Microsoft Defender for Office 365 will introduce an opt-in Safe Attachments policy to quarantine emails with password-protected attachments that cannot be scanned. Administrators can control release, users can self-release with passwords, and the feature supports various file types. Rollout begins August 2026 worldwide.
Get Vulnerability By Id leads 6 Defender updates
Week of 27 July 2026 recorded 4 updated Microsoft Defender documentation changes and 2 relevant Message Center announcements. The most active areas were Office 365, Defender XDR, Identity.
- Get Vulnerability By Id
Endpoint · Endpoint protection
Updated Microsoft Defender documentation in defender-endpoint/api/get-vulnerability-by-id.md.
- Migrate from Advanced Threat Analytics (ATA) to Microsoft Defender for Identity
Identity · Identity protection
Updated Microsoft Defender documentation in defender-for-identity/migrate-from-ata-overview.md.
- Action Required: Defer Upgrade to Microsoft Defender for Endpoint on Linux Build 101.26052.0009
Defender XDR · Endpoint protection
The upgrade to Microsoft Defender for Endpoint on Linux build 101.26052.0009 for FIPS-enabled RHEL 8 and 9 devices has been paused due to issues. The message is now outdated and can be disregarded. No action is needed if already upgraded without problems.
- Email Authentication Arc Configure
Office 365 · Email and collaboration
Updated Microsoft Defender documentation in defender-office-365/email-authentication-arc-configure.md.
- MDO Encrypted email attachment protection
Defender XDR · Email and collaboration
Microsoft Defender for Office 365 will introduce an opt-in Safe Attachments policy to quarantine emails with password-protected attachments that cannot be scanned. Administrators can control release, users can self-release with passwords, and the feature supports various file types. Rollout begins August 2026 worldwide.
Review the linked Microsoft Learn changes that apply to your managed platforms, policies, applications, and rollout plans. The archive preserves the source diff for verification.
This period briefing was assembled from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Defender XDR
2 updatesThe upgrade to Microsoft Defender for Endpoint on Linux build 101.26052.0009 for FIPS-enabled RHEL 8 and 9 devices has been paused due to issues. The message is now outdated and can be disregarded. No action is needed if already upgraded without problems.
Microsoft Defender for Endpoint
1 updateGet Vulnerability By Id
UpdatedUpdated Microsoft Defender documentation in defender-endpoint/api/get-vulnerability-by-id.md.
Microsoft Defender for Office 365
2 updatesUpdated Microsoft Defender documentation in defender-office-365/tenant-allow-block-list-about.md.
Updated Microsoft Defender documentation in defender-office-365/email-authentication-arc-configure.md.
Microsoft Defender for Identity
1 updateUpdated Microsoft Defender documentation in defender-for-identity/migrate-from-ata-overview.md.
