Post

2026-06

2026-06

This release tracker is LLM-curated and based on the official Microsoft product sources listed below. It provides an architect-grade summary of recent features, changes, and announcements. Always verify critical details against the official documentation. List of all raw markdown files for the releases are at https://github.com/pisinger/pisinger.github.io/tree/main/_ms_release_radar

Microsoft Security Release Radar - June 2026


πŸ” Microsoft Sentinel

IndicatorFeatureTypeDescription
🟑Reason over Microsoft Sentinel graphs with graph toolPreviewVisual graph-based exploration of relationships across identities, devices, threats, and signals to assess coverage, dependencies, and configuration gaps via the MCP server.

πŸ›‘οΈ Microsoft Defender Cloud

IndicatorFeatureTypeDescription
🟒API security posture management for Function Apps and Logic AppsGAAPI discovery and security posture management extended to serverless and workflow APIs beyond Azure API Management.
πŸ”΅Expanded container support for cloud scopesUpdateCloud scopes now support K8s namespace, K8s cluster, multi-cloud registry, and multi-cloud repository environment types.
🟑New multicloud security recommendations (60+)PreviewAdds coverage across AWS services (AppFlow, AppStream, Cognito, Kinesis, etc.) and GCP networking recommendations.
🟒SQL VA Express Configuration for Azure SQL MI and SynapseGASQL Vulnerability Assessment Express Configuration now GA for Azure SQL Managed Instance and Azure Synapse Analytics; automatic enablement rolling out at subscription level.
🟑Discovery and posture for serverless container workloadsPreviewInventory visibility, security recommendations, and attack path analysis for Azure Container Apps and Azure Container Instances.
🟑Kubernetes misconfiguration enforcement in Defender for ContainersPreviewAudit or block mode at admission time for Kubernetes resource configurations, preventing risky deployments before production.
🟑Vulnerability assessment extended to runtime-discovered container images on EKS and GKEPreviewVA now covers images discovered at runtime on EKS and GKE that were not previously scanned from a registry.
🟑Kubernetes node vulnerability assessment extended to EKS and GKEPreviewOS-level vulnerability detection for Kubernetes node VMs across EKS and GKE, with unified remediation guidance.
🟒Microsoft Defender for Open-Source Relational Databases on AWS RDSGADatabase threat protection and sensitive data discovery for Aurora PostgreSQL/MySQL, PostgreSQL, MySQL, and MariaDB on AWS RDS.
🟑Container-level misconfiguration recommendations for KubernetesPreviewAgentless, container-level KSPM recommendations replacing cluster-level findings; cluster-level recommendations set for deprecation at GA.
🟑New recommendation to upgrade AKS for system pod vulnerabilitiesPreviewActionable β€œUpgrade Azure Kubernetes Service Version” recommendation replacing previous non-actionable guidance.
🟒Serverless protection for Azure and AWSGADiscovery and assessment of serverless resources for misconfigurations, vulnerabilities, and insecure dependencies across Azure Web Apps, Functions, and AWS Lambda.

🎯 Microsoft Defender XDR

IndicatorFeatureTypeDescription
🟑Identity Security dashboard - Human identities cardPreviewNew card showing human identities by source (Entra ID, SaaS, on-premises) in a single view.
🟑Coverage and maturity - Observed column for SaaS IdentitiesPreviewNew Observed column and Show Only Observed Applications toggle on the Review and improve coverage side panel.
🟑Local AI agent discovery on Windows endpointsPreviewAutomatic discovery of supported local AI agents (coding agents, IDE extensions, desktop assistants, runtimes) on Windows devices.
🟑Local AI agent runtime protection on Windows endpointsPreviewRuntime inspection of agent loop (prompts, tool calls, responses) with block capability for prompt injection and unsafe actions.
🟒CloudAuditEvents, CloudDnsEvents, CloudProcessEvents advanced hunting tablesGAThree new advanced hunting schema tables for multicloud audit, DNS, and process events now generally available.
🟑AgentsInfo table in advanced huntingPreviewUnified schema for agent inventory and governance replacing AIAgentsInfo; AIAgentsInfo accessible until July 1, 2026.

πŸ” Microsoft Defender Endpoint

IndicatorFeatureTypeDescription
🟑Local AI agent discovery - macOS support and new agentsPreviewDiscovery extended to macOS endpoints; adds support for Junie CLI, Kiro CLI, Warp, Hermes Agent, Goose Desktop, Perplexity Desktop, Kiro IDE, Devin Desktop, and QClaw.
🟒Enhanced Defender deployment tool for WindowsGABundles onboarding package into executable, adds deployment key and expiry date, centralized package management page in Defender portal.
🟒Selective Response ActionsGATailor high-impact security operations on Tier-0 systems and high-value assets during onboarding with precise response action controls.
🟒Enhanced exposure score in Defender Vulnerability ManagementGANew exposure score model incorporating EPSS exploit prediction data and asset context (internet-facing status, criticality).
🟒Windows Defender Antivirus Platform 4.18.26050.15 / Engine 1.1.26050.11GAPlatform and engine update for Windows Defender Antivirus.
🟒New Microsoft Secure Score recommendation - Reduce unnecessary inbound internet exposureGAIdentifies internet-facing devices that may represent unnecessary attack surface, enabling validation and remediation of unintended exposure.
🟑Local AI agent discoveryPreviewAutomatic discovery of supported local AI agents on Windows endpoints for AI agent inventory, exposure map, and advanced hunting.
🟑Local AI agent runtime protectionPreviewRuntime protection inspecting agent loop with block capability for risky activity at the device level.

πŸ’Ώ MDE Detailed Releases

Windows

IndicatorFeatureTypeDescription
🟒Windows Defender Antivirus: Platform 4.18.26050.15 / Engine 1.1.26050.11GAPlatform and engine update for Windows Defender Antivirus with enhancements and features.

macOS

IndicatorFeatureTypeDescription
πŸ”΅macOS 11 (Big Sur) and 12 (Monterey) no longer supportedUpdateDefender for Endpoint now requires macOS 15.0.1 or newer; Big Sur and Monterey are end-of-life.

Linux

IndicatorFeatureTypeDescription
πŸ”΅Monthly security fixes included in regular releasesUpdateSecurity fixes are included as part of monthly releases; refer to Microsoft Security Update Guide for details.

πŸ›‘οΈ Microsoft Defender Unified SecOps

No new updates for June 2026.


πŸ†” Microsoft Defender Identity

IndicatorFeatureTypeDescription
πŸ”΅New Entra ID security alerts (7 alerts)UpdateAlerts for anomalous activity after Global Admin elevation, reciprocal TAP creation, suspicious service principal sign-in, bulk user deletion, privileged app role removal, spike in account updates, and spike in app-resource access.
πŸ”΅New Active Directory security alerts (2 alerts)UpdateDCSync attack detection and suspicious Entra Connect account authentication alerts.
πŸ”΅New SailPoint ISC security alertUpdateSuspected brute-force attack detection for SailPoint Identity Security Cloud.

🏒 Microsoft Entra ID

No new updates for June 2026.


☁️ Microsoft Defender Cloud Apps

IndicatorFeatureTypeDescription
🟑Salesforce connector enhancementsPreviewReal-time event monitoring for OAuth abuse, session hijacking, credential stuffing; OAuth app governance for Connected Apps and ECAs; highly privileged and unused app insights.

πŸ“§ Microsoft Defender Office 365

No new updates for June 2026.


🚨 Microsoft Defender XSPM

IndicatorFeatureTypeDescription
πŸ”΄New predefined SaaS application classifications (15 classifications)SecurityCritical asset classification rules for Entra ID, Azure, M365 Defender, Intune, Dynamics 365, Purview, SharePoint, Teams, Exchange Online, OneDrive, Office Online, Power Apps, Power Automate, Power BI, and Universal Print.

β›΅ AKS

No new updates for June 2026.


πŸ“¦ Azure Container Apps

IndicatorFeatureTypeDescription
🟑Microsoft Defender for Cloud support for Azure Container Apps (Serverless Containers Posture)PreviewExtend posture management to ACA environments within Defender for Cloud’s Serverless Containers Posture experience.
🟒Confidential Compute support on Azure Container AppsGARun regulated containerized workloads with hardware-based trusted execution environments for data-in-use protection.
🟒Monitor HTTP traffic in Azure Container AppsGADedicated Azure Monitor diagnostic setting category (ContainerAppHTTPLogs) for detailed HTTP access logs.
🟒Additional OpenTelemetry destinations (New Relic, Dynatrace, Elastic)GAExpanded third-party observability platform support via OpenTelemetry endpoints.
🟒Override Scale Rules in Azure Functions on Azure Container AppsGANew allowScalingRuleOverride property to override platform-managed KEDA scale rules.
🟑Azure Container Apps SandboxesPreviewManaged sandboxed environments for running untrusted code safely in agentic applications and multi-tenant platforms.

πŸ“Š Azure Monitor

IndicatorFeatureTypeDescription
🟑Multi-stage transformations for data collection rulesPreviewFilter, parse, aggregate, and enrich logs at the agent or during ingestion using a pipeline of declarative processors.

πŸ”¬ Defender Container Sensor

IndicatorFeatureTypeDescription
🟑Sensor v0.11.3 - EKS/GKE Private clusters supportPreviewPublic Preview of support for EKS and GKE private clusters in Defender Container Sensor.

πŸ€– Microsoft Security Copilot

No new updates for June 2026.


πŸ”Ž Microsoft Purview

IndicatorFeatureTypeDescription
🟒Data security and compliance protections for Microsoft 365 Copilot CoworkGAData security and compliance protections now generally available for M365 Copilot Cowork.
πŸ”΅Access Endpoint DLP device attribute data using Advanced HuntingNewQuery Endpoint DLP device configuration and policy sync attributes through DeviceInfo table’s DlpInfo column in Advanced Hunting.
πŸ”΅Create a DLP policy that uses device scopingNewScope Endpoint DLP policies to specific device groups using dynamic device groups defined in Entra ID.
🟑External email blocking condition for Copilot DLPPreviewNew β€œEmail is received from > External users” condition to prevent Copilot from using external email as grounding data.
🟑Enhanced matched conditions for Exchange DLP eventsPreviewDetailed non-sensitive information type condition matches surfaced in DLP alerts and Activity Explorer for Exchange Online.
πŸ”΅Monitor device health with device health reports dashboardNewDashboard for monitoring device onboarding status, policy update readiness, and feature readiness for Endpoint DLP.
🟒Email and portal notifications for Data Security InvestigationsGAInvestigators receive notifications through Purview Notification Center and email when investigations are ready.
πŸ”΅Automatic data preparation in Data Security InvestigationsUpdateData preparation now runs automatically in the background as items are added to scope.
πŸ”΅Convert supported file formats to HTML in eDiscoveryNewCloud-native file formats (.loop, .page) converted to HTML for indexing and keyword searchability in review sets.
🟑View and label files with Information Protection client on macOSPreviewInformation Protection client now supports viewing and labeling files on macOS.
πŸ”΅New sensitive information types (9 types)NewAdded definitions for China, Colombia, Greenland, Russia, Singapore, South Africa, and Ukraine physical addresses; Colombia national ID and tax ID; Russia taxpayer ID.

πŸ—οΈ Microsoft Foundry

IndicatorFeatureTypeDescription
🟒Microsoft Agent Framework stable releaseGAAgent harness with skills, memory, middleware; integrations with GitHub Copilot SDK and Claude Agent SDK; multi-agent orchestration patterns.
🟒Foundry Toolkit for VS CodeGACreate agents from templates, debug with trace visualization, connect to Toolboxes, deploy to Foundry Agent Service.
🟒Voice Live prompt agentsGAReal-time voice paths with speech recognition, text-to-speech, turn detection, interruption handling, and avatars.
🟒Foundry agents publish to Microsoft Teams and M365 CopilotGAAgents can publish to Microsoft Teams and Microsoft 365 Copilot.
🟑Hosted agents in Foundry Agent ServicePreviewManaged sandboxed sessions, state, filesystem access, and framework flexibility; expected GA by early July 2026.
🟑Toolboxes in FoundryPreviewOne governed endpoint for tools, skills, MCP clients, and enterprise data.
🟑RoutinesPreviewTimer or schedule-based agent execution for overnight triage or daily reporting.
🟑Memory in Foundry Agent ServicePreviewProcedural, user, and session memory for agents.
🟑Foundry IQ knowledge basesPreviewSLA-backed retrieval and MCP access without custom indexing glue.
🟑ASSERT, ACS, RubricPreviewPolicy-driven evaluations, deterministic runtime controls, and generated scoring criteria for agent safety.
🟑Fireworks AI on FoundryPreviewAdditional model options through Azure endpoints with enterprise controls.
🟑File system tools, memory tools, deep research agentPreviewNew agent capabilities in public preview.

🧠 Microsoft Copilot Studio

No new updates for June 2026.


πŸ“Š Microsoft Fabric

IndicatorFeatureTypeDescription
🟒Real-Time Dashboards Live RefreshGAPush-based data refresh replacing periodic polling for always-current visualizations.
🟒Eventstream streaming connectors for Apache Kafka and Azure Service BusGAHardened reliability, broader authentication (SASL_SSL, SASL_PLAINTEXT, Entra ID), production-ready throughput.
🟒Business Events Capacity ConsumptionGABusiness events metered through standard Fabric capacity model with no separate license.
🟒Fabric GraphGAScalable, enterprise-grade graph modeling and analysis for complex relationships.
🟒Data agents in Microsoft 365 CopilotGABusiness users discover and chat with governed Fabric data sources inside M365 Copilot.
🟑Real-Time Dashboards powered by AIPreviewAI-first tile editor with natural language visualization generation.
🟑Time Series Visualization in Real-Time DashboardsPreviewDedicated time-based data navigation, comparison, and customization capabilities.
🟑Secure MQTT broker and Eventstream connector with mTLSPreviewMutual TLS authentication for secure IoT data ingestion across untrusted networks.
🟑Extended IoT Hub source Eventstream connectorPreviewPreserves all event metadata including system and user-defined application properties.
🟑Pagination support for Eventstream HTTP connectorPreviewPage-based and cursor-based pagination for REST API ingestion.
🟑Activator as business events publisherPreviewNo-code business event publishing from Activator into Real-Time hub.
🟑Business events persisted into EventhousePreviewAutomatic ingestion and retention of business events in dedicated KQL tables.
🟑Activator rule actions: Copy job and Publish a business eventPreviewNew actions for data copying and downstream event triggering.
🟑Activator rules for OneLake itemsPreviewAutomate actions based on file creation, deletion, and process status for OneLake items.
🟑Analyze Business Events in Eventhouse and Real-Time DashboardsPreviewHistorical KQL queries and live operational monitoring for business events.
🟑Observability for Fabric Data Agent in Microsoft FoundryPreviewTelemetry for every Data Agent call including latency, status, and error details.
🟑Creator Agent for SQL and Eventhouse sources in Fabric Data AgentPreviewAI-assisted creation experience for Fabric Data Agent configurations.
🟑Improved NL2SQL Engine for Fabric Data AgentPreviewImproved accuracy and transparency for natural language to SQL translation.
🟑Code Interpreter Tool for Fabric Data AgentPreviewPython execution inside agent workflows for statistical analysis and visualization.

Top 5 Action Items

PriorityActionDueAffected Product(s)
πŸ”΄Migrate advanced hunting queries from AIAgentsInfo to AgentsInfo tableJuly 1, 2026Defender XDR
πŸ”΄Review and validate new SaaS application critical asset classifications in Defender Exposure ManagementImmediateDefender XSPM
πŸ”΄Enable SQL VA Express Configuration automatic rollout or validate existing configurationWithin 30 daysDefender Cloud
🟑Enable Salesforce Real-Time Event Monitoring for enhanced OAuth and identity threat detectionAs soon as possibleDefender Cloud Apps
🟑Review new Defender for Identity security alerts and tune SOAR playbooks for Entra ID and AD detectionsThis monthDefender Identity

Security Architect Observations

  • Defense-in-depth for AI agents: The introduction of local AI agent discovery and runtime protection across Windows and macOS endpoints represents a new attack surface that must be incorporated into endpoint security baselines and zero-trust architectures. Agent loop inspection (prompts, tool calls, responses) adds a critical runtime control layer.
  • Multicloud container security parity: Defender for Cloud now provides near-feature-parity for container vulnerability assessment, node scanning, and misconfiguration enforcement across AKS, EKS, and GKE. Architects should standardize on a single Defender CSPM plan for multicloud Kubernetes estates.
  • Identity detection expansion: Seven new Entra ID alerts and two new AD alerts (including DCSync detection) significantly improve coverage for identity-based attacks. The new SailPoint ISC brute-force alert extends identity threat protection to third-party IdPs, reducing blind spots in hybrid identity architectures.
  • API security posture expansion: GA of API security for Function Apps and Logic Apps extends the API security perimeter beyond API Management. Attack path analysis now covers serverless APIs, requiring updated threat models for event-driven and workflow-based architectures.
  • Compliance and data governance: New sensitive information types across 9 geopolitical regions and macOS Information Protection client support expand DLP coverage. The Copilot Cowork data security protections and external email grounding controls address prompt injection risks in AI-assisted workflows.

Security Operations Observations

  • SOC workflow changes for AI agent monitoring: New alerts from AI agent runtime protection and AI agent inventory in advanced hunting require new detection rules and incident response playbooks. SOC teams should familiarize themselves with the AgentsInfo schema before the AIAgentsInfo deprecation on July 1.
  • New identity alert tuning required: Seven new Entra ID alerts and DCSync detection will generate new signal volume. SOC teams should establish baselines for anomalous Global Admin elevation, reciprocal TAP creation, and service principal sign-in patterns to manage false positive risk.
  • Container security alert consolidation: Container-level KSPM recommendations replace cluster-level findings. SOC teams should prepare for transitional duplicate alerts and update automation rules once cluster-level recommendations are deprecated at GA.
  • Expanded multicloud monitoring scope: 60+ new multicloud security recommendations across AWS and GCP services expand the monitoring surface. SOC teams should prioritize enabling these recommendations and integrating findings into existing ticketing and remediation workflows.
  • DLP investigation improvements: Advanced Hunting access to Endpoint DLP device attributes and enhanced Exchange DLP event matching provide richer investigation context. SOC analysts can now query DLP policy sync status at scale without portal exports.

References

ProductURL
Defender XDRhttps://learn.microsoft.com/en-us/defender-xdr/whats-new
Unified SecOpshttps://learn.microsoft.com/en-us/unified-secops/whats-new
Defender Endpointhttps://learn.microsoft.com/en-us/defender-endpoint/whats-new-in-microsoft-defender-endpoint
Defender Endpoint Releaseshttps://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-endpoint-releases
Defender Identityhttps://learn.microsoft.com/en-us/defender-for-identity/whats-new
Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/whats-new
Microsoft Entra IDhttps://learn.microsoft.com/en-us/entra/fundamentals/whats-new
Defender Cloud Appshttps://learn.microsoft.com/en-us/defender-cloud-apps/release-notes
Defender Office 365https://learn.microsoft.com/en-us/defender-office-365/defender-for-office-365-whats-new
Defender Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/release-notes
AKShttps://github.com/Azure/AKS/releases
Azure Container Appshttps://learn.microsoft.com/en-us/azure/container-apps/whats-new
Azure Monitorhttps://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/whats-new
Defender Container Sensorhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-sensor-change-log
Security Copilothttps://learn.microsoft.com/en-us/copilot/security/whats-new-copilot-security
Defender Exposure Managementhttps://learn.microsoft.com/en-us/security-exposure-management/whats-new
Microsoft Purviewhttps://learn.microsoft.com/en-us/purview/whats-new
Microsoft Foundryhttps://devblogs.microsoft.com/foundry/category/whats-new/
Microsoft Copilot Studiohttps://learn.microsoft.com/en-us/microsoft-copilot-studio/whats-new
Microsoft Fabrichttps://learn.microsoft.com/en-us/fabric/fundamentals/whats-new
This post is licensed under CC BY 4.0 by the author.

MS Release Radar

Wiz Release Radar

MS Tech News