and uses direct `./` command syntax to run the support tools.

Whats New Mde Archive

Doc update

The archived Android support entry now links to the Privacy controls overview section instead of the previous anchor.

Ios Install

Doc update

The documentation now covers just-in-time registration scenarios where Company Portal is not required and notes that the device must be registered. Metadata and the publication date were also updated.

Post Ti Indicator

Doc update

The API reference now documents `rbacGroupNames` as `String[]` and `generateAlert` as `Boolean`. The 400 Bad Request description was also clarified.

Review Alerts

Doc update

The alert review page’s introductory text now links to “Investigate alerts in Microsoft Defender for Endpoint.” The page date and custom metadata were also updated.

Data Collection Analyzer

Doc update

The data collection analyzer table now uses updated links for MpCmdRun.exe and Endpoint DLP, and the -v entry includes additional troubleshooting examples such as Cloud Protection reporting and Platform Update failures.

Feedback Loop Blocking

Doc update

The article now uses repository-relative links for Microsoft Defender for Endpoint and Next-generation protection guidance.

Host Firewall Reporting

Doc update

The host firewall reporting documentation now links the Audit Filtering Platform Packet Drop and Connection references to their previous-versions URLs.

Initiate Autoir Investigation

Doc update

The API documentation now uses revised Microsoft Support URLs for the Windows 10 version 1803 and 1709 prerequisite KB articles.

Phishing

Doc update

The page now links to the revised Microsoft Defender Application Guard documentation path and the updated Microsoft Support page about phishing protection.

Switch To Mde Troubleshooting

Doc update

The documentation updates the Windows client and server version table, including references for Windows 11, Windows 10, and Windows Server 2025 through 2016.

Adv Tech Of Mdav

Doc update

The documentation now links the “industry-best” detection and blocking statement to the Defender XDR top-scoring industry tests page.

Amsi On Mdav

Doc update

The AMSI on Microsoft Defender Antivirus article now points to the updated App Control for Business and AppLocker overview path.

Android New Ux

Doc update

The Android documentation now links to the specific Network protection configuration section when explaining where related events can be viewed.

Android Privacy

Doc update

The Android privacy documentation now links to a revised Microsoft Defender for Endpoint privacy article for Android and iOS.

Automation Levels

Doc update

The table entry describing the No automated response (no automation) level was revised.

Collect Diagnostic Data

Doc update

The investigation package guidance now links to the collection instructions using the relative `respond-machine-alerts.md` path and anchor.

Configure Endpoints Gp

Doc update

The Central Store for Group Policy Administrative Templates link now points to the Microsoft Learn troubleshooting page.

Configure Endpoints Sccm

Doc update

The network protection prerequisite now links to a different support article for obtaining the antimalware platform update.

Device Control Faq

Doc update

The FAQ now states that Group Policy has no configuration user interface for device control policy groups and rules, but administrators can configure them using the related .admx and .adml files.

Enable Troubleshooting Mode

Doc update

The Windows 21H2/SV1 row retains the requirement for build 22000.593 or later, but its Microsoft Update Catalog link now points to KB5011563.

Evaluate Mdav Using Gp

Doc update

The page’s Microsoft Update Catalog URL changed from a search for “KB4052623 update” to “KB4052623.”

Evaluate Microsoft Defender Antivirus

Doc update

The page removes the offline PDF download reference and revises the PowerShell download description to identify it as a script that enables the guide’s settings.

Ios Privacy

Doc update

The Defender for Endpoint iOS privacy page now points to an updated Microsoft Support article covering common privacy questions for Android and iOS mobile devices.

Mac Support Perf Overview

Doc update

The performance overview now directly links to real-time protection statistics guidance for identifying files and processes that trigger scans.

Mac Support Sys Ext

Doc update

The guidance now refers to the MDM console’s **Device Management** option instead of **Profiles** when locating configuration profiles.

Microsoft Defender Core Service Overview

Doc update

The page now links “Application Control for Windows” to the `/app-control-for-business/appcontrol` documentation path instead of the previous WDAC path.

Microsoft Defender Endpoint Antivirus Performance Mode

Feature updateAction required

The documentation now states that the updated “Configure performance mode status” template is available only after installing the Administrative Templates for Windows 11 2024 Update (24H2).

Minimum Requirements

Doc update

The minimum requirements page now links to the Microsoft Defender Antivirus updates document using a relative link.

Network Protection Linux

Doc update

The Linux network protection documentation now links to a different Microsoft Defender SmartScreen documentation page while retaining the existing description of blocking outbound HTTP(S) traffic to low-reputation sources.

Network Protection Macos

Doc update

The network protection for macOS page now links to the updated Microsoft Defender SmartScreen documentation URL.

Support Scams

Doc update

The article now links to a different Microsoft Support page for known tech support scam numbers and popular web scams.

Uefi Scanning In Defender For Endpoint

Doc update

The UEFI scanning documentation updated its reference describing how Windows Defender System Guard helps protect against firmware attacks and secure-boot threats.

Unwanted Software

Doc update

The unwanted software guidance now links to the updated Microsoft Support URL for troubleshooting unsuccessful threat removal.

View Incidents Queue

Feature update

The incident queue now displays incidents from the last week by default instead of the last six months, with the newest listed first.

9

Migrate to Microsoft Defender for Endpoint - Onboard

Doc update

The documentation now requires completing Phases 1 and 2 first, adds macOS and Linux prerequisites for detection tests, clarifies ForceDefenderPassiveMode usage and commands, and links to troubleshooting if antivirus remains passive after uninstalling a non-Microsoft solution.

Defender Endpoint Plan 1

Doc update

The page adds licensing details for standalone, Microsoft 365 E3, and server deployments, and updates links for Windows Firewall and Application Control documentation.

Onboard Downlevel

Doc update

Several prerequisite links were updated, including links for the February 2018 update rollup, telemetry update, .NET Framework, and Endpoint Protection anti-malware platform update.

8

Mac Troubleshoot Mode

Doc update

The page received updated metadata and date information, and its troubleshooting-mode operation headings were rewritten for clarity.

Troubleshoot Np

Doc update

The troubleshooting page now uses local Markdown links for compatibility, real-time protection, and cloud-delivered protection references.

Troubleshoot Live Response

Doc update

The Live Response troubleshooting page now links to revised Windows Push Notification Services overview and firewall configuration URLs. The MPNS public IP ranges link was removed.

5

Attack Surface Reduction Rules Configure

Doc update

The page now details precedence among local settings, Group Policy, MDM, and Configuration Manager, including the MDMWinsOverGP setting and OMA-URI. It also updates Intune navigation and explains per-rule exclusions.

Defender Endpoint Demonstration Attack Surface Reduction Rules

Doc updateAction required

The documentation now warns that the setup script excludes `c:\demo` from Microsoft Defender Antivirus scanning. Administrators must copy ASR test files to a folder not excluded by Defender Antivirus or ASR rules before opening or running them, then delete the copies afterward.

Attack Surface Reduction Rules Overview

Feature updateAction required

Starting with platform version 4.18.26060, using the Unblock option to override an ASR rule in Warn mode requires administrator approval. Per-ASR rule exclusions should be used for persistent exceptions.

Attack Surface Reduction Overview

Doc update

The Attack Surface Reduction overview now uses revised links for Microsoft Defender Application Guard, WDAC, and Windows Firewall documentation.

4

Run Advanced Query Api

Doc update

The page now states that the Defender for Endpoint advanced hunting API is old and limited, and is transitioning to the Microsoft Graph security API, which offers broader data coverage, improved consistency, and better scalability.

Offboard Machine Api

Feature update

The documented supported platforms now include macOS 14 and later and supported Linux distributions, alongside the existing Windows versions. On Windows, the API still stops the sensor without removing registry onboarding information.

Schedule antivirus scans using PowerShell

Feature update

The documentation now states that after two missed scheduled quick scans, a catch-up scan runs when the device powers on or resumes from sleep or hibernation, rather than when someone signs in.

3

Client Analyzer

Doc update

The client analyzer overview now links unexpected Endpoint Data Loss Prevention behavior to the `/purview/endpoint-dlp-learn-about` page instead of the previous `/microsoft-365/compliance/endpoint-dlp-learn-about` path.

2

Stop And Quarantine File

Doc update

The stop-and-quarantine-file API documentation now uses a repository-relative link to the Microsoft Defender Antivirus compatibility page.

1
67

Quarantine Admin Manage Messages Files

Doc update

The documentation now lists Security Operator alongside Global Reader and Security Reader for read-only and preview/download access to quarantined messages. It also documents handling of encrypted Safe Attachments items and clarifies that Get-QuarantineMessage permission properties reflect the executing user.

Submissions Users Report Message Add In Configure

Doc update

The documentation improves wording and formatting for Nested app authentication, Integrated apps navigation, app-registration deletion, and FAQ guidance on deprecation, client updates, and add-in removal.

Migrate To Defender For Office 365 Setup

Doc update

The article now refers to the SCL=-1 rule as the “bypass spam filtering” mail flow rule throughout Step 3, including pilot-group exceptions and rule conditions. The article date and supporting link text were also updated.

Preset Security Policies

Doc update

The page now places the link to “Order and precedence of email protection” under a dedicated Related content heading.

How Policies And Protections Are Combined

Doc update

A footnote was revised for organizations using a non-Microsoft security service or device before Microsoft 365. It references ARC and Enhanced Filtering for Connectors and advises checking service availability.

Reports Defender For Office 365

Doc update

The documentation no longer states that the report is in preview, unavailable to some organizations, and subject to change.

Simulation automations for Attack simulation training

Doc update

The page now explains automation execution, including schedule eligibility, run creation, technique and payload selection, user assignment, region-aware delivery, and delivery batches. It also documents supported scenarios and limitations, such as one payload per run and no guarantee of maximum randomized runs.

Email Authentication Arc Configure

Doc update

The page date was updated to 08/03/2026, and vendor-specific ARC sealer mappings, header examples, and PowerShell configuration steps for Proofpoint, Mimecast, Barracuda, Sophos, and IIJ were removed.

Email Authentication Dkim Configure

Doc update

The documentation changed its wording from “Exchange 2016 and Exchange 2019” to “Exchange 2016 and later” when describing message modifications that can affect DKIM.

Safe Attachments About

New feature

The documentation now explains quarantining password-protected attachments that cannot be scanned, including release workflows, just-in-time rescanning, file-type exclusions, password limitations, and advanced hunting.

Bulk email detection and bulk complaint level (BCL) in cloud organizations

Feature update

The documentation now states that bulk messages automatically receive the Promotions tag. Enabling Bulk moves enabled routes bulk mail that would otherwise reach the Inbox to the Promotions folder, and user folder actions inform future message handling. The previous rule that added the Bulk tag is no longer required; transport rules can exclude specific senders or recipients.

Quarantine End User

Doc update

The article now explains that users can provide an attachment password for Safe Attachments rescanning. Safe files are released; malicious or unscannable files remain quarantined. It also documents the one-attempt limit, portal-only release flow, and password safety guidance.

Spam confidence level (SCL) in Microsoft 365

Doc update

The page now explains that SCL no longer determines spam verdicts or final actions in cloud organizations. It directs admins to use header values such as CAT and DIR, while describing SCL uses for mail flow rules and on-premises Exchange.

Submissions Admin

Doc update

The page updates headings and submission instructions, formats notes consistently, documents language selection for default automatic notification templates, and adds related links.

Configure connection filtering in cloud organizations

Doc update

The documentation now explains that IP Allow List bypasses and SCL 0 are inputs rather than guaranteed final filtering decisions. It also clarifies how to add IP entries and links to mail flow rule guidance.

Configure Junk Email Settings On Exo Mailboxes

Doc update

The article now clarifies that Safe Senders entries do not determine the final spam verdict and that malware, high-confidence phishing, and other detections take precedence. It also reorganizes prerequisites and refreshes PowerShell formatting and wording.

Quarantine Policies

Doc update

The page now explains quarantine policies for Safe Attachments scanning and blocked encrypted attachments, documents related PowerShell parameters and default-policy behavior, and clarifies Get-QuarantineMessage permission properties.

Message Headers Eop Mdo

Doc update

The documentation now explains that SCL does not determine spam identification or actions in cloud organizations, and clarifies SFV:SKI, SFV:SKN, and SFV:SKS values and their filtering causes. It also updates bulk-mail and formatting details.

Submissions Teams

Feature updateAction required

The Teams submission steps were lightly reworded, and the documentation now states that reporting requires users with online Teams mailboxes and an Exchange Online reporting mailbox. On-premises mailboxes aren't supported. A related submissions link was also added.

Outbound Spam Restore Restricted Users

Doc update

The article explains that hosted mailboxes use the blocked mailbox UPN, while nonhosted senders use their sending SMTP address when viewing details or removing a restricted sender.

Anti Phishing Policies About

Doc update

The documentation now lists three scenarios where the tip isn’t stamped: S/MIME-signed messages, messages delivered after an SCL -1 bypass rule, and messages sent to mailboxes created less than seven days ago.

Attack Simulation Training Landing Pages

Doc update

Updated the landing page article to say built-in templates are localized into more than 12 languages, use “selecting” instead of “clicking” for checkbox actions, and format related links as list items.

Email Analysis Investigations

Doc update

The documentation now explains email clustering for SecOps mailboxes and phishing simulations, how Explorer filter exclusions behave, and how pending actions affect remediation status.

Mdo Sec Ops Guide

Doc update

The guide now bolds the product area for three roles and adds links to the Microsoft Defender for Office 365 overview and getting-started guide.

Outbound Spam Policies Configure

Doc update

The page updates its description of outbound spam handling, records the 2021 history of the Automatic system-controlled forwarding setting, refreshes metadata, and adds links about delegated From addresses and Send As/on behalf permissions.

Prompt Injection Protection Defender For Office 365

Feature update

The guide now states that Defender for Office 365 Plan 2 detects prompt injection content in inbound email, replacing the previous reference to Plans 1 and 2. Examples were reformatted and the article date was updated.

Siem Server Integration

New feature

The documentation now includes steps for connecting the Microsoft Defender XDR connector in Microsoft Sentinel to stream Microsoft Defender for Office 365 email event data into a SIEM.

Submissions User Reported Messages Custom Mailbox

Doc update

The documentation now states that reporting mailboxes cannot be distribution groups or external/on-premises mailboxes. It also notes that default investigation-result emails are localized to each recipient’s preferred language.

Anti Phishing Protection Tuning

Doc update

The article now documents `SFV:SKN` as an example for messages where a mail flow rule skips spam filtering, and adds a related-content link. The page date was also updated.

Quarantine Shared Mailbox Messages

Feature update

The documentation now states that users can manage quarantined messages sent to shared mailboxes without automapping. Access through quarantine notifications requires an enabled quarantine policy, notification access, and Full Access permissions to the shared mailbox.

Submissions Admin Review User Reported Messages

Doc update

The documentation now states that default automatic notification templates use each user’s preferred Outlook language and are enabled automatically when automatic notifications are turned on. Custom admin-configured templates are unaffected.

Create Block Sender Lists In Office 365

Doc update

The page date and terminology were updated, “High confidence spam” formatting was standardized, a Mail flow rules in Exchange Online link was added, and one SCL guidance paragraph was commented out.

Anti Spam Protection About

Doc update

The article now defines spam and high-confidence spam by the filtering verdict instead of fixed SCL ranges. It also updates the MarkAsSpamBulkMail explanation and publication date.

Quarantine About

Doc update

The page now documents that messages quarantined by Safe Attachments policies with unscannable encrypted attachments are retained for 30 days. Admins can release them without a password, while users can provide the password to rescan their own messages.

Advanced Delivery Policy Configure

Feature update

The documentation now states that Advanced Delivery applies only when simulation messages traverse the transport pipeline. Direct Injection messages bypass the pipeline and are not covered by the policy.

Attack Simulation Training Login Pages

Doc update

The login pages documentation now labels the phishing simulation link “Simulate a phishing attack with Attack simulation training.” The linked page remains the same.

Campaigns

Doc update

The campaigns documentation now explains that `SFV:SKS` means a message was marked as spam before spam filtering, either by an Exchange mail flow rule that set the SCL or by a spam decision from on-premises Exchange in a hybrid environment.

Create Safe Sender Lists In Office 365

Doc update

The article date was updated and now links to instructions for using mail flow rules to bypass spam filtering, while directing administrators to use the documented conditions and actions to safely allow senders.

Defender For Office 365 Whats New

Feature update

The documentation now states that automatic “Mark as and notify” emails using the default template are localized according to users’ Outlook language settings. Admin-configured custom templates are unaffected.

Attack Simulation Training Faq

Doc update

The FAQ now explains that delivery uses each recipient’s mailbox time zone with “not before” logic. Recipients receive simulations at the scheduled local time and never earlier.

Submissions Result Definitions

Doc update

The “Completed | Spam” definition now says similar items are more likely to be identified by spam filtering and handled according to anti-spam policies, replacing the previous SCL-threshold blocking wording.

Tenant Allow Block List About

Feature update

The documentation now states that tenant allow/block list entries apply to messages from both internal and external senders, with special handling for internal spoofing scenarios.

Air Report False Positives Negatives

Doc update

The documentation link label changed from “Microsoft Defender for Office 365” to “Microsoft Defender for Office 365 overview”; the linked page is unchanged.

Anti Spam Policies Configure

Doc update

The article corrects punctuation in the example about routing email through a non-Microsoft protection service before delivery to Microsoft 365.

App Guard For Office Install

Doc update

The App Guard for Office installation guide now uses an updated Microsoft Support URL for verifying that KB4571756 is installed.

Eop About

Doc update

The documentation now states that messages pass through anti-spam and anti-phishing filtering, removing the broader “content filtering” wording.

Outbound Spam Protection About

Doc update

The outbound spam protection documentation now links to guidance explaining how outbound spam policy limits apply to Send As and Send on behalf permissions.

Zero Hour Auto Purge

Doc update

The documentation now states more clearly that campaign-based remediation can affect messages older than 48 hours, typically within a few hours to a few days after delivery.

3

Troubleshoot anti-spam policies in Microsoft Defender for Office 365

Doc update

The article now uses “spam filtering” and “spam verdict” terminology instead of focusing on SCL overrides. Its guidance and table clarify the effects and limitations of mail flow rules, IP Allow List entries, and Outlook Safe Senders, including the on-premises SCL context.

1

Migrate To Defender For Office 365 Onboard

Doc update

The migration document updates terminology, anchors, and metadata. It now identifies the SCL -1 mail flow rule as the bypass spam filtering mail flow rule while retaining the instruction to turn it off without deleting it.

1

Threat Explorer Threat Hunting

Doc update

The article removed the “Additional threat hunting and response capabilities” heading, its introductory text, and its anchor, replacing them with a “Related content” heading.

1

Alert Policies Defender Portal

Doc update

The Microsoft Entra permissions description was clarified, and a Related content link was added for managing incidents and alerts in Microsoft Defender XDR.

57

Accounts security posture assessment

New feature

The page adds assessments for privileged external or guest accounts, WriteDACL permissions on sensitive groups, and highly privileged service accounts. It also updates anchors and removes “(Preview)” from several existing assessment headings.

Activate the Microsoft Defender for Identity sensor v3.x

Private preview

The documentation now covers eligible domain controllers and non-domain-controller AD FS, AD CS, and Microsoft Entra Connect servers. Activation on the latter servers is in preview and currently requires manual activation; automatic activation and migration aren't supported.

Investigate Domain

New feature

Documentation now describes a Security recommendations (Preview) view for scoped users on domain pages. Users can access it from the Identity dashboard and review recommendation names, statuses, update times, details, and remediation guidance.

Remediation Actions for Compromised Users in Microsoft Defender for Identity

Feature update

The article now explains that remediation actions depend on the connector managing an identity and includes connected apps through Microsoft Defender for Cloud Apps. Enable is listed for CyberArk Identity, SailPoint Identity Security Cloud, and Salesforce, while Force password change is listed for Microsoft Entra ID as well as Active Directory.

Migrate To Sensor V3

Feature update

Migration is unsupported on non-domain-controller servers running AD FS, AD CS, or Microsoft Entra Connect, while domain controllers running these roles are included. RPC auditing is automatic from sensor 3.0.8, and v3.x updates through Windows Update without the v2.x delayed-update option. Readiness reasons now appear in the Sensors page tooltip.

What's new | Microsoft Defender for Identity

Feature update

The August 2026 documentation describes automatic auditing for eligible AD FS, AD CS, and Microsoft Entra Connect servers running sensor v3.x, sensor version 2.255.19295.47272, Windows Server 2025 domain controller migration to sensor v3.x, and migration-readiness reasons on the Sensors page.

Manage and Update Sensors

Feature update

The documentation now includes domain controllers running AD FS, AD CS, or Microsoft Entra Connect, and states that v3.x sensors update through Windows Update. It also clarifies that the per-sensor Delayed update option applies only to v2.x sensors and expands migration-state descriptions.

Microsoft Defender for Identity XDR security alerts

Doc update

The page adds entries for AADInternals private-key extraction, malicious or suspicious MFA-method registration, and updates several existing alert descriptions. It removes entries for Honeytoken Activity, stolen session-cookie replay, suspicious Entra device join or registration, and adds guidance on Classic versus Defender-format alerts and alert tuning.

Migrate from Advanced Threat Analytics

Doc update

The article now uses a shared ATA end-of-life notice, adds a Defender for Identity prerequisites link, identifies the final ATA release, and updates product names and links to Microsoft Defender.

Manage action accounts in Microsoft Defender for Identity

Doc update

The article title, wording, and screenshot descriptions were updated. It now explicitly introduces configuring a dedicated gMSA action account and clarifies the security rationale for separating action and Directory Service accounts.

Microsoft Defender for Identity classic security alerts

Doc update

The alerts documentation now explains that some vulnerability alerts may still trigger after the relevant security update. When all affected systems are patched, applicable alerts have Low severity and may show patch status in the evidence. Documentation for Group Policy Tampering was also added.

Entity tags in Microsoft Defender for Identity

Doc update

The article now uses Microsoft Defender terminology, clarifies sensitive, Exchange server, and honeytoken tagging guidance, and notes that Entra ID and SailPoint Identity Security Cloud roles are used for sensitive entity tagging.

Security alerts

Doc update

The page now explains that sensor versions can contribute to either classic or Defender-format alerts. During the transition, detections may appear in both lists with different names; Detection source identifies the format. Tuning and exclusions are format-specific.

Microsoft 365 Security Center Mdi

Doc update

The page now refers to Microsoft Defender instead of Microsoft Defender XDR and updates the alert-tuning description to say it improves threat detection coverage throughout your system.

Start your Defender for Identity deployment security assessment

Doc update

The page now states that the assessment identifies servers without a Defender for Identity sensor and helps you unde… It also updates the metadata date and changes the advanced hunting link text from Microsoft Defender XDR to Microsoft Defender.

Integrate Microsoft And Pam Services

Doc update

The page now refers to Microsoft Defender instead of Microsoft Defender XDR for automatic PAM-managed identity tagging and password resets for high-risk privileged accounts.

Security Testing Best Practices

Doc update

The guidance changes references from Microsoft Defender XDR to Microsoft Defender and updates the Security operations overview link.

Connect Okta to Microsoft Defender for Identity (Preview)

Doc updateAction required

The documentation now explicitly instructs administrators to create a custom Okta role named Microsoft Defender for Identity, assign it with the Read-Only Administrator role, and remove Super Admin after confirming both roles are assigned.

Configure Windows event auditing

Feature update

The documentation now describes automatic Windows event auditing for sensor v3.x on domain controllers, AD FS, AD CS, and Microsoft Entra Connect servers. Sensor v2.x and opted-out v3.x deployments still require manual configuration. AD CS requires an existing CA audit filter.

Integrate VPN with Microsoft Defender for Identity

Feature updateAction required

The guide now requires at least one connected, healthy Defender for Identity sensor version 2.x to receive RADIUS accounting events. It also reiterates that FIPS environments aren't supported and updates Microsoft Defender terminology and navigation.

Uninstall the Sensor

Doc update

The page now prominently warns that deleting the sensor removes the v3.x sensor software and stops monitoring on the domain controller. Steps, images, headings, and numbering were also reformatted.

Detection exclusions in Microsoft Defender XDR

Feature updateAction required

The documentation now states that existing exclusions do not automatically carry over when detections move to the Microsoft Defender XDR detection engine. Once moved, those exclusions stop applying and previously suppressed alerts can reappear.

Microsoft Defender for Identity Notifications

Doc update

The page now uses Microsoft Defender naming, refreshed navigation wording, and updated SIEM guidance that instructs automation authors to use the permanent externalId field. The event-collection link text was also updated, and the TLS certificate tip was removed.

Troubleshooting known issues

Doc update

The article now identifies two affected alerts involving the ADFS and Configuration containers, clarifies that the issue affects sensor v3.x environments, and adds a Microsoft Defender portal resolution path.

Investigate alerts in Microsoft Defender for Identity

Doc update

The article now refers to the alert details side pane, identifies Defender for Identity as the capability tuned by alert classification, and clarifies the tabs and Related Entities data in exported Excel alert reports. The metadata and date were also updated.

Daily Operational Guide - Microsoft Defender for Identity

Doc update

The guide’s title and metadata were updated, and its incident-triage guidance was streamlined. It continues to recommend reviewing the Global and Sensor Health Issues tabs and setting up service-issue email notifications.

Manage reports | Microsoft Defender for Identity

Doc update

The Defender for Identity reports article updates its metadata and clarifies that administrators should repeat the linked report-scheduling steps to change scheduled times or recipients.

Monitored Activities

Doc update

The monitored activities page now refers to Microsoft Defender’s Advanced Hunting page instead of Microsoft Defender XDR’s Advanced Hunting page; the link destination is unchanged.

Role Groups

Doc update

The role-groups documentation was updated for permissions to perform Defender for Identity response actions, including the custom Response (manage) role and listed Microsoft Entra roles.

3

Deploy the Defender for Identity sensor v3.x

Feature updateAction required

The documentation now covers v3.x sensors on non-domain-controller AD FS, AD CS, and Microsoft Entra Connect servers. Activation there is in preview, requires manual activation, and does not support automatic activation or migration.

Deploy Microsoft Defender for Identity sensors

Doc updateAction required

The deployment article now states that VPN integration and syslog notifications require the v2.x sensor on applicable domain controllers; these features aren't supported by v3.x.

1
1
99

Migrate File Policies To Purview

RetirementAction required

The documentation now describes a DLP to Purview migration tool, including prerequisites, supported SharePoint and OneDrive policies, migration steps, and unsupported scenarios. Existing file policies have a January 6, 2027 deadline for migration to maintain coverage.

SaaS Security Initiative in Microsoft Defender XDR

Doc update

The article now emphasizes SSPM recommendations organized into 12 metrics, adds prerequisite guidance, and updates instructions for accessing, prioritizing, and tracking recommendations in the Defender portal.

Govern discovered apps

Feature updateAction required

The article now requires a supported on-premises security appliance to be configured and available before importing a block script. It also clarifies unsanctioned-app blocking across integrations and governance-action precedence.

Protect your Zendesk | Microsoft Defender for Cloud Apps

Doc update

The article now refers to the Zendesk environment, adds navigation anchors, identifies OAuth credential creation in Zendesk for the connector, and clarifies the SaaS security posture management and rate-limit sections.

Ems Cloud App Security Govt Service Byok

Doc update

The page now clarifies that enabling customer-managed data encryption is available only in the Microsoft Defender portal, updates screenshot descriptions, labels the disabling-encryption note as a warning, and improves the key-rotation section heading and anchor.

Connect Zoom | Microsoft Defender for Cloud Apps

Doc update

Updated metadata and introductory wording, expanded the related-information reference to SaaS security posture management and Microsoft Secure Score, and added a lead-in to the connection steps.

Generic SIEM integration

Doc update

The documentation states that existing Defender for Cloud Apps SIEM agents continue functioning until November 2025. It also confirms that new SIEM agents cannot be configured and that Microsoft Sentinel agent integration remains supported in preview.

Anomaly detection policies in Microsoft Defender for Cloud Apps

Doc update

The documentation now explains the heuristic and machine-learning baselines, clarifies the seven-day learning period and dynamic threat detection model, updates navigation and terminology, and lists activity by terminated users as a detection.

Apps Manual Onboarding With Microsoft Entra Id

Doc updateAction required

The article now advises verifying licenses, administrative access, and app configuration before onboarding. It also specifies that catalog applications appear in the Connected Apps table on the Conditional Access App Control page.

Configure activity monitoring to protect user privacy

Doc update

The article now provides expanded guidance for configuring privacy groups, granting admins permission to view private activities, and viewing those activities in the activity log. Wording, headings, image descriptions, anchors, and audit-log explanations were also refined.

File policies in Microsoft Defender for Cloud Apps

Doc update

The article now uses clearer file-policy terminology, adds updated limitation structure and screenshot text, and directs administrators to Policies > Policy management in the Microsoft Defender portal to review violations.

Investigate accounts from connected apps

Doc update

The article now explains how to view and use the Cloud application accounts inventory, investigate accounts, filter by account type, and take actions. It also updates headings, anchors, screenshot descriptions, and metadata.

Cloud discovery policies

Doc update

The article now explains that selecting “Tag app as unsanctioned” automatically blocks access when the policy matches, and defines app tags as labels for filtering and targeting discovered apps.

Integrate with Corrata

Doc update

The article now includes a pre-deployment licensing section and clearer deployment instructions, along with wording, image-description, metadata, and formatting updates.

Integrate with iboss

Doc updateAction required

The page adds a reminder to confirm required licenses, clarifies deployment instructions, updates the section heading, and improves the setup screenshot description.

Create policies to control OAuth apps

Doc update

The article now explains creating and managing app permission policies to control OAuth app behavior, including notifications, permission investigation, and approval or banning. It also notes that OAuth app policies trigger alerts only for policies authorized by users in the tenant.

Protect your Amazon Web Services environment

Doc update

The Protect AWS page received clearer wording, a renamed section with an HTML anchor, updated connector API guidance, and minor credential wording changes. Page metadata was also updated.

Submit an App Catalog update request

Doc update

The page now has clearer section titles and anchors, updated metadata, and more precise wording about when to open a support ticket and how such tickets are reviewed.

DLP content inspection

Doc update

The article now identifies “Grant permission” as one-time administrator consent, clarifies that content and metadata are inspected by default, and adds guidance for configuring file policies that inspect protected files.

Governing connected apps

Doc update

The page now clarifies role restrictions, that malware governance actions apply only to connected apps, and that Microsoft Entra synchronization can revert the Suspend user or other affected governance actions. It also refines OAuth permission guidance and wording.

Integrate with Zscaler

Doc update

The article now explicitly describes prerequisites and deployment steps, and clarifies that unsanctioned apps are blocked according to settings in the Zscaler portal.

Work with IP ranges and tags

Doc update

The article now more clearly describes defining IP ranges, assigning categories and custom tags, using built-in tag IDs, and creating tags. It also updates terminology, metadata, and image alt text.

Add custom apps to cloud discovery

Doc update

The documentation now highlights that using **Remove all tags** removes the **Custom app** tag, while retaining instructions for filtering custom apps by that tag. Wording around custom apps was also clarified.

Create cloud discovery policies

Doc update

The article now includes expanded introductory guidance, clearer wording for saved organization-wide alert defaults, updated metadata, and more descriptive screenshot alt text.

Release Notes

Feature update

Starting in August 2026, new Defender for Cloud Apps customers will have unified RBAC automatically enabled, providing centralized role and permission management across Microsoft Defender products.

Remediate OAuth app threats with app governance alerts

Doc update

The page now refers to the Defender portal Alerts and Incidents pages, clarifies which approval, ban, notification, and permission-revocation procedures apply to Salesforce and Google Workspace, and improves screenshot descriptions.

Integrate with Open Systems

Doc update

The page now includes a licensing prerequisite and introductory instructions for deploying the Defender for Cloud Apps and Open Systems integration. Metadata was also updated.

Protect your Miro environment

Doc update

The article now uses a clearer prerequisites link, adds a named anchor, renames the “Main threats” section to “Main threats to your Miro environment,” and introduces a table of supported governance actions.

Import user groups from connected apps

Doc update

The page now uses a more specific heading and anchor for importing a user group from a connected app, and clarifies the Salesforce standard profiles link text. Documentation metadata was also updated.

Create snapshot cloud discovery reports

Doc update

The article now explicitly describes creating a snapshot report by manually uploading firewall or proxy traffic logs to validate the log format and gain initial cloud app visibility before using the automatic log collector.

Microsoft Data Classification Services integration

Doc update

The article title and terminology were refined, and the masking instruction now explicitly states that selecting the checkbox unmasks the last four characters of a match. Metadata was also updated.

Protect your Azure environment

Doc update

The page now introduces the steps for connecting Azure to Defender for Cloud Apps, refreshes best-practice link wording, and updates its metadata.

Cloud discovery data anonymization

Doc update

The page date and authoring metadata were updated. Wording now identifies Defender for Cloud Apps as generating reports from anonymized data and states that each username resolution action is recorded in the portal’s Audit log.

Configure Defender for Cloud Apps user email notifications

Doc update

The page now describes customizing end-user email notifications with HTML templates, branding, titles, and content placeholders, and notes supported notification types and differences from admin notifications. It also updates the sample-template wording and page metadata.

US Government offerings

Doc update

The page date changed to August 7, 2026. The documented list now retains only app metadata associated with a known phishing campaign; three other examples were removed.

Get Started

Doc update

The getting-started guidance now directs Defender for Endpoint users to the Defender portal, rather than Microsoft Defender XDR, to turn on the required setting.

5

Deploy conditional access app control for any web app using AD FS

Doc update

The instructions now specify using the AD FS SingleSignOnService Location from the federation metadata and explicitly require a Microsoft Defender for Cloud Apps license. They also clarify which values are needed when configuring the relying party trust.

5

Investigate activities using the API

Doc update

The article now describes scanning and retrieving large volumes of activity data, clarifies pagination wording, and reorganizes the next-steps links under Related content.

Manage IP address ranges using the API

Doc update

The article now provides clearer coverage of Data Enrichment API operations, Python CSV synchronization, pagination using `nextQueryFilters`, deletion behavior, and Defender for Cloud Apps support.

3
2

Set up Microsoft Defender for Cloud Apps

Doc update

The article was retitled and updated with clearer Microsoft Purview Information Protection setup ordering, an Identity Inventory irreversibility warning, refreshed links, and wording corrections.

1
1
1
195

Technical onboarding guide for Bright Security (preview)

Doc update

The guide updates its date, adds navigation anchors, clarifies the Azure Marketplace listing and DevOps onboarding prerequisites, and reorganizes GitHub and Azure DevOps scan configuration and verification instructions.

AI model security (Preview)

Doc update

The documentation reiterates that AI model scanning is in preview, included with the Defender for AI Services plan, and has no additional scanning charge during preview; related threat protection costs may still apply.

Migrate from classic Defender for SQL APIs

RetirementAction required

The guidance identifies classic Vulnerability Assessment and Advanced Threat Protection APIs, explains the move from database-level to server-level configuration, and provides a read-only PowerShell script to find affected SQL Database, Managed Instance, and Synapse resources.

Release Notes

RetirementAction required

The documentation announces that classic Defender for SQL Vulnerability Assessment and Advanced Threat Protection APIs will retire on August 16, 2027, alongside updates covering CVE queries, storage malware scanning, AWS/GCP identity assessments, GuardDuty coverage, and Cosmos DB availability.

Review and remediate SQL vulnerability assessment findings

Doc update

The instructions now explain how to open vulnerability summaries from SQL server or database resources, use Resource Health to start scans, and review findings from the Microsoft Defender for Cloud page. Screenshots, links, and metadata were also updated.

Transition from disable rules to exemptions

Doc updateAction required

The article now explains how to migrate existing disable rules to exemptions and includes a Standard Assignments REST API example for vulnerability-based exemptions matching CVE ID, severity, and CVSS score.

Remediate machine vulnerabilities

Doc update

The article updates scanning prerequisites, changes the review workflow to use Recommendations > Vulnerabilities with filtering and resource grouping, and adds an Azure Resource Graph query for software update recommendations.

How to consume and export scan results

Doc update

The documentation now directs administrators to the Recommendations page, filter Scanner to SQL Vulnerability Assessment, and use the selected recommendations view. The Resource Graph Explorer example now queries assessments, filters by scanner, and uses updated result fields.

Prepare for retirement of the Log Analytics agent

RetirementAction required

The documentation now describes the Log Analytics (MMA) agent as retired in November 2024, updates affected Defender for Servers features, and clarifies replacement recommendations and onboarding guidance.

Enable and configure Microsoft Defender for Storage (classic)

Doc updateAction required

The page now clarifies that classic-plan users must migrate to access malware scanning, sensitive data threat detection, and per-storage-account pricing. It also expands instructions for excluding storage accounts, including tagging accounts and disabling protection with PowerShell or Azure CLI.

Express configuration vulnerability findings

Doc update

The article now clarifies how to identify classic versus express configuration, adds explicit Azure portal steps for scan history and rules, and improves headings, wording, and section links.

Stream alerts to monitoring solutions

Doc update

The page now separates PowerShell and Azure portal setup paths, labels Splunk- and QRadar-specific guidance, updates reference links, and clarifies Microsoft Graph Security API alert streaming and related content.

Scan for vulnerabilities on SQL servers

Doc update

The article updates guidance for reviewing SQL vulnerability assessment findings from Defender for Cloud or an individual resource page. It adds modern and legacy experience guidance, explains baselines, and directs administrators to use recommendation exemptions for findings they choose to ignore.

View and remediate vulnerabilities for running containers

Doc update

The article was revised for clearer wording, updated metadata, simplified prerequisite instructions, and refreshed links and step descriptions. The documented component combinations and recommendation workflow were clarified.

Simulate alerts for SQL servers on machines

Doc update

The article updates terminology, clarifies the simulation flow and target machines, revises implementation details, and directs users to Security Alerts > Simulate Alerts with refreshed screenshots.

Enable data security posture management

Doc update

The article now provides clearer prerequisites and setup guidance for enabling scanning of AWS S3 buckets and RDS instances, with updated links and next-step navigation.

Migrate from Defender for Storage (classic)

Doc update

The page now explicitly states that moving to the new Defender for Storage plan cannot be reversed, expands the benefits description, clarifies policy behavior, and updates migration-method guidance and script references.

Manage Security Incidents

Doc update

The incidents article now provides clearer steps for finding and managing incidents, improves screenshot descriptions, clarifies incident and alert wording, and updates the next-steps link.

Remediate code with Microsoft Security Copilot

Doc update

The article now explains that Copilot generates pull requests to correct Infrastructure as Code misconfigurations, adds a before-you-begin section, clarifies the remediation steps, and emphasizes developer review before merging.

What is Cloud Security Posture Management (CSPM)

Feature updateAction required

Starting October 27, 2026, Foundational CSPM will no longer be enabled by default for new Azure subscriptions. The documentation also adds Azure Database for PostgreSQL flexible server assessments and lists PostgreSQL and MySQL flexible servers as supported database types.

Configure the Microsoft Security DevOps Azure DevOps extension

Doc update

The documentation now explains installing the Microsoft Security DevOps extension, configuring YAML pipelines with static analysis tools, and publishing SARIF findings to Defender for Cloud. It also documents the optional SARIF SAST Scans Tab extension for displaying results in the pipeline’s Scans tab.

Determine access control requirements for multicloud security

Doc update

The article now focuses on determining permissions and access controls for multicloud deployments as part of CSPM and CWPP design. It adds an overview and sections for defining objectives and assessing requirements, with updated metadata.

Download a CSV report

Doc update

The page now covers exporting both security alerts and recommendations as CSV reports, with separate procedures, a prerequisites section, and updated navigation metadata.

Explore risks to pre-deployment generative AI artifacts

Doc update

The article now more clearly explains how Defender for Cloud CSPM scans AI artifacts for known library vulnerabilities and how to use Cloud Security Explorer to find affected containers and Azure OpenAI code repositories. It also adds prerequisite guidance and corrects remediation links.

Gain application and end-user context for AI alerts

Doc update

The article now describes adding end-user and application context to Azure AI API calls, clarifies misspelled UserSecurityContext fields, and adds supported API and SDK guidance. It also specifies that the parameters are unsupported with models deployed through the Azure AI model inference API.

Disable vulnerability findings on images (risk-based)

Doc update

The page now warns that deleting a disable rule re-enables findings for the affected scope; suppressed findings reappear and affect secure score. It also adds related-content structure and updated metadata.

Query software bill of materials (SBOM)

Doc update

The article now describes querying repository and package data in the cloud security graph, adds a prerequisite note, updates the heading anchor, and refreshes metadata.

Set up continuous export in the Azure portal

Doc update

Updated the setup heading and anchor, clarified how vulnerability assessment findings are included, and specified export destinations and the separate CSV alert export guidance.

Configure vulnerability assessment for Docker Hub

Doc update

The Defender for Cloud Docker Hub vulnerability assessment page updates its date and metadata, clarifies the Azure subscription prerequisite, and adds an explicit step for onboarding a Docker Hub organization.

Assign access to workload owners

Doc update

The article now describes how AWS and GCP onboarding creates security connectors and an IAM role, and clarifies assigning RBAC permissions to account or project connectors at subscription, resource group, or resource scope.

Disable vulnerability findings for virtual machines

Doc update

The page title and heading now explicitly refer to virtual machines, and the guidance uses “recommendation exemptions” terminology. The prerequisite to review vulnerability assessment findings was also reworded and repositioned.

Enable threat protection for AI services

Retirement

The documentation states that the current Microsoft Purview configuration method for Microsoft Foundry is being deprecated and links to a new configuration method.

Explore and investigate Defender for SQL security alerts

Doc update

The article’s date and authoring metadata were updated, introductory wording was revised, and the alerts section received a named anchor and a more specific heading: “Open SQL security alerts in Defender for Cloud.”

Review pull request annotations in GitHub and Azure DevOps

Doc update

The documentation now explains that Defender for Cloud pull request annotations help identify and resolve security issues before code is merged in GitHub and Azure DevOps. It also updates wording, metadata, and related-content navigation.

Sql Azure Vulnerability Assessment Rules

Feature update

The documentation now notes the transition from grouped recommendations to individual recommendations and explains that the Scanner filter can locate SQL Vulnerability Assessment recommendations in alerts and recommendations experiences. It also updates the changelog link.

Explore risks to sensitive data

Doc update

The article now explains that findings can be identified, prioritized, and exported for sharing with data owners. It also expands abbreviations and product terminology for PaaS databases and Amazon S3 buckets.

Summarize recommendations with Microsoft Security Copilot

Doc update

The article now uses simpler wording to explain summarizing Defender for Cloud recommendations with Microsoft Security Copilot, understanding risks, and deciding what to address first. The documented steps remain the same.

Identify SQL Servers protected by Microsoft Monitoring Agent

Doc update

The article description now focuses on identifying SQL Server instances using the legacy Microsoft Monitoring Agent, deploying Azure Arc, and migrating to the updated agent. The pricing notice was also updated to call out possible migration-related pricing impact.

Review data security alerts

Doc update

The page date and authoring metadata were updated, and the “Next step” heading was changed to “Next steps” with a named anchor added.

Sql Azure Vulnerability Assessment Overview

RetirementAction required

The documentation now states that APIs for classic vulnerability assessment configuration and classic Defender for SQL Advanced Threat Protection will be retired on August 16, 2027, with migration guidance provided.

Release Notes Recommendations Alerts

Retirement

The deprecated grouped recommendation data is no longer available through the API. Azure portal and Azure Resource Graph updates may take several days. Related Defender for SQL Vulnerability Assessment recommendations were also released as generally available.

Defender For Sql Servers Introduction

Doc update

The Defender for SQL servers on machines page now links vulnerability assessment reports to the section for viewing vulnerabilities in graphical, interactive reports. The documented scan interval remains 12 hours.

Container runtime antimalware detection and blocking

Doc update

The page now documents enabling antimalware through Defender sensor auto-provisioning, Helm for sensor 0.10.x or later, or the AKS preview API. It also updates prerequisites and removes earlier multicloud and `--antimalware` instructions.

Recommendations Reference Data

Doc update

The reference page no longer lists recommendations for resolving vulnerability findings in SQL databases and SQL servers on machines, including their related policy links and high-severity labels.

Configure agentless code scanning (Preview)

Doc update

The article’s wording and metadata were updated, the “Scanning tools” section was renamed “Supported scanning tools,” and the Template Analyzer license label was clarified.

Technical onboarding guide for 42Crunch (preview)

Doc update

The article now describes integrating 42Crunch audit and scan findings with Defender for Cloud, adds Azure DevOps configuration steps, and clarifies the DevOps connection requirement for viewing results. It also labels the integration as preview.

Binary drift detection and blocking

Feature update

Binary drift blocking now lists sensor version 0.10.2 or later for AKS and multicloud, and supports the multicloud ARC extension without specifying a preview release train. The documentation also warns that deleting a rule can change alerting or blocking behavior.

Enable preview features in the Defender portal

Doc update

The article now clarifies prerequisites, enablement steps, the up-to-24-hour activation period, new preview recommendations, and where to find Defender for Cloud in the Azure portal. It also adds related-content links and updated metadata.

Support Matrix Defender For Containers

Feature update

The support matrix combines binary drift detection and blocking into one GA capability for AKS, EKS, and GKE, and updates the listed sensor requirement and cloud availability. Azure Government and Azure operated by 21Vianet support are also clarified for selected entries.

Connect Mend.io to Defender for Cloud (Preview)

Doc update

The page date and authoring metadata were updated, the Mend.io account prerequisite and Azure portal link were reworded, and the section heading now reads “Connect Mend.io to Defender for Cloud.”

Support Matrix Defender For Cloud

Feature update

The support matrix changes an additional Defender for Azure Cosmos DB entry from NA to GA and updates the AI interactions link to a corrected Microsoft Purview anchor.

Enable agentless machine scanning

Doc update

The article now details supported Azure, AWS, and GCP machines, Kubernetes coverage, capabilities by plan, scan limitations, unsupported configurations, permissions, and the 24-hour schedule. It also directs administrators to review coverage before enabling scanning.

Microsoft Defender for Storage on-demand malware scanning

New feature

The documentation now describes scanning specific blobs, files, containers, file shares, or path prefixes through the REST API, in addition to scanning an entire storage account. It also documents portal initiation and retry scenarios for individual objects.

Opt in to Foundational CSPM

Feature updateAction required

Starting October 27, 2026, Foundational CSPM will be disabled by default for new Azure subscriptions. It remains free; existing subscriptions retain their current configuration, and AWS and GCP environments are unaffected.

Cloud asset inventory

Doc update

The article now covers connected resources across Azure, AWS, and GCP; filtering, exporting, investigation, installed-application details, and Azure Resource Graph software inventory queries. It also clarifies summary metrics and assets outside configured cloud scopes.

Disable and remove Defender for Containers

Doc update

The documentation adds commands and procedures for disabling Defender for Containers and removing Defender components, extensions, Azure Policy integrations, and related AWS or GCP resources from AKS, EKS, GKE, and Arc-connected clusters. It also adds checks to confirm plans, extensions, and Defender pods are removed.

Enable cloud infrastructure entitlement management (CIEM)

Feature update

The documentation states that starting August 6, 2026, Defender for Cloud will continue identifying overprovisioned AWS and GCP identities but will stop calculating and displaying detailed unused permission actions.

What is Serverless protection?

Feature updateAction required

The documentation states that stale recommendations will be removed starting August 18 and adds instructions for enabling Serverless protection for Azure subscriptions and connected AWS accounts through Defender CSPM.

Enable Microsoft Defender for Azure Cosmos DB

Doc update

The article now provides clearer prerequisite, portal, PowerShell, CLI, ARM template, and Azure Policy guidance. It also explains how to verify protection status and use sample alerts to test alerting, automation, and notification pipelines.

Validate alerts in Microsoft Defender for Cloud

Doc update

The article now uses clearer alert descriptions, identifies sample alerts in delivery guidance, separates Defender for Endpoint prerequisites, and refines Windows and Defender for Containers testing instructions.

Microsoft Defender for Storage on-upload malware scanning

Doc update

The article now clarifies enablement prerequisites and supported configuration methods, adds an overview of upload triggers and scanning stages, and updates links to costs, results, limitations, and privacy information.

Remediate EDR solution recommendations

Doc updateAction required

The page now explicitly requires agentless scanning and Defender for Servers Plan 2 or Defender CSPM for EDR recommendation investigation and remediation. It also clarifies supported machine coverage and when Defender for Endpoint integration is available.

Introduction to Defender for Storage malware scanning

Doc update

The page now explains scanning an entire storage account or targeted items, including individual blobs, containers, and path prefixes. It also adds supported content types and sizes, limitations, privacy and regional processing details, and an additional investigation use case.

Review and manage recommendation exemptions

Doc update

The article now provides separate steps for reviewing exemptions from the Recommendations and Inventory pages, clarifies Resource Graph query guidance, and adds instructions for locating exemptions and cleaning up duplicates.

Kubernetes data plane hardening

Doc update

The article now explains Azure Policy for Kubernetes more precisely, describes resource-exclusion parameters, clarifies recommendation-based installation by cluster type, updates deployment links, and adds compliant and intentionally noncompliant workload examples.

Workflow automation in Microsoft Defender for Cloud

Doc update

The article now clarifies Logic Apps navigation, legacy trigger guidance, DeployIfNotExist policy behavior, and data schema access. It also improves headings, links, screenshots, and accessibility text.

Enable Just-in-Time Access

Doc update

The article now documents enabling and requesting just-in-time VM access through Azure virtual machines in the Azure portal, PowerShell, and the Defender for Cloud REST API. It also clarifies that the PowerShell `-Name` parameter specifies the JIT policy name for each VM.

Operating system misconfigurations

Doc update

The article now more clearly describes OS baseline misconfiguration assessment and remediation, updates terminology and links, and adds a “Supported systems and requirements” section heading.

Map container images from code to runtime

Doc update

The article now describes mapping from CI/CD pipelines to registries and Kubernetes runtime, covers DevOps connectors, Docker labels, and GitHub attestations, and adds prerequisites and Azure portal verification guidance.

Create automatic tickets with governance rules

Doc update

The page now describes governance rules as automatically opening ServiceNow ITSM tickets for selected recommendations or severity levels. It also clarifies the ServiceNow permissions prerequisite, rule criteria, and next-step resources.

Discover sensitive data in cloud resources

Doc update

The article now presents prerequisites as a linked checklist and uses simpler wording for reviewing sensitive data findings, recommendations, and alerts. The publication date and authoring metadata were also updated.

Enable File Integrity Monitoring

Doc update

The page now clearly describes configuring File Integrity Monitoring in the Azure portal after enabling Defender for Servers Plan 2, using the Defender for Endpoint agent and agentless machine scanning. It also improves links, headings, and disablement instructions.

Manage Respond Alerts

Doc update

The page now uses clearer wording for filtering, investigating, updating alert statuses, and finding related guidance. It also specifies that remediating an agent-based alert does not remediate its corresponding agentless alert until the next scan.

Set Up Automated Remediation for Malware Detection

Doc update

The documentation now details remediation options, links ABAC setup to scan results, clarifies Logic App and Event Grid Function App guidance, and explains using blob copy operations. It also adds guidance for allowing downstream applications to process blobs only after a clean scan result.

Cross-tenant management

Doc update

The documentation now explains that Azure Lighthouse grants managing-tenant identities access to delegated resources without creating local users or role assignments in the managed tenant. It also states that the managed tenant’s Azure Activity Log records these actions and identifies the acting user.

Customize data sensitivity settings

Doc updateAction required

The article now directs administrators to review prerequisites and enable sensitive data discovery before configuring settings. It also clarifies that supported types are a subset of Microsoft Purview’s built-in types and updates related wording and navigation.

Remediate system updates and patches recommendations

Doc update

The article now calls out prerequisites before verification or remediation, renames the **Fix option** to **Fix**, clarifies that updates are applied as a one-time fix, and simplifies navigation instructions and heading structure.

Assign a recommendation to an active user

Doc update

The page date and authoring metadata were updated, and the guidance was rewritten for clarity. It still describes suggestions of up to three users based on control plane activity and assigning recommendations with notifications and due dates.

Create a ticket in Defender for Cloud

Doc update

The article now introduces prerequisites, clarifies supported incident, change request, and problem ticket types, explains that deleting the integration removes associated assignments within up to 24 hours, and updates the next-steps heading and anchor.

Disable Microsoft Defender for Cloud plans

Doc update

The page now clarifies multicloud navigation, identifies the Defender for Storage resource-level override, adds a Defender for SQL resource-level section, and updates metadata and heading anchors.

Discover generative AI workloads

Doc update

The article adds a prerequisites section, clarifies the wording for node findings, updates the Next steps heading and anchor, and refreshes documentation metadata.

Estimate costs with the Microsoft Defender for Cloud cost calculator

Doc update

The documentation now recommends adding assets from onboarded Azure environments, using scripts for environments not yet onboarded such as AWS or GCP, and uploading the CSV generated by the script. It also adds guidance for manually adding a custom environment and clarifies the permissions overview.

Grant and request tenant-wide permissions

Doc update

The documentation now identifies Global Administrators as responsible for granting or requesting Azure permissions needed to view organization-wide Defender for Cloud information. It also clarifies the limited-view banner workflow and updates section headings and links.

Kubernetes misconfiguration enforcement

Doc update

The documentation now adds prerequisite and permissions guidance, an OCI artifact reference for the policy bundle, and clearer instructions for setting the Helm value that enables misconfiguration enforcement. It also explains the admission controller’s Audit-mode behavior.

Enable Microsoft Defender for SQL Servers on Machines

Doc update

The article now uses updated metadata, clarifies that administrators should verify all machines are protected before enabling the plan, and adds a named anchor with a pluralized “Next steps” heading.

Review changes in file integrity monitoring

Doc update

The article now explicitly covers tracked file and registry changes, clarifies the Defender for Endpoint agent prerequisite, and expands the explanation of the Log Analytics agent/MMA terminology and previous experience option.

Review the software inventory in Defender for Cloud

Doc update

The article now links to prerequisites, changes the section heading to “Browse the software inventory,” and documents exporting filtered inventory to CSV and saving queries in Resource Graph Explorer.

Verify SQL machine protection

Doc update

The article now presents procedures for checking coverage across an Azure subscription or for an individual SQL server VM. It explicitly names the protection-status recommendation and troubleshooting guide, and reiterates that recommendation status refreshes every 12 hours.

View exported data in Azure Monitor

Doc update

Updated the article date and metadata, refreshed Azure portal links, and clarified the Azure Monitor log alert and Custom log search instructions.

Assess Defender for Endpoint EDR settings

Doc update

The article now more clearly explains how Defender for Cloud uses agentless scanning to assess Defender for Endpoint EDR settings, identify misconfigurations, and provide actionable recommendations. Prerequisite and remediation links were also refreshed, along with metadata and the publication date.

Check the status of your free trial

Doc update

The page adds a prerequisite step and clarifies that the command lists Defender for Cloud pricing configurations, including each plan’s free trial status.

Overview of Defender for Databases

Feature update

The overview now documents threat protection and sensitive data discovery for supported open-source databases in Azure and AWS, CSPM configuration assessments for Azure PostgreSQL flexible server, and Aurora PostgreSQL and Aurora MySQL RDS instances.

Overview of Defender for Servers in Defender for Cloud

Doc update

The overview now states that Defender for Servers no longer uses the Log Analytics agent or Azure Monitor Agent for most plan features, with agentless scanning and Defender for Endpoint integration replacing them. It also links to the AWS and GCP support matrix.

Resolve VPC service controls issues

Doc update

The article now explains that GCP Logs Explorer can identify when VPC Service Controls block Defender for Cloud API calls. It also clarifies that the ingress and egress policy configuration is validated by the next scheduled agentless disk scan, which may take up to 24 hours.

Add Defender for Cloud data to Power BI

Doc update

The article now explicitly directs readers to use Azure Resource Graph queries in Power BI, improves the introductory and sample-query wording, and updates metadata.

Connect your AWS Account

Doc update

The guide now recommends limiting Azure portal views to 10,000 resources or fewer. For larger AWS environments, it advises distributing AWS connectors across multiple Azure subscriptions and using the Azure portal global filter.

Connect your GCP Project

Doc update

The documentation now recommends limiting each Azure portal view to 10,000 resources or fewer. For larger GCP environments, it suggests distributing GCP connectors across multiple Azure subscriptions and using the portal’s global filter.

Resolve Domain Restricted Sharing policy

Doc update

The guide now explicitly directs administrators to review prerequisites, clarifies the connected GCP project requirement, and specifies permission to modify organization-level GCP policies.

Respond to Microsoft Defender for DNS alerts

Doc update

The page date and authoring metadata were updated. The unexpected-activity guidance now links to “Mitigate the alert,” and the “Next step” section was renamed “Next steps” with an anchor added.

Set up continuous export with Azure Policy

Doc update

The page now explicitly refers to Azure Policy `DeployIfNotExist` policies for continuous export, updates the next-steps heading and anchor, and refreshes its metadata date.

Threat intelligence report

Doc update

The page updates its metadata, changes wording from mitigating a specific issue to mitigating similar threats, and adds an introduction to steps for accessing a threat intelligence report.

Understand malware scanning results

Doc update

The article’s date and authoring metadata were updated, failure wording was clarified, and a named anchor plus revised “Next steps” heading were added.

Disable Defender for SQL Servers on Machines

Doc update

The article now uses the full plan name and links directly to the Azure portal in the resource-level disablement steps. The publication date and authoring metadata were also updated.

Microsoft Defender for Cloud Overview

Doc update

The Defender for Cloud introduction page now links to a support matrix for comparing workload protection coverage across Azure, AWS, and GCP. The page metadata was also updated.

Protect your databases with Defender for Databases

Doc update

The page metadata was updated, the pricing and cost-calculator paragraph was removed, and references were clarified to identify Defender for Cloud workbooks and the Defender for Cloud coverage workbook.

Edit DevOps connectors

Doc update

The page metadata was refreshed, and the prerequisite now says “create an Azure account for free” with the existing link.

Exempt resources from recommendations

Doc update

The exemption article’s metadata was refreshed, and its guidance on creating exemptions through the Defender for Cloud portal versus the Azure Policy API was updated.

Release Notes Archive

Doc update

The archive now uses updated anchors for CMK-encrypted VM agentless scanning, automated remediation scripts, and AWS agentless scanning. A link to “Disable specific findings” was removed.

Verify Defender for Containers deployment

Doc update

The documentation now specifies that Defender collectors for Arc-enabled clusters and Helm deployments run as a Kubernetes DaemonSet, with a pod scheduled on each node.

Agentless Data Collection

Doc update

The agentless data collection documentation now links AWS permission instructions to the AWS setup section and GCP permission instructions to the GCP setup section.

Alerts Containers

Doc update

The documentation now lists Malware detection and states that it detects malware running in the container.

Attack Path

Doc update

The Attack paths article now links to the Azure section of the agentless scanning instructions using the updated page anchor.

Defender For Storage Introduction

Doc update

The Defender for Storage overview now specifies that on-demand malware scanning can target individual blobs, files, containers, or file shares.

Episode Twenty Three

Doc update

The episode twenty-three documentation now links to `/defender-xdr/defender-threat-intelligence` for information about Defender TI instead of the previous path.

14

Onboard a management group to Microsoft Defender for Cloud

Doc updateAction required

The page now explicitly states that Microsoft.Security must be registered at management group scope before onboarding so Defender for Cloud policies can be assigned and evaluated. It also updates headings, anchors, metadata, and the next-step link text.

Onboard agentless containers for CSPM

Doc update

The article now provides clearer onboarding direction for Azure, AWS, and GCP, including its coverage of running containers, registry vulnerabilities, and Kubernetes configuration analysis. It also clarifies AKS trusted access terminology.

Plan a Defender for Servers deployment

Feature updateAction required

The documentation now describes 500 MB of free daily ingestion per node for eligible security data and says Defender for Servers Plan 2 must be enabled on the reporting Log Analytics workspace. Data must use a supported collection method, such as Azure Monitor Agent.

Deploy Defender for Containers to private clusters (Preview)

Doc update

The article now explicitly describes deployment through Helm charts or an Azure Arc-enabled Kubernetes extension and names the Helm on Amazon EKS, Helm on Google Kubernetes Engine, and Azure Arc-enabled Kubernetes tabs. The publication date and documentation metadata were also updated.

Deploy Defender sensor and Azure Policy to clusters using Azure CLI

Doc update

The article now includes prerequisites, numbered AKS deployment steps, and explicit Defender sensor and Azure Policy extension instructions for Arc-connected EKS, GKE, and Kubernetes clusters. It also clarifies TCP 443 firewall access for private clusters and adds deployment verification links.

Deploy Defender for Azure SQL Databases

Doc update

The article now explicitly identifies the Azure subscription, AWS account, or GCP project used to enable Defender for Azure SQL Databases. It also updates metadata and adds a stable anchor to the “Next steps” heading.

Tutorial Enable Cspm Plan

Feature update

Starting October 27, 2026, Foundational CSPM will no longer be enabled by default for new Azure subscriptions. Its free capabilities will remain available and can be enabled at any time.

5

Enable API security posture with Defender CSPM

Doc update

The page now states that disabling the API posture extension offboards all APIs from the Defender CSPM plan and disables API security posture management. It also updates related link text and the Azure free account wording.

Set up continuous export with REST API

Doc update

The page date and authoring metadata were updated, the Azure subscription signup text now says “free Azure account,” and the “Next step” heading was changed to “Next steps” with an anchor added.

3

Defender Sensor Change Log

Doc update

The changelog now documents seven sensor releases with security and dependency updates. Several also improve Kubernetes pod inventory reliability when processing pod deletion events.

Integrate AWS CloudTrail logs

Doc update

The page title now identifies Microsoft Defender for Cloud, and the CloudTrail warning clarifies that disabling ingestion removes data from the one-time historical collection while re-enabling it starts a new collection. The next-step heading and anchor were also updated.

2

Troubleshoot Defender for SQL on Machines configuration

Doc update

The article now clarifies its scope for Defender for SQL on Machines in commercial clouds, adds prerequisite guidance, and improves links and wording for enabling protection and resolving instance-level misconfigurations.

2

Understand just-in-time virtual machine access

Doc update

The article now uses clearer Azure and AWS headings, anchors, and tab identifiers; clarifies approved access requests and expiration behavior; and adds decision-flow diagram references and a next-steps link.

1

Attack path analysis and enhanced risk-hunting for containers

Doc update

The article description, prerequisites wording, attack-path guidance link text, metadata, and publication date were updated. It now describes deploying a mock vulnerable container image to explore container risks with Cloud Security Explorer.

45

Manage EIoT monitoring support | Microsoft Defender for IoT

Doc update

The page adds guidance for calculating detected devices for standalone licensing and warns that disabling Enterprise IoT security stops all purpose-built alerts, vulnerabilities, and recommendations. It also clarifies cancellation steps for legacy plan customers.

Microsoft Defender for IoT Feature Support and Retirement

Doc update

The page now uses clearer terminology for the legacy and replacement micro agents, presents tutorial links as a list, and renames the final section to “Related content.” Support and retirement wording remains included.

Manage OT Plans and Licenses

Doc update

The migration guidance now explicitly instructs administrators to select Microsoft 365 as the price plan, save the change, and then update site details to match the license. Wording, metadata, and related-content labeling were also updated.

Review Security Initiatives

Doc update

The page metadata, wording, heading, anchor, and OT Security prerequisite guidance were updated. The review section is now titled “Review OT and Enterprise IoT security initiatives in the Defender portal.”

Enterprise Iot Manage

Doc update

The article now refers to Microsoft 365 E5 or E5 Security plans, clarifies that disabling enterprise IoT security removes access to alerts, vulnerabilities, and recommendations, and updates the standalone-license link text.

How to configure the DMI Decoder

Doc update

The article now provides clearer descriptions of SMBIOS requirements, renamed configuration sections, stable anchors, corrected module twin JSON formatting, and reorganized related links.

Manage IoT and OT Devices with the Cloud Device Inventory

Doc update

The article was refreshed with clearer wording, updated terminology and capitalization, improved formatting of UI labels, and revised instructions for filtering, exporting, and identifying devices that have not recently communicated.

View and Manage Alerts on the Azure Portal

Doc update

The article adds clearer navigation for viewing alerts, a considerations section, refreshed grouping-option formatting, and minor wording, punctuation, metadata, and title updates.

Microsoft Defender for IoT alerts

Doc update

The article now includes an overview of viewing, investigating, and managing alerts across supported locations, with clearer terminology, navigation links, synchronization wording, and remediation references.

Control the OT traffic monitored by Microsoft Defender for IoT

Doc update

The article now uses clearer terminology and navigation for the OT sensor deployment path, subnet configuration, ICS subnet definition, port and VLAN naming, DNS lookup, and DHCP procedures. Metadata and section formatting were also updated.

Create trends and statistics reports in Defender for IoT

Doc update

The page now clarifies the role-requirements link, renames “Next steps” to “Related content,” and revises wording for cloud-connected sensor reports. The same related report links remain available, with metadata also updated.

Audit Microsoft Defender for IoT user activity

Doc update

The article now separates prerequisites and states that users must be default privileged admins or have the Admin role on the sensor. Setup wording for Azure portal and OT network sensors was also streamlined.

Create Custom Alerts

Doc update

The guide updates capitalization, phrasing, drop-down terminology, the Save button label, and changes the “Next steps” heading to “Related content.”

Set up sites in Microsoft Defender for IoT

Doc update

The article now links to prerequisites and recommends having the IP or MAC address of at least one OT device discovered by Microsoft Defender for Endpoint before associating devices with a site. Minor wording and metadata were also updated.

Investigate incidents and alerts

Doc update

The page refreshes metadata and clarifies how to investigate Defender for IoT incidents, use the DeviceInfo Site property in advanced hunting, and interpret the San Francisco site query.

Manage sites in Microsoft Defender for IoT

Doc update

The article title, metadata, and introductory wording were updated. The site assignment instructions now clarify that a manual site assignment remains until the device is reset, while automatic reassignment is prevented.

Investigate CIS benchmark recommendation

Doc update

The article’s publication date changed from June 12 to July 3, 2026, and its custom authoring metadata was updated. The supplied content excerpt is unchanged.

Set Up Rbac

Doc update

The Defender for IoT RBAC setup article now directs readers to review prerequisites before configuring roles and permissions. Its metadata was also updated.

Tutorial Servicenow

Doc update

The tutorial replaces the “Next steps” section and ServiceNow Store access line with “Related content” and a “Next step” heading.

Tutorial Splunk

Doc update

The tutorial removes bold formatting from the Splunk access instruction and changes “Next steps” to “Next step.”

Device Inventory

Doc update

The documentation now describes Vendor as the device’s hardware vendor, as identified from the MAC address.

20

Create and manage Users on an OT Network Sensor

Doc update

The article now clearly covers creating, editing, and removing sensor users, Active Directory integration, and privileged-access recovery. Prerequisites are presented as notes, and headings, links, metadata, and related-content formatting were updated.

Investigate Devices in the OT Sensor Device Map

Doc update

The article now highlights prerequisites, including an activated sensor and required permissions, and warns that deleting a device permanently removes it from inventory. It also refreshes wording and navigation labels throughout the device map and notification guidance.

Request

Doc update

The documentation standardizes table separators, uses a dash for the empty vendor description cell, and updates the details field guidance and link.

View and Manage Alerts on your OT Sensor

Doc update

The page title and metadata were updated, and alert-viewing, management, and export instructions were reformatted with clearer step numbering and wording.

Set up Single Sign-on for Microsoft Defender for IoT Sensor Console

Doc updateAction required

The Defender for IoT SSO article now identifies Microsoft Graph User.Read as the required permission and states that an administrator must grant tenant-wide consent. Wording, headings, metadata, and related-content formatting were also updated.

Import extra data for detected OT devices - Microsoft Defender for IoT

Doc update

The article now clarifies the OT sensor prerequisite, adds the need for a CSV-capable editor, restructures the import steps, updates terminology, and specifies that devices omitted from an authorized-devices import are marked not authorized and can generate new traffic alerts.

Set Up SNMP MIB Monitoring on an OT Sensor

Feature updateAction required

The guide now instructs administrators to access the Defender for IoT CLI over SSH as the cyberx user before setup. It also expands encryption names and updates related guidance.

Manage your OT device inventory from a sensor console

Doc update

The article now describes viewing, filtering, editing, exporting, merging duplicate devices, and deleting inactive devices. It also clarifies that deletion applies to devices matching the current Last Activity filter and updates export time-zone guidance.

Verify and Update Detected Device Inventory

Doc update

The page received updated metadata and wording, a new sentence introducing the device-inventory viewing steps, and clearer headings and text for editing individual device properties.

Provision OT Sensors for Cloud Management

Doc update

The article’s title, metadata, role-prerequisite wording, connectivity-team responsibilities, direct-connection context, and endpoint-download heading were revised.

3

Accelerate OT alert workflows - Microsoft Defender for IoT

Doc update

The page now highlights required Azure portal permissions or OT sensor access, clarifies migration guidance for alert exclusion rules, and warns that deleting custom alert rules is irreversible. Links and wording were also updated.

2

Get started with enterprise IoT

Doc updateAction required

The page now tells administrators to assign obtained licenses to specific users before using them. It also clarifies that the device count refers to identified unique devices; metadata was updated.

Get Started

Doc update

The page’s `ms.custom` metadata changed from `msecd-doc-authoring-1013` to `msecd-doc-authoring-1016`.

1

Ot Deploy Path

Doc update

The guide changes the “Next steps” heading to “Next step” and removes the sentence beneath it.

1
1

Troubleshoot the Sensor

Doc update

The page title changed from “Troubleshoot the sensor” to “Troubleshoot the Sensor,” and the “Next steps” heading was renamed “Related content.”

210

Develop a SIEM solution for Microsoft Sentinel

Doc update

The new guide covers the ISV solution lifecycle: learning, building, testing, publishing, previewing, and go-to-market. It explains packaging connectors with security content and lists development workspace permissions and Defender portal onboarding steps.

Connect Microsoft Purview

Doc update

The documentation now states that customers should use the Microsoft 365 auditing solution moving forward after the AIP analytics and audit logs preview retirement.

Ueba Reference

Doc update

The UEBA reference now lists AWS GuardDuty (Preview) and CommonSecurityLog (Preview), with links to their data connectors, tables, and event details.

Build an agent in Azure AI Foundry

Doc update

The documentation adds a how-to guide for creating and testing an agent that uses Microsoft Sentinel data lake telemetry to correlate identity, access, and endpoint signals before publishing to Security Copilot.

Connect Logstash Data Connection Rules

Feature updateAction required

The documentation now references output plugin v2.5.0, revises supported Logstash versions, adds version 9.0.8, and flags required security updates for listed versions.

Decide which platform solution components to build

Doc update

A new article explains how to select and combine Sentinel data lake connectors, Security Copilot agents, the Sentinel MCP server, custom graphs, notebook jobs, and SIEM content based on customer scenarios.

How to publish a Microsoft Security Copilot Agent

Doc update

A new article explains how to package a Microsoft Security Copilot agent, configure its Partner Center offer, submit listing metadata, and complete review and certification for the Microsoft Security Store.

Ingest Data to Microsoft Sentinel Data Lake

Doc update

A new article explains how to use KQL jobs to create tables and ingest scheduled sample IdentityDrift telemetry for querying and agent testing. It also documents production connector options, onboarding prerequisites, and required Security Administrator or Security Operator permissions.

Migrate QRadar Detection Rules to Microsoft Sentinel

Doc update

The article now provides more detail on inventorying and comparing QRadar detections, selecting migration paths, and understanding Microsoft Sentinel rule types, including Fusion. It also updates formatting, links, metadata, and examples.

Microsoft Sentinel solution for SAP applications overview

Doc update

The documentation now describes the solution’s agentless data connector, SAP Integration Suite package, security content, supported SAP data sources, threat detections, monitored configuration, and production-system pricing.

Build Azure Logic Apps with Microsoft Sentinel MCP tools

Doc update

The page now focuses on using the entity analyzer MCP tool in Azure Logic Apps to enrich entities and automate verdicts. It also clarifies supported authentication options and the Security Reader requirement, and updates page metadata.

Track your Microsoft Sentinel Migration with a Workbook

Doc update

The guide now explains that the DeploymentandMigration watchlist stores actions used to track migration progress and that MITRE coverage maps deployed analytics rules to identify detection gaps. Wording, formatting, and SOAR references were also updated.

Monitor the health and role of your SAP systems

Feature updateAction required

The SAP connector page no longer displays system role and health as a table. Administrators should use the SAPSystems KQL function for roles and SentinelHealth or the SAP data collection health alert for health signals. Unknown SIDs are treated as production for security and billing.

Generate playbooks using AI in Microsoft Sentinel

Feature updateAction required

The generator is now documented as available to Microsoft Sentinel customers in the Defender portal without a separate Security Copilot license or Security Compute Units. Dedicated Security Copilot workspace setup was removed; Automation Playbooks Read and Write permissions are now required to generate and deploy playbooks.

Migrate Splunk SOAR Automation to Microsoft Sentinel

Doc update

The article’s formatting and metadata were refreshed, including clearer list and table formatting, an expanded Microsoft Sentinel Incidents REST API link, updated GitHub playbook wording, and revised next-step text.

Use the SIEM Migration Experience

Doc update

The article now explicitly instructs users to export detection rules, confirms that Security Copilot must be enabled, and clarifies analysis status, matched detections, recommendations, and reports. It also states that the tool does not consume SCUs or generate SCU-based charges.

Agent Creation Tool Collection in Microsoft Sentinel MCP Server

Doc update

The article now explains that the unified MCP server exposes Sentinel tool collections, links to the getting-started guidance, and more explicitly identifies the endpoint as the MCP server endpoint for Security Copilot agent creation tools. Title and metadata were also refreshed.

Enable Entity Behavior Analytics

Doc update

The article now links to required roles and permissions, lists Amazon GuardDuty and supported CommonSecurityLog vendor events, and adds guidance for UEBA tables, schemas, and related articles.

Microsoft Sentinel Migration: Ingest Data into Target Platform

Doc update

The article now more clearly describes exporting legacy SIEM data and ingesting it into Microsoft Sentinel data lake, Azure Data Explorer (ADX), or Azure Blob Storage. ADX steps and links were revised, including explicit Windows requirements for LightIngest.

Export Splunk Data to Target Platform

Doc update

The article’s title, metadata, introductory guidance, and section heading were updated. The introduction now explicitly states that historical Splunk data should be exported in CSV format before migration to Azure.

Migrate Playbooks To Automation Rules

Doc update

Updated the migration page’s metadata, wording, punctuation, and references to required roles and procedures for playbooks used by one or multiple analytics rules.

Connect Services Windows Based

Doc update

The documentation now states that Windows Event Forwarding events are written to the `WindowsEvent` table, not `SecurityEvent`. It also notes that built-in rules querying `SecurityEvent` won't match data stored only in `WindowsEvent`.

Connect Defender For Cloud

Doc update

The article updates its metadata and wording, including clearer subscription-status text and guidance to query Defender for Cloud alerts where the product name is Azure Security Center. It also refreshes the introductory links and closing guidance.

Create Incidents From Alerts

Doc update

The article now specifies that Microsoft Defender XDR incident integration or onboarding Sentinel to the Defender portal causes Defender XDR to correlate incidents, and clarifies the Microsoft security data connector section and Azure account link.

Sap Solution Security Content

Doc update

The page date changed to August 4, 2026, and sections covering static SAP security parameter monitoring and SAP audit-log monitoring were removed.

Migration

Doc update

The page metadata was updated, and the migration-process heading and explanatory text were refined. A named anchor was also added for the migration-process section.

Collect SAP HANA audit logs in Microsoft Sentinel

Doc update

The article description now focuses on ingesting SAP HANA audit logs into Microsoft Sentinel for customer-managed environments and identifies security, infrastructure, and SAP BASIS teams as relevant audiences. The publication metadata was updated, and a “Learn more” line was removed.

Sentinel Security Copilot

Doc update

The Sentinel Security Copilot article now states that Sentinel data can be used in both the standalone Security Copilot portal and the embedded experience in the Microsoft Defender portal after Sentinel onboarding.

Migration Arcsight Historical Data

Doc update

The documentation updates its publication metadata and clarifies that event data retrieved from ESM can be combined with unstructured data alongside CEF data. The listed export formats remain CEF, CSV, and key-value pairs.

Windows Security Event Id Reference

Doc update

The article now states that Windows Security Events via AMA writes to the `SecurityEvent` table, while Windows Forwarded Events writes to `WindowsEvent`. It also adds guidance for forwarded events that do not trigger built-in rules.

Deployment Solution Configuration

Doc update

The page metadata was updated, and connection pivots, the agent deprecation notice, a deployment image, introductory SAP guidance, and the SAP data connector agent update link were removed.

Microsoft Sentinel Defender Portal

Doc update

The AI-assisted SOC row now lists Native Security Copilot references for automated incident summaries, guided response actions, and script analysis.

Package Platform Solution

Doc update

The article covering prerequisites, package manifests, ZIP creation, and Microsoft Security Store publishing was deleted.

Investigate Incidents with UEBA Data

Doc update

The article received updated wording, formatting, metadata, image markup, and related-content organization. Its preview notice and descriptions of UEBA investigation steps were also edited for consistency.

Use a Microsoft Sentinel MCP Tool in Microsoft Foundry

Doc update

The article title, description, metadata, and formatting were updated. Its description now highlights app registration, authentication, and connecting Sentinel or custom MCP tools to Microsoft Foundry agents.

Detection lifecycle management recommendations

Feature update

The Microsoft Sentinel comparison table changed custom detection rules from “No” to “Yes (Preview)” for one management capability. The article’s guidance wording and metadata were also updated.

Feature Availability

Doc update

The feature-availability table changes one availability indicator for the Codeless Connectors Platform from “No” to “Yes.” Its Public preview status remains unchanged.

<PlaybookName>

Doc update

The documentation now describes required ARM template files, folder layouts, metadata fields, validation checks, and incident-versus-alert trigger types for Sentinel playbooks.

Anomalies Reference

Doc update

The reference now explains that listed UEBA anomalies are stored in the Anomalies table, distinguishes BehaviorInfo insights, and documents Check Point, Fortinet, GuardDuty, and Zscaler anomaly types with data sources, ATT&CK mappings, and activity criteria.

Connect Your SAP System to Microsoft Sentinel

Doc update

A new guide explains prerequisites and steps to connect SAP to Microsoft Sentinel, including Azure resource deployment, required permissions, DCR authorization, and SAP client setup.

Create Parsers for Microsoft Sentinel Solutions

Doc update

The documentation now explains parser YAML structure, required fields, validation rules, KQL query design, and common submission issues for custom log tables, Syslog, and CEF connectors.

Cross Workspace

Doc update

The article describing Microsoft Sentinel for SAP across multiple workspaces was deleted, including guidance on separate SAP and SOC workspaces, access, data residency, and preview limitations.

Microsoft Sentinel SIEM and platform solution overview

Doc update

A new overview explains the differences between SIEM and platform solutions, including their purposes, audiences, content types, foundations, data scopes, tooling, and publishing flows. It also links to guidance for building and publishing SIEM solutions.

Microsoft Sentinel SIEM solution quality guidelines

Doc update

Microsoft added guidance for ISVs covering data connectors, analytics rules, playbooks, hunting queries, and parsers. New connectors must use the Codeless Connector Framework, and solutions must include at least one analytics rule.

Package a SIEM solution for Microsoft Sentinel

Doc update

Microsoft added documentation covering the V3 packaging tool, generated artifacts, deployment through Azure portal or CLI, content validation, and local checks before submission.

Update

Doc update

The Microsoft Sentinel SAP data connector agent update reference was deleted. It documented the update process and options such as `--confirm-all-prompts`, `--no-testrun`, `--force`, `--containername`, `--sdk`, and `--preview`.

Sentinel Analytic Rules Creation

Doc update

The article now includes multiple YAML examples, a complete sample rule, NRT field guidance, title constraints, status values, and ATT&CK v16 tactic requirements, including a five-tactic limit and valid values.

Publish SIEM solutions to Microsoft Sentinel

Doc update

The Microsoft Sentinel publishing article was revised and expanded with clearer prerequisites and a new section explaining Partner Center tabs, required fields, and default values for Sentinel solution offers.

Create and manage Microsoft Sentinel playbooks

Doc update

The article now clarifies prerequisites, authentication guidance, trigger examples, output descriptions, and links for creating analytics rules. Metadata and wording were also refreshed.

Configure Microsoft Sentinel Content

Doc update

The article was reorganized into dedicated sections for data connectors, analytics rules, automation rules, and playbooks, with refreshed wording and links to setup guidance.

Systemconfig Json

Doc update

The Microsoft Sentinel SAP solution reference for configuring the data connector agent’s systemconfig.json file was deleted, including its configuration structure and settings for secrets, authentication, ABAP, Azure, logging, and connector options.

Configure your SAP system for the Microsoft Sentinel solution

Doc update

The article description and content were streamlined by removing connection-agent sections, agent installation references, role-creation procedures, and SNC connection guidance. The user section was renamed to focus on creating an SAP user for the Microsoft Sentinel role.

Sentinel Workbook Creation

Doc update

The article now explains gallery template and WorkbooksMetadata.json attributes, including naming, paths, dependencies, versions, and schema requirements. It also warns that JSON syntax errors can cause build failures.

Guide to build and publish Microsoft Sentinel SIEM solutions

Doc update

The guide now focuses on the Microsoft Sentinel SIEM solution lifecycle, adds a lifecycle diagram, and documents prerequisites for publishing to Azure Commercial Marketplace, including joining the Microsoft Cloud Partner Program and creating a Partner Center account.

Microsoft Sentinel integration onboarding concepts

Doc update

A new concept article introduces onboarding as Part 1 of the Building Microsoft Sentinel Integrations series. It provides series context, prerequisites, related links, and guidance for approaching later integration procedures.

Sap Logserv Overview

Doc update

The article now explains LogServ stream routing, DCR-based filtering before ingestion, examples for excluding log types, ASIM content reuse, and verification timing after DCR changes.

Microsoft Sentinel solutions for SAP overview

Doc update

The Microsoft Sentinel SAP overview now describes separate foundation solutions for SAP applications and SAP BTP, along with SAP LogServ, partner add-ons, and community contributions. It also adds a recent SAP attack example and an attack-replay link.

Create Manage Use Automation Rules

Doc update

The article was refreshed with clearer wording for trigger selection and improved formatting for trigger and condition tables, along with updated metadata.

GitHub

Doc update

The article updates GitHub Actions and Azure DevOps customization guidance, including triggers, smart deployments, deployment paths, default configurations, and related documentation links.

Defender portal

Doc update

The article now provides clearer Azure and Defender portal instructions, adds wizard screenshots and steps for automated responses, validation, review, creation, and monitoring, and updates related terminology and links.

Work With Threat Indicators

Doc update

The article updates terminology and examples for threat intelligence management and ingestion rules, and adds portal-specific steps for viewing queries against the ThreatIntelIndicators table in the Defender and Azure portals.

Stop SAP data collection

Doc update

The article now distinguishes temporary stops, by pausing the SAP Cloud Integration Data Collector flow, from permanent stops, which involve removing SAP systems, undeploying the flow, and reversing SAP-side configuration. Optional cleanup of related Azure resources is also documented.

Handle Ingestion Delay in Microsoft Sentinel

Doc update

The page received wording, formatting, metadata, and link updates. Its related-content links now point to scheduled analytics rules, alert customization, template management, and data connector health guidance.

Connect Threat Intelligence Tip

Doc update

The guidance now explicitly names the application ID, tenant ID, client secret, and Microsoft Graph tiIndicators API permission required for TIP integration with Microsoft Sentinel. Section headings and connector-enablement steps were also clarified.

Map Data Fields to Microsoft Sentinel Entities

Doc update

The article now explicitly covers adding or changing entity mappings in existing analytics rules and while creating new scheduled analytics rules. It also updates formatting, metadata, and related-content links.

Authenticate Playbooks To Sentinel

Doc update

The article now uses clearer terminology for Azure Logic Apps connections, managed identities, service principals, and application credentials, with updated headings, links, and screenshot descriptions.

Use matching analytics in Microsoft Sentinel to detect threats

Doc updateAction required

The article clarifies supported data sources and adds an explicit prerequisite to install a supported data connector and its corresponding Content hub solution before enabling the rule. It also updates terminology, examples, and a related link.

Move To Defender

Doc update

The article’s metadata, role link, multitenant portal name, connector-routing wording, and analytics-rule reference were updated.

Transformation Filter Split

Feature updateAction required

The documentation now requires Microsoft Sentinel data lake onboarding and an Analytics-tier table for split transformations. It also clarifies DCR interactions and warns that deleting a rule immediately stops its data processing.

Audit Track Tasks

Doc update

The article clarifies task-detail fields, adds steps for observing record changes, and updates wording for querying and interpreting incident-task records.

Watchlists Create

Doc update

The documentation now clarifies how to create a storage container, upload a watchlist CSV for SAS URL reference, and add the watchlist from Azure Storage. Related Microsoft Sentinel links were also refreshed.

Audit Microsoft Sentinel queries and activities

Doc update

The article now more clearly explains using AzureActivity and LAQueryLogs to audit Sentinel activity, including deleted resources, non-successful queries, resource-intensive clients, active users, and access to sensitive tables. Metadata and heading structure were also updated.

Connect Azure Functions Template

Doc update

Updated the Microsoft Sentinel Azure Functions connector article with clearer links, section headings, deployment guidance, and Key Vault reference information.

Resource Context Rbac

Doc update

The article now provides clearer guidance for users needing access to specific workspace data, revises the architecture description, and expands the Logstash example to explain Beats input, the Microsoft Sentinel output plugin, and the `azure_resource_id` field.

Soc Optimization Access

Doc update

The documentation now identifies optimization metrics in the Overview tab for both the Defender portal and Azure portal, and clarifies the optimization details pane wording. Guidance for acting on recommendations and managing statuses remains documented.

Defender portal

Doc update

The article now provides streamlined Defender portal steps and clearer guidance on KQL parameters, entity types, strong identifiers, and dynamic activity titles. Publication and authoring metadata were also updated.

Entity Behaviors Layer

New feature

The article now describes anomaly insights on behavior records, including first-seen activity, unusual volumes, uncommon values, and threat-intelligence matches. It also clarifies entity-enrichment queries, supported Fortinet data, and the requirement for actively sending logs.

Application card for Microsoft Sentinel SIEM

Generally available

The documentation describes the SOAR playbook generator as an AI-assisted LLM feature in the Microsoft Defender portal. It clarifies that generated playbooks are code-based Python scripts running in a managed environment and specifies the permissions required to generate and deploy them.

Connect Aws Configure Environment

Doc update

The page now uses clearer Microsoft Sentinel terminology, improves navigation and headings, clarifies the GuardDuty-to-S3 export step, and refreshes related links and metadata.

Deployment Overview

Feature update

The overview removes containerized data connector guidance and now describes the agentless connector as the solution’s deployment model. It also adds links for SAP Cloud Connector sizing, throughput, and isolation.

False Positives

Doc update

The page now defines service principals, renames the exceptions section to focus on analytics rule queries, adds a section anchor, and clarifies references to Kusto documentation and automation-rule procedures.

Bookmarks

Doc update

Updated metadata and wording clarify bookmark creation, Advanced hunting availability, MITRE ATT&CK mapping, the Bookmarks tab, incident viewing, and deletion behavior.

Custom Graphs Overview

Doc update

The guidance now states that interactive-session graphs are temporary, on-demand graph jobs materialize graphs for 30 days before deletion, and custom graph activity is billed under the Microsoft Sentinel graph meter. It also updates terminology, examples, and links.

Multiple Tenants Service Providers

Doc update

The article now presents prerequisites and steps more clearly, including resource-provider registration, delegated directory and subscription selection, and the GDAP requirement for deploying connectors from Lighthouse-only managed workspaces.

Powerbi

Doc updateAction required

The Sentinel Power BI article now explains that scheduled refresh is configured on the report’s backing dataset, which is created when the report is published. It also specifies the required Log Analytics read-access credentials and adds detail about query results and published reports.

Configure Data Transformation

Doc update

The article now labels the data collection rule reference section, clarifies which DCR procedures require verification, and warns that deleting the legacy table and custom data connector is irreversible and may affect existing queries, workbooks, or integrations.

Configure Table Settings in Microsoft Sentinel

Doc update

The page now focuses on retention and data tier settings for Sentinel and Defender XDR tables, adds Table insights for monitoring ingestion health and costs, and revises its permissions section and related-content links.

Connect Microsoft 365 Defender

Doc update

The page now describes the KQL query as a 14-day event-volume trend for validating ingestion consistency, notes that TVM tables aren't ingested into Microsoft Sentinel, and improves references to the relevant query documentation.

Defender portal

Doc update

The article now provides separate steps for viewing existing analytics rule templates in the Defender portal and Azure portal, and updates the procedure wording and metadata.

Import Export Analytics Rules

Doc update

The article now explicitly describes exporting analytics rules to ARM template JSON files and importing them into other workspaces or tenants. Section headings and anchors were also updated for clarity.

Normalization Manage Parsers

Doc update

The page now provides clearer links to architecture, deployment instructions, and the ASIM watchlist template. It also clarifies filtering and parameter-less custom parsers, parser union behavior, and watchlist-based exclusion of built-in parsers.

Private endpoint

Doc update

The documentation now provides clearer wording for private-endpoint Azure Machine Learning workspace creation and explains notebook code execution, kernel output, variable persistence, and expression results. Sample output formatting and page metadata were also updated.

Workspace Manager

Doc update

Updated metadata, added anchors, renamed headings, and clarified when content items are published to member workspaces.

Collaborate In Microsoft Teams

Doc update

The page metadata was updated, Microsoft Sentinel role names were expanded in links, and screenshot descriptions were made more specific.

Connect Aws S3 Waf

Doc update

The documentation updates wording and clarifies that the second CloudFormation template creates the remaining AWS resources, including the S3 bucket, SQS queue, and IAM role.

Defender portal

Doc update

The article updates its metadata, clarifies NRT rule wording, adds a Defender portal viewing section, rephrases creation instructions, and corrects the wizard step numbering.

Run Playbooks

Doc update

The page clarifies how to assign the Microsoft Sentinel Automation Contributor role through Azure Lighthouse, updates playbook run-history wording, and removes a statement about manually running playbooks on entities in the Defender portal.

Use Playbook Templates

Doc update

The page received wording refinements for deployment procedures, Content hub filtering, nested playbooks, and connection creation. The publication date and authoring metadata were also updated.

Connect Dns Ama

Doc update

The documentation clarifies that Azure Arc is required for collecting events from non-Azure virtual machines and identifies the JSON filter examples as equivalent definitions for the DCR API payload.

Auditing Lake Activities

Doc updateAction required

The page now states that users must have the View-Only Audit Logs or Audit Logs role and remote PowerShell access before running the audit-log script. The page metadata and link wording were also updated.

Configure Fusion Rules

Doc update

The page’s publication date and authoring metadata were updated, and several Fusion descriptions and scheduled analytics rule guidance were reworded for clarity, including the Customer-Managed Keys link text.

Data Connection Rules Reference Azure Storage

Doc updateAction required

The reference now explains that BlobCreated events are sent through an Azure Storage notification queue before connector processing, and adds setup guidance for notification and dead-letter queues.

Detection Tuning

Doc update

The article’s date and metadata were updated, introductory wording was revised, and the “Types of insights” heading was renamed to “Types of analytics rule insights” with a named anchor added.

Skill Up Resources

Doc update

The page adds a link to an open-source Microsoft Sentinel Training Lab with guided exercises and updates terminology and metadata.

Connect Azure Active Directory

Doc update

The page metadata was updated, and references now explicitly name the Microsoft Entra ID data connector and Microsoft Sentinel in linked guidance.

Connect Azure Stack

Doc update

Updated the page metadata, clarified that dashboards use data collected from Azure Stack Hub virtual machines, identified them as Microsoft Sentinel dashboards, and refined the screenshot description.

Define Playbook Access Restrictions

Doc update

The page metadata was refreshed, and the “Sample policy” section was renamed to “Review a sample access restriction policy” with a new anchor. A trailing “For more information” line was removed.

Normalization

Doc update

The page now links to the Agent Event schema and documents the Asset Entity schema for normalizing asset inventories and change feeds. The page date was also updated.

Purview Solution

Doc update

The article now links to the procedure for modifying Microsoft Purview analytics rule templates and identifies the referenced Kusto documentation as applying to the sample `PurviewDataSensitivityLogs` query. The page metadata was also updated.

Surface Custom Details In Alerts

Doc update

The article now uses the labels “Microsoft Defender portal” and “Microsoft Azure portal,” and its publication date and authoring metadata were updated.

Turn on auditing and health monitoring in Microsoft Sentinel

Doc update

The page now explains that enabling auditing and health monitoring collects resource health and audit data in the SentinelHealth and SentinelAudit tables for monitoring, alerting, and investigation. The page metadata was also updated.

Watchlists Queries

Doc update

The page date and custom metadata were updated, and the example query text now uses clearer wording for the Log Analytics screenshot and guidance on creating custom analytics rules with watchlists.

Work With Anomaly Rules

Doc update

The anomaly comparison step now links more clearly to the quality assessment guidance, and the anomaly detection resources heading was revised. Page metadata was also updated.

Connect Azure Virtual Desktop

Doc update

The article’s date and authoring metadata were updated, and the query guidance now states that queries can run after Azure Virtual Desktop data is connected to Microsoft Sentinel.

Create Tasks Playbook

Doc update

The playbook text now says the task targets the user associated with the researched malicious IP address. The document date and authoring metadata were also updated.

Multiple Workspace View

Doc update

The article now states that selecting an incident and choosing **View full details** or **Investigate** switches to the selected incident’s workspace context. Documentation metadata was also updated.

Notebook Get Started

Doc update

The guide’s publication date and custom metadata were updated, and the description of the MpConfigEdit tabbed configuration tool was reworded.

Offboard

Doc update

The Microsoft Sentinel offboarding page now links directly to the “Implications of removing Microsoft Sentinel from your workspace” guidance in its pre-removal review step. The document date and authoring metadata were also updated.

Sentinel Mcp Use Tool Visual Studio Code

Doc update

The verification step now specifies that administrators should confirm the tools appear under the MCP server they added. The document date and authoring metadata were also updated.

Sentinel Overview

Doc update

The overview now links to “Build and publish Microsoft Sentinel SIEM solutions” at the updated documentation path.

Sentinel Solutions Delete

Doc update

The documentation now states that deleting a solution does not delete active, cloned, saved, or custom items. The page date and authoring metadata were also updated.

Summary Rules

Doc update

The article date and custom authoring metadata were updated, and its introductory sentence was revised from “This section” to “This article.”

Use Multiple Workspaces

Doc update

The article metadata was refreshed, and the closing text now directs readers to the next step in the deployment guide.

Watchlists Manage

Doc update

The documentation now says explicitly that uploading a file after removing items does not delete those items from the existing watchlist. It also updates the page metadata.

Data Transformation

Doc update

The page date was updated, and the guidance now specifies that transformations to Analytics tables in Sentinel-enabled Log Analytics workspaces are exempt from Azure Monitor’s filtering ingestion charge. The Azure Monitor reference link was also updated.

Sap Solution Function Reference

Doc update

The page date was updated, AI-usage metadata was added, and documentation for seven SAP functions—including BAPI_XMI_LOGON and TH_SERVER_LIST—was removed.

Best Practices

Doc update

The Microsoft Sentinel best practices page now links partners to “Build and publish Microsoft Sentinel SIEM solutions” instead of the previous partner integration guide.

Prepare Multiple Workspaces

Doc update

The Azure Lighthouse guidance sentence now ends correctly with a period instead of an extra “u”.

Threat Detection

Doc update

The threat detection page now links to the updated Microsoft Defender Threat Intelligence page.

Threat Intelligence Integration

Doc update

The Sentinel threat intelligence integration article now links to the current Defender Threat Intelligence page and updated Microsoft Sentinel GitHub playbook location.

Kickstart

Doc update

The Microsoft Sentinel for SAP applications kickstart deployment script reference was deleted, including its command-line parameter guidance for secret storage, connection modes, configuration paths, and SAP server settings.

Sap Audit Log Workbook

Doc update

The page no longer includes guidance about the workbook’s hosting workspace or selecting a different SOC workspace when SOC data is stored elsewhere.

Solution Setup Essentials

Doc update

The documentation page describing SIEM and platform solution types, prerequisites, and setup requirements was deleted.

Systemconfig

Doc update

The 247-line Microsoft Sentinel SAP reference for the legacy systemconfig.ini file was deleted. It documented configuration sections and settings for data connector agent versions earlier than June 22, 2023.

25

Migrate to the Microsoft Sentinel agentless SAP data connector

RetirementAction required

The guide now states that Microsoft will permanently retire and disable the containerized SAP connector agent on September 14, 2026. It also directs new deployments to the agentless connector and confirms existing analytics rules, workbooks, and playbooks remain functional.

Configure Connector Login Detection

Doc update

The documentation now highlights that the machine learning algorithm needs 30 days of Windows Security events to establish a user-behavior baseline before detecting incidents.

Develop Custom Graph Solutions for Microsoft Sentinel

New feature

The new guide explains how to build, test, materialize, query, package, and publish notebook-based custom graph solutions using Sentinel data lake tables and Graph Query Language. It also documents prerequisites, permissions, tools, and the preview status.

Connect your TIP with the upload API (Preview)

Doc update

The article now identifies the upload API as a preview API, clarifies STIX-supported uploads and prerequisites, renames the configuration section, and updates related links and permission wording.

Update SAP connector and DCR settings

Doc update

A new article explains how to update SAP data connectors and data collection rules independently, including polling settings, connector resource selection, and API Playground examples.

Update Sap Data Connector

Doc update

The Microsoft Sentinel for SAP applications article describing SAP data connector agent updates, including preview automatic-update procedures, prerequisites, and commands, was deleted.

Setup Azure Storage Connector

Doc update

The page’s date and authoring metadata were updated, and descriptions of the queue-based blob-pointer model and service-principal authentication were refreshed.

Create a pull codeless connector for Microsoft Sentinel

Doc update

The article distinguishes pull/polling connectors from push connectors and focuses its instructions on connectors that periodically fetch data through APIs. It also links to the Microsoft Sentinel Visual Studio Code extension.

Graph Visualization

Feature update

The documentation now explains that only graphs materialized by published graph jobs appear in Graph management, on-demand job graphs are retained for 30 days, scheduled jobs rebuild graphs, and graph queries incur graph-meter charges. It also notes that predefined queries use a default LIMIT clause that can cap visualization results.

Terraform API Setup

Doc update

The article now explains how to create custom IAM roles, service accounts, workload identity resources, and Pub/Sub resources with Terraform, plus clearer validation and Azure Government references.

Sentinel Mcp Chatgpt Claude Connector

Doc update

The documentation was updated with clearer wording for securely saving the one-time client secret, separate ChatGPT and Claude setup guidance, and a clarification that ChatGPT desktop users must first complete custom connector setup on the web.

Connect Mdti Data Connector

Doc update

The documentation now explicitly identifies intelligence ingested from the Defender Threat Intelligence connector, while updating related links and page metadata.

Sentinel Graph Overview

Doc update

The page now explains how to author a custom graph in a Jupyter notebook with the Microsoft Sentinel VS Code extension, publish and materialize it with a graph job, and query or visualize it with GQL in the Defender portal.

Monitor Data Connector Health

Doc update

The article now identifies SentinelHealth as a Microsoft Sentinel log table for supported data connector health events and improves the health-drift query reference. The publication date and authoring metadata were also updated.

Investigation graph

Doc update

The article’s metadata was refreshed, and wording and link formatting were updated in the investigation graph and threat intelligence instructions.

Connect Services Api Based

Doc update

The article now says table names are listed under each connector in the Data connectors reference and adds a Microsoft Entra ID Protection example. Documentation metadata was also updated.

Data Connector Connection Rules Reference

Feature update

The documented maximum for both `RequestTimeoutInSeconds` and `TimeoutInSeconds` increased from 180 to 300 seconds. Their default values remain 100 and 20 seconds, respectively.

Normalization Schema Asset

Doc update

The asset normalization schema now uses “Microsoft Entra” terminology instead of “Azure Active Directory” and updates the identity-directory example accordingly.

Deploy Data Connector Agent Container

Doc update

The documentation page for connecting SAP systems to Microsoft Sentinel was deleted, including guidance for both the agent and agentless connector options, prerequisites, and deployment steps.

12

Deploy Sap Security Content

Doc update

The page removes agent-based deployment sections, related imagery, and multi-workspace setup guidance. It now describes installing the SAP solution with the agentless data connector and viewing deployed security content.

Deploy for Dynamics 365 Finance and Operations

Doc update

The article’s wording, formatting, and deployment step descriptions were updated, and the publication date and metadata were revised. The documented prerequisite remains Dynamics 365 Finance version 10.0.33 or later.

Optimize Costs with a Prepurchase Plan

Doc update

The Microsoft Sentinel prepurchase plan article clarifies its 200 GB/day pricing example and adds a warning that purchases are final and cannot be canceled or exchanged. It also includes minor wording, formatting, and metadata updates.

Quickstart Onboard

Doc update

The quickstart now links directly to content hub installation and data connector setup, labels the section for the Azure Activity data connector, identifies the wizard tabs where defaults should remain, and reorganizes related content.

Deploy Custom Content from your Repository

Doc update

Updated the article’s title, metadata, wording, punctuation, and formatting. The deployment status section is now a top-level heading, and repository connection removal instructions were streamlined.

Sentinel Solutions Deploy

Doc update

The documentation received wording updates, clearer content-type links, expanded ARM terminology, and added guidance and a link for configuring data connectors. Support and content customization instructions were also clarified.

Deploy Sap Btp Solution

Doc update

The page metadata was refreshed, and the scaling guidance now labels the linked resource as the SAP BTP onboarding script library.

Deploy Command Line

Doc update

The documentation for deploying the Microsoft Sentinel SAP data connector agent from the command line was deleted, including prerequisites and procedures for managed identities, registered applications, configuration files, and SNC.

Sap Solution Deploy Alternate

Doc update

The documentation page for expert, custom, manual, and on-premises deployment of the Microsoft Sentinel for SAP data connector agent was deleted, including its Azure Key Vault and CLI instructions.

9

Sample KQL queries for Microsoft Sentinel data lake

Doc update

The article now describes its audience and query coverage more clearly, including threat detection, anomaly identification, baseline creation, and IOC matching. It also updates Microsoft Entra ID terminology, refines the CommonSecurityLog example, and improves section wording and formatting.

Sentinel Hunting Rules Creation

Feature update

The documentation adds sample hunting queries and a template, updates validation guidance, supports ATT&CK Framework v16, and limits queries to five tactics. Names may be up to 100 characters, must use ASCII, and analytic-rule-only fields can cause review failure.

Conduct End-to-end Threat Hunting with Hunts

Doc update

Updated the Hunts article title and metadata, clarified instructions and terminology, refined section headings, and renamed “Next steps” to “Related content.”

Hunting Capabilities in Microsoft Sentinel

Doc update

The hunting documentation was updated with clearer wording for query examples and result-delta metrics, a revised Azure Data Explorer link title, and reorganized custom connector resources.

Run KQL queries on the Microsoft Sentinel data lake

New feature

The documentation now describes running long-running KQL queries asynchronously, including queries that may exceed the 8-minute synchronous timeout. It also clarifies external-table examples, time-range requirements for stored results, and adds `estimate_data_size()`.

Create custom hunting queries in Microsoft Sentinel

Doc update

The article now describes writing, cloning, and editing KQL-based hunting queries, clarifies the navigation sequence, and specifies that queries from content hub solutions or repositories must be edited in their original source.

6

Customize Alert Details

Doc update

The article now directs readers to its alert details properties table for customization guidance and for identifying preview-labeled properties. It also updates the publication metadata and related-content introduction.

Delete Incident

Doc update

The article now clarifies the reference for deleting a single incident, adds a request for deleting an incident by ID, and updates its metadata and links.

Incident Navigate Triage

Doc update

The Microsoft Sentinel incident navigation and triage page now introduces required roles and permissions and provides steps for navigating to and triaging incidents. Its date and authoring metadata were also updated.

Create Incident Manually

Doc update

The page date and custom metadata were updated, and the Microsoft Sentinel API description was clarified to identify the Incidents operation group and its get, create, update, and delete operations.

2

Troubleshoot Sentinel Solutions

Doc update

The troubleshooting article now links to SIEM solution quality guidelines and guidance on deciding which components to include in a solution.

1

Develop a Security Copilot agent platform solution

Doc update

Added a Sentinel how-to guide for creating a Security Copilot workspace and an IdentityDrift investigation agent that correlates Entra ID, Defender for Endpoint, and Defender for Cloud signals.

11

Easm Copilot

Doc update

The page now uses clearer bold headings and expanded descriptions for attack-surface snapshots, risk and CVE prioritization, Security Copilot insights, and attack-surface curation. Image markup was also updated, and several example prompt rows were removed.

Modifying Inventory Assets

Doc update

The article received wording and grammar updates, clearer bulk-selection instructions, revised image formatting and descriptions, and updated metadata.

Inventory Filters

Doc update

The article now links directly to asset-specific filter guidance, uses clearer section titles and anchors, and clarifies the procedure for removing the default Approved state filter. Metadata was also updated.

Using And Managing Discovery

Doc update

The article now includes an introductory explanation, clearer terminology for seed assets, updated section labeling and navigation, and more descriptive screenshot captions. Metadata was also updated.

Understand billable assets in Microsoft Defender EASM

Doc update

The Microsoft Defender EASM article now more clearly explains host:IP combinations and how billable resolving hosts affect IP and domain counts. Screenshots, metadata, and article naming were also updated.

Use domain asset filters

Doc update

The article metadata was refreshed, the title changed to “Use domain asset filters,” and the defined-value and freeform sections were renamed and given anchors.

ASN asset filters

Doc update

The article’s introductory text and description of filter sorting were rewritten for clarity. The publication date and custom metadata were also updated.

IP address asset filters

Doc update

The article’s publication date, custom authoring identifier, and introductory text were updated.

SSL certificate asset filters

Doc update

The documentation now uses clearer wording for filters that require manually entered search values. The list organization is unchanged; metadata was also updated.

4

Understand dashboards in Microsoft Defender EASM

Doc update

The page was retitled and revised to describe eight dashboards, including inventory, attack surface, security posture, compliance, and risk insights. Several explanations and terms were also clarified.

Understand asset details in Microsoft Defender EASM

Doc update

The article title, headings, terminology, explanatory wording, and screenshot markup were updated. Terms such as “Signature algorithm Object Identifier” and “Autonomous System Numbers” are now expanded.

Microsoft Defender EASM page asset filters

Doc update

The article was retitled and rebranded for Microsoft Defender EASM, its heading and introductory text were revised, and it now describes defined-value and freeform filters for page-asset searches, including IP version and domain status.

31

What's new in Microsoft Security Exposure Management

New feature

The August 2026 entries cover keyless Microsoft Foundry authentication, portal scan cancellation, an Azure DevOps connector preview, MAI-Augmented scan profiles, and an updated overview dashboard preview. Attack-path links and older release-note content were also updated.

Work with attack paths in Microsoft Security Exposure Management

Doc update

The page was retitled and reorganized as a how-to guide covering attack-path generation, data sources, data availability, fluctuating results, and the separate Defender for Cloud cloud-only experience. The previous dashboard overview and screenshot were removed.

Install and run Defender CLI

Feature update

The guide now describes two authentication methods, tenant environment variables, asynchronous scan execution with Job IDs, and selectable AI model profiles, including a MAI-augmented preview profile. Installation instructions were also reorganized by platform.

Start using Microsoft Security Exposure Management

Doc update

The article now directs users to Exposure Management > Overview and describes the Resolve Now and Monitor Exposure sections, including prioritized remediation categories and internet-exposed resource views. Prerequisites are now linked separately.

Prerequisites and support in Microsoft Security Exposure Management

Feature updateAction required

The documentation now states that Defender for Cloud with CSPM and Microsoft Defender Vulnerability Management must be enabled for full dashboard value. It also specifies that the service is available only in the public cloud, not national or sovereign clouds.

What is Microsoft Security Exposure Management?

Feature update

The documentation now states that Microsoft Security Exposure Management is available only in Public Cloud and unavailable in national or sovereign clouds, including US Gov and China Gov. It also adds descriptions of the Overview dashboard’s Resolve Now and Monitor Exposure views.

Defender CLI setup for agentic code security

Feature updateAction required

The documentation adds a prerequisite requiring accounts to have at least one listed permission before running Defender CLI commands and updates the Defender.InteractiveLogin scope identifier.

Risk evaluation framework changelog

Generally available

The changelog now lists 80+ Defender for SQL Vulnerability Assessment recommendations as generally available, with a link to the database-level recommendations experience.

Security Events

Doc update

The `security-events.md` page was deleted, including prerequisites and steps for reviewing, filtering, and opening security events in the Microsoft Defender portal.

Codename MDASH Overview

New feature

The documentation now describes direct GitHub and Azure DevOps connectors, on-demand local or CI/CD scans through Defender CLI, and integration with AI coding environments. It also changes the status label from “private preview” to “preview” and reorganizes capability, language-support, and setup information.

Trigger an on-demand agentic scan (private preview)

Feature update

The documentation now covers SCM connectors, including GitHub and Azure DevOps. Repositories may take up to one hour to become available after connector activation, and each scan can use the default GPT-General profile or the MAI-Augmented preview profile.

Getting Started with Codename MDASH

Feature update

The onboarding requirements now support remote scanning through either GitHub or Azure DevOps, refer to a linked list of required models, and document two authentication methods for the Foundry project endpoint. Detailed RBAC requirements are now provided through linked guidance.

Mdash Initiative

Doc update

The MDASH Scans documentation now explains how to cancel queued or running scans, what the confirmation dialog displays, and how to provide a cancellation reason. Consumed tokens are not refunded.

Review Attack Paths

Doc update

The documentation page describing attack path prerequisites, dashboards, grouping, choke points, blast radius, path examination, and recommendations was deleted.

5
13

Tvm Software Inventory

New feature

The documentation now describes vulnerability reporting for supported Microsoft Store applications, including Microsoft Store-tagged CVE evidence and suggested queries.

Defender Vulnerability Management Trial

Doc update

The documentation now names the user-trial setting, adds links to trial-management sections, clarifies the 30-day extension request, and states that trial data is retained for approximately 180 days before permanent deletion.

Tvm Browser Extensions

Doc update

The documentation now explicitly names browser extension assessment, updates the licensing prerequisite wording, and says to use permission details and risk levels when deciding whether to allow or block an extension.

Hunt for exposed devices

Doc update

The page now explicitly identifies the listed products and plans as applying to Advanced hunting queries in Microsoft Defender Vulnerability Management. The page date and authoring metadata were also updated.

Hardware and firmware assessment

Doc update

The article now explicitly refers to Microsoft Defender XDR plus Microsoft Defender for Identity preview customers and clarifies that BIOS recommendations appear when a specific BIOS version is installed on at least 5% of devices across organizations. Metadata was also updated.

Fixed Reported Inaccuracies

Feature update

The page now lists June–August 2026 corrections to detections, recommendations, CVSS scores, and tags, plus MDVM support for additional applications.

1
1
1
1

Mdb Onboard Devices

Doc update

The instructions for configuring Intune in Entra ID and adding enrolled devices to a Defender for Business device group now use consistent numbered-list formatting.

14

Mto Cross Cloud

Doc update

The article now explicitly names the MFA trust setting, distinguishes home and target tenant configuration, adds section anchors, and clarifies terminology for added cross-cloud tenants.

Use workbooks in multitenant management

Doc update

The article was rewritten with clearer steps for opening Workbooks and using the Situational Awareness workbook. It also clarifies tenant selection and current workbook limitations.

How Microsoft names threat actors

Doc update

The page adds Frontier Blizzard, Storm-2581, and Storm-3127; updates several Storm group classifications to financially motivated; and revises links to Defender XDR threat analytics and Microsoft Graph Threat Intelligence APIs.

Set up Microsoft Defender multitenant management

Doc updateAction required

The requirements page now instructs readers to verify tenant access with Microsoft Entra B2B, clarifies related-link titles, standardizes note formatting, and updates metadata.

Microsoft Defender portal implementation guide for MSSPs

Doc update

The page now explains that available email and collaboration capabilities depend on using Microsoft Entra B2B or GDAP. It adds notes on B2B Exchange RBAC limitations and GDAP workload and role requirements, and updates the email-management examples.

Defender Portal

Doc update

The overview now refers to Microsoft Threat Intelligence and describes capabilities in Microsoft Defender XDR and Microsoft Sentinel that aggregate and enrich threat data from multiple sources.

Defender Xdr Portal

Doc update

The documentation now refers to “Defender XDR” instead of “Defender for XDR” in the automated investigation and response description.

Zero Trust

Doc update

The linked topic changed from “What is Microsoft Defender Threat Intelligence (Defender TI)?” to “What is Microsoft Threat Intelligence in Microsoft Defender XDR?” with a new destination URL.

3

Microsoft Sentinel Onboard

Doc update

The page date and onboarding wording were updated to point readers to feature documentation and service-specific prerequisites for unified security operations.

Plan

Doc update

The overview now uses “Microsoft Threat Intelligence” and links to its Defender XDR page and getting-started guidance instead of the previous Defender Threat Intelligence references.

2

Cases Overview

Retirement

The documentation now states that MDTI projects are deprecated and directs users to link threat indicators to cases in the Microsoft Defender portal.

Threat Intelligence Overview

Doc update

The page now uses relative paths for its screenshots, updates terminology and the Microsoft Threat Intelligence link, and replaces two related links with a Threat analytics link in Microsoft Defender XDR.

1

Mto Endpoint Security Policy

Doc update

The article now includes a prerequisite reminder, clearer instructions for viewing policies in Intune, and links to related multitenant management content. Documentation metadata was also updated.

1

Hunting Overview

Doc update

The overview replaces the Infrastructure chaining entry with a Threat analytics link for tracking emerging threats and reviewing Microsoft threat research and insights. The reactive hunting table formatting was also adjusted.

1
11

Data Sets

Retirement

The data sets page was deleted. Its notice stated that Defender TI will be merged into Microsoft Defender and retired on August 1, 2026; existing customers retain access until then.

Gathering Vulnerability Intelligence

Retirement

The tutorial page was deleted. Its notice stated that Defender TI will be discontinued and merged into Microsoft Defender, with existing customers retaining access until August 1, 2026.

Infrastructure Chaining

Retirement

The infrastructure chaining documentation was deleted. It described Defender TI investigation workflows and stated that Defender TI will be merged into Microsoft Defender before retirement on August 1, 2026.

Using Copilot Threat Intelligence Defender Xdr

Doc update

The documentation page for using Microsoft Security Copilot with Defender Threat Intelligence was deleted, including its requirements, access locations, usage steps, and built-in prompt guidance.

Analyst Insights

Retirement

The Analyst insights page was deleted. Its previous notice stated that Defender TI will be discontinued and merged into Microsoft Defender, with existing access available until August 1, 2026.

Reputation Scoring

RetirementAction required

The reputation-scoring page was deleted. Its notice says Defender TI will be discontinued and merged into Microsoft Defender; existing customers retain access until August 1, 2026.

Searching And Pivoting

RetirementAction required

The searching and pivoting article was removed. Its notice states that Defender TI will be merged into Microsoft Defender, with existing access continuing until August 1, 2026.

Sorting Filtering And Downloading Data

Retirement

The how-to article covering sorting, filtering, and downloading Defender TI data was deleted. Its notice states that Defender TI will be discontinued and merged into Microsoft Defender, with current access continuing until August 1, 2026.

Using Projects

RetirementAction required

The “Using Projects” documentation was removed. It stated that Defender TI will be discontinued and merged into Microsoft Defender, with existing customer access continuing until August 1, 2026.

Using Tags

RetirementAction required

The “Using tags in Microsoft Defender Threat Intelligence” page was deleted. Its content stated that Defender TI will be discontinued and merged into Defender, with existing access continuing until August 1, 2026.

1