2026-04
2026-04
This release tracker is LLM-curated and based on the official Microsoft product sources listed below. It provides an architect-grade summary of recent features, changes, and announcements. Always verify critical details against the official documentation. List of all raw markdown files for the releases are at https://github.com/pisinger/pisinger.github.io/tree/main/_ms_release_radar
Microsoft Security Release Radar - April 2026
π¦ Azure Container Apps
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π‘ | Defender for Cloud support for Azure Container Apps (Serverless Containers Posture) | Preview | Bring Azure Container Apps environments into Defender for Cloudβs Serverless Containers Posture experience for unified posture management. |
| π’ | Confidential Compute support on Azure Container Apps | GA | Run regulated containerized workloads with hardware-level isolation for data-in-use protection. |
| π’ | Monitor HTTP traffic in Azure Container Apps | GA | New ContainerAppHTTPLogs diagnostic setting category exposes detailed HTTP access logs for high-volume request data. |
| π’ | Additional OpenTelemetry destinations (New Relic, Dynatrace, Elastic) | GA | Enhanced OTel capabilities with expanded third-party observability platform endpoint options. |
| π’ | Override Scale Rules in Azure Functions on Azure Container Apps | GA | New allowScalingRuleOverride property lets customers override platform-managed KEDA scale rules. |
| π‘ | Azure Container Apps Sandboxes | Preview | Run untrusted code safely in sandboxed environments for agentic apps, multi-tenant platforms, and CI/CD systems. |
π§± Azure Container Instances
No updates for April 2026.
β΅ AKS
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π΄ | CVE-2026-31431: Linux kernel algif_aead local privilege escalation | Security | Lets a pod escalate to root on the underlying node. Affects Ubuntu 20.04 FIPS, 22.04, 24.04, and Azure Linux 3.0. Mitigation in node image versions 202604.13.0 and 202604.24.0. |
| π΄ | Ingress NGINX project retirement announced | Security | Maintenance ended March 2026. Production workloads supported through November 2026. Migrate to Gateway API implementation. |
| β« | AKS Kubernetes LTS version 1.29 deprecated | Deprecation | Upgrade clusters to a supported version. |
| β« | AKS Kubernetes version 1.32 moved to Long Term Support only | Deprecation | Use LTS support plan or upgrade to a supported standard-support version. |
| π‘ | AKS-managed NAT Gateway V2 preview | Preview | New outbound type in supported public Azure regions. |
| π‘ | Custom kube-reserved and hard eviction kubelet configuration preview | Preview | Customize default kubelet configuration through custom node preview feature. |
| π‘ | AKS List Available VM SKUs API preview | Preview | View VM SKUs supported on AKS and available in your subscription. |
| π‘ | AKS-managed GPU metrics in Azure Managed Prometheus | Preview | GPU metrics supported by default in Prometheus and Grafana dashboards. |
| π‘ | Capacity Based Surge for node pool upgrades | Preview | Set MaxUnavailable and MaxSurge values with fallback behavior for capacity constraints. |
| π’ | Gateway API-based ingress for application routing add-on | GA | Generally available alternative to Ingress NGINX. |
| π’ | AKS Automatic clusters can migrate to AKS Standard in additional regions | GA | Managed system node pools can now migrate after adding a system node pool. |
| π’ | spec.minReadySeconds in Application Routing Gateway ConfigMap | GA | Reduces disruption during rolling upgrades with extra initialization time. |
| π΄ | Istio CRD installer busybox registry fix | Security/Fix | Fixed issue where CRD installer could pull busybox from unintended registry in AGC environments. |
| π΄ | AKS Automatic ClusterRoleBinding protection | Security/Fix | Blocks privileged ClusterRoleBinding create/update to reduce privilege escalation risk via service account impersonation. |
| π΅ | Fixed empty PUT reconcile failures with CustomRouteTableInvalidUpdateAttempt | Fix | Resolved failures on clusters using bring-your-own route tables. |
| π΅ | Artifact Streaming + Pod Sandboxing validation | Fix | Added validation to prevent enabling unsupported combination. |
| β« | AKS 1.36 Automatic clusters preconfigured with Gateway API | Deprecation | New Automatic clusters will use Gateway API instead of Managed NGINX due to Ingress NGINX retirement. |
| β« | Mesh Membership requires Managed Gateway API add-on | Deprecation | Clusters must have Gateway API enabled before joining an Azure Kubernetes Application Network. |
| β« | HTTP Proxy Trusted CA limit of 20 certificates | Deprecation | Cannot add more than 20 Trusted CA certificates when using HTTP Proxy. |
| β« | kube-proxy reduced privileges for K8s 1.30+ | Deprecation | kube-proxy uses NET_ADMIN and SYS_RESOURCE capabilities instead of privileged: true. |
| β« | Fleet-managed resources via ClusterResourcePlacement | Deprecation | Fleet-managed resources deployed through managed namespace selection for separate rollout. |
| π΅ | Azure Policy add-on updated to 1.16.1 | Update | Gatekeeper updated to 3.20.1-8 with CVE fixes. |
| π΅ | Istio add-on revisions updated (asm-1-27, asm-1-28, asm-1-29) | Update | asm-1-29 available, asm-1-26 deprecated. |
| π΅ | Azure Monitor Container Insights updated to 3.3.0 | Update | Updated container monitoring agent. |
| π΅ | Node Auto Provisioning updated to Karpenter v1.10.2 | Update | Artifact Streaming uniformly disabled by default. |
| π΅ | Application Routing NGINX updated to 1.13.9 | Update | Updated NGINX ingress controller image. |
| π΅ | Azure Disk/File/Blob CSI drivers updated | Update | Multiple CSI driver versions updated across AKS versions. |
| π΅ | Cloud-provider-azure components updated | Update | April 2026 releases for cloud-controller-manager, cloud-node-manager, health-probe-proxy. |
| π΅ | Cilium updated to v1.17.10 | Update | Updated for K8s 1.32 and 1.33 to support Gateway API scenarios. |
β‘ Azure Functions
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π’ | Azure Functions support for Java 25 | GA | Develop and deploy apps using Java 25 on Linux and Windows, including Flex Consumption plan. |
| β« | Azure Functions runtime v3 on Linux Consumption stops September 30, 2026 | Deprecation | Function Apps using runtime v3 will stop functioning. Migrate to runtime v4 or Flex Consumption. |
| π’ | Azure Functions supports MCP resource triggers | GA | Expose resources directly from Functions-hosted MCP servers for Python, TypeScript, .NET, and Java. |
| β« | Python support on Azure Functions Windows retired March 31, 2027 | Deprecation | Python apps on Windows will stop running. Migrate to Linux before March 31, 2027. |
π Azure Logic Apps
No updates for April 2026.
π Azure Monitor
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π‘ | OTLP ingestion options for container monitoring | Preview | Published and reorganized OpenTelemetry public preview documentation for container monitoring. |
| π‘ | Service Level Indicators (SLIs) public preview | Preview | New article for Service Level Indicators public preview. |
| π‘ | Performance Diagnostics configurable threshold values | Preview | New configurable threshold values feature in public preview. |
| π’ | Azure Monitor pipeline GA updates | GA | GA updates across pipeline documentation including TLS setup, transformations, sizing, troubleshooting. |
| π’ | Reliability guide for Azure Monitor Logs | GA | Comprehensive guide covering availability zone protection, workspace replication, data export, DR recommendations. |
| β« | HTTP Data Collector API deprecation notices | Deprecation | Added deprecation notices with migration guidance to Logs Ingestion API. |
| β« | Application Insights Classic API retirement dates | Deprecation | Updated with explicit retirement dates for Node.js and .NET SDKs. |
| π΅ | Observability Agent documentation rewritten | Update | Four Copilot Observability Agent articles reorganized around common scenarios. |
| π΅ | App Center migration guidance updated | Update | Clearer support-request steps and revised retirement timeline. |
| π΅ | OpenTelemetry data collection guidance reorganized | Update | Task-based articles for data collection, resource detection, configuration, and enablement. |
| π΅ | Java configuration guidance consolidated | Update | JMX metrics, sampling overrides, and telemetry processors in one article. |
| π΅ | Connection strings guidance simplified | Update | Removed duplicate setup steps, points to main OTel configuration experience. |
| π΅ | Logs Ingestion API documentation updated | Update | Migration guidance, workspace overview, and DCR cross-references added. |
| π΅ | Summary rules documentation updated | Update | Thresholds corrected, parameter naming fixed, limitations section updated. |
| π΅ | REST API Index restructured | Update | APIs organized into Azure Monitor, Application Insights, and Logs sections. |
βοΈ Microsoft Defender Cloud Apps
No updates for April 2026.
π§ Microsoft Copilot Studio
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π’ | Hold and resume for voice-enabled agents | GA | Pause mid-conversation and resume for more natural calling experience. |
| π‘ | Real-time voice agents (Preview) | Preview | Build and deploy real-time voice agents with NLU, multilingual, knowledge integration, and voice tuning. |
| π’ | Automated agent evaluations via Power Automate connector | GA | Trigger agent evaluations automatically using Copilot Studio connector. |
| π‘ | Automated agent evaluations from REST API (Preview) | Preview | Integrate evaluation into CI/CD and custom automation pipelines via Power Platform API. |
| π’ | Agent usage estimator | GA | Forecast Copilot credit consumption before deploying at scale. |
| π‘ | Custom metrics for agent analytics (Preview) | Preview | Define custom analytics categories and visualize alongside built-in analytics. |
| π’ | Agent-to-agent (A2A) protocol connectivity | GA | Connect agents to other agents using the A2A protocol. |
| π‘ | Display name suffix for agents (Preview) | Preview | Identify agents across environments in Teams and M365 Copilot using environment variables. |
| π‘ | GPT-5.5 Reasoning (Deep) experimental model (Preview) | Preview | Experimental model for agents requiring deep analytical reasoning. |
| π’ | Analytics Viewer role | GA | Share analytics access without granting broader maker permissions. |
π¬ Defender Container Sensor
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π‘ | Sensor v0.10.4 β Preview | Preview | Upgraded Go and dependencies to address security vulnerabilities and improve runtime stability. |
| π‘ | Sensor v0.9.53 β Preview | Preview | Upgraded Go and dependencies to address security vulnerabilities and improve runtime stability. |
| π’ | Sensor v0.8.50 β GA | GA | Upgraded Go and dependencies to address security vulnerabilities and improve runtime stability. |
π¨ Microsoft Security Exposure Management
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π΅ | APIs with Sensitive Data classification rule | Update | New predefined Cloud resource classification for critical assets list identifying APIs containing sensitive data. |
π‘οΈ Microsoft Defender Cloud
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π’ | Defender for Containers runtime protection on EKS Bottlerocket | GA | Runtime protection now generally available for EKS Bottlerocket clusters. |
| π’ | Anti-malware detection and blocking | GA | Anti-malware detection and blocking is now generally available. |
| π’ | DNS Detection for Kubernetes | GA | DNS-based threat detection for Kubernetes is now generally available. |
| π’ | Defender for Storage integration in Azure portal Storage Center | GA | Integrated storage security in the Azure portal Storage Center experience. |
| π’ | Container security capabilities in Azure Government cloud | GA | Container security now available in Azure Government cloud. |
| π΅ | Defender for SQL servers on machines plan update for Fairfax | Update | Updated plan for Fairfax (US Government) customers. |
π‘οΈ Microsoft Defender Unified SecOps
No updates for April 2026.
π― Microsoft Defender XDR
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π‘ | View action status in Activities tab (Preview) | Preview | Track automatic attack disruption and predictive shielding action status per incident. |
| π‘ | AIAgentsInfo table expanded columns (Preview) | Preview | Deeper visibility into AI agents beyond Copilot Studio, including Foundry, third-party, and LOB agents. |
| π’ | Built-in alert tuning rules | GA | Suppress alerts from common benign activity in Defender for Endpoint and Defender for Office 365 without affecting AIR investigations. |
| π’ | Defender Experts navigation entry | GA | Dedicated Defender Experts entry in Defender portal navigation menu for consistent access. |
π Microsoft Defender Endpoint
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π‘ | Secure Boot 2023 certificate recommendation in Microsoft Secure Score | Preview | Identifies devices that havenβt transitioned to new Secure Boot 2023 certificates ahead of June 2026 expiration. |
| π‘ | View action status in Activities tab (Preview) | Preview | Track automatic attack disruption and predictive shielding action status for Contain user, GPO hardening, Safeboot hardening. |
| π’ | Linux build 101.26032.0000 | GA | Release version 30.126032.0000.0 with expanded kernel module visibility and offline intelligence update optimization. |
| π’ | macOS build 101.26032.0016 | GA | Release version 20.126032.16.0 with bug and performance fixes. |
| π’ | macOS build 4.18.25040.1 | GA | Native root detection for Microsoft Defender now GA. |
| π’ | Windows Antivirus Platform 4.18.26030.3011 / Engine 1.1.26030.3008 | GA | March 2026 Windows Antivirus release. |
| π’ | macOS build 101.26022.0020 | GA | Resolved performance regression causing degraded responsiveness under high load. |
| π’ | macOS build 101.26022.0018 | GA | Bug and performance fixes including CVE-2025-68664/5 LangGrinch fix. |
πΏ MDE Detailed Releases
Windows
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π΄ | CVE-2026-41091: Microsoft Defender Elevation of Privilege Vulnerability | Security/Fix | Improper link resolution before file access (Important). Fixed in Engine 1.1.26040.8. |
| π΄ | CVE-2026-45584: Microsoft Defender Remote Code Execution Vulnerability | Security/Fix | Heap-based buffer overflow (Critical). Fixed in Engine 1.1.26040.8. |
| π΄ | CVE-2026-45498: Microsoft Defender Denial of Service Vulnerability | Security/Fix | DoS vulnerability (Low). Fixed in Platform 4.18.26040.7. |
| π΅ | Performance improvement for SFC cache build during engine reload | Update | Optimized SFC cache build performance during engine reload. |
| π΅ | Reduced API calls for Device Control to prevent Entra throttling | Update | Reduced API calls and improved logging for Device Control. |
| π΅ | Improved TVM Block logic handling | Update | Enhanced TVM Block logic processing. |
| π΅ | Fixed TVM Warn temporary paths exclusion issue | Fix | Resolved issue when Tamper Protection Exclusions and DLAM are enabled. |
| π΅ | Fixed Defender managed type when migrating from Co-management to Intune | Fix | Corrected managed type handling during migration. |
macOS
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π’ | Native root detection for Microsoft Defender | GA | Native root detection for Microsoft Defender is now generally available. |
| π΅ | Bug and performance fixes (101.26032.0016) | Update | General bug and performance improvements. |
| π΅ | Performance improvement and bug fixes (4.18.25040.1) | Update | Performance improvements alongside root detection GA. |
| π΅ | Resolved performance regression under high load (101.26022.0020) | Fix | Fixed degraded responsiveness and stability under high load conditions. |
| π΄ | CVE-2025-68664/5 LangGrinch (langchain vulnerability) (101.26022.0018) | Security | Fixed langchain vulnerability. |
| π΅ | macOS >= 14 only packaging (101.26022.0018) | Update | Packaging now supports macOS 14 and later only. |
| π΅ | Bug and performance fixes (101.26022.0018) | Update | General bug and performance improvements. |
Linux
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π΅ | Expanded visibility into Linux kernel module (.ko) file activity | Update | Includes creation, rename, and deletion monitoring for kernel modules. |
| π΅ | Offline security intelligence update optimization | Update | Updates now run at most once per configured interval, reducing redundant downloads during service restarts. |
| π΅ | Resolved SELinux policy cleanup issue on RHEL-based systems | Fix | Ensures safe removal of legacy SELinux modules while preserving customer-defined policies during upgrades. |
π’ Microsoft Entra ID
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π’ | Microsoft Entra Agent ID platform | GA | Identity and authorization framework for AI agents with OAuth 2.0, MCP, and A2A protocol support. |
| π‘ | Account Discovery for connected applications (Preview) | Preview | Visibility into all accounts including orphan accounts within connected applications. Requires Entra ID Governance or Entra Suite license. |
| π‘ | Entra ID federation with External ID (EEID) (Preview) | Preview | Let users sign in to customer-facing apps using existing workforce Entra ID identities via standards-based federation. |
| π‘ | App-based branding via Branding themes (Preview) | Preview | Create different branding experiences for specific applications. |
| π΅ | Migrate from Entra Connect Sync to Entra Cloud Sync | Update | Beginning July 2026, phased transition notifications. Cloud Sync replaces Connect Sync for identity synchronization. |
| π΅ | SCIM provisioning apps to use modern authentication | Update | OAuth 2.0 Client Credentials and workload identity federation replacing Authorization Code grant. |
| π‘ | $count filtering in sign-ins API (Preview) | Preview | Perform count computations directly in sign-ins API requests. |
| π΅ | Workload identity-based auth for SAP SuccessFactors provisioning | Update | New authentication option starting May 2026 using Entra workload identity and short-lived tokens instead of static credentials. |
π Microsoft Fabric
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π‘ | Stream Mirrored Database change feeds into Eventstreams (Preview) | Preview | Stream Delta CDF row-level changes from mirrored databases into Eventstream for low-latency event-driven processing. |
| π‘ | Custom CA and mTLS support in Eventstream connectors (Preview) | Preview | Specify custom CA and client certificates from Azure Key Vault for Kafka-based sources and Schema Registry. |
| π’ | Eventstream SQL operator | GA | Production-ready code-first transformation operator with multiple destinations and event-time processing. |
| π‘ | Customer Managed Keys (CMK) for Eventhouse (Preview) | Preview | Bring your own Azure Key Vault key to encrypt Eventhouse data at rest. |
| π΅ | Stream SQL Change Events to Fabric Eventstream | Update | SQL Server 2025, Azure SQL DB, and Azure SQL MI push CloudEvents-formatted changes directly into Eventstream. |
| π‘ | Eventstream workspace monitoring (Preview) | Preview | Automatic Eventhouse tables for per-minute data volume, watermark delay, backlog, and error metrics. |
ποΈ Microsoft Foundry
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π’ | Foundry Local model inference | GA | Production-ready local model inference on Windows, macOS Apple Silicon, and Linux x64. |
| π’ | GPT-5.5 model available | GA | Latest GPT-5 family model with default quota for Tier 5 and Tier 6 subscriptions. |
| π‘ | Microsoft Agent Framework tracing (Preview) | Preview | Agent Framework agents emit OpenTelemetry traces into Foundry for debugging and production observability. |
| π‘ | Hosted-agent tracing (Preview) | Preview | Hosted-agent sessions, tool calls, and run steps surface in Foundry traces. |
| π‘ | CodeAct with Hyperlight (alpha) | Preview | Sandboxed Python code execution in Hyperlight micro-VMs for low-risk tool chains. |
| π‘ | Continuous evaluation custom evaluators (Preview) | Preview | Bring code-based or prompt-based evaluators into continuous evaluation. |
| π‘ | Agent Monitoring Dashboard (Preview) | Preview | Track operational metrics and evaluation results including token usage, latency, success rate, and evaluator scores. |
| π’ | Agent inventory in Foundry Control Plane | GA | Find supported agents across subscription from Operate view. |
| π‘ | GPT-image-2 (Preview) | Preview | OpenAIβs latest image generation model with 4K resolution, editing, and up to 10 images per request. |
| π‘ | Microsoft first-party AI models (Preview) | Preview | MAI-Image-2, MAI-Image-2-Efficient, MAI-Voice-1, and MAI-Transcribe-1. |
| π’ | Gemma 4 in Foundry catalog | GA | Google DeepMindβs open-weight models with multimodal input and up to 256K context. |
| π’ | Claude Opus 4.7 | GA | Anthropicβs most capable GA model with stronger instruction following and improved vision. |
| π’ | Microsoft Agent Framework 1.0 | GA | Unified multi-agent orchestration SDK for .NET and Python reaches GA. |
| π’ | Foundry Toolkit for VS Code | GA | Model playground, agent builder, and one-click deploy. |
| π‘ | Batch evaluations for third-party agents (Preview) | Preview | Cloud-based batch evaluations against agents built on any framework. |
| π‘ | Audio and image input in score model grader (Preview) | Preview | Evaluation graders accept audio and image content alongside text. |
| π’ | Notification center | GA | Tenant-level notifications with email delivery for critical alerts. |
| π΅ | SDK & language updates | Update | Python/JS/TS beta agents, .NET 2.0 GA, Java streaming fix. |
π Microsoft Defender Identity
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π‘ | Identity Explorer (Preview) | Preview | Visualize identity attack paths and exposure scenarios as interactive graphs using hunting graph. Requires Sentinel Data Lake license. |
| π‘ | Custom account correlation rules (Preview) | Preview | Link accounts belonging to the same identity using UPN prefix, suffix, or domain rules. |
| π’ | Automatic Windows event auditing configuration for sensors v3.x | GA | Streamlines deployment by automatically applying required auditing settings to new sensors and correcting misconfigurations. |
π± Microsoft Intune
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π΅ | Multi Admin Approval enforces on API calls by automation | Update | MAA now applies to Microsoft Graph API calls by service principals and automation scripts. HTTP 403 if approval headers missing. |
| π΅ | EPM support approved elevation requests from all device users | Update | Expanded from primary user/enroller to all users of a device, improving shared device scenarios. |
| π΅ | Configure credential manager permissions for Android Enterprise | Update | Control which apps act as system-level credential providers on Android 14+ managed devices. |
| π΅ | Block location setting for Android Enterprise with three options | Update | Location setting now has Device default, Location enabled, and Location disabled options. |
| π΅ | Access management for Apple services | Update | Configure service access for Apple accounts on organization-owned devices via ABM/ASM. |
| π΅ | Userless ADE for visionOS and tvOS devices | Update | Enroll and manage Apple Vision Pro and Apple TV through ABM/ASM without user affinity. |
| π΅ | Support for Ubuntu 26.04 LTS | Update | Ubuntu 22.04 LTS support ends August 2026. |
| π‘ | Preview new device page in Intune admin center | Preview | Redesigned single device view with Device action status, Tools and reports, Properties, and Device details tabs. |
| π΅ | Suspend and restore Managed Home Screen remote actions | Update | Temporarily suspend MHS on Android devices without removing policies or requiring PIN. |
| π΅ | Updated minimum Intune Management Extension version (1.58.103.0) | Update | Devices on earlier versions no longer receive configurations or updates. |
| π΅ | Autopatch update risk visibility report | Update | Classifies devices as Current, Exposed, or Critical with granular patch compliance insight. |
| π΅ | Microsoft Edge v139 security baseline | Update | New settings, updated defaults, and retired settings. Existing profiles donβt auto-update. |
| π΅ | Direct Android LOB app management | Update | Upload APK files directly to Intune without publishing to Managed Google Play for COBO and COSU devices. |
| π΅ | New protected apps: Harvey AI, Continia Expense App | Update | Newly available protected apps for Intune. |
| π‘ | Change Review Agent suggestions in Multi Admin Approval (Preview) | Preview | Risk-based recommendations for Windows PowerShell scripts directly in MAA experience. |
| π΅ | Compliance policy reporting guidance | Update | Clarified reporting behavior for device check-in timing and user association. |
| β« | Intune Data Warehouse (beta) connector retirement in Power BI | Deprecation | Transition to connector v2 or OData Feed connector. Transition starts April 20, 2026. |
| π΅ | Support for Android XR devices | Update | Manage Android XR devices using Android Enterprise dedicated and fully managed enrollment modes. |
| π΅ | New TeamViewer connector experience | Update | Replaces existing connector. Must migrate within 12 months to maintain functionality. |
π§ Microsoft Defender Office 365
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π‘ | Promotions folder for bulk email (Preview) | Preview | Configure anti-spam policies to deliver bulk mail below BCL threshold to Promotions folder in supported Outlook versions. |
| π’ | Security Copilot email summary on Email entity page | GA | Generate AI summary of email entity data directly from Email entity page with Security Copilot subscription. |
| π’ | Remove users from Teams chats | GA | Remove internal users from Teams chats in Teams message entity panel is now generally available. |
| π’ | New RBAC permission for email content associated with alerts | GA | Granular Unified RBAC permission for analysts to preview/download email messages associated with security alerts. |
π Microsoft Purview
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π‘ | Collection policies support sensitivity labels as condition (Preview) | Preview | Scope detection to items with specific sensitivity labels for browser and network cloud apps. |
| π΅ | Teams call logs retention policies | Update | New PowerShell-based retention policies for Teams call data records separate from chat retention. |
| π‘ | Glossary migration and asset enablement (Preview) | Preview | One-time process to migrate glossary terms into Unified Catalog for centralized management. |
| π‘ | Bulk import/edit/move for Unified Catalog (Preview) | Preview | Bulk create data products, critical data elements, glossary terms, and move terms between governance domains. |
| π’ | Advanced resource sets | GA | Now available to all customers with pricing consistent with classic data governance rates. |
| π‘ | Data quality on-premises support for Oracle and SQL Server (Preview) | Preview | On-premises database scanning via Kubernetes-hosted runtime without data leaving premises. |
| π‘ | Data quality thresholds with alerts (Preview) | Preview | Configure alerts for rule-level and data asset-level thresholds. |
| π‘ | DLP URL contains text condition for unmanaged cloud apps (Preview) | Preview | Scope DLP rules to specific URLs or exclude URLs from policy enforcement. |
| π‘ | Email notifications for browser and network DLP (Preview) | Preview | End-user email notifications with 10-minute batching window when activity is blocked. |
| π‘ | DLP policy tip reference for Outlook mobile and macOS (Preview) | Preview | Reference article for DLP policy tips on Android, iOS, and macOS Outlook. |
| π‘ | Proactive AI insights from DSPM (Preview) | Preview | Auto-creates and refreshes investigation every 24 hours with exfiltration risk counts across five categories. |
| π΅ | Data Security Investigation Contributor role | Update | Auto-provides access to Compliance Administrator, Organization Management, Data Security Management, and Insider Risk Management role groups. |
| π‘ | Sentinel with partner solutions for Varonis (Preview) | Preview | DSPM now supports Varonis for holistic Salesforce data insights. |
| π‘ | CMK encryption for eDiscovery direct exports (Preview) | Preview | Customer-managed key encryption for exported investigation data at rest. |
| π΅ | eDiscovery review set limit increased to 100 | Update | Maximum review sets per case increased from 20 to 100. |
| π‘ | Advanced review set explorer (Preview) | Preview | New left navigation pane, KQL operators, sample queries, and Getting started tab. |
| π‘ | Preview content while triaging Insider Risk alerts (Preview) | Preview | Identify false positives and confirm sensitive data presence before escalation. |
| π’ | Auto-labeling policies with label override for files | GA | Option to always override lower-priority labels even if manually applied, now extended to SharePoint and OneDrive files. |
| π’ | Sensitivity labels for user-defined permissions in Office for the web | GA | Apply labels configured for user-defined permissions while using Office for the web. |
| π΅ | Label policies Export to CSV/Zip | Update | Export policy configuration for sensitivity labels and DLP policies. |
| π’ | Export policy configuration as ZIP | GA | Point-in-time snapshot of all DLP and sensitivity label publishing policies in XML format. |
π€ Microsoft Security Copilot
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π‘ | Security Analyst Agent (Public Preview) | Preview | Deep multi-step investigations across Defender and Sentinel telemetry to surface high-impact risks with prioritized insights and evidence. |
π Microsoft Sentinel
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π΅ | Account Name now consistently UPN prefix for analytics rule alerts | Update | Update automation by July 1, 2026. Account Name will always be UPN prefix only. New UPN-related fields added. |
| π‘ | Microsoft Sentinel data federation (Preview) | Preview | Analyze security data in-place from Fabric, ADLS, and Databricks without copying, using KQL, notebooks, and custom graphs. |
| π‘ | Transform data with filter and split features (Preview) | Preview | Reduce noise before ingestion, control costs, and route data between analytics and data lake tiers. |
| π‘ | VS Code connector builder agent (Preview) | Preview | AI-powered low-code agent to build Sentinel connectors in minutes. |
| π‘ | Build custom security graphs (Preview) | Preview | Tailored graphs across Sentinel data lake and third-party data to uncover attack paths and blast radius. |
| π’ | Entity analyzer | GA | Out-of-the-box explainable entity risk assessments for URLs and identities. Charged for SCUs starting April 1, 2026. |
| π’ | AI-powered SIEM migration tool | GA | Accelerate migrations from Splunk and QRadar with AI-assisted experience. |
| π‘ | Cost estimation tool (Preview) | Preview | Guided meter-level cost estimator with three-year projections for data growth and spend planning. |
| π‘ | Row-level access using Sentinel scoping (Preview) | Preview | Row-level RBAC to control data access without workspace separation. |
Top 5 Action Items
| Priority | Action | Due | Affected Product(s) |
|---|---|---|---|
| π΄ | Apply AKS node image upgrade to versions 202604.13.0+ to mitigate CVE-2026-31431 (Linux kernel LPE) | Immediate | AKS |
| π΄ | Apply Windows Defender Antivirus Engine 1.1.26040.8 to fix CVE-2026-45584 (Critical RCE) and CVE-2026-41091 (Important EoP) | Immediate | Defender Endpoint |
| π΄ | Migrate from Ingress NGINX to Gateway API-based ingress before November 2026 | November 2026 | AKS |
| π΄ | Update Sentinel automation rules and Logic Apps to use UPN prefix/suffix instead of full UPN for Account Name | July 1, 2026 | Sentinel |
| π΄ | Migrate Azure Functions runtime v3 on Linux Consumption to v4 or Flex Consumption | September 30, 2026 | Azure Functions |
Security Architect Observations
- AKS CVE-2026-31431 (algif_aead LPE) is the highest-severity item this month β any pod (including non-root, no special capabilities) can escalate to node root. Existing nodes are not patched in-place; node image upgrade or DaemonSet mitigation is required. Combined with the Ingress NGINX retirement, AKS tenants face two concurrent migration pressures that should be sequenced carefully.
- Three CVEs in Microsoft Defender Antivirus (one Critical RCE CVE-2026-45584, one Important EoP CVE-2026-41091, one Low DoS CVE-2026-45498) require immediate engine/platform updates. The heap-based buffer overflow (RCE) is particularly concerning for environments where Defender processes untrusted files.
- Entra Connect Sync to Cloud Sync migration begins July 2026 with phased notifications. Organizations with complex sync configurations (large directories, advanced features) will be in later waves, but should begin readiness assessment now. The SCIM modern auth and SAP SuccessFactors workload identity changes add to the identity modernization roadmap.
- Sentinel Account Name consistency change (UPN prefix only by July 1) will break automation rules and playbooks that use full UPN equality checks. This requires a systematic audit of all downstream automation before the deadline.
- Purview auto-labeling with override now extends to SharePoint and OneDrive files, enabling mandatory label application even over manually applied lower-priority labels. Review existing label policies to prevent unintended overrides in sensitive data environments.
Security Operations Observations
- Defender XDR built-in alert tuning rules (GA) reduce noise from common benign activity in Defender for Endpoint and Office 365 without affecting AIR investigations β review and enable to improve SOC efficiency.
- Security Analyst Agent in Security Copilot (Preview) performs multi-step investigations across Defender and Sentinel β evaluate for Tier 1 triage automation to reduce mean-time-to-respond.
- Defender for Identity Identity Explorer (Preview) provides interactive attack path visualization β useful for proactive lateral movement and privilege escalation discovery, but requires Sentinel Data Lake license.
- MDE Linux kernel module visibility expanded to include creation, rename, and deletion events β update detection rules to cover kernel module file activity as a potential rootkit or persistence indicator.
- Purview DSPM proactive AI insights auto-generate daily investigations with exfiltration risk counts β integrate into existing data security monitoring workflows for continuous sensitive data exposure visibility.
- Intune Multi Admin Approval now applies to API automation β service principals and scripts modifying Intune resources will get HTTP 403 without approval headers. Update automation scripts or use the Exclusions tab to prevent operational disruption.
References
This post is licensed under CC BY 4.0 by the author.