Post

2026-04

2026-04

This release tracker is LLM-curated and based on the official Microsoft product sources listed below. It provides an architect-grade summary of recent features, changes, and announcements. Always verify critical details against the official documentation. List of all raw markdown files for the releases are at https://github.com/pisinger/pisinger.github.io/tree/main/_ms_release_radar

Microsoft Security Release Radar - April 2026


πŸ“¦ Azure Container Apps

IndicatorFeatureTypeDescription
🟑Defender for Cloud support for Azure Container Apps (Serverless Containers Posture)PreviewExtends posture management to Azure Container Apps environments from a single Defender for Cloud workflow.
🟒Confidential Compute support on Azure Container AppsGARun regulated/sensitive containerized workloads with hardware-level isolation for data in use.
🟒Monitor HTTP traffic in Azure Container AppsGANew ContainerAppHTTPLogs diagnostic setting category exposes detailed HTTP access logs for high-volume request data via Azure Monitor.
🟒Additional OpenTelemetry destinations (New Relic, Dynatrace, Elastic)GAExpands OTel third-party observability platform support with new endpoint options.
🟒Override Scale Rules in Azure Functions on Azure Container AppsGANew allowScalingRuleOverride property lets customers override platform-managed KEDA scale rules.
🟑Azure Container Apps SandboxesPreviewRun untrusted code safely with session-level isolation, state preservation, and burst handling for agentic/multi-tenant/CI-CD workloads.
πŸ”΅AI & Serverless GPU Workloads (ComfyUI, Gemma 4 + Ollama)UpdateNew blog patterns for running multimedia AI and self-hosted LLMs on ACA with serverless GPUs (T4/A100), scale-to-zero, and per-second billing.

β›΅ AKS

IndicatorFeatureTypeDescription
πŸ”΄CVE-2026-31431: Linux kernel algif_aead local privilege escalationSecurityLets a pod escalate to root on the underlying node. Affects Ubuntu 20.04 FIPS, 22.04, 24.04, and Azure Linux 3.0. Mitigation in node images 202604.13.0 and 202604.24.0.
πŸ”΄Ingress NGINX project retirement β€” migrate to Gateway APISecurityUpstream Ingress NGINX maintenance ended March 2026. Production workloads supported through Nov 2026 on application routing add-on. Migrate to Gateway API implementation.
⚫AKS Kubernetes LTS version 1.29 deprecatedDeprecationUpgrade clusters to a supported version.
⚫AKS Kubernetes version 1.32 moved to LTS-onlyDeprecationUse LTS support plan or upgrade to standard-support version.
⚫AKS Automatic clusters to preconfigure with Gateway API (starting 1.36)DeprecationManaged NGINX ingress replaced by Kubernetes Gateway API due to upstream Ingress NGINX retirement.
⚫Istio add-on revision asm-1-26 deprecatedDeprecationUpgrade to asm-1-27, asm-1-28, or asm-1-29.
🟑AKS-managed NAT Gateway V2 outbound typePreviewPreview support for StandardV2 NAT Gateway in supported public Azure regions.
🟑Custom kube-reserved and hard eviction kubelet configurationPreviewCustomize default kubelet configuration through custom node preview feature registration.
🟑AKS List Available VM SKUs APIPreviewView VM SKUs supported on AKS and available in subscription.
🟑AKS-managed GPU metrics in Azure Managed PrometheusPreviewGPU metrics supported by default in Azure Managed Prometheus and Grafana dashboards.
🟑Capacity Based Surge for node pool upgradesPreviewSet MaxUnavailable and MaxSurge values; falls back to in-place upgrade if surge capacity unavailable.
🟒Gateway API-based ingress for application routing add-onGAGenerally available; replaces Ingress NGINX for new AKS Automatic clusters on 1.36+.
🟒AKS Automatic clusters can migrate to Standard in additional regionsGAManaged system node pools can now migrate to AKS Standard clusters.
🟒spec.minReadySeconds in Application Routing Gateway ConfigMapGAHelps applications needing extra initialization time after health check.
πŸ”΄Istio CRD installer busybox registry fixSecurity/FixFixed issue where CRD installer could pull busybox from unintended registry in AGC environments.
πŸ”΄ClusterRoleBinding protection for AKS Automatic managed system node poolsSecurity/FixBlocks ClusterRoleBinding create/update when roleRef targets privileged ClusterRoles, reducing privilege escalation risk.
πŸ”΅New Kubernetes patch versions: 1.35.2, 1.35.3, 1.34.5, 1.34.6, 1.33.9, 1.33.10UpdateNew patch versions available for standard support.
πŸ”΅Azure Policy add-on updated to 1.16.1 (Gatekeeper 3.20.1-8)UpdateIncludes CVE fixes.
πŸ”΅Istio add-on revisions updated (asm-1-27 to 1.27.9-2, asm-1-28 to 1.28.6-1, asm-1-29 to 1.29.2-1)UpdatePatch version upgrades for Istio service mesh.
πŸ”΅Azure Monitor Container Insights updated to 3.3.0UpdateUpdated container monitoring agent.
πŸ”΅Node Auto Provisioning updated to Karpenter Azure v1.10.2UpdateArtifact Streaming uniformly disabled by default.
πŸ”΅Application Routing NGINX updated to 1.13.9UpdateNGINX image version update.
πŸ”΅Azure Disk CSI driver updated (v1.34.3 / v1.33.9)UpdateCSI driver updates per AKS version.
πŸ”΅Azure File CSI driver updated (v1.35.2 / v1.34.5 / v1.33.9)UpdateCSI driver updates per AKS version.
πŸ”΅Azure Blob CSI driver updated (v1.27.4 / v1.26.11)UpdateCSI driver updates per AKS version.
πŸ”΅Cloud-provider-azure components updated (v1.32.16, v1.33.11, v1.34.8, v1.35.3)UpdateApril 2026 releases for cloud-controller-manager, cloud-node-manager, health-probe-proxy.
πŸ”΅Cilium updated to v1.17.10UpdateUpdated for Kubernetes 1.32 and 1.33 to support Gateway API scenarios.
πŸ”΅kube-proxy reduced privileges (K8s 1.30+)UpdateUses NET_ADMIN and SYS_RESOURCE capabilities instead of privileged: true.
πŸ”΅Fleet-managed resources via ClusterResourcePlacementUpdateManaged namespace selection for separate rollout from customer workloads.
πŸ”΅HTTP Proxy: max 20 Trusted CA certificatesUpdateNew limitation enforced.
πŸ”΅Mesh Membership requires Managed Gateway API add-onUpdateRequired for joining Azure Kubernetes Application Network.

πŸ“Š Azure Monitor

IndicatorFeatureTypeDescription
🟑OTLP ingestion options for container monitoringPreviewPublished documentation for ingesting OTLP data with AMA, AKS autoinstrumentation for Python/.NET, and OpenTelemetry protocol ingestion.
🟑Service Level Indicators (SLIs)PreviewNew article for creating and managing SLIs in Azure Monitor.
🟑Performance Diagnostics configurable threshold valuesPreviewNew configurable threshold feature for VM Performance Diagnostics.
🟒Azure Monitor pipeline GA updatesGATLS setup, transformations, sizing, troubleshooting, and Kubernetes gateway guidance published.
🟒Reliability guide for Azure Monitor LogsGAComprehensive guide covering AZ protection, workspace replication, data export, and DR recommendations.
⚫HTTP Data Collector API deprecation noticesDeprecationLogs Ingestion API overview updated with deprecation notices and migration guidance for the replacement API.
⚫Application Insights Classic API retirement datesDeprecationUpdated with explicit retirement dates for Node.js and .NET SDKs; migration to OpenTelemetry recommended.
πŸ”΅Observability agent documentation rewrittenUpdateFour Azure Copilot observability agent articles reorganized around common scenarios.
πŸ”΅Syslog troubleshooting for Linux AMAUpdateNew diagnostic section for syslog upload failures on Linux.
πŸ”΅App Center migration guidance updatedUpdateClearer support-request steps and revised retirement timeline.
πŸ”΅OpenTelemetry guidance reorganizedUpdateApplication Insights OTel guidance restructured into task-based articles.
πŸ”΅Java configuration consolidatedUpdateJMX metrics, sampling overrides, and telemetry processors in one article.
πŸ”΅Summary rules updatedUpdateThresholds corrected, parameter naming fixed, PowerShell syntax errors fixed.
πŸ”΅Logs Ingestion API prerequisites updatedUpdateGet-AzAccessToken code sample updated for SecureString breaking change.

☁️ Microsoft Defender Cloud Apps

No April 2026 updates found.


🧠 Microsoft Copilot Studio

IndicatorFeatureTypeDescription
🟒Agent-to-agent (A2A) protocolGAConnect agents to other agents using the A2A protocol.
🟑Real-time voice agentsPreviewBuild and deploy real-time voice agents with NLU, multilingual support, knowledge integration, and voice tuning.
🟑Automated agent evaluations from REST APIPreviewRun evaluations via Power Platform API for CI/CD and custom automation pipelines.
🟑Custom metrics for agent analyticsPreviewDefine custom analytics categories and visualize alongside built-in analytics.
🟑Display name suffix for agentsPreviewIdentify agents across environments in Teams and M365 Copilot using environment variables.
🟑GPT-5.5 Reasoning (Deep) experimental modelPreviewExperimental model for agents requiring deep analytical reasoning.
🟑Analytics Viewer rolePreviewShare analytics access without granting broader maker permissions.
πŸ”΅Hold and resume for voice-enabled agentsUpdatePause mid-conversation and resume where left off for natural calling experience.
πŸ”΅Trigger agent evaluations with Power Automate connectorUpdateAutomate evaluations using Copilot Studio connector, reducing manual effort.
πŸ”΅Agent usage estimatorUpdateForecast Copilot credit consumption before deploying at scale.

πŸ”¬ Defender Container Sensor

IndicatorFeatureTypeDescription
🟑Sensor v0.10.4 β€” Go dependency upgradesPreviewUpgraded Go and related dependencies to address security vulnerabilities and improve runtime stability.
🟑Sensor v0.9.53 β€” Go dependency upgradesPreviewUpgraded Go and related dependencies to address security vulnerabilities and improve runtime stability.
🟒Sensor v0.8.50 β€” Go dependency upgradesGAUpgraded Go and related dependencies to address security vulnerabilities and improve runtime stability.

🚨 Microsoft Defender XSPM (Exposure Management)

IndicatorFeatureTypeDescription
πŸ”΅New predefined classification: APIs with Sensitive DataUpdateNew Cloud resource classification rule added to critical assets list for APIs containing sensitive data.

πŸ›‘οΈ Microsoft Defender Cloud

IndicatorFeatureTypeDescription
🟒Defender for Containers runtime protection on EKS BottlerocketGARuntime protection now supports AWS Bottlerocket OS on EKS.
🟒Anti-malware detection and blockingGAAnti-malware detection and blocking is now generally available.
🟒DNS Detection for KubernetesGADNS-based threat detection for Kubernetes is now generally available.
🟒Defender for Storage integration in Azure portal Storage CenterGAIntegrated storage security in Azure portal Storage Center.
🟒Container security capabilities in Azure Government cloudGAContainer security now available in Azure Government cloud.
πŸ”΅Defender for SQL servers on machines plan update for FairfaxUpdateUpdated plan for Fairfax (US Government) customers.

πŸ›‘οΈ Microsoft Defender Unified SecOps

No April 2026 updates found.


🎯 Microsoft Defender XDR

IndicatorFeatureTypeDescription
🟑View action status in Activities tab (Preview)PreviewTrack automatic attack disruption and predictive shielding action status per incident.
🟑AIAgentsInfo table expanded columnsPreviewDeeper visibility into AI agents (Copilot Studio, Foundry, third-party, custom LOB agents) in advanced hunting.
🟒Built-in alert tuning rulesGASuppress alerts from common benign activity in Defender for Endpoint and Defender for Office 365 without affecting AIR investigations.
🟒Defender Experts in navigation menuGADefender Experts for XDR now appears as a distinct entry in the Defender portal navigation menu.

πŸ†” Microsoft Defender Identity

IndicatorFeatureTypeDescription
🟑Identity Explorer (Preview)PreviewVisualize identity attack paths and exposure scenarios as interactive graphs using hunting graph. Requires Sentinel Data Lake license.
🟑Custom account correlation rules (Preview)PreviewLink accounts belonging to the same identity using UPN prefix, suffix, or domain rules.
🟒Automatic Windows event auditing configuration for sensors v3.xGAAutomatically applies required auditing settings to new sensors and corrects misconfigurations on existing ones.

πŸ“§ Microsoft Defender Office 365

IndicatorFeatureTypeDescription
🟑Promotions folder for bulk emailPreviewConfigure anti-spam policies to deliver bulk mail below BCL threshold to Promotions folder in supported Outlook versions.
🟒Security Copilot email summary on Email entity pageGAGenerate AI summary of email entity data from the Email entity page.
🟒Remove users from Teams chatsGARemove internal users from Teams chats in the Teams message entity panel.
🟒New RBAC permission for email content associated with alertsGAGranular Unified RBAC permission to preview/download email messages associated with security alerts.

🏒 Microsoft Entra ID

IndicatorFeatureTypeDescription
🟒Microsoft Entra Agent ID platformGAIdentity and authorization framework for AI agents with OAuth 2.0, MCP, and A2A protocol support.
🟑Account Discovery for connected applicationsPreviewVisibility into all accounts in connected applications including orphan accounts; requires ID Governance or Entra Suite license.
🟑Entra ID federation with External ID (EEID)PreviewStandards-based federation for workforce-to-customer sign-in scenarios.
🟑App-based branding via Branding themesPreviewCreate different branding experiences for specific applications.
🟑$count filtering in sign-ins APIPreviewPerform count computations directly in Microsoft Graph sign-ins API requests.
πŸ”΅Migrate from Entra Connect Sync to Entra Cloud SyncUpdateTransition beginning July 2026; phased rollout with tailored guidance. Cloud Sync replaces Connect Sync for identity synchronization.
πŸ”΅SCIM provisioning apps to use modern authenticationUpdateOAuth 2.0 Authorization Code grant replaced with Client Credentials and workload identity federation.
πŸ”΅SAP SuccessFactors: switch from basic auth to workload identityUpdateNew authentication option available May 2026; SAP plans to deprecate basic auth by November 2026.

πŸ“Š Microsoft Fabric

IndicatorFeatureTypeDescription
🟑Stream Mirrored Database change feeds into EventstreamsPreviewStream Delta CDF row-level changes from mirrored databases into Fabric Eventstream for low-latency event-driven processing.
🟑Custom CA and mTLS support in Eventstream connectorsPreviewSpecify custom CA and client certificates from Azure Key Vault for Kafka-based sources and Confluent Schema Registry.
🟑Customer Managed Keys (CMK) for EventhousePreviewBring your own Azure Key Vault key to encrypt Eventhouse data at rest.
🟑Eventstream workspace monitoringPreviewAutomatic creation of Eventhouse tables for per-minute data volume, watermark delay, backlog, and error metrics.
🟒Eventstream SQL operatorGAProduction-ready code-first transformation operator with multiple destinations and event-time processing.
πŸ”΅Stream SQL Change Events to Fabric EventstreamUpdateSQL Server 2025, Azure SQL DB, and Azure SQL MI push CloudEvents-formatted changes directly into Eventstream.

πŸ—οΈ Microsoft Foundry

IndicatorFeatureTypeDescription
🟒Foundry LocalGALocal model inference production-ready on Windows, macOS (Apple Silicon), and Linux x64.
🟒Microsoft Agent Framework 1.0GAUnified multi-agent orchestration SDK for .NET and Python.
🟒Microsoft Foundry Toolkit for VS CodeGAModel playground, agent builder, and one-click deploy.
🟒Notification centerGATenant-level notifications with email delivery for critical alerts.
🟒Claude Opus 4.7GAAnthropic’s most capable model available in Foundry.
🟑Agent Framework tracing (OpenTelemetry)PreviewAgent Framework agents emit OpenTelemetry traces into Foundry for debugging and production observability.
🟑Hosted-agent tracingPreviewHosted-agent sessions, tool calls, and run steps surface in Foundry traces.
🟑CodeAct with Hyperlight (alpha)PreviewSandboxed Python code execution in Hyperlight micro-VMs for low-risk tool chains.
🟑Continuous evaluation custom evaluatorsPreviewBring code-based or prompt-based evaluators into continuous evaluation.
🟑Agent Monitoring DashboardPreviewTrack operational metrics and evaluation results (token usage, latency, success rate, evaluator scores).
🟑GPT-image-2PreviewOpenAI’s latest image generation model with 4K resolution, editing, and up to 10 images per request.
🟑Microsoft first-party AI models (MAI-Image-2, MAI-Voice-1, MAI-Transcribe-1)PreviewImage generation, text-to-speech, and speech recognition models.
🟑Batch evaluations for third-party agentsPreviewCloud-based batch evaluations against agents built on any framework.
🟑Audio and image input in score model graderPreviewEvaluation graders accept audio and image content alongside text.
🟒GPT-5.5GALatest GPT-5 family model with default quota for Tier 5 and Tier 6 subscriptions.
🟒Gemma 4GAGoogle DeepMind’s open-weight models with multimodal input and up to 256K context.
🟒Agent inventory in Foundry Control PlaneGAFind supported agents across subscription from Operate view.

πŸ”Ž Microsoft Purview

IndicatorFeatureTypeDescription
🟑Collection policies: sensitivity labels as conditionPreviewScope detection to items with specific sensitivity labels for browser and network cloud apps detection.
🟑Glossary migration and asset enablementPreviewOne-time migration of glossary terms into Unified Catalog for centralized management.
🟑Bulk import/edit/move in Unified CatalogPreviewBulk create data products, critical data elements, glossary terms; bulk edit and move between governance domains.
🟑Data quality: on-premises Oracle and SQL Server supportPreviewOn-premises database scanning via Kubernetes-hosted runtime; data stays on premises.
🟑Data quality thresholds with alertsPreviewConfigure alerts for rule-level and data asset-level thresholds.
🟑Unsaved file protection (JIT)PreviewExtends just-in-time DLP protection to brand-new files and files with unsaved modifications.
🟑DLP: URL contains text condition for unmanaged cloud appsPreviewScope DLP rules to specific URLs or exclude URLs from policy enforcement.
🟑Email notifications for browser and network DLPPreviewNotify end users via email when activity is blocked; 10-minute batching window.
🟑DLP policy tip reference for Outlook mobile/macOSPreviewNew reference article for DLP policy tips on Android, iOS, and macOS Outlook.
🟑Proactive AI insights from DSPMPreviewAutomatic 24-hour investigation refresh with DSPM exfiltration objective card across five risk categories.
🟑Customer-managed key encryption for eDiscovery exportsPreviewCMK encryption for direct export packages in eDiscovery.
🟑Advanced review set explorer with left navigationPreviewBrowse review set schema, insert KQL operators, run sample queries with new Getting Started tab.
🟑Preview content while triaging Insider Risk alertsPreviewPreview content to identify false positives and confirm sensitive data before escalation.
🟒Advanced resource setsGAAvailable to all customers with consistent pricing.
🟒Auto-labeling policies: override lower-priority labelsGAOption to always override existing lower-priority labels for SharePoint/OneDrive files.
🟒Export policy configuration as ZIPGAPoint-in-time snapshot of DLP and sensitivity label publishing policies in XML format.
πŸ”΅Teams call logs retention policiesUpdateNew PowerShell-based retention policies for Teams call data records, separate from chat retention.
πŸ”΅Sensitivity labels for user-defined permissions in Office for webUpdateUsers can apply labels configured for user-defined permissions in Office for the web (requires co-authoring).
πŸ”΅Export policies option on Label policies pageUpdateExport to CSV or ZIP with detailed policy and label information.
πŸ”΅Data Security Investigation Contributor roleUpdateAutomatic access for Compliance Administrator, Organization Management, Data Security Management, and Insider Risk Management role groups.
πŸ”΅Microsoft Sentinel with Varonis for Salesforce data insightsUpdatePartner solution integration for holistic data insights.
πŸ”΅eDiscovery: max review sets per case increased to 100UpdateIncreased from 20 to 100 for eDiscovery with premium feature support.

πŸ€– Microsoft Security Copilot

IndicatorFeatureTypeDescription
🟑Security Analyst AgentPreviewDeep multi-step investigations across Defender and Sentinel telemetry; surfaces prioritized risks with reasoning and evidence. Supports flexible analysis, data integration, interactive exploration, and conversation assistance.

πŸ” Microsoft Sentinel

IndicatorFeatureTypeDescription
🟑Data federation (powered by Microsoft Fabric)PreviewAnalyze security data in-place from Fabric, ADLS, and Azure Databricks without copying; use KQL, notebooks, and custom graphs across federated and native data.
🟑Transform data with filter and split featuresPreviewReduce noise before ingestion, control costs, and route data between analytics and data lake tiers.
🟑VS Code connector builder agent (AI-powered)PreviewLow-code agent builds custom Microsoft Sentinel connectors in minutes.
🟑Build custom security graphsPreviewBuild tailored security graphs across Sentinel data lake and third-party data to uncover attack paths and blast radius.
🟑Cost estimation tool with three-year projectionsPreviewGuided, meter-level cost estimator for modeling data growth and predicting spend.
🟑Configure row-level access using scoping (row-level RBAC)PreviewDefine logical scopes, tag data at ingestion, assign users via Unified RBAC β€” no workspace separation needed.
🟒Entity analyzerGAOut-of-the-box, explainable entity risk assessments for URLs and identities using threat intelligence, prevalence, and organizational context. Billed via SCUs starting April 1, 2026.
🟒AI-powered SIEM migration toolGAAI-assisted migration from Splunk and QRadar to Microsoft Sentinel.
πŸ”΅Account Name UPN prefix consistency changeUpdateAccount Name now consistently UPN prefix only. Update automation rules and Logic Apps by July 1, 2026.

πŸ” Microsoft Defender Endpoint

IndicatorFeatureTypeDescription
🟑Secure Boot 2023 certificate recommendation in Microsoft Secure ScorePreviewIdentifies devices that haven’t transitioned to new Secure Boot 2023 certificates ahead of June 2026 expiration.
🟑View action status in Activities tabPreviewTrack automatic attack disruption and predictive shielding action status (Contain user, GPO hardening, Safeboot hardening).
🟒Linux build 101.26032.0000GAExpanded kernel module visibility, offline security intelligence update optimization, SELinux policy cleanup fix.
🟒macOS build 101.26032.0016GABug and performance fixes.
🟒macOS build 4.18.25040.1GANative root detection GA; performance improvements and bug fixes.
🟒macOS build 101.26022.0020GAResolved performance regression under high load.
🟒macOS build 101.26022.0018GAmacOS >= 14 only; CVE-2025-68664/5 LangGrinch fix; bug and performance fixes.

πŸ’Ώ MDE Detailed Releases

Windows

IndicatorFeatureTypeDescription
πŸ”΄CVE-2026-41091: Microsoft Defender Elevation of Privilege VulnerabilitySecurity/FixImproper link resolution before file access (Important); fixed in Engine 1.1.26040.8.
πŸ”΄CVE-2026-45584: Microsoft Defender Remote Code Execution VulnerabilitySecurity/FixHeap-based buffer overflow (Critical); fixed in Engine 1.1.26040.8.
πŸ”΄CVE-2026-45498: Microsoft Defender Denial of Service VulnerabilitySecurity/Fix(Low); fixed in Platform 4.18.26040.7.
πŸ”΅Performance improvement for SFC cache build during engine reloadUpdatePerformance optimization for SFC cache build.
πŸ”΅Reduced API calls for Device Control to prevent Entra throttlingUpdateReduced API calls and improved logging for Device Control.
πŸ”΅Improved TVM Block logic handlingUpdateImproved threat and vulnerability management block logic.
πŸ”΅Fixed TVM Warn temporary paths exclusion issueUpdateFixed exclusion issue when Tamper Protection Exclusions and DLAM are enabled.
πŸ”΅Fixed Defender managed type when migrating from Co-management to IntuneUpdateMigration fix for Defender managed type.

macOS

IndicatorFeatureTypeDescription
🟒Native root detection for Microsoft DefenderGANative root detection is now generally available.
πŸ”΅Bug and performance fixes (101.26032.0016)UpdateGeneral bug and performance fixes.
πŸ”΅Performance improvement and bug fixes (4.18.25040.1)UpdatePerformance improvements and general bug fixes.
πŸ”΅Resolved performance regression under high load (101.26022.0020)UpdateFixed degraded responsiveness and stability under high load conditions.
πŸ”΄macOS >= 14 only (101.26022.0018)SecurityPackaging change: macOS 14+ only supported.
πŸ”΄CVE-2025-68664/5 LangGrinch (langchain vulnerability) (101.26022.0018)SecurityFixed langchain vulnerability.
πŸ”΅Bug and performance fixes (101.26022.0018)UpdateGeneral bug and performance fixes.

Linux

IndicatorFeatureTypeDescription
πŸ”΅Expanded visibility into Linux kernel module (.ko) file activityUpdateCreation, rename, and deletion visibility for kernel module files.
πŸ”΅Offline security intelligence update optimizationUpdateOffline updates now run at most once per configured interval, reducing redundant downloads.
πŸ”΅Resolved SELinux policy cleanup issue on RHEL-based systemsUpdateSafe removal of legacy SELinux modules while preserving customer-defined policies.

Top 5 Action Items

PriorityActionDueAffected Product(s)
πŸ”΄Apply AKS node image updates (202604.13.0 / 202604.24.0) to mitigate CVE-2026-31431 (Linux kernel LPE)ImmediatelyAKS
πŸ”΄Migrate from Ingress NGINX to Gateway API-based application routingNovember 2026AKS
πŸ”΄Update automation rules and Logic Apps for Sentinel Account Name UPN prefix changeJuly 1, 2026Microsoft Sentinel
πŸ”΄Apply Windows Defender Antivirus engine update (1.1.26040.8) to fix CVE-2026-45584 (RCE - Critical) and CVE-2026-41091 (EoP - Important)ImmediatelyMicrosoft Defender Endpoint
πŸ”΄Plan migration from Entra Connect Sync to Entra Cloud SyncStarting July 2026 (phased)Microsoft Entra ID

Security Architect Observations

  • AKS CVE-2026-31431 is critical: A Linux kernel LPE allowing pod-to-node root escalation affects Ubuntu 20.04 FIPS, 22.04, 24.04, and Azure Linux 3.0. Node image upgrade is required β€” existing nodes are not patched in place. The mitigation DaemonSet from the advisory should be applied immediately for pools already on 202604.24.0.
  • Ingress NGINX retirement creates a major migration wave: With upstream maintenance ending March 2026 and production support through November 2026, all AKS clusters using the application routing add-on with NGINX must migrate to Gateway API. AKS Automatic clusters on 1.36+ will default to Gateway API. Plan the migration as a structured project with testing windows.
  • Entra Connect Sync to Cloud Sync transition: Beginning July 2026, Microsoft will notify customers of phased transition windows. Cloud Sync does not yet support all advanced scenarios β€” organizations with complex sync configurations or large directories will be in later waves. Review the feature comparison and begin SOA (Source of Authority) planning now.
  • Sentinel Account Name consistency change: The UPN prefix-only change (effective July 1, 2026) will break automation rules and Logic Apps that use strict equality on AccountName. Replace with Contains/Starts with operators and use the new UPNSuffix field. Audit all playbooks and automation before the deadline.
  • Defender for Cloud container security expansion: GA of runtime protection on EKS Bottlerocket, DNS Detection for Kubernetes, and anti-malware detection/blocking significantly broadens container threat coverage. Evaluate enabling these for existing EKS and AKS clusters.
  • Entra Agent ID platform GA: A new identity framework for AI agents using OAuth 2.0, MCP, and A2A protocols. Architects should evaluate this for governing agent identities in enterprise environments, especially as agent adoption grows across Copilot Studio, Foundry, and third-party platforms.

Security Operations Observations

  • Three CVEs in Windows Defender Antivirus require immediate patching: CVE-2026-45584 (Critical RCE, heap-based buffer overflow) and CVE-2026-41091 (Important EoP) are fixed in Engine 1.1.26040.8. CVE-2026-45498 (Low DoS) is fixed in Platform 4.18.26040.7. Prioritize deployment via your endpoint management tooling.
  • Security Analyst Agent in Security Copilot (Preview): Performs multi-step investigations across Defender and Sentinel telemetry without requiring query writing. SOC teams should pilot this to evaluate its effectiveness for triage and Tier-1 investigation workflows.
  • Sentinel data federation and filter/split features: These reduce ingestion costs and enable in-place analysis of Fabric/ADLS/Databricks data. Operations teams should evaluate which data sources can be federated rather than ingested, and configure filter/split rules to route noise to the data lake tier.
  • Defender XDR built-in alert tuning rules are now GA: Suppress alerts from common benign activity in Defender for Endpoint and Office 365 without affecting AIR. Review and enable these to reduce alert fatigue.
  • Identity Explorer (Preview) in Defender Identity: Visualizes identity attack paths and lateral movement routes. SOC analysts should use this for proactive threat hunting and privilege escalation path discovery, especially for high-value identities.
  • Purview DSPM proactive AI insights: Automatic 24-hour investigation refresh with exfiltration risk categorization. SOC teams monitoring data exfiltration should enable this and integrate findings into their incident response workflow.

References

ProductURL
Defender XDRhttps://learn.microsoft.com/en-us/defender-xdr/whats-new
Unified SecOpshttps://learn.microsoft.com/en-us/unified-secops/whats-new
Defender Endpointhttps://learn.microsoft.com/en-us/defender-endpoint/whats-new-in-microsoft-defender-endpoint
Defender Endpoint Releaseshttps://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-endpoint-releases
Defender Identityhttps://learn.microsoft.com/en-us/defender-for-identity/whats-new
Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/whats-new
Microsoft Entra IDhttps://learn.microsoft.com/en-us/entra/fundamentals/whats-new
Defender Cloud Appshttps://learn.microsoft.com/en-us/defender-cloud-apps/release-notes
Defender Office 365https://learn.microsoft.com/en-us/defender-office-365/defender-for-office-365-whats-new
Defender Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/release-notes
AKShttps://github.com/Azure/AKS/releases
Azure Container Appshttps://learn.microsoft.com/en-us/azure/container-apps/whats-new
Azure Monitorhttps://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/whats-new
Defender Container Sensorhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-sensor-change-log
Security Copilothttps://learn.microsoft.com/en-us/copilot/security/whats-new-copilot-security
Defender Exposure Managementhttps://learn.microsoft.com/en-us/security-exposure-management/whats-new
Microsoft Purviewhttps://learn.microsoft.com/en-us/purview/whats-new
Microsoft Foundryhttps://devblogs.microsoft.com/foundry/category/whats-new/
Microsoft Copilot Studiohttps://learn.microsoft.com/en-us/microsoft-copilot-studio/whats-new
Microsoft Fabrichttps://learn.microsoft.com/en-us/fabric/fundamentals/whats-new
This post is licensed under CC BY 4.0 by the author.

MS Release Radar

Wiz Release Radar

MS Tech News