2026-06
This release tracker is LLM-curated and based on the official Microsoft product sources listed below. It provides an architect-grade summary of recent features, changes, and announcements. Always verify critical details against the official documentation. List of all raw markdown files for the releases are at https://github.com/pisinger/pisinger.github.io/tree/main/_ms_release_radar
Microsoft Security Release Radar - June 2026
π Microsoft Sentinel
No new features, updates, or security patches were present in the provided release notes for this reporting period.
π‘οΈ Microsoft Defender Cloud
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π’ | Expanded multicloud security coverage | GA | Significantly broadens posture assessment for AWS and GCP environments, adding support for about 90 new resource types and over 200 new security recommendations across data, identity and access, networking, compute, and container categories. These recommendations now affect Cloud secure score. |
| π’ | Cloud security reporting | GA | Create, customize, and share cloud security insights across your organization using built-in and custom reports in the Microsoft Defender portal. Custom cards can be tailored when building custom reports. |
| π’ | API security posture management for Function Apps and Logic Apps | GA | Extends API security posture management beyond Azure API Management to serverless and workflow APIs, with automated onboarding, security recommendations, and attack path analysis. |
| π’ | SQL Vulnerability Assessment Express Configuration | GA | Now generally available for Azure SQL Managed Instance and Azure Synapse Analytics workspaces at no extra cost, removing the need for a customer-managed storage account. A new unified SQL VA REST API provides consistent management across supported SQL resource types. |
| π’ | Microsoft Defender for Open-Source Relational Databases on AWS RDS | GA | Generally available for Amazon Web Services RDS instances; usage starts appearing on July 2026 bills. Provides database threat protection and sensitive data discovery for Aurora PostgreSQL, Aurora MySQL, PostgreSQL, MySQL, and MariaDB. |
| π’ | Serverless protection for Azure and AWS | GA | Discover serverless resources and assess them for misconfigurations, vulnerabilities, and insecure dependencies across Azure Web Apps, Azure Functions, and AWS Lambda. |
| π΅ | Support for additional Azure regions in the UAE geography | New/Updated | Defender for APIs and API security posture management with Defender CSPM expanded to UAE North and UAE Central regions. API discovery and posture capabilities for Azure Function Apps and Azure Logic Apps also expanded to these regions. |
| π΅ | General availability of Defender for Key Vault in Azure Government cloud | New/Updated | Defender for Key Vault in Azure Government cloud now aligns with the commercial cloud offering in feature coverage and runtime protection capabilities. |
| π΅ | Expanded container support for cloud scopes | New/Updated | Cloud scopes now support K8s namespace, K8s cluster, multi-cloud registry, and multi-cloud repository for greater flexibility grouping container and Kubernetes resources. |
| π‘ | New multicloud security recommendations | Preview | More than 60 new multicloud security recommendations in public preview across AWS AppFlow, AppStream, AppSync, Athena, Auto Scaling, CodeBuild, Cognito, Comprehend, DMS, DataSync, FSx, Kendra, Keyspaces, Kinesis, MQ, Neptune, and QuickSight. |
| π‘ | Discovery and posture for serverless container workloads | Preview | Adds inventory visibility, security recommendations for misconfigurations and vulnerability assessment findings, and attack path analysis for Azure Container Apps and Azure Container Instances. |
| π‘ | Kubernetes misconfiguration enforcement in Defender for Containers | Preview | Extends Kubernetes security from audit to audit or block mode at deployment time, preventing risky Kubernetes deployments before they reach production. Available only in commercial clouds. |
| π‘ | Vulnerability assessment extended to runtime-discovered container images on EKS and GKE | Preview | Runtime-discovered container images on Amazon EKS and Google GKE are now assessed for vulnerabilities, providing additional findings beyond registry-based scanning. AWS or GCP must be onboarded into Defender for Cloud. |
| π‘ | Kubernetes node vulnerability assessment extended to EKS and GKE | Preview | OS-level vulnerabilities in Kubernetes node VMs across EKS and GKE are now detected, surfacing an βUpgrade Kubernetes nodesβ recommendation. Requires agentless scanning enabled. |
| π‘ | Container-level misconfiguration recommendations for Kubernetes | Preview | Agentless, container-level KSPM misconfiguration recommendations replace previous cluster-level findings with more granular insights. Cluster-level recommendations will be deprecated at GA. |
| π‘ | New actionable recommendation to upgrade AKS for system pod vulnerabilities | Preview | Replaces the previous non-actionable recommendation with a resolvable remediation path for vulnerabilities in AKS-managed system pods. |
π― Microsoft Defender XDR
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π’ | Phishing Triage Agent and Security Alert Triage Agent least-privilege permission | GA | Agents now use the more limited Email & collaboration content: Emails associated with alerts (read) permission instead of the broader All Emails (read) permission. |
| π’ | Advanced hunting schema tables GA | GA | The DisruptionAndResponseEvents, CloudAuditEvents, CloudDnsEvents, and CloudProcessEvents tables are now generally available in advanced hunting. |
| π‘ | Entity enrichments with threat intelligence | Preview | Entity pages for IP addresses, domains, URLs, and files now include a Threat Intelligence Insights tab surfacing reputation scores, attributed threat reports, infrastructure relationships, and sandbox analysis from Microsoft Threat Intelligence. |
| π‘ | Identity Security dashboard β Human identities card | Preview | New card showing human identities by source (Entra ID, SaaS, and on-premises) for a single view of where human identities live. |
| π‘ | Coverage and maturity β Observed SaaS applications | Preview | The Review and improve coverage side panel for SaaS Identities now includes an Observed column and a Show Only Observed Applications toggle. |
| π‘ | Local AI agent discovery on Windows endpoints | Preview | Automatically discovers supported local AI agents running on onboarded Windows devices; discovered agents appear as assets in the AI agent inventory, exposure map, and advanced hunting. |
| π‘ | Local AI agent runtime protection on Windows endpoints | Preview | Runtime protection inspects the agent loop and can block risky activity before execution, helping stop prompt injection and unsafe agent actions at the device level. |
| π‘ | AgentsInfo advanced hunting table | Preview | New unified schema supporting agent inventory and governance for all agent types. The AIAgentsInfo table remains accessible until July 1, 2026. |
π Microsoft Defender Endpoint
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π’ | Local AI agent discovery β macOS support and new agents | Preview | [macOS] Local AI agent discovery now supports macOS endpoints and adds discovery for Junie CLI, Kiro CLI, Warp, Hermes Agent, Goose Desktop, Perplexity Desktop, Kiro IDE, Devin Desktop, and QClaw. |
| π’ | Enhanced Defender deployment tool for Windows | GA | [Windows] New version bundles the onboarding package into the executable, generates a required deployment key, supports package expiry dates, and adds a Deployment packages page in the Defender portal for centralized visibility. |
| π’ | Selective Response Actions | GA | Enables precise control over how response actions are applied on Tier-0 systems and other high-value assets during onboarding. |
| π’ | Enhanced exposure score in Defender Vulnerability Management | GA | New exposure score model incorporates exploit prediction data (EPSS) and asset context factors such as internet-facing status and criticality to improve risk prioritization. |
| π’ | New Microsoft Secure Score recommendation | GA | New recommendation Reduce unnecessary inbound internet exposure on internet-facing devices provides centralized visibility to validate expected exposure and prioritize remediation. |
| π‘ | Local AI agent discovery | Preview | [Windows] Automatically discovers supported local AI agents running on onboarded Windows devices, surfacing them in the AI agent inventory, exposure map, and advanced hunting. |
| π‘ | Local AI agent runtime protection | Preview | [Windows] Inspects the agent loop on Windows endpoints and can block risky activity before execution, helping stop prompt injection and unsafe agent actions at the device level. |
| π’ | Windows Defender Antivirus platform release | GA | [Windows] Platform 4.18.26050.15 / Engine 1.1.26050.11 released; see MDE Detailed Releases section for enhancements. |
| π’ | Linux build release | GA | [Linux] Build 101.26042.0009 released; see MDE Detailed Releases section for enhancements and a fix. |
πΏ MDE Detailed Releases
Windows
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π΄ | Fixed CVE-2026-50656 (Elevation of Privilege) | Security | [Windows] Addressed Microsoft Defender Elevation of Privilege vulnerability in the Microsoft Malware Protection Engine, improving protection against local privilege escalation scenarios. |
| π΅ | Controlled Folder Access notification fix | New/Updated | [Windows] Resolved an issue where Controlled Folder Access toast notifications continuously appeared for the C: drive because of AMD driver injection into protected processes. |
| π΅ | Endpoint DLP Chrome upload enforcement reliability | New/Updated | [Windows] Improved Endpoint DLP enforcement reliability for Chrome uploads to Google Drive, ensuring policy-based blocking is consistently applied during bulk file transfers. |
| π΅ | Endpoint DLP custom JIT notification fix | New/Updated | [Windows] Fixed an issue in Endpoint DLP where Chrome and Firefox uploads could occasionally display the default JIT notification instead of the organization-configured custom message due to a timing-related race condition. |
macOS
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π΅ | Security and critical updates | New/Updated | [macOS] Build 101.26042.0020 includes security and critical updates as part of the monthly release cycle. |
Linux
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π’ | Fixed build issue causing disablement after upgrade/reinstall | GA/FIX | [Linux] Fixed an issue where Defender for Endpoint on Linux could become disabled after upgrade or reinstall scenarios followed by a system reboot for builds 101.26042.0000β101.26042.0009. |
| π’ | Offline security intelligence updates | GA | [Linux] Customers can now configure offline security intelligence updates using Security Settings Management policies in the Defender portal. |
| π‘ | Scheduled antivirus scans | Preview | [Linux] Customers can centrally schedule antivirus scans on Linux using managed JSON and policy settings through the Defender portal. |
| π΅ | Better user attribution in security events | New/Updated | [Linux] File, process, and network security events now include the original login userβs ID even when actions are performed via sudo or under root, improving insider threat detection and investigations. |
| π΅ | Improved login event accuracy | New/Updated | [Linux] Improved login event accuracy by preventing stale remote IP data from being reused across different login event types. |
| π΅ | Added package publishing support for newer Linux distributions | New/Updated | [Linux] Added support for Fedora 43, RockyLinux 10, AlmaLinux 10, and SUSE Linux Enterprise Server 16. |
| π΅ | Faster threat remediation | New/Updated | [Linux] Malware is now quarantined and cleaned up more quickly, improving response time when threats are detected. |
| π΅ | EDR SDK updates and stability improvements | New/Updated | [Linux] Updates and stability improvements help the Defender agent run more reliably with continuous protection. |
π‘οΈ Microsoft Defender Unified SecOps
No new features, updates, or security patches were present in the provided release notes for this reporting period.
π Microsoft Defender Identity
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π’ | Identity risk score | GA | Now generally available; score ranges from 0 to 100 and reflects how likely an identity is to be compromised and how much damage a compromise could cause, based on criticality level and privileged role assignments. |
| π΅ | New Defender for Identity security alerts | New/Updated | New alerts added for Entra ID (anomalous activity after Global Admin elevation, reciprocal Temporary Access Pass creation, suspicious service principal sign-in, suspicious bulk user deletion, suspicious privileged app role removal, suspicious sign-in with spike in account updates, spike in distinct application-resource access combinations), Active Directory (DCSync attack, suspicious Entra Connect account authentication), and SailPoint ISC suspected brute-force attack. |
| π‘ | NHI inventory enhancements | Preview | Expanded Entra ID inventory now includes all Microsoft Entra service principals, and the Permissions tab shows assigned Microsoft Entra roles alongside API permissions. |
| π‘ | Visibility into service principals used by AI agents | Preview | Non-human identity inventory now identifies which Entra ID service principals are used by AI agents via a new βUsed by AI agentsβ column and insight card. |
π’ Microsoft Entra ID
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π’ | BYOD support for Windows client using Entra registration | GA | Bring Your Own Device support for Windows client using Entra-registered devices is now generally available, enabling users and partners to access corporate resources from their own devices without requiring domain join. |
| π’ | Jailbreak/Root Detection in Authenticator App | GA | Microsoft Authenticator now blocks users with rooted/jailbroken devices from adding or using work or school accounts; users must move to compliant devices. Secure by default with no admin configuration required. |
| π’ | SCIM 2.0 APIs for Microsoft Entra ID in US Gov cloud | GA | Standards-based option for managing users and groups in Microsoft Entra using SCIM 2.0 is now generally available in the US Government cloud. |
| π΅ | External users directly assigned to Access Packages | New/Updated | Entitlement Management admins can now directly assign external users not in the directory to an access package using the userβs email; users are invited as Guest users and governed. |
| π΅ | Kerberos key rotation improved reliability | New/Updated | Enhanced validation logic attempts decryption with both primary and secondary Kerberos keys during key rollover, improving resiliency and reducing authentication disruption. |
| π΅ | Extended Conditional Access protections for Agentβs user accounts | New/Updated | Conditional Access now supports targeting agent user accounts with precision, protecting against risky agent activity, requiring compliant devices for agents, and applying device platform and network filters. |
| π΅ | Domainless SAML IdP federation for workforce tenants | New/Updated | Domainless SAML federation allows external users to authenticate using IdP-managed credentials regardless of email domain, removing the need for domain matching. |
| π΅ | Microsoft Entra Backup and Recovery | New/Updated | Built-in solution automatically backs up critical directory objects (users, groups, applications, Conditional Access policies, etc.) so admins can restore them to a previously known good state. Retains daily backups for 7 days for P1/P2 tenants. |
| π΅ | New built-in Entra role for SOC identity response | New/Updated | New SOC Identity Responder built-in role enables SOC analysts to perform identity containment actions (disable users, revoke sessions, force password resets) without broad directory administrative privileges. Supports PIM and role-assignable groups. |
| π΅ | Prevent unauthorized changes to AD groups with AD group enforcement | New/Updated | For customers using group provisioning to AD, designated AD groups can be locked so modifications can only be made through the Entra provisioning service, preventing drift. |
| π΅ | Improved restore experience for device-bound Authenticator app passkeys on iOS | New/Updated | Starting August 2026, users with iCloud and iCloud Keychain backup enabled will see an improved restore flow for device-bound Authenticator passkeys on new iOS devices. |
π± Microsoft Intune
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π’ | Enrollment time grouping for new Apple ADE enrollment policies | GA | Identify a deviceβs Microsoft Entra security group during enrollment so policies, apps, and settings can be applied earlier in the setup process for iOS/iPadOS and macOS. |
| π΅ | Available macOS PKG apps update automatically | New/Updated | [macOS] Updates now deploy automatically when the same app policy is updated with a new version, eliminating the need for users to manually select Install or Reinstall. |
| π΅ | Newly available protected app for Intune | New/Updated | ChatGPT is now available as a protected app for Microsoft Intune. |
| π΅ | Enterprise App Management support for GCC High and DoD | New/Updated | [Windows] EAM extended to GCC High and DoD cloud environments for discovering, deploying, and keeping prepackaged apps up to date. |
| π΅ | Auto-update for Enterprise App Management applications | New/Updated | [Windows] Intune now supports automatic updates for EAM applications, detecting newer versions and updating targeted devices automatically. |
| π΅ | New Android Enterprise settings in the Intune settings catalog | New/Updated | [Android Enterprise] New settings added for Applications (block apps from exposing app functions, block widgets from work profile apps), Connectivity (preferential network service, block airplane mode, block cellular 2G, block configuring cell broadcasts/mobile networks/VPN, block network reset, block outgoing calls/SMS, block ultra wideband, select minimum Wi-Fi security level), and General (block printing, block setting user icon/wallpaper, block adding eSIM profiles). |
| π΅ | Support for WPA3-Personal in iOS/iPadOS Wi-Fi profiles | New/Updated | [iOS/iPadOS] WPA3-Personal is now supported as a security-type option for Wi-Fi device configuration profiles. |
| π΅ | Microsoft Tunnel adds support for RHEL 9.7 | New/Updated | [Linux] Microsoft Tunnel Gateway now supports Red Hat Enterprise Linux 9.7, requiring Podman 5.8.2. Customers upgrading from Podman v3 must recreate containers and reinstall Tunnel. |
| π΅ | Updated security baseline for Microsoft 365 Apps for Enterprise | New/Updated | [Windows] Version v2512 baseline aligns with the most recent security guidance; three settings are pending availability in a future update. |
| π΅ | New Microsoft Defender Antivirus settings for Linux Server devices | New/Updated | [Linux] Linux Server Antivirus policy now includes offline security intelligence update and scheduled scan settings. |
| π΅ | New setting added to Windows security baseline version 25H2 | New/Updated | [Windows 11] Added Disable Internet Explorer 11 Launch Via COM Automation setting with baseline default of Enabled to reduce attack surface. |
| π΅ | Multi Admin Approval now enforces on API calls made by automation | New/Updated | API calls made by automation through Microsoft Graph API are now subject to the same approval workflow as interactive operations; calls without required approval headers return HTTP 403. |
| π΅ | Managed Win32 app content now requires HTTPS delivery | New/Updated | Intune now requires HTTPS delivery for managed Win32 app content; organizations using Microsoft Connected Cache without HTTPS may see increased internet traffic. |
| π΅ | Android Enterprise personally owned devices with work profile uses Android Management API | New/Updated | [Android Enterprise] Personally owned devices with work profile now use web-based enrollment and a modern policy delivery implementation aligned with corporate-owned devices. |
| π΅ | Custom top bar elements on Managed Home Screen | New/Updated | [Android Enterprise] Custom text up to 63 characters can now be displayed in the top bar of Managed Home Screen, supporting dynamic variables for kiosk scenarios. |
| π΅ | Managed Home Screen exit lock task mode password now requires device configuration profile | New/Updated | [Android Enterprise] Exit lock task mode password for Managed Home Screen can no longer be configured via app configuration policy; must use a device configuration profile. |
| π΅ | New Block Bluetooth sharing setting | New/Updated | [Android Enterprise] New setting in the settings catalog to block Bluetooth sharing on fully managed, dedicated, and corporate-owned work profile devices. |
| π΅ | Use DDM to manage Apple Intelligence settings | New/Updated | [iOS/iPadOS, macOS] Apple deprecated several intelligence-related settings in the MDM restrictions payload with release 26.4; use DDM configurations instead. |
| π΅ | Silence apps on Managed Home Screen | New/Updated | [Android Enterprise] Apps can now be silenced when Managed Home Screen prompts for authentication, preventing activities, notifications, and toasts during locked states. |
| π΅ | New Microsoft Edge settings in the Windows settings catalog | New/Updated | [Windows] 148 new Microsoft Edge settings added, including New Tab Page feed visibility, M365 authentication popups in work profiles, Copilot side pane auto-open, extended SharedWorker lifetime, developer tools allowlist/blocklist, WebSocket proxy max connections, browsing with Copilot controls, and Copilot new tab page policies. |
| π΅ | New 802.1x Wired Networks device configuration profile for iOS/iPadOS | New/Updated | [iOS/iPadOS 17+] Supports EAP protocols (TLS, PEAP, TTLS) for secure wired Ethernet access, ideal for M-series iPads in education and regulated industries. |
| π΅ | Detect and block Shadow AI using properties catalog, device query, and security baseline | Preview | [Windows] Using Intune, detect and block a Local AI Agent like OpenClaw via a Properties catalog policy, Device Query, and the Local AI Agent Baseline β OpenClaw (Preview). |
| π΅ | In-place renewal of Cloud PKI issuing CAs | New/Updated | Issuing CAs can now be renewed in-place without creating new CAs or manually updating SCEP profiles, keeping certificate issuance uninterrupted. |
| π΅ | Strict Tunnel Mode for Microsoft Tunnel on Android | New/Updated | [Android] All network traffic is forced through the VPN tunnel; if the connection drops, all traffic is blocked until reconnection. Requires Android Management API. |
| π΅ | Grant enhanced security permissions to a Mobile Threat Defense app on Android | New/Updated | [Android] New toggle grants exemptions (suspension, hibernation, power restrictions, user controls) to one MTD partner app per tenant on COBO and COPE devices. |
| π΅ | Vulnerability Remediation Agent now uses Microsoft Entra agentic identity | Preview | The agent now uses an Entra agentic identity instead of a human user identity. Human user identity support expires 90 days after this release. |
| π΅ | Advanced Intune capabilities added to Microsoft 365 E3 and E5 | New/Updated | EMS E3 (in M365 E3) now includes Remote Help, Advanced Analytics, and Intune Plan 2. M365 E5 adds Endpoint Privilege Management, Enterprise Application Management, and Microsoft Cloud PKI. Rolling out gradually with 30-day advance notice. |
| π΅ | APP Multiple Managed Accounts | New/Updated | [iOS/iPadOS] Mobile application management now supports multiple managed accounts within the same app, starting with Microsoft Teams on iOS/iPadOS v8.10.0 or later. |
βοΈ Microsoft Defender Cloud Apps
| Indicator | Feature | Type | Description |
|---|---|---|---|
| β« | File policies retiring January 6, 2027 | Deprecation | File-based data protection is moving from Defender for Cloud Apps to Microsoft Purview. File policies retire on January 6, 2027; review and recreate them as Microsoft Purview DLP or auto-labeling policies before the retirement date. |
| π‘ | Salesforce connector enhancements | Preview | Real-Time Event Monitoring data ingestion for near real-time detection of identity and OAuth threats, plus OAuth app governance for Salesforce Connected Apps and External Client Apps (ECAs). Includes new insights for highly privileged and unused apps, with permissions visible on the App governance page. |
π§ Microsoft Defender Office 365
No new features, updates, or security patches were present in the provided release notes for this reporting period.
π¨ Microsoft Security Exposure Management
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π΅ | New predefined classifications for AI agents | New/Updated | Added Executive-Sponsored AI Agent classification to the critical assets list for agents created or owned by senior executives. |
| π΅ | New predefined Identity classifications | New/Updated | Added Widespread Local Admin on Servers, Widespread Local Admin on Workstations, and Widespread Local Admin on Servers and Workstations classification rules to the critical assets list. |
| π΅ | New predefined SaaS application classifications | New/Updated | Added 16 new SaaS application classifications to the critical assets list for Microsoft Entra ID, Azure, 365 Defender, Intune, Dynamics 365, Purview, SharePoint Online, Teams, Exchange Online, OneDrive, Office Online, Power Apps, Power Automate, Power BI, and Universal Print. |
| π‘ | Overview dashboard | Preview | Updated overview dashboard consolidates signals from cloud resources and devices into a single, action-oriented view organized around Resolve Now and Monitor Exposure. |
β΅ AKS
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π’ | Kubernetes version 1.36 | GA | Now generally available and supported as a Long Term Support (LTS) version; no preview enablement required. |
| π’ | FIPS on Ubuntu 22.04 node pools | GA | FIPS 140-3 compliance now supported on Ubuntu 22.04 node pools; FIPS and Trusted Launch can be enabled in the same node pools when using Ubuntu on AKS. |
| π’ | NVIDIA RTX PRO 6000 Blackwell Server Edition GPU VM sizes | GA | Supported as managed GPUs on Ubuntu node pools using the NVIDIA GRID driver. |
| π’ | Confidential VMs with Azure Linux | GA | Generally available for AKS workloads using Azure Linux. |
| π΄ | Istio service mesh add-on CVE-2026-47774 | Security | Revisions asm-1-29 and asm-1-28 upgraded to patches 1.29.4 and 1.28.8 to address CVE-2026-47774. Restart workload pods to trigger re-injection of the updated istio-proxy sidecar. |
| π΅ | Windows Server 2022 retirement extended | New/Updated | Windows Server 2022 retires on June 30, 2028; not supported in Kubernetes 1.37+. Starting June 30, 2029, AKS will remove all existing node images, causing scaling failures. |
| π΅ | AKS Automatic β disable default application routing add-on | New/Updated | On AKS Automatic clusters running Kubernetes 1.36+, the default application routing add-on with Gateway API can be disabled to use the Istio-based service mesh add-on with Istio CNI. |
| π΅ | Deployment Safeguards in Enforce mode expanded | New/Updated | Now applies default resource requests to DaemonSets and Jobs in addition to Deployments and StatefulSets. |
| π΅ | Custom Prometheus metric scraping and log collection on AKS Automatic | New/Updated | Now supported on AKS Automatic clusters with managed system node pools. |
| π΅ | IPv6 pod CIDR auto-derivation | New/Updated | AKS now automatically derives the IPv6 pod CIDR from the pod subnet when creating dual-stack Azure CNI static block allocation clusters. |
| π΅ | Windows gMSA CoreDNS conflict validation | New/Updated | AKS now rejects enabling gMSA or changing its root domain name when the clusterβs coredns-custom ConfigMap already defines a server block for the same domain. |
| π΅ | FIPS rejection on Kata node pools | New/Updated | AKS now rejects enabling FIPS on Pod Sandboxing (Kata) workload runtime node pools because the Kata node image doesnβt carry FIPS compliance. |
| π΅ | Pod Sandboxing on Standard_DadsV7-series | New/Updated | Pod Sandboxing (Kata) node pools can now be created on Standard_DadsV7-series VM sizes. |
| π΅ | AKS Automatic migration to Base SKU | New/Updated | AKS Automatic clusters with managed system node pools can now be migrated to the AKS Base SKU. |
| π΅ | Azure Service Mesh add-on default behavior changes | New/Updated | For asm-1-30 (estimated early July), new installations will use Istio CNI instead of privileged init containers for proxy redirection. Gateway pod node preferences also change for asm-1-30+. |
| π΅ | Fixed Azure Policy add-on exemption for aks-istio-system | New/Updated | Fixed an issue where the aks-istio-system namespace was not exempted from the Azure Policy add-on when using application routing with Gateway API in Istio mode. |
| π΅ | Fixed Multiple Standard Load Balancers label selector validation | New/Updated | Fixed a bug where valid domain-prefixed label keys were rejected in node selectors; validation now follows standard Kubernetes semantics. |
| π΅ | Component updates | New/Updated | Azure File CSI Driver upgraded to v1.35.4 on AKS 1.35/1.36; Azure Blob Storage CSI driver upgraded to v1.26.14 (1.33) and v1.27.7 (1.34+); Cilium updated to v1.17.15 (1.32) and v1.16.19 (1.31); Cloud Provider Azure updated to June 18, 2026 releases; new Windows, Azure Linux, and Ubuntu node images published. |
π¦ Azure Container Apps
No new features, updates, or security patches were present in the provided release notes for this reporting period.
π§± Azure Container Instances
No new features, updates, or security patches were present in the provided release notes for this reporting period.
β‘ Azure Functions
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π’ | Rolling updates in Flex Consumption | GA | Zero-downtime deployments now generally available in the Flex Consumption plan, gracefully replacing live instances by draining batches while dynamically scaling out the latest version. |
| π’ | Azure Functions supports hosting MCP Apps | GA | Supports building and hosting Model Context Protocol (MCP) Apps using the Azure Functions MCP Extension, enabling interactive UIs that render directly within chat experiences for Python, TypeScript, .NET, and Java. |
| π’ | Override Scale Rules in Azure Functions on Azure Container Apps | GA | Customers can now override platform-managed KEDA scaling rules with custom KEDA scaling rules via the allowScalingRuleOverride property, available in API version 2026-03-02-preview and later. |
| π’ | Azure Functions Support for Node.js 24 | GA | Node.js 24 is now generally available for Azure Functions on Linux and Windows, including the Flex Consumption plan. Remote Build on Flex Consumption is rolling out over the coming week. |
| π’ | Built-in Grafana dashboards | GA | Zero-setup Grafana dashboards for health, performance, and scale of function apps directly in the Azure portal; no separate Grafana instance required. |
| π‘ | New project templates and template gallery for Azure Functions in VS Code | Preview | Redesigned Create New Project experience with a rich, visual template gallery replacing the multi-step Quick Pick wizard, plus a βGenerate with Copilotβ mode. |
| π‘ | Azure Functions includes managed connectors | Preview | 1,400+ managed connectors now available as first-class triggers and operations, enabling direct connections to Microsoft 365, Salesforce, ServiceNow, SAP, Dynamics, and other systems. |
| π‘ | Serverless agents runtime | Preview | Supports building AI agents as a first-class workload using a markdown-first programming model, responding to conversations, reacting to events, and taking actions across enterprise systems. Supported on the Flex Consumption plan. |
| π‘ | Copilot-assisted coding & agent skills | Preview | AI assistant plugins and agent skills for VS Code, CLI, and azd that provide current Azure Functions expertise following the Agent Skills open standard, grounded in official Azure documentation. |
| π‘ | Go language support | Preview | Go is now supported as a first-class language option for event-driven serverless apps on the Flex Consumption plan. |
π Azure Logic Apps
No new features, updates, or security patches were present in the provided release notes for this reporting period.
π Azure Monitor
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π‘ | Azure Copilot Observability Agent | Preview | Expanded Observability Agent documentation with 12 new articles covering autonomous operations, deep investigations, context memory, custom instructions, resource provisioning, and transparency. |
| π‘ | Multi-stage transformations for data collection rules | Preview | Filter, parse, aggregate, and enrich logs at the agent or during ingestion using a pipeline of declarative processors. |
| π’ | Metrics export for Log Analytics workspaces | GA | Metrics export reached general availability; updated create and reference articles with expanded configuration details. |
| π΅ | Tutorial: Alert on virtual machine issues | New/Updated | New tutorial for configuring Azure Monitor alerts on virtual machine issues, covering metric, log, and activity log alert rule creation and management. |
| π΅ | Azure Monitor overview page | New/Updated | New article introducing the Azure Monitor overview page, surfacing health status, key signals, and recommended actions across monitored resources. |
| π΅ | Service Level Indicators | New/Updated | Service Level Indicators reached general availability. |
| π΅ | Configure health rollup | New/Updated | New how-to article for configuring health rollup in Azure Monitor health models, covering count, percentage, and impact-based aggregation strategies. |
| π‘ | Protected tables in a Log Analytics workspace | Preview | Preview feature restricting write and delete access on sensitive tables at the table level. |
| π‘ | Dynamic thresholds for query-based metric alerts | Preview | Query-based metric alert rules now support dynamic thresholds, applying machine learning to PromQL expressions over Prometheus and OpenTelemetry metrics. |
| π΅ | Diagnostic settings FAQ expanded | New/Updated | Starting June 15, 2026, export billing for platform logs streamed through diagnostic settings expands to all remaining Azure resources; previously free log categories may now incur charges. |
π¬ Defender Container Sensor
No new features, updates, or security patches were present in the provided release notes for this reporting period.
π€ Microsoft Security Copilot
No new features, updates, or security patches were present in the provided release notes for this reporting period.
π Microsoft Purview
No new features, updates, or security patches were present in the provided release notes for this reporting period.
ποΈ Microsoft Foundry
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π’ | Claude generally available | GA | Anthropicβs Claude models are now generally available in Microsoft Foundry, hosted on Azure with the Messages API, prompt caching, extended thinking, and tool streaming. |
| π’ | Foundry agents publish to Microsoft 365 Copilot and Teams | GA | Agents can now be published directly into Microsoft 365 Copilot and Teams through a single governed publishing pipeline, supporting goal-oriented execution with checkpoints and human escalation. |
| π’ | Foundry Toolkit for VS Code | GA | Now generally available for creating agents from templates, debugging runs locally with trace visualization, connecting to Toolboxes, and deploying to Foundry Agent Service. |
| π’ | Microsoft Agent Framework stable release | GA | Agent harness with skills, memory, and middleware; integrations with GitHub Copilot SDK and Claude Agent SDK; and multi-agent orchestration patterns including Magentic-One are now in stable release. |
| π’ | Voice Live prompt agents | GA | Generally available for real-time voice agent scenarios. |
| π‘ | Foundry autopilot agents | Preview | New agent category with its own Entra Agent ID, productivity license, email, calendar, and Teams presence, designed for shared spaces like group chats. |
| π‘ | Toolboxes in Foundry | Preview | Adds Skills, Work IQ, Fabric IQ, Browser Automation, and Tool Search, providing one managed endpoint for tools, skills, MCP clients, and enterprise data. |
| π‘ | Routines in Foundry Agent Service | Preview | Scheduled and triggered agent run control for timer-based or schedule-based execution. |
| π‘ | Agent Optimizer | Preview | Closed-loop evaluate β generate candidates β rank β deploy workflow for hosted agents; public preview expected roughly 30 days after June 3 announcement. |
| π‘ | Memory enhancements | Preview | New procedural memory, management experiences, and time-to-live (TTL) controls in Foundry Agent Service. |
| π‘ | Voice Live API 2026-06-01-preview | Preview | Adds the azure-realtime-native structured voice type and a client-side echo cancellation reference option. |
| π‘ | Foundry Local on Azure Local | Preview | Multi-node Kubernetes deployment, disconnected/air-gapped operation, new vLLM inference runtime, automatic GPU inference tuning, and model caching. |
| π‘ | Improved NL2SQL Engine for Fabric Data Agent | Preview | Improves accuracy, transparency, and resilience when translating natural language to SQL; asks clarifying questions and surfaces structured diagnostics. |
| π‘ | Code Interpreter Tool for Fabric Data Agent | Preview | Runs Python directly inside agent workflows for statistical analysis, forecasting, and visualization beyond database queries. |
| π‘ | Creator Agent for SQL and Eventhouse sources | Preview | AI-assisted creation experience generating and refining Fabric Data Agent configurations for SQL and Eventhouse scenarios. |
| π΅ | Foundry joins the OpenEnv standard | New/Updated | Hosted agents, Toolboxes, Memory, Managed Compute, and evaluation/optimization stack unified into a reinforcement-learning loop, including post-training via Tinker and ECHO. |
| π΅ | SDK updates | New/Updated | Java azure-ai-projects 2.1.0 (GA) with Data Generation, Models, and Routines preview clients; .NET 2.1.0-beta.4; Python and JS/TS converging on 2.3.0 release. |
| π΅ | Hosted agents expected GA | New/Updated | Expected to reach general availability by early July 2026, with sandboxed sessions, state, filesystem access, and framework flexibility. |
π§ Microsoft Copilot Studio
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π’ | Windows 365 for Agents MCP server | GA | Gives agents full operational control of a Windows 365 cloud PC, including desktop interaction, browser automation, and semantic UI inspection. |
| π’ | Claude Sonnet 5 or GPT-5.5 Chat | GA | Now selectable as the agentβs primary AI model for improved response quality and reasoning. |
| π‘ | New agent experience | Preview | Production-ready preview using an enhanced orchestration runtime for improved response quality and reasoning, available alongside the classic experience. |
| π‘ | Microsoft IQ | Preview | Connects agents to organizational data, giving access to emails, calendar events, files, Teams messages, and people information. |
| π‘ | Skills | Preview | Modular, self-contained sets of instructions that can be created once, added to multiple agents, and exported as Markdown or packages. |
| π‘ | Memory | Preview | Persistent context across interactions capturing user preferences and patterns per user for more relevant and personalized responses. |
| π‘ | Condition groups | Preview | Manage multiple conditions in a single Message, Question, or prompt node, reducing branching and making topic flows easier to review and maintain. |
| π‘ | Voice agents with Teams Phone Agent | Preview | Handle specialized call workflows like billing, prescription refills, and order status with seamless handoff between Teams Phone Agent and custom voice agents. |
| π‘ | Connect other agents | Preview | Agents can delegate requests to specialized agents, enabling modular solutions with a single front-door agent routing to the right specialist. |
| π‘ | Foundry IQ integration | Preview | Grounds agent responses in a knowledge base already built and tuned in Azure AI Foundry. |
π Microsoft Fabric
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π’ | Real-Time Dashboards Live Refresh | GA | Pushes new data to dashboard tiles as soon as it lands, replacing periodic refresh polling with always-current visualizations. |
| π’ | Eventstream streaming connectors for Apache Kafka and Azure Service Bus | GA | Hardened reliability, broader authentication support (SASL_SSL, SASL_PLAINTEXT, Microsoft Entra), and production-ready throughput for ingesting Kafka topics and Service Bus queues. |
| π’ | Business Events Capacity Consumption | GA | Metered through the standard Fabric capacity model with no separate license required. |
| π’ | Fabric Graph | GA | Scalable, enterprise-grade graph solution for modeling, visualizing, and analyzing complex relationships within data. |
| π’ | Operations agent | GA | Autonomous agent that monitors data with Real-Time Intelligence, reasons over Fabric IQ ontology, and runs pipelines, notebooks, user data functions, and Power Automate flows with approval, tracing, audit, and governance. |
| π’ | Data agents in Microsoft 365 Copilot | GA | Business users can discover and chat with governed Fabric data sources directly inside Microsoft 365 Copilot, with admin-managed publishing and Entra ID-enforced data permissions. |
| π‘ | Workspace outbound access protection for Azure and Fabric events | Preview | Extends outbound network controls to cross-workspace event consumption, requiring the Real-Time Events connector in workspace data connection rules. |
| π‘ | Real-Time Dashboards powered by AI | Preview | AI-first tile editor where users describe needs in natural language and Copilot generates visualizations without requiring KQL expertise. |
| π‘ | Time Series Visualization in Real-Time Dashboards | Preview | Dedicated capabilities for navigating, comparing, and customizing time-based data, including legend search, pin-and-overlay, multiple aligned-time panels, and zoom with a time slider. |
| π‘ | Secure MQTT broker and Eventstream connector with mTLS | Preview | Eventstream MQTT source connector now supports specifying CA and client certificates from Azure Key Vault for mutually authenticated encrypted connections. |
| π‘ | Extended IoT Hub source Eventstream connector | Preview | Preserves all event metadata, including system properties and user-defined application properties, enabling device identity joining and ingestion latency computation. |
| π‘ | Pagination support for Eventstream HTTP connector | Preview | Ingests paginated REST API responses through page-based or cursor-based pagination without custom orchestration. |
| π‘ | Activator as business events publisher | Preview | Activator can emit structured business events into Real-Time hub when conditions are met, making signals discoverable and routable. |
| π‘ | Business events persisted into Eventhouse | Preview | Each business event maps to a dedicated KQL table in Eventhouse by default for historical queries and correlation. |
| π‘ | Activator rule actions: Copy job and Publish a business event | Preview | New actions for copying data between sources/destinations and triggering downstream processes that consume business events. |
| π‘ | Activator rules for OneLake items | Preview | Create and manage Activator rules for OneLake items to automate actions based on file creation/deletion or process statuses. |
| π‘ | Billing for Fabric Planning | Preview | Hybrid model combining role-based and session-based pricing with job-based pricing for automated operations, metering against unified Fabric capacity-unit (CU) model. |
| π‘ | Observability for Fabric Data Agent in Microsoft Foundry | Preview | Surfaces telemetry for every call to a Fabric Data Agent used as a tool inside a Foundry agent, including latency, status, and error details. |
π GitHub Security
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π’ | Innersource security advisories | GA | GitHub Advanced Security enterprise customers can now publish internal security advisories with a new REST API endpoint; Dependabot notifies affected repositories and opens upgrade PRs. |
| π’ | GitHub Code Quality | GA | Generally available on GitHub Enterprise Cloud and GitHub Team; pairs CodeQL deterministic analysis with AI-assisted detection for maintainability and reliability issues, with Copilot Autofix suggestions. |
| π‘ | Open source license compliance | Preview | Enterprise-wide license policy with ruleset-based checks that block noncompliant dependencies before they reach production; integrates with pull request checks and introduces the Enterprise Open Source License Policy Manager role. |
| π‘ | AI security detections on pull requests | Preview | AI-powered security detections on pull requests expand vulnerability coverage beyond CodeQL-supported languages; requires GitHub Code Security and GitHub Copilot license. |
| π‘ | Security reviews in the GitHub Copilot app | Preview | /security-review slash command scans current workstream changes and returns high-confidence security findings, actionable suggestions, and a prioritized view for vulnerability classes like injection flaws and XSS. |
| π΅ | CodeQL 2.26.1 | New/Updated | Improved framework coverage for Go, Java/Kotlin, and JavaScript/TypeScript; reduced false positives in Rust analysis. |
| π΅ | Improvements to secret scanning and public monitoring | New/Updated | Resend is now a secret scanning partner; new secret types from APIclub and Resend are detected; VolcEngine secrets are blocked by push protection by default; secret_category field added to webhook payload. |
| π΅ | Dependabot no longer infers .npmrc | New/Updated | Dependabot now supports a scope property on registries in dependabot.yml to generate correct .npmrc, making dependabot.yml the authoritative source for registry configuration. |
| π΅ | Upcoming cloud data retention policy for closed security alerts | New/Updated | Starting August 25, 2026, closed Dependabot alerts closed two or more years ago will move to archival storage and no longer appear in the UI or API; can be downloaded as CSV by admins. |
| π΅ | npm publish-time malware scanning and dual-use metadata | New/Updated | Newly published npm packages are automatically scanned before becoming available (typical delay ~5 minutes). New contentPolicy field and required DISCLOSURE file for dual-use content. |
| π΅ | Dependabot alerts on malicious packages across more ecosystems | New/Updated | GitHub Advisory Database now ingests malware advisories from the OpenSSF malicious-packages repository, expanding coverage across npm, PyPI, and more. |
| π΅ | GitHub Actions holds potentially malicious workflows for approval | New/Updated | Certain workflow runs in public repositories are now held for approval by a repository collaborator with write access before executing, protecting against compromised credential attacks. |
| π΅ | Dependabot version updates introduce default package cooldown | New/Updated | Dependabot now waits at least three days after a new release before opening a version update PR, reducing risk from compromised or broken releases; security updates remain immediate. |
| π΅ | npm v12 install-time security defaults | New/Updated | allowScripts defaults to off; --allow-git and --allow-remote default to none. Dependency lifecycle scripts and git/remote dependencies now require explicit opt-in. |
| π΅ | npm 2FA-bypass GAT deprecation | New/Updated | Granular access tokens configured to bypass 2FA will lose the ability to perform sensitive account, package, and organization management actions; expected early August 2026. Publishing will require human 2FA approval. |
| π΅ | Code scanning AI security detections billing | New/Updated | During public preview, AI security detections require a GitHub Copilot license and draw down AI credits; usage consumes credits only when detections run. |
π‘οΈ Microsoft Defender Cloud (Defender Recommendations & Alerts)
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π’ | SQL VA individual recommendations at database level | GA | Multiple individual SQL Vulnerability Assessment recommendations (xp_cmdshell, latest updates, GUEST role, ad hoc distributed queries, CLR, trusted assemblies, ownership chaining, remote admin connections, default trace, CHECK_POLICY, password expiration, principal mapping, AUTO_CLOSE, BUILTIN\Administrators, sa account, PUBLIC role permissions, sa login, unused service broker endpoints, Database Mail XPs, server permissions, database user name conflicts, etc.) released in GA as part of transitioning from grouped server-level to individual database-level recommendations. |
| π’ | Upgrade Azure Kubernetes Service to remove vulnerabilities from AKS system pods | GA | New actionable recommendation to remediate vulnerabilities in AKS-managed system pods, replacing the previous non-actionable version. |
| π’ | Container images in Docker Hub registry should have vulnerability findings resolved | GA | New recommendation requiring vulnerability findings in Docker Hub registry container images to be resolved. |
| π’ | Unused API endpoints should be disabled and removed from Function Apps | GA | New API security recommendation for Azure Function Apps. |
| π’ | Unused API endpoints should be disabled and removed from Logic Apps | GA | New API security recommendation for Azure Logic Apps. |
| π’ | Authentication should be enabled on API endpoints hosted in Function Apps | GA | New API security recommendation requiring authentication on Azure Function Apps API endpoints. |
| π’ | Authentication should be enabled on API endpoints hosted in Logic Apps | GA | New API security recommendation requiring authentication on Azure Logic Apps API endpoints. |
| π’ | PostgreSQL Flexible Server Defender CSPM recommendations | GA | New recommendations for Azure Database for PostgreSQL Flexible Servers including logfiles.retention_days, pgaudit settings, public IP access, private endpoint, Azure services access, geo-redundant backups, and require_secure_transport. |
| π‘ | Custom IAM roles should be configured on EMR clusters | Preview | New multicloud identity recommendation for Amazon EMR. |
| π‘ | Security configuration should be enabled on EMR clusters | Preview | New multicloud data recommendation for Amazon EMR. |
| π‘ | Public network access should be disabled on EMR cluster primary nodes | Preview | New multicloud networking recommendation for Amazon EMR. |
| π‘ | Kerberos authentication should be enabled on EMR clusters | Preview | New multicloud identity recommendation for Amazon EMR. |
| π‘ | Termination protection should be enabled on EMR clusters | Preview | New multicloud compute recommendation for Amazon EMR. |
| π‘ | Logging should be enabled and encrypted on EMR clusters | Preview | New multicloud data recommendation for Amazon EMR. |
| π‘ | IAM Database Authentication should be enabled on DB Cluster | Preview | New multicloud identity recommendation. |
| π‘ | Deletion protection should be enabled on Neptune DB clusters | Preview | New multicloud data recommendation. |
| π‘ | Public access should be disabled on Neptune DB instances | Preview | New multicloud networking recommendation. |
| π‘ | New preview multicloud recommendations for AWS MSK, OpenSearch, GCP App Engine, Certificate Manager | Preview | New recommendations across networking, data, identity and access, and compute categories. |
| π‘ | An abnormally large number of rows were extracted from your SQL server | Preview | New preview alert for SQL Database and Azure Synapse Analytics. |
| π‘ | ECS Fargate and Azure serverless container recommendations | Preview | New recommendations for IAM task roles least privilege, elevated privileges, read-only root filesystem, public exposure, ECS Exec logging, ECS Exec disabled, Azure Container Apps authentication, public internet exposure, managed identities least privilege, and Azure Container Instances public exposure and managed identities least privilege. |
| π‘ | EKS and GKE node vulnerability assessment recommendations | Preview | New recommendations for resolving vulnerability findings on EKS and GKE nodes. |
Top 5 Action Items
| Priority | Action | Due | Affected Product(s) |
|---|---|---|---|
| π΄ | Restart AKS workload pods to re-inject the updated istio-proxy sidecar after the Istio add-on patch for CVE-2026-47774. | Immediate | AKS |
| π΄ | Migrate Defender for Cloud Apps file policies to Microsoft Purview DLP or auto-labeling policies before January 6, 2027. | January 6, 2027 | Defender Cloud Apps |
| π΄ | Update Microsoft Defender Antivirus on Windows to Platform 4.18.26060.3008 / Engine 1.1.26060.3008 to address CVE-2026-50656. | Immediate | Defender Endpoint |
| π΄ | Upgrade Linux Defender for Endpoint to build 101.26042.0011 if running affected builds 101.26042.0000β101.26042.0009. | Immediate | Defender Endpoint |
| π΄ | Update automation scripts making Microsoft Graph API calls to Intune to include required Multi Admin Approval headers, or add exclusions if immediate code changes are not feasible. | Immediate | Intune |
| π‘ | Review Cloud secure score changes caused by the expanded multicloud security coverage GA and assess newly added AWS/GCP recommendations. | July 2026 | Defender Cloud |
| π‘ | Enable Salesforce Real-Time Event Monitoring in the Salesforce console for improved OAuth and identity threat detection coverage. | July 2026 | Defender Cloud Apps |
| π‘ | Update advanced hunting queries using the AIAgentsInfo table to use the new AgentsInfo table before July 1, 2026. | July 1, 2026 | Defender XDR |
| π‘ | Transition existing Vulnerability Remediation Agent instances from human user identity to Microsoft Entra agentic identity within 90 days of release. | September 2026 | Intune |
| π‘ | Prepare npm automation for a short availability delay after publishing due to new publish-time malware scanning. | August 2026 | GitHub Security |
| π‘ | Stop using npm 2FA-bypass granular access tokens for sensitive account, package, and organization management actions. | Early August 2026 | GitHub Security |
| π’ | Evaluate Kubernetes misconfiguration enforcement in audit or block mode for proactive prevention of non-compliant deployments. | Q3 2026 | Defender Cloud |
| π’ | Review and adopt the new SQL VA Express Configuration for Azure SQL Managed Instance and Azure Synapse Analytics workspaces. | Q3 2026 | Defender Cloud |
| π’ | Evaluate local AI agent discovery and runtime protection preview features for Windows and macOS endpoints. | Q3 2026 | Defender Endpoint, Defender XDR |
Security Architect Observations
- Identity and agent governance expansion: Microsoft is heavily investing in AI agent identity governance across Entra ID, Defender Identity, Defender XDR, and Defender Endpoint. Architects should evaluate how agent identities (Entra Agent IDs, service principals used by AI agents, and local AI agent discovery) fit into existing Zero Trust architectures and privileged access management frameworks.
- Multicloud posture maturation: Defender for Cloudβs expanded multicloud coverage with 200+ new recommendations across 90 AWS/GCP resource types significantly deepens hybrid cloud defense-in-depth. Architects should reassess cloud security score baselines and ensure AWS/GCP onboarding includes agentless scanning to leverage container and node vulnerability assessments.
- Kubernetes admission control evolution: The introduction of Kubernetes misconfiguration enforcement in Defender for Containers shifts Kubernetes security from passive monitoring to proactive admission control. Architects should plan for audit-to-block mode transitions and assess impact on CI/CD pipelines and developer workflows.
- Deprecation and migration risks: The Defender for Cloud Apps file policy retirement (January 2027) and the
AIAgentsInfotable deprecation (July 2026) require coordinated migration planning. Architects should inventory affected policies and queries now to avoid operational gaps. - BYOD and device compliance boundary shifts: Entra ID BYOD support for Windows client and Intuneβs enhanced Android/iOS settings expand the device compliance perimeter. Architects should review Conditional Access policies to ensure new device types and platforms are appropriately governed without weakening security posture.
- Supply chain security controls: GitHubβs npm publish-time scanning, install-time security defaults, and Dependabot cooldowns materially improve supply chain resilience. Architects should update internal developer guidance and CI/CD templates to align with these new defaults.
Security Operations Observations
- New identity threat detections: Defender Identity added 10 new alerts covering Entra ID, Active Directory, and SailPoint ISC, including detection for DCSync attacks, suspicious Entra Connect authentication, and anomalous Global Admin elevation activity. SOC teams should review detection coverage, tune false positives, and update playbooks.
- AI agent runtime protection: Defender Endpointβs preview runtime protection for local AI agents on Windows introduces new alert types for blocked and audited agent loop activities (prompt injection, unsafe tool calls). SOC teams should prepare triage workflows and investigate how these alerts correlate with broader XDR incidents.
- Advanced hunting schema changes: The GA of
CloudAuditEvents,CloudDnsEvents,CloudProcessEvents, andDisruptionAndResponseEventstables, plus the previewAgentsInfotable, provide richer multicloud and AI agent telemetry. SOC analysts should update hunting queries and detection rules before theAIAgentsInfodeprecation on July 1, 2026. - AKS component patching urgency: CVE-2026-47774 in the Istio add-on and the Windows Defender Antivirus CVE-2026-50656 both require immediate action. Operations teams should prioritize pod restarts and Windows AV platform updates in production.
- Intune automation breakage risk: Multi Admin Approval now applies to Microsoft Graph API calls, which may break existing automation scripts. Operations teams must audit service principal usage for Intune modifications and implement approval headers or exclusions before enforcement causes failures.
- Salesforce connector enhancements: The new Real-Time Event Monitoring ingestion for Salesforce significantly improves OAuth abuse and session hijacking detection latency. SOC teams should coordinate with Salesforce admins to enable the required event types and validate alert fidelity.