Microsoft Security Exposure Management
Vulnerabilities and exposure

What's new in Microsoft Security Exposure Management

In brief

The August 2026 entries cover keyless Microsoft Foundry authentication, portal scan cancellation, an Azure DevOps connector preview, MAI-Augmented scan profiles, and an updated overview dashboard preview. Attack-path links and older release-note content were also updated.

What Defender admins need to know

Administrators can use the new connection, scanning, and dashboard options. Keyless authentication uses a one-time onboarding script; API-key authentication remains available. No required action is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.


title: Release notesWhat's new in Microsoft Security Exposure Management description: This page is updated frequently with the latest updates in Microsoft Security Exposure Management. ms.topic: overview ms.author: dlanger

https://aka.ms/msem/rss

August 2026

Keyless authentication for the Microsoft Foundry connection preview

You can now connect your Microsoft Foundry resource to codename MDASH using Keyless authentication, the recommended method.

Keyless relies on a managed identity instead of a stored secret - no API key is kept in Defender, and there's no key to rotate.

Setup uses a one-time onboarding script. API key authentication remains available as an alternative.

For more information, see Authentication methods.

Codename MDASH - Cancel scan

Scan cancellation, previously available only in Defender CLI, is now also available in the Microsoft Defender portal.

You can cancel queued or running scans from the scan details page in the Scans tab.

For more information, see Cancel scan.

Codename MDASH - Azure DevOps connector preview

The Azure DevOps connector is now available in preview for Codename MDASH - Agentic code scanner. Security teams can connect Azure DevOps organizations from the Microsoft Defender portal, onboard repositories, and trigger remote on-demand agentic code scans for the onboarded repositories.

For more information, see Create an Azure DevOps connector.

July 2026

Codename MDASH - MAI-Augmented scan profile now available for on-demand scans preview

Expanding on the previously released Defender CLI support, the MAI-Augmented scan profile is now also available in preview for on-demand scans triggered from the Microsoft Defender portal. Security teams can select this profile when starting an on-demand scan from the Manage scans. For more information, see Trigger an on-demand agentic scan.

Codename MDASH - MAI-Augmented scan profile preview

The MAI-Augmented scan profile is now available in preview as part of Codename MDASH. The MAI-Augmented profile can be used when triggering a scan through the Defender CLI.
It includes MAI-Cyber-1-Flash, a new cyber-specialized model that extends the current agentic scanner in addition to the existing required models.

Security teams can choose this profile when triggering a scan from Defender CLI or continue using a scan profile based on the existing models.

For more information, see Scan with a scan profile (Preview).

Codename MDASH - Agentic code scanner private preview

Codename MDASH - Agentic code scanner is now available in private preview in Microsoft Security Exposure Management.

Classification Description
Executive-Sponsored AI Agent This rule applies to AI agents that are created or owned by senior executives in the organization. As such, these agents may be granted access to sensitive data and act on the executive's behalf. Compromise could lead to unauthorized actions performed under executive authority, and exposure of sensitive executive-level data - without the executive's identity being directly compromised.
AI Agent with Privileged Business System Write AccessThis rule applies to AI agents configured with tools that can perform high-risk write operations on business-critical systems. These operations include creating, modifying, and deleting records such as sales orders, customer data, financial transactions, and legal agreements. Compromise could lead to significant business impact.

For more information, see Predefined classifications.

For more information, see Predefined classifications.

Overview dashboard (preview)

The updated Microsoft Security Exposure Management overview dashboard is now in preview. The dashboard consolidates signals from cloud resources and devices into a single, action-oriented view of exposure risk, organized around two core actions: Resolve Now and Monitor Exposure.

For more information, see Start using Microsoft Security Exposure Management.

New predefined classifications

The following predefined SaaS application classification rules were added to the critical assets list. These classifications require onboarding to Microsoft Defender for Cloud Apps.

Read more about it in this blog: Refining Attack Paths: Prioritizing Real-World, Exploitable Threats

For more information, see Overview of attack paths and Review attack pathsReview attack paths.

May 2025

  • View risks in the environment the same way attackers do
  • Identify low hanging fruit chokepoints that significantly expose the environment to risk

For more information, see, Review attack pathsReview attack paths

External data connectors

Content versioning notifications

The new versioning feature in Microsoft Security Exposure Management offers proactive notifications about upcoming version updates, giving users advanced visibility into anticipated metric changes and their impact on their related initiatives. A dedicated side panel provides comprehensive details about each update, including the expected release date, release notes,What's new in Microsoft Security Exposure Management, current and new metric values, and any changes to related initiative scores. Additionally, users can share direct feedback on the updates within the platform, fostering continuous improvement and responsiveness to user needs.

For more information on exposure insights, see Overview - Exposure insights

For more information, see, SaaS security initiative

October 2024

New in attack paths

We have introduced four new features designed to enhance your security management and risk mitigation efforts. These features provide valuable insights into the attack paths identified within your environment, enabling you to prioritize risk mitigation strategies effectively and reduce the impact of potential threats.

The new features include:

  • Attack path widget on exposure management overview page: Provides users with an at-a-glance, high-level view of discovered attack paths. It displays a timeline of newly identified paths, key entry points, target types, and more, ensuring security teams stay informed about emerging threats and can respond quickly.
  • Attack path dashboard: Provides a high-level overview of all identified attack paths within the environment. This feature enables security teams to gain valuable insights into the types of paths identified, top entry points, target assets, and more, helping to prioritize risk mitigation efforts effectively.
  • Choke points: Highlights critical assets that multiple attack paths intersect, identifying them as key vulnerabilities within the environment. By focusing on these choke points, security teams can efficiently reduce risk by addressing high-impact assets, thus preventing attackers from progressing through various paths.
  • Blast radius: Allows users to visually explore the paths from a choke point. It provides a detailed visualization showing how the compromise of one asset could affect others, enabling security teams to assess the broader implications of an attack and prioritize mitigation strategies more effectively.

For more information, see Overview of attack paths.

September 2024

New Enterprise IoT Security Initiative

With this new initiative, Enterprise IoT Security offers a powerful solution to identify unmanaged IoT devices and enhance your security. With continuous monitoring, vulnerability assessments, and tailored recommendations designed for Enterprise IoT devices, you gain comprehensive visibility into the risks posed by these devices. This initiative not only helps you understand the potential threats but also strengthens your organization's resilience in mitigating them.

For more information, see, Review security initiatives

New predefined classifications

The following predefined classification rule was added to the critical assets list:

ClassificationDescription
Hyper-V ServerThis rule applies to devices identified as Hyper-V servers within a domain. These servers are essential for running and managing virtual machines within your infrastructure, serving as the core platform for their creation and management.

For more information, see, Predefined classifications

Enhanced visibility for scoped users

This change now allows users who have been granted access to only some of the organization's devices to see the list of affected assets in metrics, recommendations, events, and initiative history within their specific scope.

For more information, see Prerequisites and support.

Proactively manage your security posture

Read how the ExposureGraphEdges and ExposureGraphNodes tables in Advanced Hunting helps your organizations proactively manage and understand your security posture by analyzing asset relationships and potential vulnerabilities.

Blog - Microsoft Security Exposure Management Graph: Prioritization is the king

For more information, see, Query the enterprise exposure graph

August 2024

New predefined classifications

The following predefined Identity classification rules were added to the critical assets list:

ClassificationDescription
External Identity Provider AdministratorThis rule applies to identities assigned with the Microsoft Entra "External Identity Provider Administrator" role.
Domain Name AdministratorThis rule applies to identities assigned with the Microsoft Entra "Domain Name Administrator" role.
Permissions Management AdministratorThis rule applies to identities assigned with the Microsoft Entra "Permissions Management Administrator" role.
Billing AdministratorThis rule applies to identities assigned with the Microsoft Entra "Billing Administrator" role.
License AdministratorThis rule applies to identities assigned with the Microsoft Entra "License Administrator" role.
Teams AdministratorThis rule applies to identities assigned with the Microsoft Entra "Teams Administrator" role.
External ID User Flow AdministratorThis rule applies to identities assigned with the Microsoft Entra "External ID User Flow Administrator" role.
External ID User Flow Attribute AdministratorThis rule applies to identities assigned with the Microsoft Entra "External ID User Flow Attribute Administrator" role.
B2C IEF Policy AdministratorThis rule applies to identities assigned with the Microsoft Entra "B2C IEF Policy Administrator" role.
Compliance Data AdministratorThis rule applies to identities assigned with the Microsoft Entra "Compliance Data Administrator" role.
Authentication Policy AdministratorThis rule applies to identities assigned with the Microsoft Entra "Authentication Policy Administrator" role.
Knowledge AdministratorThis rule applies to identities assigned with the Microsoft Entra "Knowledge Administrator" role.
Knowledge ManagerThis rule applies to identities assigned with the Microsoft Entra "Knowledge Manager" role.
Attribute Definition AdministratorThis rule applies to identities assigned with the Microsoft Entra "Attribute Definition Administrator" role.
Attribute Assignment AdministratorThis rule applies to identities assigned with the Microsoft Entra "Attribute Assignment Administrator" role.
Identity Governance AdministratorThis rule applies to identities assigned with the Microsoft Entra "Identity Governance Administrator" role.
Cloud App Security AdministratorThis rule applies to identities assigned with the Microsoft Entra "Cloud App Security Administrator" role.
Windows 365 AdministratorThis rule applies to identities assigned with the Microsoft Entra "Windows 365 Administrator" role.
Yammer AdministratorThis rule applies to identities assigned with the Microsoft Entra "Yammer Administrator" role.
Authentication Extensibility AdministratorThis rule applies to identities assigned with the Microsoft Entra "Authentication Extensibility Administrator" role.
Lifecycle Workflows AdministratorThis rule applies to identities assigned with the Microsoft Entra "Lifecycle Workflows Administrator" role.

For more information, see, Predefined classifications

New Initiative Event

A new event type has been created to notify users when a new initiative is added to MSEM.

For more information, see, Overview - Exposure insights

News from the Research Team

Read more about what the research team has been up to in this blog - Bridging the On-premises to Cloud Security Gap: Cloud Credentials Detection

July 2024

New predefined classifications

The following predefined classification rules were added to the critical assets list:

ClassificationDescription
ExchangeThis rule applies to devices identified as operational Exchange servers within a domain. These servers might hold sensitive data of the organization.
VMware ESXiThis rule applies to devices identified as operational ESXi servers. These devices might hold other sensitive or critical devices.
VMware vCenterThis rule applies to devices identified as operational VMware vCenter and frequently used by admins to manage the virtual infrastructure.
Identity with Privileged Azure RoleThis rule applies to identities assigned with a Privileged Azure role, over a potentially business-critical scope.
Exchange AdministratorThis rule applies to identities assigned with the Microsoft Entra "Exchange Administrator" role.
SharePoint AdministratorThis rule applies to identities assigned with the Microsoft Entra "SharePoint Administrator" role.
Compliance AdministratorThis rule applies to identities assigned with the Microsoft Entra "Compliance Administrator" role.
Groups AdministratorThis rule applies to identities assigned with the Microsoft Entra "Groups Administrator" role.
Confidential Azure Virtual MachineThis rule applies to Azure confidential Virtual Machines.
Locked Azure Virtual MachineThis rule applies to Azure virtual machines that are safeguarded by a lock.
Azure Virtual Machine with High Availability and PerformanceThis rule applies to Azure Virtual Machines that use premium Azure storage and are configured with an availability set.
Immutable Azure StorageThis rule applies to Azure storage accounts that have immutability support enabled.
Immutable and Locked Azure StorageThis rule applies to Azure storage accounts that have immutability support enabled with a locked policy in place.
Azure Virtual Machine has a Critical Signed-in userThis rule applies to Azure Virtual Machines with a Critical user signed in protected by Defender for Endpoint with high or very high-criticality users signed in.
Azure Key Vaults with Many Connected IdentitiesThis rule applies to Azure Key Vaults with high access compared to others, indicating critical workload usage.

For more information, see, Predefined classifications

May 2024

Integration with Threat Analytics

For more information, see, Review security initiatives

New Exposure Management Tables

For more information, see, Query the enterprise exposure graph

April 2024

Critical Asset Protection

  • Microsoft Security Exposure Management introduces a contextual risk-based approach, allowing organizations to identify and prioritize critical assets effectively. By assessing potential exposures in real time, security teams gain clarity and focus on safeguarding their digital assets.

  • Blog - Critical Asset Protection with Microsoft Security Exposure Management

For more information, see, Overview of critical asset management