Microsoft Defender for Office 365 will localize the default "Mark and notify" email template based on users' Outlook language settings, improving clarity in user-reported message notifications. Rollout starts June 2026 worldwide, completing by September 2026. No action is required; admins may inform users and review settings.
Microsoft Purview | Data Security Triage Agent Summaries for DLP Alerts in Microsoft Defender XDR leads 19 Defender updates
August 2026 recorded 8 updated Microsoft Defender documentation changes and 11 relevant Message Center announcements. The most active areas were Defender XDR, Endpoint, Office 365.
- Microsoft Purview | Data Security Triage Agent Summaries for DLP Alerts in Microsoft Defender XDR
Defender XDR · General
Microsoft Purview introduces AI-generated summaries and categorizations for DLP alerts within Microsoft Defender XDR, aiding security analysts in triage. The Data Security Triage Agent can be deployed from Defender XDR, with management in Purview. Rollout starts April 2026 (preview) and August 2027 (GA). Existing policies remain unchanged.
- Tenant will be auto-enabled into Microsoft Defender Unified RBAC
Defender XDR · Identity protection
Microsoft Defender Unified RBAC will auto-enable on tenants starting late September 2026, completing by December 2026. It unifies access management across Defender and Sentinel workloads, importing existing roles with a 30-day notification period before activation. Opt-out is available post-activation; other Microsoft permissions remain unchanged.
- Microsoft Edge: Retirement of Windows Information Protection (WIP) and Microsoft Defender Application Guard (MDAG)
Defender XDR · Endpoint protection
Microsoft Edge will retire support for Windows Information Protection (WIP) and Microsoft Defender Application Guard (MDAG) by late September 2026. Organizations using these on Windows 10 must migrate to Microsoft Purview solutions and Edge's built-in security features, as these capabilities are already removed in Windows 11 version 24H2.
- Troubleshoot Network Extension (NetExt) issues in Defender for Endpoint on Mac
Endpoint · Troubleshooting
Updated Microsoft Defender documentation in defender-endpoint/mac-troubleshoot-netext-mde.md.
- Tenant Allow Block List Email Spoof Configure
Office 365 · Email and collaboration
Updated Microsoft Defender documentation in defender-office-365/tenant-allow-block-list-email-spoof-configure.md.
Review the linked Microsoft Learn changes that apply to your managed platforms, policies, applications, and rollout plans. The archive preserves the source diff for verification.
This period briefing was assembled from the tracked Microsoft Learn and Message Center changes.
19 updates by product
Microsoft Defender XDR
11 updatesMicrosoft Purview | Data Security Triage Agent Summaries for DLP Alerts in Microsoft Defender XDR
NewMicrosoft Purview introduces AI-generated summaries and categorizations for DLP alerts within Microsoft Defender XDR, aiding security analysts in triage. The Data Security Triage Agent can be deployed from Defender XDR, with management in Purview. Rollout starts April 2026 (preview) and August 2027 (GA). Existing policies remain unchanged.
Microsoft Defender for Office 365's AIR experience will add a manual refresh button, replacing auto-refresh, and simplify investigation names by removing email subjects and UPNs. These changes improve performance, reduce network activity, and support data minimization. No admin action is required, but workflow updates are recommended.
Microsoft Teams will introduce a "Report a meeting" feature starting August 2026, allowing users to report suspicious or malicious activity during meetings. Reports help security teams investigate threats via Microsoft Defender and Teams admin center. The feature is enabled by default, with administrative controls and data collection for security investigations.
Microsoft Teams will introduce a "Report a call" feature for group calls, allowing users to report suspicious calls from call history. Administrators can review reports in Teams admin center and Microsoft Defender. The feature rolls out from August to October 2026 and is enabled by default.
Microsoft Edge will retire support for Windows Information Protection (WIP) and Microsoft Defender Application Guard (MDAG) by late September 2026. Organizations using these on Windows 10 must migrate to Microsoft Purview solutions and Edge's built-in security features, as these capabilities are already removed in Windows 11 version 24H2.
Update Microsoft Defender for Endpoint Android to version 1.0.9107.0101 or later by mid-September 2026 to avoid disruption in mobile threat protection due to infrastructure changes. Administrators should verify and update devices and inform users managing their own updates. No other configuration changes are needed.
Microsoft Defender Unified RBAC will auto-enable on tenants starting late September 2026, completing by December 2026. It unifies access management across Defender and Sentinel workloads, importing existing roles with a 30-day notification period before activation. Opt-out is available post-activation; other Microsoft permissions remain unchanged.
Microsoft Defender for Identity now includes a new sensor health issue, "No Windows events received from domain controller," to alert administrators of missing Windows events. This improves visibility into event collection gaps affecting detections. It is available now, requires no pre-rollout action, and helps identify domain controller issues.
Microsoft Defender for Office 365 will tag promotional emails as “promotions” and can auto-move them to a Promotions folder, learning user preferences over time. Public preview starts mid-April 2026; general availability begins late July 2026. Admins can configure settings, and users can train the system by moving messages.
Microsoft Defender for Identity now includes a health alert for missing domain controller network traffic, helping administrators detect traffic collection issues affecting visibility. The alert appears in sensor health tabs, requires no pre-rollout action, and guides troubleshooting if triggered after rollout. No impact on end users or compliance.
Microsoft Defender for Endpoint
6 updatesUpdated Microsoft Defender documentation in defender-endpoint/mac-troubleshoot-netext-mde.md.
Updated Microsoft Defender documentation in defender-endpoint/mac-support-perf.md.
Overview for how to troubleshoot performance issues for Microsoft Defender for Endpoint on macOS
UpdatedUpdated Microsoft Defender documentation in defender-endpoint/mac-support-perf-overview.md.
Updated Microsoft Defender documentation in defender-endpoint/mac-support-sys-ext.md.
Updated Microsoft Defender documentation in defender-endpoint/mac-exclusions.md.
Updated Microsoft Defender documentation in defender-endpoint/use-intune-config-manager-microsoft-defender-antivirus.md.
Microsoft Defender for Office 365
2 updatesSafe Links About
UpdatedUpdated Microsoft Defender documentation in defender-office-365/safe-links-about.md.
Updated Microsoft Defender documentation in defender-office-365/tenant-allow-block-list-email-spoof-configure.md.
