Post

2026-06

2026-06

This release tracker is LLM-curated and based on the official Microsoft product sources listed below. It provides an architect-grade summary of recent features, changes, and announcements. Always verify critical details against the official documentation. List of all raw markdown files for the releases are at https://github.com/pisinger/pisinger.github.io/tree/main/_ms_release_radar

Microsoft Security Release Radar - June 2026

πŸ” Microsoft Sentinel

No new features, updates, or security patches were present in the provided release notes for this reporting period.


πŸ›‘οΈ Microsoft Defender Cloud

IndicatorFeatureTypeDescription
🟒Expanded multicloud security coverageGASignificantly broadens posture assessment for AWS and GCP environments, adding support for about 90 new resource types and over 200 new security recommendations across data, identity and access, networking, compute, and container categories. These recommendations now affect Cloud secure score.
🟒Cloud security reportingGACreate, customize, and share cloud security insights across your organization using built-in and custom reports in the Microsoft Defender portal. Custom cards can be tailored when building custom reports.
🟒API security posture management for Function Apps and Logic AppsGAExtends API security posture management beyond Azure API Management to serverless and workflow APIs, with automated onboarding, security recommendations, and attack path analysis.
🟒SQL Vulnerability Assessment Express ConfigurationGANow generally available for Azure SQL Managed Instance and Azure Synapse Analytics workspaces at no extra cost, removing the need for a customer-managed storage account. A new unified SQL VA REST API provides consistent management across supported SQL resource types.
🟒Microsoft Defender for Open-Source Relational Databases on AWS RDSGAGenerally available for Amazon Web Services RDS instances; usage starts appearing on July 2026 bills. Provides database threat protection and sensitive data discovery for Aurora PostgreSQL, Aurora MySQL, PostgreSQL, MySQL, and MariaDB.
🟒Serverless protection for Azure and AWSGADiscover serverless resources and assess them for misconfigurations, vulnerabilities, and insecure dependencies across Azure Web Apps, Azure Functions, and AWS Lambda.
πŸ”΅Support for additional Azure regions in the UAE geographyNew/UpdatedDefender for APIs and API security posture management with Defender CSPM expanded to UAE North and UAE Central regions. API discovery and posture capabilities for Azure Function Apps and Azure Logic Apps also expanded to these regions.
πŸ”΅General availability of Defender for Key Vault in Azure Government cloudNew/UpdatedDefender for Key Vault in Azure Government cloud now aligns with the commercial cloud offering in feature coverage and runtime protection capabilities.
πŸ”΅Expanded container support for cloud scopesNew/UpdatedCloud scopes now support K8s namespace, K8s cluster, multi-cloud registry, and multi-cloud repository for greater flexibility grouping container and Kubernetes resources.
🟑New multicloud security recommendationsPreviewMore than 60 new multicloud security recommendations in public preview across AWS AppFlow, AppStream, AppSync, Athena, Auto Scaling, CodeBuild, Cognito, Comprehend, DMS, DataSync, FSx, Kendra, Keyspaces, Kinesis, MQ, Neptune, and QuickSight.
🟑Discovery and posture for serverless container workloadsPreviewAdds inventory visibility, security recommendations for misconfigurations and vulnerability assessment findings, and attack path analysis for Azure Container Apps and Azure Container Instances.
🟑Kubernetes misconfiguration enforcement in Defender for ContainersPreviewExtends Kubernetes security from audit to audit or block mode at deployment time, preventing risky Kubernetes deployments before they reach production. Available only in commercial clouds.
🟑Vulnerability assessment extended to runtime-discovered container images on EKS and GKEPreviewRuntime-discovered container images on Amazon EKS and Google GKE are now assessed for vulnerabilities, providing additional findings beyond registry-based scanning. AWS or GCP must be onboarded into Defender for Cloud.
🟑Kubernetes node vulnerability assessment extended to EKS and GKEPreviewOS-level vulnerabilities in Kubernetes node VMs across EKS and GKE are now detected, surfacing an β€œUpgrade Kubernetes nodes” recommendation. Requires agentless scanning enabled.
🟑Container-level misconfiguration recommendations for KubernetesPreviewAgentless, container-level KSPM misconfiguration recommendations replace previous cluster-level findings with more granular insights. Cluster-level recommendations will be deprecated at GA.
🟑New actionable recommendation to upgrade AKS for system pod vulnerabilitiesPreviewReplaces the previous non-actionable recommendation with a resolvable remediation path for vulnerabilities in AKS-managed system pods.

🎯 Microsoft Defender XDR

IndicatorFeatureTypeDescription
🟒Phishing Triage Agent and Security Alert Triage Agent least-privilege permissionGAAgents now use the more limited Email & collaboration content: Emails associated with alerts (read) permission instead of the broader All Emails (read) permission.
🟒Advanced hunting schema tables GAGAThe DisruptionAndResponseEvents, CloudAuditEvents, CloudDnsEvents, and CloudProcessEvents tables are now generally available in advanced hunting.
🟑Entity enrichments with threat intelligencePreviewEntity pages for IP addresses, domains, URLs, and files now include a Threat Intelligence Insights tab surfacing reputation scores, attributed threat reports, infrastructure relationships, and sandbox analysis from Microsoft Threat Intelligence.
🟑Identity Security dashboard β€” Human identities cardPreviewNew card showing human identities by source (Entra ID, SaaS, and on-premises) for a single view of where human identities live.
🟑Coverage and maturity β€” Observed SaaS applicationsPreviewThe Review and improve coverage side panel for SaaS Identities now includes an Observed column and a Show Only Observed Applications toggle.
🟑Local AI agent discovery on Windows endpointsPreviewAutomatically discovers supported local AI agents running on onboarded Windows devices; discovered agents appear as assets in the AI agent inventory, exposure map, and advanced hunting.
🟑Local AI agent runtime protection on Windows endpointsPreviewRuntime protection inspects the agent loop and can block risky activity before execution, helping stop prompt injection and unsafe agent actions at the device level.
🟑AgentsInfo advanced hunting tablePreviewNew unified schema supporting agent inventory and governance for all agent types. The AIAgentsInfo table remains accessible until July 1, 2026.

πŸ” Microsoft Defender Endpoint

IndicatorFeatureTypeDescription
🟒Local AI agent discovery β€” macOS support and new agentsPreview[macOS] Local AI agent discovery now supports macOS endpoints and adds discovery for Junie CLI, Kiro CLI, Warp, Hermes Agent, Goose Desktop, Perplexity Desktop, Kiro IDE, Devin Desktop, and QClaw.
🟒Enhanced Defender deployment tool for WindowsGA[Windows] New version bundles the onboarding package into the executable, generates a required deployment key, supports package expiry dates, and adds a Deployment packages page in the Defender portal for centralized visibility.
🟒Selective Response ActionsGAEnables precise control over how response actions are applied on Tier-0 systems and other high-value assets during onboarding.
🟒Enhanced exposure score in Defender Vulnerability ManagementGANew exposure score model incorporates exploit prediction data (EPSS) and asset context factors such as internet-facing status and criticality to improve risk prioritization.
🟒New Microsoft Secure Score recommendationGANew recommendation Reduce unnecessary inbound internet exposure on internet-facing devices provides centralized visibility to validate expected exposure and prioritize remediation.
🟑Local AI agent discoveryPreview[Windows] Automatically discovers supported local AI agents running on onboarded Windows devices, surfacing them in the AI agent inventory, exposure map, and advanced hunting.
🟑Local AI agent runtime protectionPreview[Windows] Inspects the agent loop on Windows endpoints and can block risky activity before execution, helping stop prompt injection and unsafe agent actions at the device level.
🟒Windows Defender Antivirus platform releaseGA[Windows] Platform 4.18.26050.15 / Engine 1.1.26050.11 released; see MDE Detailed Releases section for enhancements.
🟒Linux build releaseGA[Linux] Build 101.26042.0009 released; see MDE Detailed Releases section for enhancements and a fix.

πŸ’Ώ MDE Detailed Releases

Windows

IndicatorFeatureTypeDescription
πŸ”΄Fixed CVE-2026-50656 (Elevation of Privilege)Security[Windows] Addressed Microsoft Defender Elevation of Privilege vulnerability in the Microsoft Malware Protection Engine, improving protection against local privilege escalation scenarios.
πŸ”΅Controlled Folder Access notification fixNew/Updated[Windows] Resolved an issue where Controlled Folder Access toast notifications continuously appeared for the C: drive because of AMD driver injection into protected processes.
πŸ”΅Endpoint DLP Chrome upload enforcement reliabilityNew/Updated[Windows] Improved Endpoint DLP enforcement reliability for Chrome uploads to Google Drive, ensuring policy-based blocking is consistently applied during bulk file transfers.
πŸ”΅Endpoint DLP custom JIT notification fixNew/Updated[Windows] Fixed an issue in Endpoint DLP where Chrome and Firefox uploads could occasionally display the default JIT notification instead of the organization-configured custom message due to a timing-related race condition.

macOS

IndicatorFeatureTypeDescription
πŸ”΅Security and critical updatesNew/Updated[macOS] Build 101.26042.0020 includes security and critical updates as part of the monthly release cycle.

Linux

IndicatorFeatureTypeDescription
🟒Fixed build issue causing disablement after upgrade/reinstallGA/FIX[Linux] Fixed an issue where Defender for Endpoint on Linux could become disabled after upgrade or reinstall scenarios followed by a system reboot for builds 101.26042.0000–101.26042.0009.
🟒Offline security intelligence updatesGA[Linux] Customers can now configure offline security intelligence updates using Security Settings Management policies in the Defender portal.
🟑Scheduled antivirus scansPreview[Linux] Customers can centrally schedule antivirus scans on Linux using managed JSON and policy settings through the Defender portal.
πŸ”΅Better user attribution in security eventsNew/Updated[Linux] File, process, and network security events now include the original login user’s ID even when actions are performed via sudo or under root, improving insider threat detection and investigations.
πŸ”΅Improved login event accuracyNew/Updated[Linux] Improved login event accuracy by preventing stale remote IP data from being reused across different login event types.
πŸ”΅Added package publishing support for newer Linux distributionsNew/Updated[Linux] Added support for Fedora 43, RockyLinux 10, AlmaLinux 10, and SUSE Linux Enterprise Server 16.
πŸ”΅Faster threat remediationNew/Updated[Linux] Malware is now quarantined and cleaned up more quickly, improving response time when threats are detected.
πŸ”΅EDR SDK updates and stability improvementsNew/Updated[Linux] Updates and stability improvements help the Defender agent run more reliably with continuous protection.

πŸ›‘οΈ Microsoft Defender Unified SecOps

No new features, updates, or security patches were present in the provided release notes for this reporting period.


πŸ†” Microsoft Defender Identity

IndicatorFeatureTypeDescription
🟒Identity risk scoreGANow generally available; score ranges from 0 to 100 and reflects how likely an identity is to be compromised and how much damage a compromise could cause, based on criticality level and privileged role assignments.
πŸ”΅New Defender for Identity security alertsNew/UpdatedNew alerts added for Entra ID (anomalous activity after Global Admin elevation, reciprocal Temporary Access Pass creation, suspicious service principal sign-in, suspicious bulk user deletion, suspicious privileged app role removal, suspicious sign-in with spike in account updates, spike in distinct application-resource access combinations), Active Directory (DCSync attack, suspicious Entra Connect account authentication), and SailPoint ISC suspected brute-force attack.
🟑NHI inventory enhancementsPreviewExpanded Entra ID inventory now includes all Microsoft Entra service principals, and the Permissions tab shows assigned Microsoft Entra roles alongside API permissions.
🟑Visibility into service principals used by AI agentsPreviewNon-human identity inventory now identifies which Entra ID service principals are used by AI agents via a new β€œUsed by AI agents” column and insight card.

🏒 Microsoft Entra ID

IndicatorFeatureTypeDescription
🟒BYOD support for Windows client using Entra registrationGABring Your Own Device support for Windows client using Entra-registered devices is now generally available, enabling users and partners to access corporate resources from their own devices without requiring domain join.
🟒Jailbreak/Root Detection in Authenticator AppGAMicrosoft Authenticator now blocks users with rooted/jailbroken devices from adding or using work or school accounts; users must move to compliant devices. Secure by default with no admin configuration required.
🟒SCIM 2.0 APIs for Microsoft Entra ID in US Gov cloudGAStandards-based option for managing users and groups in Microsoft Entra using SCIM 2.0 is now generally available in the US Government cloud.
πŸ”΅External users directly assigned to Access PackagesNew/UpdatedEntitlement Management admins can now directly assign external users not in the directory to an access package using the user’s email; users are invited as Guest users and governed.
πŸ”΅Kerberos key rotation improved reliabilityNew/UpdatedEnhanced validation logic attempts decryption with both primary and secondary Kerberos keys during key rollover, improving resiliency and reducing authentication disruption.
πŸ”΅Extended Conditional Access protections for Agent’s user accountsNew/UpdatedConditional Access now supports targeting agent user accounts with precision, protecting against risky agent activity, requiring compliant devices for agents, and applying device platform and network filters.
πŸ”΅Domainless SAML IdP federation for workforce tenantsNew/UpdatedDomainless SAML federation allows external users to authenticate using IdP-managed credentials regardless of email domain, removing the need for domain matching.
πŸ”΅Microsoft Entra Backup and RecoveryNew/UpdatedBuilt-in solution automatically backs up critical directory objects (users, groups, applications, Conditional Access policies, etc.) so admins can restore them to a previously known good state. Retains daily backups for 7 days for P1/P2 tenants.
πŸ”΅New built-in Entra role for SOC identity responseNew/UpdatedNew SOC Identity Responder built-in role enables SOC analysts to perform identity containment actions (disable users, revoke sessions, force password resets) without broad directory administrative privileges. Supports PIM and role-assignable groups.
πŸ”΅Prevent unauthorized changes to AD groups with AD group enforcementNew/UpdatedFor customers using group provisioning to AD, designated AD groups can be locked so modifications can only be made through the Entra provisioning service, preventing drift.
πŸ”΅Improved restore experience for device-bound Authenticator app passkeys on iOSNew/UpdatedStarting August 2026, users with iCloud and iCloud Keychain backup enabled will see an improved restore flow for device-bound Authenticator passkeys on new iOS devices.

πŸ“± Microsoft Intune

IndicatorFeatureTypeDescription
🟒Enrollment time grouping for new Apple ADE enrollment policiesGAIdentify a device’s Microsoft Entra security group during enrollment so policies, apps, and settings can be applied earlier in the setup process for iOS/iPadOS and macOS.
πŸ”΅Available macOS PKG apps update automaticallyNew/Updated[macOS] Updates now deploy automatically when the same app policy is updated with a new version, eliminating the need for users to manually select Install or Reinstall.
πŸ”΅Newly available protected app for IntuneNew/UpdatedChatGPT is now available as a protected app for Microsoft Intune.
πŸ”΅Enterprise App Management support for GCC High and DoDNew/Updated[Windows] EAM extended to GCC High and DoD cloud environments for discovering, deploying, and keeping prepackaged apps up to date.
πŸ”΅Auto-update for Enterprise App Management applicationsNew/Updated[Windows] Intune now supports automatic updates for EAM applications, detecting newer versions and updating targeted devices automatically.
πŸ”΅New Android Enterprise settings in the Intune settings catalogNew/Updated[Android Enterprise] New settings added for Applications (block apps from exposing app functions, block widgets from work profile apps), Connectivity (preferential network service, block airplane mode, block cellular 2G, block configuring cell broadcasts/mobile networks/VPN, block network reset, block outgoing calls/SMS, block ultra wideband, select minimum Wi-Fi security level), and General (block printing, block setting user icon/wallpaper, block adding eSIM profiles).
πŸ”΅Support for WPA3-Personal in iOS/iPadOS Wi-Fi profilesNew/Updated[iOS/iPadOS] WPA3-Personal is now supported as a security-type option for Wi-Fi device configuration profiles.
πŸ”΅Microsoft Tunnel adds support for RHEL 9.7New/Updated[Linux] Microsoft Tunnel Gateway now supports Red Hat Enterprise Linux 9.7, requiring Podman 5.8.2. Customers upgrading from Podman v3 must recreate containers and reinstall Tunnel.
πŸ”΅Updated security baseline for Microsoft 365 Apps for EnterpriseNew/Updated[Windows] Version v2512 baseline aligns with the most recent security guidance; three settings are pending availability in a future update.
πŸ”΅New Microsoft Defender Antivirus settings for Linux Server devicesNew/Updated[Linux] Linux Server Antivirus policy now includes offline security intelligence update and scheduled scan settings.
πŸ”΅New setting added to Windows security baseline version 25H2New/Updated[Windows 11] Added Disable Internet Explorer 11 Launch Via COM Automation setting with baseline default of Enabled to reduce attack surface.
πŸ”΅Multi Admin Approval now enforces on API calls made by automationNew/UpdatedAPI calls made by automation through Microsoft Graph API are now subject to the same approval workflow as interactive operations; calls without required approval headers return HTTP 403.
πŸ”΅Managed Win32 app content now requires HTTPS deliveryNew/UpdatedIntune now requires HTTPS delivery for managed Win32 app content; organizations using Microsoft Connected Cache without HTTPS may see increased internet traffic.
πŸ”΅Android Enterprise personally owned devices with work profile uses Android Management APINew/Updated[Android Enterprise] Personally owned devices with work profile now use web-based enrollment and a modern policy delivery implementation aligned with corporate-owned devices.
πŸ”΅Custom top bar elements on Managed Home ScreenNew/Updated[Android Enterprise] Custom text up to 63 characters can now be displayed in the top bar of Managed Home Screen, supporting dynamic variables for kiosk scenarios.
πŸ”΅Managed Home Screen exit lock task mode password now requires device configuration profileNew/Updated[Android Enterprise] Exit lock task mode password for Managed Home Screen can no longer be configured via app configuration policy; must use a device configuration profile.
πŸ”΅New Block Bluetooth sharing settingNew/Updated[Android Enterprise] New setting in the settings catalog to block Bluetooth sharing on fully managed, dedicated, and corporate-owned work profile devices.
πŸ”΅Use DDM to manage Apple Intelligence settingsNew/Updated[iOS/iPadOS, macOS] Apple deprecated several intelligence-related settings in the MDM restrictions payload with release 26.4; use DDM configurations instead.
πŸ”΅Silence apps on Managed Home ScreenNew/Updated[Android Enterprise] Apps can now be silenced when Managed Home Screen prompts for authentication, preventing activities, notifications, and toasts during locked states.
πŸ”΅New Microsoft Edge settings in the Windows settings catalogNew/Updated[Windows] 148 new Microsoft Edge settings added, including New Tab Page feed visibility, M365 authentication popups in work profiles, Copilot side pane auto-open, extended SharedWorker lifetime, developer tools allowlist/blocklist, WebSocket proxy max connections, browsing with Copilot controls, and Copilot new tab page policies.
πŸ”΅New 802.1x Wired Networks device configuration profile for iOS/iPadOSNew/Updated[iOS/iPadOS 17+] Supports EAP protocols (TLS, PEAP, TTLS) for secure wired Ethernet access, ideal for M-series iPads in education and regulated industries.
πŸ”΅Detect and block Shadow AI using properties catalog, device query, and security baselinePreview[Windows] Using Intune, detect and block a Local AI Agent like OpenClaw via a Properties catalog policy, Device Query, and the Local AI Agent Baseline β€” OpenClaw (Preview).
πŸ”΅In-place renewal of Cloud PKI issuing CAsNew/UpdatedIssuing CAs can now be renewed in-place without creating new CAs or manually updating SCEP profiles, keeping certificate issuance uninterrupted.
πŸ”΅Strict Tunnel Mode for Microsoft Tunnel on AndroidNew/Updated[Android] All network traffic is forced through the VPN tunnel; if the connection drops, all traffic is blocked until reconnection. Requires Android Management API.
πŸ”΅Grant enhanced security permissions to a Mobile Threat Defense app on AndroidNew/Updated[Android] New toggle grants exemptions (suspension, hibernation, power restrictions, user controls) to one MTD partner app per tenant on COBO and COPE devices.
πŸ”΅Vulnerability Remediation Agent now uses Microsoft Entra agentic identityPreviewThe agent now uses an Entra agentic identity instead of a human user identity. Human user identity support expires 90 days after this release.
πŸ”΅Advanced Intune capabilities added to Microsoft 365 E3 and E5New/UpdatedEMS E3 (in M365 E3) now includes Remote Help, Advanced Analytics, and Intune Plan 2. M365 E5 adds Endpoint Privilege Management, Enterprise Application Management, and Microsoft Cloud PKI. Rolling out gradually with 30-day advance notice.
πŸ”΅APP Multiple Managed AccountsNew/Updated[iOS/iPadOS] Mobile application management now supports multiple managed accounts within the same app, starting with Microsoft Teams on iOS/iPadOS v8.10.0 or later.

☁️ Microsoft Defender Cloud Apps

IndicatorFeatureTypeDescription
⚫File policies retiring January 6, 2027DeprecationFile-based data protection is moving from Defender for Cloud Apps to Microsoft Purview. File policies retire on January 6, 2027; review and recreate them as Microsoft Purview DLP or auto-labeling policies before the retirement date.
🟑Salesforce connector enhancementsPreviewReal-Time Event Monitoring data ingestion for near real-time detection of identity and OAuth threats, plus OAuth app governance for Salesforce Connected Apps and External Client Apps (ECAs). Includes new insights for highly privileged and unused apps, with permissions visible on the App governance page.

πŸ“§ Microsoft Defender Office 365

No new features, updates, or security patches were present in the provided release notes for this reporting period.


🚨 Microsoft Security Exposure Management

IndicatorFeatureTypeDescription
πŸ”΅New predefined classifications for AI agentsNew/UpdatedAdded Executive-Sponsored AI Agent classification to the critical assets list for agents created or owned by senior executives.
πŸ”΅New predefined Identity classificationsNew/UpdatedAdded Widespread Local Admin on Servers, Widespread Local Admin on Workstations, and Widespread Local Admin on Servers and Workstations classification rules to the critical assets list.
πŸ”΅New predefined SaaS application classificationsNew/UpdatedAdded 16 new SaaS application classifications to the critical assets list for Microsoft Entra ID, Azure, 365 Defender, Intune, Dynamics 365, Purview, SharePoint Online, Teams, Exchange Online, OneDrive, Office Online, Power Apps, Power Automate, Power BI, and Universal Print.
🟑Overview dashboardPreviewUpdated overview dashboard consolidates signals from cloud resources and devices into a single, action-oriented view organized around Resolve Now and Monitor Exposure.

β›΅ AKS

IndicatorFeatureTypeDescription
🟒Kubernetes version 1.36GANow generally available and supported as a Long Term Support (LTS) version; no preview enablement required.
🟒FIPS on Ubuntu 22.04 node poolsGAFIPS 140-3 compliance now supported on Ubuntu 22.04 node pools; FIPS and Trusted Launch can be enabled in the same node pools when using Ubuntu on AKS.
🟒NVIDIA RTX PRO 6000 Blackwell Server Edition GPU VM sizesGASupported as managed GPUs on Ubuntu node pools using the NVIDIA GRID driver.
🟒Confidential VMs with Azure LinuxGAGenerally available for AKS workloads using Azure Linux.
πŸ”΄Istio service mesh add-on CVE-2026-47774SecurityRevisions asm-1-29 and asm-1-28 upgraded to patches 1.29.4 and 1.28.8 to address CVE-2026-47774. Restart workload pods to trigger re-injection of the updated istio-proxy sidecar.
πŸ”΅Windows Server 2022 retirement extendedNew/UpdatedWindows Server 2022 retires on June 30, 2028; not supported in Kubernetes 1.37+. Starting June 30, 2029, AKS will remove all existing node images, causing scaling failures.
πŸ”΅AKS Automatic β€” disable default application routing add-onNew/UpdatedOn AKS Automatic clusters running Kubernetes 1.36+, the default application routing add-on with Gateway API can be disabled to use the Istio-based service mesh add-on with Istio CNI.
πŸ”΅Deployment Safeguards in Enforce mode expandedNew/UpdatedNow applies default resource requests to DaemonSets and Jobs in addition to Deployments and StatefulSets.
πŸ”΅Custom Prometheus metric scraping and log collection on AKS AutomaticNew/UpdatedNow supported on AKS Automatic clusters with managed system node pools.
πŸ”΅IPv6 pod CIDR auto-derivationNew/UpdatedAKS now automatically derives the IPv6 pod CIDR from the pod subnet when creating dual-stack Azure CNI static block allocation clusters.
πŸ”΅Windows gMSA CoreDNS conflict validationNew/UpdatedAKS now rejects enabling gMSA or changing its root domain name when the cluster’s coredns-custom ConfigMap already defines a server block for the same domain.
πŸ”΅FIPS rejection on Kata node poolsNew/UpdatedAKS now rejects enabling FIPS on Pod Sandboxing (Kata) workload runtime node pools because the Kata node image doesn’t carry FIPS compliance.
πŸ”΅Pod Sandboxing on Standard_DadsV7-seriesNew/UpdatedPod Sandboxing (Kata) node pools can now be created on Standard_DadsV7-series VM sizes.
πŸ”΅AKS Automatic migration to Base SKUNew/UpdatedAKS Automatic clusters with managed system node pools can now be migrated to the AKS Base SKU.
πŸ”΅Azure Service Mesh add-on default behavior changesNew/UpdatedFor asm-1-30 (estimated early July), new installations will use Istio CNI instead of privileged init containers for proxy redirection. Gateway pod node preferences also change for asm-1-30+.
πŸ”΅Fixed Azure Policy add-on exemption for aks-istio-systemNew/UpdatedFixed an issue where the aks-istio-system namespace was not exempted from the Azure Policy add-on when using application routing with Gateway API in Istio mode.
πŸ”΅Fixed Multiple Standard Load Balancers label selector validationNew/UpdatedFixed a bug where valid domain-prefixed label keys were rejected in node selectors; validation now follows standard Kubernetes semantics.
πŸ”΅Component updatesNew/UpdatedAzure File CSI Driver upgraded to v1.35.4 on AKS 1.35/1.36; Azure Blob Storage CSI driver upgraded to v1.26.14 (1.33) and v1.27.7 (1.34+); Cilium updated to v1.17.15 (1.32) and v1.16.19 (1.31); Cloud Provider Azure updated to June 18, 2026 releases; new Windows, Azure Linux, and Ubuntu node images published.

πŸ“¦ Azure Container Apps

No new features, updates, or security patches were present in the provided release notes for this reporting period.


🧱 Azure Container Instances

No new features, updates, or security patches were present in the provided release notes for this reporting period.


⚑ Azure Functions

IndicatorFeatureTypeDescription
🟒Rolling updates in Flex ConsumptionGAZero-downtime deployments now generally available in the Flex Consumption plan, gracefully replacing live instances by draining batches while dynamically scaling out the latest version.
🟒Azure Functions supports hosting MCP AppsGASupports building and hosting Model Context Protocol (MCP) Apps using the Azure Functions MCP Extension, enabling interactive UIs that render directly within chat experiences for Python, TypeScript, .NET, and Java.
🟒Override Scale Rules in Azure Functions on Azure Container AppsGACustomers can now override platform-managed KEDA scaling rules with custom KEDA scaling rules via the allowScalingRuleOverride property, available in API version 2026-03-02-preview and later.
🟒Azure Functions Support for Node.js 24GANode.js 24 is now generally available for Azure Functions on Linux and Windows, including the Flex Consumption plan. Remote Build on Flex Consumption is rolling out over the coming week.
🟒Built-in Grafana dashboardsGAZero-setup Grafana dashboards for health, performance, and scale of function apps directly in the Azure portal; no separate Grafana instance required.
🟑New project templates and template gallery for Azure Functions in VS CodePreviewRedesigned Create New Project experience with a rich, visual template gallery replacing the multi-step Quick Pick wizard, plus a β€œGenerate with Copilot” mode.
🟑Azure Functions includes managed connectorsPreview1,400+ managed connectors now available as first-class triggers and operations, enabling direct connections to Microsoft 365, Salesforce, ServiceNow, SAP, Dynamics, and other systems.
🟑Serverless agents runtimePreviewSupports building AI agents as a first-class workload using a markdown-first programming model, responding to conversations, reacting to events, and taking actions across enterprise systems. Supported on the Flex Consumption plan.
🟑Copilot-assisted coding & agent skillsPreviewAI assistant plugins and agent skills for VS Code, CLI, and azd that provide current Azure Functions expertise following the Agent Skills open standard, grounded in official Azure documentation.
🟑Go language supportPreviewGo is now supported as a first-class language option for event-driven serverless apps on the Flex Consumption plan.

πŸ” Azure Logic Apps

No new features, updates, or security patches were present in the provided release notes for this reporting period.


πŸ“Š Azure Monitor

IndicatorFeatureTypeDescription
🟑Azure Copilot Observability AgentPreviewExpanded Observability Agent documentation with 12 new articles covering autonomous operations, deep investigations, context memory, custom instructions, resource provisioning, and transparency.
🟑Multi-stage transformations for data collection rulesPreviewFilter, parse, aggregate, and enrich logs at the agent or during ingestion using a pipeline of declarative processors.
🟒Metrics export for Log Analytics workspacesGAMetrics export reached general availability; updated create and reference articles with expanded configuration details.
πŸ”΅Tutorial: Alert on virtual machine issuesNew/UpdatedNew tutorial for configuring Azure Monitor alerts on virtual machine issues, covering metric, log, and activity log alert rule creation and management.
πŸ”΅Azure Monitor overview pageNew/UpdatedNew article introducing the Azure Monitor overview page, surfacing health status, key signals, and recommended actions across monitored resources.
πŸ”΅Service Level IndicatorsNew/UpdatedService Level Indicators reached general availability.
πŸ”΅Configure health rollupNew/UpdatedNew how-to article for configuring health rollup in Azure Monitor health models, covering count, percentage, and impact-based aggregation strategies.
🟑Protected tables in a Log Analytics workspacePreviewPreview feature restricting write and delete access on sensitive tables at the table level.
🟑Dynamic thresholds for query-based metric alertsPreviewQuery-based metric alert rules now support dynamic thresholds, applying machine learning to PromQL expressions over Prometheus and OpenTelemetry metrics.
πŸ”΅Diagnostic settings FAQ expandedNew/UpdatedStarting June 15, 2026, export billing for platform logs streamed through diagnostic settings expands to all remaining Azure resources; previously free log categories may now incur charges.

πŸ”¬ Defender Container Sensor

No new features, updates, or security patches were present in the provided release notes for this reporting period.


πŸ€– Microsoft Security Copilot

No new features, updates, or security patches were present in the provided release notes for this reporting period.


πŸ”Ž Microsoft Purview

No new features, updates, or security patches were present in the provided release notes for this reporting period.


πŸ—οΈ Microsoft Foundry

IndicatorFeatureTypeDescription
🟒Claude generally availableGAAnthropic’s Claude models are now generally available in Microsoft Foundry, hosted on Azure with the Messages API, prompt caching, extended thinking, and tool streaming.
🟒Foundry agents publish to Microsoft 365 Copilot and TeamsGAAgents can now be published directly into Microsoft 365 Copilot and Teams through a single governed publishing pipeline, supporting goal-oriented execution with checkpoints and human escalation.
🟒Foundry Toolkit for VS CodeGANow generally available for creating agents from templates, debugging runs locally with trace visualization, connecting to Toolboxes, and deploying to Foundry Agent Service.
🟒Microsoft Agent Framework stable releaseGAAgent harness with skills, memory, and middleware; integrations with GitHub Copilot SDK and Claude Agent SDK; and multi-agent orchestration patterns including Magentic-One are now in stable release.
🟒Voice Live prompt agentsGAGenerally available for real-time voice agent scenarios.
🟑Foundry autopilot agentsPreviewNew agent category with its own Entra Agent ID, productivity license, email, calendar, and Teams presence, designed for shared spaces like group chats.
🟑Toolboxes in FoundryPreviewAdds Skills, Work IQ, Fabric IQ, Browser Automation, and Tool Search, providing one managed endpoint for tools, skills, MCP clients, and enterprise data.
🟑Routines in Foundry Agent ServicePreviewScheduled and triggered agent run control for timer-based or schedule-based execution.
🟑Agent OptimizerPreviewClosed-loop evaluate β†’ generate candidates β†’ rank β†’ deploy workflow for hosted agents; public preview expected roughly 30 days after June 3 announcement.
🟑Memory enhancementsPreviewNew procedural memory, management experiences, and time-to-live (TTL) controls in Foundry Agent Service.
🟑Voice Live API 2026-06-01-previewPreviewAdds the azure-realtime-native structured voice type and a client-side echo cancellation reference option.
🟑Foundry Local on Azure LocalPreviewMulti-node Kubernetes deployment, disconnected/air-gapped operation, new vLLM inference runtime, automatic GPU inference tuning, and model caching.
🟑Improved NL2SQL Engine for Fabric Data AgentPreviewImproves accuracy, transparency, and resilience when translating natural language to SQL; asks clarifying questions and surfaces structured diagnostics.
🟑Code Interpreter Tool for Fabric Data AgentPreviewRuns Python directly inside agent workflows for statistical analysis, forecasting, and visualization beyond database queries.
🟑Creator Agent for SQL and Eventhouse sourcesPreviewAI-assisted creation experience generating and refining Fabric Data Agent configurations for SQL and Eventhouse scenarios.
πŸ”΅Foundry joins the OpenEnv standardNew/UpdatedHosted agents, Toolboxes, Memory, Managed Compute, and evaluation/optimization stack unified into a reinforcement-learning loop, including post-training via Tinker and ECHO.
πŸ”΅SDK updatesNew/UpdatedJava azure-ai-projects 2.1.0 (GA) with Data Generation, Models, and Routines preview clients; .NET 2.1.0-beta.4; Python and JS/TS converging on 2.3.0 release.
πŸ”΅Hosted agents expected GANew/UpdatedExpected to reach general availability by early July 2026, with sandboxed sessions, state, filesystem access, and framework flexibility.

🧠 Microsoft Copilot Studio

IndicatorFeatureTypeDescription
🟒Windows 365 for Agents MCP serverGAGives agents full operational control of a Windows 365 cloud PC, including desktop interaction, browser automation, and semantic UI inspection.
🟒Claude Sonnet 5 or GPT-5.5 ChatGANow selectable as the agent’s primary AI model for improved response quality and reasoning.
🟑New agent experiencePreviewProduction-ready preview using an enhanced orchestration runtime for improved response quality and reasoning, available alongside the classic experience.
🟑Microsoft IQPreviewConnects agents to organizational data, giving access to emails, calendar events, files, Teams messages, and people information.
🟑SkillsPreviewModular, self-contained sets of instructions that can be created once, added to multiple agents, and exported as Markdown or packages.
🟑MemoryPreviewPersistent context across interactions capturing user preferences and patterns per user for more relevant and personalized responses.
🟑Condition groupsPreviewManage multiple conditions in a single Message, Question, or prompt node, reducing branching and making topic flows easier to review and maintain.
🟑Voice agents with Teams Phone AgentPreviewHandle specialized call workflows like billing, prescription refills, and order status with seamless handoff between Teams Phone Agent and custom voice agents.
🟑Connect other agentsPreviewAgents can delegate requests to specialized agents, enabling modular solutions with a single front-door agent routing to the right specialist.
🟑Foundry IQ integrationPreviewGrounds agent responses in a knowledge base already built and tuned in Azure AI Foundry.

πŸ“Š Microsoft Fabric

IndicatorFeatureTypeDescription
🟒Real-Time Dashboards Live RefreshGAPushes new data to dashboard tiles as soon as it lands, replacing periodic refresh polling with always-current visualizations.
🟒Eventstream streaming connectors for Apache Kafka and Azure Service BusGAHardened reliability, broader authentication support (SASL_SSL, SASL_PLAINTEXT, Microsoft Entra), and production-ready throughput for ingesting Kafka topics and Service Bus queues.
🟒Business Events Capacity ConsumptionGAMetered through the standard Fabric capacity model with no separate license required.
🟒Fabric GraphGAScalable, enterprise-grade graph solution for modeling, visualizing, and analyzing complex relationships within data.
🟒Operations agentGAAutonomous agent that monitors data with Real-Time Intelligence, reasons over Fabric IQ ontology, and runs pipelines, notebooks, user data functions, and Power Automate flows with approval, tracing, audit, and governance.
🟒Data agents in Microsoft 365 CopilotGABusiness users can discover and chat with governed Fabric data sources directly inside Microsoft 365 Copilot, with admin-managed publishing and Entra ID-enforced data permissions.
🟑Workspace outbound access protection for Azure and Fabric eventsPreviewExtends outbound network controls to cross-workspace event consumption, requiring the Real-Time Events connector in workspace data connection rules.
🟑Real-Time Dashboards powered by AIPreviewAI-first tile editor where users describe needs in natural language and Copilot generates visualizations without requiring KQL expertise.
🟑Time Series Visualization in Real-Time DashboardsPreviewDedicated capabilities for navigating, comparing, and customizing time-based data, including legend search, pin-and-overlay, multiple aligned-time panels, and zoom with a time slider.
🟑Secure MQTT broker and Eventstream connector with mTLSPreviewEventstream MQTT source connector now supports specifying CA and client certificates from Azure Key Vault for mutually authenticated encrypted connections.
🟑Extended IoT Hub source Eventstream connectorPreviewPreserves all event metadata, including system properties and user-defined application properties, enabling device identity joining and ingestion latency computation.
🟑Pagination support for Eventstream HTTP connectorPreviewIngests paginated REST API responses through page-based or cursor-based pagination without custom orchestration.
🟑Activator as business events publisherPreviewActivator can emit structured business events into Real-Time hub when conditions are met, making signals discoverable and routable.
🟑Business events persisted into EventhousePreviewEach business event maps to a dedicated KQL table in Eventhouse by default for historical queries and correlation.
🟑Activator rule actions: Copy job and Publish a business eventPreviewNew actions for copying data between sources/destinations and triggering downstream processes that consume business events.
🟑Activator rules for OneLake itemsPreviewCreate and manage Activator rules for OneLake items to automate actions based on file creation/deletion or process statuses.
🟑Billing for Fabric PlanningPreviewHybrid model combining role-based and session-based pricing with job-based pricing for automated operations, metering against unified Fabric capacity-unit (CU) model.
🟑Observability for Fabric Data Agent in Microsoft FoundryPreviewSurfaces telemetry for every call to a Fabric Data Agent used as a tool inside a Foundry agent, including latency, status, and error details.

πŸ™ GitHub Security

IndicatorFeatureTypeDescription
🟒Innersource security advisoriesGAGitHub Advanced Security enterprise customers can now publish internal security advisories with a new REST API endpoint; Dependabot notifies affected repositories and opens upgrade PRs.
🟒GitHub Code QualityGAGenerally available on GitHub Enterprise Cloud and GitHub Team; pairs CodeQL deterministic analysis with AI-assisted detection for maintainability and reliability issues, with Copilot Autofix suggestions.
🟑Open source license compliancePreviewEnterprise-wide license policy with ruleset-based checks that block noncompliant dependencies before they reach production; integrates with pull request checks and introduces the Enterprise Open Source License Policy Manager role.
🟑AI security detections on pull requestsPreviewAI-powered security detections on pull requests expand vulnerability coverage beyond CodeQL-supported languages; requires GitHub Code Security and GitHub Copilot license.
🟑Security reviews in the GitHub Copilot appPreview/security-review slash command scans current workstream changes and returns high-confidence security findings, actionable suggestions, and a prioritized view for vulnerability classes like injection flaws and XSS.
πŸ”΅CodeQL 2.26.1New/UpdatedImproved framework coverage for Go, Java/Kotlin, and JavaScript/TypeScript; reduced false positives in Rust analysis.
πŸ”΅Improvements to secret scanning and public monitoringNew/UpdatedResend is now a secret scanning partner; new secret types from APIclub and Resend are detected; VolcEngine secrets are blocked by push protection by default; secret_category field added to webhook payload.
πŸ”΅Dependabot no longer infers .npmrcNew/UpdatedDependabot now supports a scope property on registries in dependabot.yml to generate correct .npmrc, making dependabot.yml the authoritative source for registry configuration.
πŸ”΅Upcoming cloud data retention policy for closed security alertsNew/UpdatedStarting August 25, 2026, closed Dependabot alerts closed two or more years ago will move to archival storage and no longer appear in the UI or API; can be downloaded as CSV by admins.
πŸ”΅npm publish-time malware scanning and dual-use metadataNew/UpdatedNewly published npm packages are automatically scanned before becoming available (typical delay ~5 minutes). New contentPolicy field and required DISCLOSURE file for dual-use content.
πŸ”΅Dependabot alerts on malicious packages across more ecosystemsNew/UpdatedGitHub Advisory Database now ingests malware advisories from the OpenSSF malicious-packages repository, expanding coverage across npm, PyPI, and more.
πŸ”΅GitHub Actions holds potentially malicious workflows for approvalNew/UpdatedCertain workflow runs in public repositories are now held for approval by a repository collaborator with write access before executing, protecting against compromised credential attacks.
πŸ”΅Dependabot version updates introduce default package cooldownNew/UpdatedDependabot now waits at least three days after a new release before opening a version update PR, reducing risk from compromised or broken releases; security updates remain immediate.
πŸ”΅npm v12 install-time security defaultsNew/UpdatedallowScripts defaults to off; --allow-git and --allow-remote default to none. Dependency lifecycle scripts and git/remote dependencies now require explicit opt-in.
πŸ”΅npm 2FA-bypass GAT deprecationNew/UpdatedGranular access tokens configured to bypass 2FA will lose the ability to perform sensitive account, package, and organization management actions; expected early August 2026. Publishing will require human 2FA approval.
πŸ”΅Code scanning AI security detections billingNew/UpdatedDuring public preview, AI security detections require a GitHub Copilot license and draw down AI credits; usage consumes credits only when detections run.

πŸ›‘οΈ Microsoft Defender Cloud (Defender Recommendations & Alerts)

IndicatorFeatureTypeDescription
🟒SQL VA individual recommendations at database levelGAMultiple individual SQL Vulnerability Assessment recommendations (xp_cmdshell, latest updates, GUEST role, ad hoc distributed queries, CLR, trusted assemblies, ownership chaining, remote admin connections, default trace, CHECK_POLICY, password expiration, principal mapping, AUTO_CLOSE, BUILTIN\Administrators, sa account, PUBLIC role permissions, sa login, unused service broker endpoints, Database Mail XPs, server permissions, database user name conflicts, etc.) released in GA as part of transitioning from grouped server-level to individual database-level recommendations.
🟒Upgrade Azure Kubernetes Service to remove vulnerabilities from AKS system podsGANew actionable recommendation to remediate vulnerabilities in AKS-managed system pods, replacing the previous non-actionable version.
🟒Container images in Docker Hub registry should have vulnerability findings resolvedGANew recommendation requiring vulnerability findings in Docker Hub registry container images to be resolved.
🟒Unused API endpoints should be disabled and removed from Function AppsGANew API security recommendation for Azure Function Apps.
🟒Unused API endpoints should be disabled and removed from Logic AppsGANew API security recommendation for Azure Logic Apps.
🟒Authentication should be enabled on API endpoints hosted in Function AppsGANew API security recommendation requiring authentication on Azure Function Apps API endpoints.
🟒Authentication should be enabled on API endpoints hosted in Logic AppsGANew API security recommendation requiring authentication on Azure Logic Apps API endpoints.
🟒PostgreSQL Flexible Server Defender CSPM recommendationsGANew recommendations for Azure Database for PostgreSQL Flexible Servers including logfiles.retention_days, pgaudit settings, public IP access, private endpoint, Azure services access, geo-redundant backups, and require_secure_transport.
🟑Custom IAM roles should be configured on EMR clustersPreviewNew multicloud identity recommendation for Amazon EMR.
🟑Security configuration should be enabled on EMR clustersPreviewNew multicloud data recommendation for Amazon EMR.
🟑Public network access should be disabled on EMR cluster primary nodesPreviewNew multicloud networking recommendation for Amazon EMR.
🟑Kerberos authentication should be enabled on EMR clustersPreviewNew multicloud identity recommendation for Amazon EMR.
🟑Termination protection should be enabled on EMR clustersPreviewNew multicloud compute recommendation for Amazon EMR.
🟑Logging should be enabled and encrypted on EMR clustersPreviewNew multicloud data recommendation for Amazon EMR.
🟑IAM Database Authentication should be enabled on DB ClusterPreviewNew multicloud identity recommendation.
🟑Deletion protection should be enabled on Neptune DB clustersPreviewNew multicloud data recommendation.
🟑Public access should be disabled on Neptune DB instancesPreviewNew multicloud networking recommendation.
🟑New preview multicloud recommendations for AWS MSK, OpenSearch, GCP App Engine, Certificate ManagerPreviewNew recommendations across networking, data, identity and access, and compute categories.
🟑An abnormally large number of rows were extracted from your SQL serverPreviewNew preview alert for SQL Database and Azure Synapse Analytics.
🟑ECS Fargate and Azure serverless container recommendationsPreviewNew recommendations for IAM task roles least privilege, elevated privileges, read-only root filesystem, public exposure, ECS Exec logging, ECS Exec disabled, Azure Container Apps authentication, public internet exposure, managed identities least privilege, and Azure Container Instances public exposure and managed identities least privilege.
🟑EKS and GKE node vulnerability assessment recommendationsPreviewNew recommendations for resolving vulnerability findings on EKS and GKE nodes.

Top 5 Action Items

PriorityActionDueAffected Product(s)
πŸ”΄Restart AKS workload pods to re-inject the updated istio-proxy sidecar after the Istio add-on patch for CVE-2026-47774.ImmediateAKS
πŸ”΄Migrate Defender for Cloud Apps file policies to Microsoft Purview DLP or auto-labeling policies before January 6, 2027.January 6, 2027Defender Cloud Apps
πŸ”΄Update Microsoft Defender Antivirus on Windows to Platform 4.18.26060.3008 / Engine 1.1.26060.3008 to address CVE-2026-50656.ImmediateDefender Endpoint
πŸ”΄Upgrade Linux Defender for Endpoint to build 101.26042.0011 if running affected builds 101.26042.0000–101.26042.0009.ImmediateDefender Endpoint
πŸ”΄Update automation scripts making Microsoft Graph API calls to Intune to include required Multi Admin Approval headers, or add exclusions if immediate code changes are not feasible.ImmediateIntune
🟑Review Cloud secure score changes caused by the expanded multicloud security coverage GA and assess newly added AWS/GCP recommendations.July 2026Defender Cloud
🟑Enable Salesforce Real-Time Event Monitoring in the Salesforce console for improved OAuth and identity threat detection coverage.July 2026Defender Cloud Apps
🟑Update advanced hunting queries using the AIAgentsInfo table to use the new AgentsInfo table before July 1, 2026.July 1, 2026Defender XDR
🟑Transition existing Vulnerability Remediation Agent instances from human user identity to Microsoft Entra agentic identity within 90 days of release.September 2026Intune
🟑Prepare npm automation for a short availability delay after publishing due to new publish-time malware scanning.August 2026GitHub Security
🟑Stop using npm 2FA-bypass granular access tokens for sensitive account, package, and organization management actions.Early August 2026GitHub Security
🟒Evaluate Kubernetes misconfiguration enforcement in audit or block mode for proactive prevention of non-compliant deployments.Q3 2026Defender Cloud
🟒Review and adopt the new SQL VA Express Configuration for Azure SQL Managed Instance and Azure Synapse Analytics workspaces.Q3 2026Defender Cloud
🟒Evaluate local AI agent discovery and runtime protection preview features for Windows and macOS endpoints.Q3 2026Defender Endpoint, Defender XDR

Security Architect Observations

  • Identity and agent governance expansion: Microsoft is heavily investing in AI agent identity governance across Entra ID, Defender Identity, Defender XDR, and Defender Endpoint. Architects should evaluate how agent identities (Entra Agent IDs, service principals used by AI agents, and local AI agent discovery) fit into existing Zero Trust architectures and privileged access management frameworks.
  • Multicloud posture maturation: Defender for Cloud’s expanded multicloud coverage with 200+ new recommendations across 90 AWS/GCP resource types significantly deepens hybrid cloud defense-in-depth. Architects should reassess cloud security score baselines and ensure AWS/GCP onboarding includes agentless scanning to leverage container and node vulnerability assessments.
  • Kubernetes admission control evolution: The introduction of Kubernetes misconfiguration enforcement in Defender for Containers shifts Kubernetes security from passive monitoring to proactive admission control. Architects should plan for audit-to-block mode transitions and assess impact on CI/CD pipelines and developer workflows.
  • Deprecation and migration risks: The Defender for Cloud Apps file policy retirement (January 2027) and the AIAgentsInfo table deprecation (July 2026) require coordinated migration planning. Architects should inventory affected policies and queries now to avoid operational gaps.
  • BYOD and device compliance boundary shifts: Entra ID BYOD support for Windows client and Intune’s enhanced Android/iOS settings expand the device compliance perimeter. Architects should review Conditional Access policies to ensure new device types and platforms are appropriately governed without weakening security posture.
  • Supply chain security controls: GitHub’s npm publish-time scanning, install-time security defaults, and Dependabot cooldowns materially improve supply chain resilience. Architects should update internal developer guidance and CI/CD templates to align with these new defaults.

Security Operations Observations

  • New identity threat detections: Defender Identity added 10 new alerts covering Entra ID, Active Directory, and SailPoint ISC, including detection for DCSync attacks, suspicious Entra Connect authentication, and anomalous Global Admin elevation activity. SOC teams should review detection coverage, tune false positives, and update playbooks.
  • AI agent runtime protection: Defender Endpoint’s preview runtime protection for local AI agents on Windows introduces new alert types for blocked and audited agent loop activities (prompt injection, unsafe tool calls). SOC teams should prepare triage workflows and investigate how these alerts correlate with broader XDR incidents.
  • Advanced hunting schema changes: The GA of CloudAuditEvents, CloudDnsEvents, CloudProcessEvents, and DisruptionAndResponseEvents tables, plus the preview AgentsInfo table, provide richer multicloud and AI agent telemetry. SOC analysts should update hunting queries and detection rules before the AIAgentsInfo deprecation on July 1, 2026.
  • AKS component patching urgency: CVE-2026-47774 in the Istio add-on and the Windows Defender Antivirus CVE-2026-50656 both require immediate action. Operations teams should prioritize pod restarts and Windows AV platform updates in production.
  • Intune automation breakage risk: Multi Admin Approval now applies to Microsoft Graph API calls, which may break existing automation scripts. Operations teams must audit service principal usage for Intune modifications and implement approval headers or exclusions before enforcement causes failures.
  • Salesforce connector enhancements: The new Real-Time Event Monitoring ingestion for Salesforce significantly improves OAuth abuse and session hijacking detection latency. SOC teams should coordinate with Salesforce admins to enable the required event types and validate alert fidelity.

References

ProductURL
Defender XDRhttps://learn.microsoft.com/en-us/defender-xdr/whats-new
Unified SecOpshttps://learn.microsoft.com/en-us/unified-secops/whats-new
Defender Endpointhttps://learn.microsoft.com/en-us/defender-endpoint/whats-new-in-microsoft-defender-endpoint
Defender Endpoint Releaseshttps://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-endpoint-releases
Defender Identityhttps://learn.microsoft.com/en-us/defender-for-identity/whats-new
Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/whats-new
Microsoft Entra IDhttps://learn.microsoft.com/en-us/entra/fundamentals/whats-new
Microsoft Intunehttps://learn.microsoft.com/en-us/intune/whats-new/
Defender Cloud Appshttps://learn.microsoft.com/en-us/defender-cloud-apps/release-notes
Defender Office 365https://learn.microsoft.com/en-us/defender-office-365/defender-for-office-365-whats-new
Defender Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/release-notes
AKShttps://github.com/Azure/AKS/releases
Azure Container Appshttps://learn.microsoft.com/en-us/azure/container-apps/whats-new
Azure Container Instanceshttps://www.microsoft.com/releasecommunications/api/v2/azure?search=Azure%20Container%20Instances&$top=100
Azure Functionshttps://www.microsoft.com/releasecommunications/api/v2/azure?search=Azure%20Functions&$top=100
Azure Logic Appshttps://www.microsoft.com/releasecommunications/api/v2/azure?search=Logic%20Apps&$top=100
Azure Monitorhttps://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/whats-new
Defender Container Sensorhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-sensor-change-log
Security Copilothttps://learn.microsoft.com/en-us/copilot/security/whats-new-copilot-security
Defender Exposure Managementhttps://learn.microsoft.com/en-us/security-exposure-management/whats-new
Microsoft Purviewhttps://learn.microsoft.com/en-us/purview/whats-new
Microsoft Foundryhttps://devblogs.microsoft.com/foundry/category/whats-new/
Microsoft Copilot Studiohttps://learn.microsoft.com/en-us/microsoft-copilot-studio/whats-new
Microsoft Fabrichttps://learn.microsoft.com/en-us/fabric/fundamentals/whats-new
GitHub Securityhttps://github.blog/changelog/
Defender Recommendations & Alertshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/release-notes-recommendations-alerts
This post is licensed under CC BY 4.0 by the author.