Microsoft Sentinel
Cloud and workloads

customer intent: As a security team member, I want to stay updated on the latest features and enhancements in Microsoft Sentinel so that I can effect…

In brief

The documentation states that the containerized SAP data connector agent will be permanently disabled on September 14, 2026. Dependent analytics rules, workbooks, hunting queries, and playbooks will stop returning results for affected SAP systems.

What Defender admins need to know

Migrate affected deployments to the SAP agentless connector before the deadline to avoid losing SAP logs and related detections.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

What's new in Microsoft Sentinel

[!INCLUDE reference-to-feature-availability]

August 2026

New data sources for UEBA behaviors and anomaly detection (Preview)

Microsoft Sentinel UEBA expands coverage with new data sources for both the behaviors layer and anomaly detection.

Fortinet FortiGate behaviors

The UEBA behaviors layer now supports Fortinet FortiGate firewall events from the CommonSecurityLog table. More than 40 new behaviors identify administrative activity on FortiGate appliances, including rapid system reconfigurations, configuration backups, certificate changes, and security service disruptions. These behaviors are mapped to MITRE ATT&CK techniques including T1685, T1070, T1078, and T1602.002.

Check Point, Fortinet, Zscaler, and AWS GuardDuty anomalies

UEBA anomaly detection now supports Check Point, Fortinet FortiGate, and Zscaler firewall, VPN, and web proxy events from the CommonSecurityLog table. Ten new anomaly rules compare each user and device against its own history and organization-wide activity to identify:

  • Anomalous and failed VPN sign-ins
  • Unusual access to high-risk web categories
  • Bursts of security detections on a potentially compromised device
  • Suspicious administrative changes

The new anomaly rules are mapped to MITRE ATT&CK techniques including T1078, T1133, T1110, T1071, T1562, and T1567. Events are enriched with source IP geolocation, ISP, and threat intelligence context.

UEBA anomaly detection also supports identity-linked AWS GuardDuty findings from the AWSGuardDuty table, mapped to MITRE ATT&CK techniques including T1078, T1078.004, T1110, T1087.004, and T1567.002.

UEBA anomalies on behaviors (Preview)

Microsoft Sentinel now adds contextual anomaly insights directly to UEBA behavior records. These insights help analysts identify first-seen activity, unusually high behavior volumes, uncommon values, and threat intelligence matches without manually correlating raw events. For more information, see Investigate anomalies on UEBA behaviors.

SAP solution releases

The SAP agentless solution version 1.1.12 adds audit log performance enhancements and the force-sal-filesystem parameter. The SAP BTP solution version 3.1.1 adds an analytic rule for unaudited custom apps with login-only activity and renames analytic rules with the SAP BTP prefix. The SAP LogServ solution version 3.0.5 lets customers using RISE with SAP activate existing ASIM-based security content for standard SAP LogServ logs; HANA detections now use Syslog instead of the custom log, with updated connector coverage and fallback handling. For more information, see the SAP LogServ integration blog series.

July 2026

  • Custom detection rules support in Microsoft Sentinel Repositories (Preview)

  • Agentless data connector for Sentinel Solution for SAP now generally available. Learn more from our Tech Community blog.

  • Deprecation: ContainerizedRetirement: The containerized SAP data connector agent will be outpermanently disabled on September 14, 2026, and will stop delivering SAP logs to Microsoft Sentinel. Analytics rules, workbooks, hunting queries, and playbooks that depend on these logs will stop returning results for affected SAP systems. Creation of support by September 30th 2026.new containerized agents is already disabled. The generally available agentless data connector is the supported replacement, and the retirement doesn't change pricing or billing meters. Migrate to the agentless SAP data connector today. All new deployments only havebefore the new agentless connector option that is billed at the same price.retirement date.

Call to action: update queries and automation by July 1, 2026 - standardized account entity naming in incidents and alerts