What's new in Microsoft Security Exposure Management
In brief
The August 2026 entries cover keyless Microsoft Foundry authentication, portal scan cancellation, an Azure DevOps connector preview, MAI-Augmented scan profiles, and an updated overview dashboard preview. Attack-path links and older release-note content were also updated.
What Defender admins need to know
Administrators can use the new connection, scanning, and dashboard options. Keyless authentication uses a one-time onboarding script; API-key authentication remains available. No required action is stated.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
title: Release notesWhat's new in Microsoft Security Exposure Management
description: This page is updated frequently with the latest updates in Microsoft Security Exposure Management.
ms.topic: overview
ms.author: dlanger
https://aka.ms/msem/rss
August 2026
Keyless authentication for the Microsoft Foundry connection preview
You can now connect your Microsoft Foundry resource to codename MDASH using Keyless authentication, the recommended method.
Keyless relies on a managed identity instead of a stored secret - no API key is kept in Defender, and there's no key to rotate.
Setup uses a one-time onboarding script. API key authentication remains available as an alternative.
For more information, see Authentication methods.
Codename MDASH - Cancel scan
Scan cancellation, previously available only in Defender CLI, is now also available in the Microsoft Defender portal.
You can cancel queued or running scans from the scan details page in the Scans tab.
For more information, see Cancel scan.
Codename MDASH - Azure DevOps connector preview
The Azure DevOps connector is now available in preview for Codename MDASH - Agentic code scanner. Security teams can connect Azure DevOps organizations from the Microsoft Defender portal, onboard repositories, and trigger remote on-demand agentic code scans for the onboarded repositories.
For more information, see Create an Azure DevOps connector.
July 2026
Codename MDASH - MAI-Augmented scan profile now available for on-demand scans preview
Expanding on the previously released Defender CLI support, the MAI-Augmented scan profile is now also available in preview for on-demand scans triggered from the Microsoft Defender portal. Security teams can select this profile when starting an on-demand scan from the Manage scans. For more information, see Trigger an on-demand agentic scan.
Codename MDASH - MAI-Augmented scan profile preview
The MAI-Augmented scan profile is now available in preview as part of Codename MDASH. The MAI-Augmented profile can be used when triggering a scan through the Defender CLI.
It includes MAI-Cyber-1-Flash, a new cyber-specialized model that extends the current agentic scanner in addition to the existing required models.
Security teams can choose this profile when triggering a scan from Defender CLI or continue using a scan profile based on the existing models.
For more information, see Scan with a scan profile (Preview).
Codename MDASH - Agentic code scanner private preview
Codename MDASH - Agentic code scanner is now available in private preview in Microsoft Security Exposure Management.
| Classification | Description |
|---|---|
| Executive-Sponsored AI Agent | This rule applies to AI agents that are created or owned by senior executives in the organization. As such, these agents may be granted access to sensitive data and act on the executive's behalf. Compromise could lead to unauthorized actions performed under executive authority, and exposure of sensitive executive-level data - without the executive's identity being directly compromised. |
For more information, see Predefined classifications.
For more information, see Predefined classifications.
Overview dashboard (preview)
The updated Microsoft Security Exposure Management overview dashboard is now in preview. The dashboard consolidates signals from cloud resources and devices into a single, action-oriented view of exposure risk, organized around two core actions: Resolve Now and Monitor Exposure.
For more information, see Start using Microsoft Security Exposure Management.
New predefined classifications
The following predefined SaaS application classification rules were added to the critical assets list. These classifications require onboarding to Microsoft Defender for Cloud Apps.
Read more about it in this blog: Refining Attack Paths: Prioritizing Real-World, Exploitable Threats
For more information, see Overview of attack paths and Review attack pathsReview attack paths.
May 2025
- View risks in the environment the same way attackers do
- Identify low hanging fruit chokepoints that significantly expose the environment to risk
For more information, see, Review attack pathsReview attack paths
External data connectors
Content versioning notifications
The new versioning feature in Microsoft Security Exposure Management offers proactive notifications about upcoming version updates, giving users advanced visibility into anticipated metric changes and their impact on their related initiatives. A dedicated side panel provides comprehensive details about each update, including the expected release date, release notes,What's new in Microsoft Security Exposure Management, current and new metric values, and any changes to related initiative scores. Additionally, users can share direct feedback on the updates within the platform, fostering continuous improvement and responsiveness to user needs.
For more information on exposure insights, see Overview - Exposure insights
For more information, see, SaaS security initiative
October 2024
New in attack paths
We have introduced four new features designed to enhance your security management and risk mitigation efforts. These features provide valuable insights into the attack paths identified within your environment, enabling you to prioritize risk mitigation strategies effectively and reduce the impact of potential threats.
The new features include:
Attack path widget on exposure management overview page: Provides users with an at-a-glance, high-level view of discovered attack paths. It displays a timeline of newly identified paths, key entry points, target types, and more, ensuring security teams stay informed about emerging threats and can respond quickly.Attack path dashboard: Provides a high-level overview of all identified attack paths within the environment. This feature enables security teams to gain valuable insights into the types of paths identified, top entry points, target assets, and more, helping to prioritize risk mitigation efforts effectively.Choke points: Highlights critical assets that multiple attack paths intersect, identifying them as key vulnerabilities within the environment. By focusing on these choke points, security teams can efficiently reduce risk by addressing high-impact assets, thus preventing attackers from progressing through various paths.Blast radius: Allows users to visually explore the paths from a choke point. It provides a detailed visualization showing how the compromise of one asset could affect others, enabling security teams to assess the broader implications of an attack and prioritize mitigation strategies more effectively.
For more information, see Overview of attack paths.
September 2024
New Enterprise IoT Security Initiative
With this new initiative, Enterprise IoT Security offers a powerful solution to identify unmanaged IoT devices and enhance your security. With continuous monitoring, vulnerability assessments, and tailored recommendations designed for Enterprise IoT devices, you gain comprehensive visibility into the risks posed by these devices. This initiative not only helps you understand the potential threats but also strengthens your organization's resilience in mitigating them.
For more information, see, Review security initiatives
New predefined classifications
The following predefined classification rule was added to the critical assets list:
For more information, see, Predefined classifications
Enhanced visibility for scoped users
This change now allows users who have been granted access to only some of the organization's devices to see the list of affected assets in metrics, recommendations, events, and initiative history within their specific scope.
For more information, see Prerequisites and support.
Proactively manage your security posture
Read how the ExposureGraphEdges and ExposureGraphNodes tables in Advanced Hunting helps your organizations proactively manage and understand your security posture by analyzing asset relationships and potential vulnerabilities.
Blog - Microsoft Security Exposure Management Graph: Prioritization is the king
For more information, see, Query the enterprise exposure graph
August 2024
New predefined classifications
The following predefined Identity classification rules were added to the critical assets list:
For more information, see, Predefined classifications
New Initiative Event
A new event type has been created to notify users when a new initiative is added to MSEM.
For more information, see, Overview - Exposure insights
News from the Research Team
Read more about what the research team has been up to in this blog - Bridging the On-premises to Cloud Security Gap: Cloud Credentials Detection
July 2024
New predefined classifications
The following predefined classification rules were added to the critical assets list:
For more information, see, Predefined classifications
May 2024
Integration with Threat Analytics
New integration with Threat Analytics to enhance the set of domain security initiatives with threat-based security initiatives. These initiatives focus on specific attack techniques and active threat actors, as seen and analyzed by expert Microsoft security researchers.Blog- Respond to trending threats and adopt zero-trust with Exposure Management
For more information, see, Review security initiatives
New Exposure Management Tables
MSEM released two new powerful tables within Advanced Hunting:ExposureGraphNodesandExposureGraphEdges.Blog- Microsoft Security Exposure Management Graph: unveiling the power
For more information, see, Query the enterprise exposure graph
April 2024
Critical Asset Protection
Microsoft Security Exposure Management introduces a contextual risk-based approach, allowing organizations to identify and prioritize critical assets effectively. By assessing potential exposures in real time, security teams gain clarity and focus on safeguarding their digital assets.Blog- Critical Asset Protection with Microsoft Security Exposure Management
For more information, see, Overview of critical asset management
@@ -1,5 +1,5 @@ ----title: Release notes+title: What's new in Microsoft Security Exposure Management description: This page is updated frequently with the latest updates in Microsoft Security Exposure Management. ms.topic: overview ms.author: dlanger@@ -22,8 +22,47 @@ Learn more about MSEM by reading the [Microsoft Security and Compliance blog](ht > > `https://aka.ms/msem/rss` +## August 2026++### Keyless authentication for the Microsoft Foundry connection preview++You can now connect your Microsoft Foundry resource to codename MDASH using **Keyless authentication**, the recommended method. ++Keyless relies on a managed identity instead of a stored secret - no API key is kept in Defender, and there's no key to rotate.++Setup uses a one-time onboarding script. API key authentication remains available as an alternative.++For more information, see [Authentication methods](mdash-foundry-integration.md#authentication-methods).++### Codename MDASH - Cancel scan++Scan cancellation, previously available only in Defender CLI, is now also available in the Microsoft Defender portal. ++You can cancel queued or running scans from the scan details page in the **Scans** tab.++For more information, see [Cancel scan](mdash-initiative.md#cancel-a-scan).++### Codename MDASH - Azure DevOps connector preview++The Azure DevOps connector is now available in preview for Codename MDASH - Agentic code scanner. Security teams can connect Azure DevOps organizations from the Microsoft Defender portal, onboard repositories, and trigger remote on-demand agentic code scans for the onboarded repositories.++For more information, see [Create an Azure DevOps connector](/security-exposure-management/create-azure-devops-connector).+ ## July 2026 +### Codename MDASH - MAI-Augmented scan profile now available for on-demand scans preview++Expanding on the previously released Defender CLI support, the MAI-Augmented scan profile is now also available in preview for on-demand scans triggered from the Microsoft Defender portal. Security teams can select this profile when starting an on-demand scan from the Manage scans. For more information, see [Trigger an on-demand agentic scan](/security-exposure-management/create-azure-devops-connector).++### Codename MDASH - MAI-Augmented scan profile preview++The MAI-Augmented scan profile is now available in preview as part of Codename MDASH. The MAI-Augmented profile can be used when triggering a scan through the Defender CLI. +It includes MAI-Cyber-1-Flash, a new cyber-specialized model that extends the current agentic scanner in addition to the existing required models. ++Security teams can choose this profile when triggering a scan from Defender CLI or continue using a scan profile based on the existing models.++For more information, see [Scan with a scan profile (Preview)](defender-cli.md#scan-with-a-scan-profile-preview).+ ### Codename MDASH - Agentic code scanner private preview Codename MDASH - Agentic code scanner is now available in private preview in Microsoft Security Exposure Management.@@ -49,7 +88,7 @@ The following predefined **AI agent** classification rules were added to the cri | Classification | Description | | -------------- | ----------- | | Executive-Sponsored AI Agent | This rule applies to AI agents that are created or owned by senior executives in the organization. As such, these agents may be granted access to sensitive data and act on the executive's behalf. Compromise could lead to unauthorized actions performed under executive authority, and exposure of sensitive executive-level data - without the executive's identity being directly compromised. |-| AI Agent with Privileged Business System Write Access | This rule applies to AI agents configured with tools that can perform high-risk write operations on business-critical systems. These operations include creating, modifying, and deleting records such as sales orders, customer data, financial transactions, and legal agreements. Compromise could lead to significant business impact. |+ For more information, see [Predefined classifications](predefined-classification-rules-and-levels.md). @@ -65,6 +104,12 @@ The following predefined **Identity** classification rules were added to the cri For more information, see [Predefined classifications](predefined-classification-rules-and-levels.md). +### Overview dashboard (preview)++The updated Microsoft Security Exposure Management overview dashboard is now in preview. The dashboard consolidates signals from cloud resources and devices into a single, action-oriented view of exposure risk, organized around two core actions: **Resolve Now** and **Monitor Exposure**.++For more information, see [Start using Microsoft Security Exposure Management](get-started-exposure-management.md).+ ### New predefined classifications The following predefined **SaaS application** classification rules were added to the critical assets list. These classifications require onboarding to Microsoft Defender for Cloud Apps.@@ -296,7 +341,7 @@ The changes bring greater clarity, focus, and prioritization empowering security Read more about it in this blog: [Refining Attack Paths: Prioritizing Real-World, Exploitable Threats](https://techcommunity.microsoft.com/blog/securityexposuremanagement/refining-attack-paths-prioritizing-real-world-exploitable-threats/4454051) -For more information, see [Overview of attack paths](work-attack-paths-overview.md) and [Review attack paths](review-attack-paths.md).+For more information, see [Overview of attack paths](work-attack-paths-overview.md) and [Review attack paths](work-attack-paths-overview.md). ## May 2025 @@ -407,7 +452,7 @@ Our attack path calculations now include support for **Discretionary Access Cont - View risks in the environment the same way attackers do - Identify low hanging fruit chokepoints that significantly expose the environment to risk -For more information, see, [Review attack paths](review-attack-paths.md)+For more information, see, [Review attack paths](work-attack-paths-overview.md) ### External data connectors @@ -439,7 +484,7 @@ To learn more about creating new custom roles in Microsoft Defender unified RBAC ### Content versioning notifications -The new versioning feature in Microsoft Security Exposure Management offers proactive notifications about upcoming version updates, giving users advanced visibility into anticipated metric changes and their impact on their related initiatives. A dedicated side panel provides comprehensive details about each update, including the expected release date, release notes, current and new metric values, and any changes to related initiative scores. Additionally, users can share direct feedback on the updates within the platform, fostering continuous improvement and responsiveness to user needs.+The new versioning feature in Microsoft Security Exposure Management offers proactive notifications about upcoming version updates, giving users advanced visibility into anticipated metric changes and their impact on their related initiatives. A dedicated side panel provides comprehensive details about each update, including the expected release date, What's new in Microsoft Security Exposure Management, current and new metric values, and any changes to related initiative scores. Additionally, users can share direct feedback on the updates within the platform, fostering continuous improvement and responsiveness to user needs. For more information on exposure insights, see [Overview - Exposure insights](exposure-insights-overview.md) @@ -455,146 +500,3 @@ The SaaS Security initiative delivers a clear view of your SaaS security coverag For more information, see, [SaaS security initiative](/defender-cloud-apps/saas-security-initiative) -## October 2024--### New in attack paths--We have introduced four new features designed to enhance your security management and risk mitigation efforts. These features provide valuable insights into the attack paths identified within your environment, enabling you to prioritize risk mitigation strategies effectively and reduce the impact of potential threats.--The new features include:--- **Attack path widget on exposure management overview page**: Provides users with an at-a-glance, high-level view of discovered attack paths. It displays a timeline of newly identified paths, key entry points, target types, and more, ensuring security teams stay informed about emerging threats and can respond quickly.-- **Attack path dashboard**: Provides a high-level overview of all identified attack paths within the environment. This feature enables security teams to gain valuable insights into the types of paths identified, top entry points, target assets, and more, helping to prioritize risk mitigation efforts effectively.-- **Choke points**: Highlights critical assets that multiple attack paths intersect, identifying them as key vulnerabilities within the environment. By focusing on these choke points, security teams can efficiently reduce risk by addressing high-impact assets, thus preventing attackers from progressing through various paths.-- **Blast radius**: Allows users to visually explore the paths from a choke point. It provides a detailed visualization showing how the compromise of one asset could affect others, enabling security teams to assess the broader implications of an attack and prioritize mitigation strategies more effectively.--For more information, see [Overview of attack paths](work-attack-paths-overview.md).--## September 2024--### New Enterprise IoT Security Initiative--With this new initiative, Enterprise IoT Security offers a powerful solution to identify unmanaged IoT devices and enhance your security. With continuous monitoring, vulnerability assessments, and tailored recommendations designed for Enterprise IoT devices, you gain comprehensive visibility into the risks posed by these devices. This initiative not only helps you understand the potential threats but also strengthens your organization's resilience in mitigating them.--For more information, see, [Review security initiatives](initiatives.md)--### New predefined classifications--The following predefined classification rule was added to the critical assets list:--| Classification | Description |-| ------------------------------------------------------------ | ------------------------------------------------------------ |-| **Hyper-V Server** | This rule applies to devices identified as Hyper-V servers within a domain. These servers are essential for running and managing virtual machines within your infrastructure, serving as the core platform for their creation and management. |--For more information, see, [Predefined classifications](predefined-classification-rules-and-levels.md)--### Enhanced visibility for scoped users--This change now allows users who have been granted access to only some of the organization's devices to see the list of affected assets in metrics, recommendations, events, and initiative history within their specific scope.--For more information, see [Prerequisites and support](prerequisites.md).--### Proactively manage your security posture--Read how the *ExposureGraphEdges* and *ExposureGraphNodes* tables in Advanced Hunting helps your organizations proactively manage and understand your security posture by analyzing asset relationships and potential vulnerabilities.--**Blog** - [Microsoft Security Exposure Management Graph: Prioritization is the king](https://techcommunity.microsoft.com/t5/security-compliance-and-identity/microsoft-security-exposure-management-graph-prioritization-is/ba-p/4160316)--For more information, see, [Query the enterprise exposure graph](query-enterprise-exposure-graph.md)--## August 2024--### New predefined classifications--The following predefined **Identity** classification rules were added to the critical assets list:--| Classification | Description |-| --------------------------------------------- | ------------------------------------------------------------ |-| External Identity Provider Administrator | This rule applies to identities assigned with the Microsoft Entra "External Identity Provider Administrator" role. |-| Domain Name Administrator | This rule applies to identities assigned with the Microsoft Entra "Domain Name Administrator" role. |-| Permissions Management Administrator | This rule applies to identities assigned with the Microsoft Entra "Permissions Management Administrator" role. |-| Billing Administrator | This rule applies to identities assigned with the Microsoft Entra "Billing Administrator" role. |-| License Administrator | This rule applies to identities assigned with the Microsoft Entra "License Administrator" role. |-| Teams Administrator | This rule applies to identities assigned with the Microsoft Entra "Teams Administrator" role. |-| External ID User Flow Administrator | This rule applies to identities assigned with the Microsoft Entra "External ID User Flow Administrator" role. |-| External ID User Flow Attribute Administrator | This rule applies to identities assigned with the Microsoft Entra "External ID User Flow Attribute Administrator" role. |-| B2C IEF Policy Administrator | This rule applies to identities assigned with the Microsoft Entra "B2C IEF Policy Administrator" role. |-| Compliance Data Administrator | This rule applies to identities assigned with the Microsoft Entra "Compliance Data Administrator" role. |-| Authentication Policy Administrator | This rule applies to identities assigned with the Microsoft Entra "Authentication Policy Administrator" role. |-| Knowledge Administrator | This rule applies to identities assigned with the Microsoft Entra "Knowledge Administrator" role. |-| Knowledge Manager | This rule applies to identities assigned with the Microsoft Entra "Knowledge Manager" role. |-| Attribute Definition Administrator | This rule applies to identities assigned with the Microsoft Entra "Attribute Definition Administrator" role. |-| Attribute Assignment Administrator | This rule applies to identities assigned with the Microsoft Entra "Attribute Assignment Administrator" role. |-| Identity Governance Administrator | This rule applies to identities assigned with the Microsoft Entra "Identity Governance Administrator" role. |-| Cloud App Security Administrator | This rule applies to identities assigned with the Microsoft Entra "Cloud App Security Administrator" role. |-| Windows 365 Administrator | This rule applies to identities assigned with the Microsoft Entra "Windows 365 Administrator" role. |-| Yammer Administrator | This rule applies to identities assigned with the Microsoft Entra "Yammer Administrator" role. |-| Authentication Extensibility Administrator | This rule applies to identities assigned with the Microsoft Entra "Authentication Extensibility Administrator" role. |-| Lifecycle Workflows Administrator | This rule applies to identities assigned with the Microsoft Entra "Lifecycle Workflows Administrator" role. |--For more information, see, [Predefined classifications](predefined-classification-rules-and-levels.md)--### New Initiative Event--A new event type has been created to notify users when a new initiative is added to MSEM.--For more information, see, [Overview - Exposure insights](exposure-insights-overview.md)--### News from the Research Team--Read more about what the research team has been up to in this blog - [Bridging the On-premises to Cloud Security Gap: Cloud Credentials Detection](https://techcommunity.microsoft.com/t5/security-compliance-and-identity/bridging-the-on-premises-to-cloud-security-gap-cloud-credentials/ba-p/4211794)--## July 2024--### New predefined classifications--The following predefined classification rules were added to the critical assets list:--| Classification | Description |-| ------------------------------------------------------------ | ------------------------------------------------------------ |-| **Exchange** | This rule applies to devices identified as operational Exchange servers within a domain. These servers might hold sensitive data of the organization. |-| **VMware ESXi** | This rule applies to devices identified as operational ESXi servers. These devices might hold other sensitive or critical devices. |-| **VMware vCenter** | This rule applies to devices identified as operational VMware vCenter and frequently used by admins to manage the virtual infrastructure. |-| **Identity with Privileged Azure Role** | This rule applies to identities assigned with a Privileged Azure role, over a potentially business-critical scope. |-| **Exchange Administrator** | This rule applies to identities assigned with the Microsoft Entra "Exchange Administrator" role. |-| **SharePoint Administrator** | This rule applies to identities assigned with the Microsoft Entra "SharePoint Administrator" role. |-| **Compliance Administrator** | This rule applies to identities assigned with the Microsoft Entra "Compliance Administrator" role. |-| **Groups Administrator** | This rule applies to identities assigned with the Microsoft Entra "Groups Administrator" role. |-| **Confidential Azure Virtual Machine** | This rule applies to Azure confidential Virtual Machines. |-| **Locked Azure Virtual Machine** | This rule applies to Azure virtual machines that are safeguarded by a lock. |-| **Azure Virtual Machine with High Availability and Performance** | This rule applies to Azure Virtual Machines that use premium Azure storage and are configured with an availability set. |-| **Immutable Azure Storage** | This rule applies to Azure storage accounts that have immutability support enabled. |-| **Immutable and Locked Azure Storage** | This rule applies to Azure storage accounts that have immutability support enabled with a locked policy in place. |-| **Azure Virtual Machine has a Critical Signed-in user** | This rule applies to Azure Virtual Machines with a Critical user signed in protected by Defender for Endpoint with high or very high-criticality users signed in. |-| **Azure Key Vaults with Many Connected Identities** | This rule applies to Azure Key Vaults with high access compared to others, indicating critical workload usage. |--For more information, see, [Predefined classifications](predefined-classification-rules-and-levels.md)--## May 2024--### Integration with Threat Analytics--- New integration with Threat Analytics to enhance the set of domain security initiatives with threat-based security initiatives. These initiatives focus on specific attack techniques and active threat actors, as seen and analyzed by expert Microsoft security researchers.--- **Blog** - [Respond to trending threats and adopt zero-trust with Exposure Management](https://techcommunity.microsoft.com/t5/security-compliance-and-identity/respond-to-trending-threats-and-adopt-zero-trust-with-exposure/ba-p/4130133)--For more information, see, [Review security initiatives](initiatives.md)--### New Exposure Management Tables--- MSEM released two new powerful tables within Advanced Hunting: *ExposureGraphNodes* and *ExposureGraphEdges*.--- **Blog** - [Microsoft Security Exposure Management Graph: unveiling the power](https://techcommunity.microsoft.com/t5/security-compliance-and-identity/microsoft-security-exposure-management-graph-unveiling-the-power/ba-p/4148546)--For more information, see, [Query the enterprise exposure graph](query-enterprise-exposure-graph.md)--## April 2024--### Critical Asset Protection--- Microsoft Security Exposure Management introduces a contextual risk-based approach, allowing organizations to identify and prioritize critical assets effectively. By assessing potential exposures in real time, security teams gain clarity and focus on safeguarding their digital assets.--- **Blog** - [Critical Asset Protection with Microsoft Security Exposure Management](https://techcommunity.microsoft.com/t5/security-compliance-and-identity/critical-asset-protection-with-microsoft-security-exposure/ba-p/4122645)--For more information, see, [Overview of critical asset management](critical-asset-management.md)- 