Post

2026-07

2026-07

This release tracker is LLM-curated and based on the official Microsoft product sources listed below. It provides an architect-grade summary of recent features, changes, and announcements. Always verify critical details against the official documentation. List of all raw markdown files for the releases are at https://github.com/pisinger/pisinger.github.io/tree/main/_ms_release_radar

Microsoft Security Release Radar - July 2026

πŸ“¦ Azure Container Apps

IndicatorFeatureTypeDescription
🟑Azure Container Apps SandboxesPreviewPublic preview of sandboxed execution environments for improved isolation. Also introduces HTTP traffic logs, additional managed OpenTelemetry destinations for New Relic, Dynatrace, and Elastic, and custom KEDA scale rule overrides for Azure Functions on Container Apps.
πŸ”΅Regional expansionNew/UpdatedAzure Container Apps now available in six additional regions: Germany North, New Zealand North, Chile Central, Korea South, Belgium Central, and Jio India Central.
πŸ”΅Bring Your Own Orchestrator for JobsNew/UpdatedCommunity-maintained templates for connecting existing workflow engines (Airflow, Temporal, Argo Workflows, Durable Functions, Logic Apps Standard, Dapr Workflow) to Container Apps Jobs.

β›΅ AKS

IndicatorFeatureTypeDescription
🟒Artifact StreamingGAStream container images from Azure Container Registry to AKS. AKS pulls only necessary layers for initial pod startup, reducing deployment time.
🟒Secure TLS bootstrappingGA/FixNow enabled by default in westcentralus and eastasia regions for enhanced cluster security.
🟒Secure Boot for GPU nodesGA/FixSecure Boot now supported when using GPUs with Azure Linux OS.
🟒Trusted Launch managementGA/FixvTPM and Secure Boot can now be enabled/disabled on existing Linux node pools.
🟑Node Disruption PolicyPreviewControl when reimage-triggering operations are allowed so disruptive changes happen during defined windows.
🟑Automatic zone placementPreviewAKS dynamically selects best availability zones for node pools without manual specification.
🟑Prepared Image SpecificationPreviewCreate preconfigured node images with required container images and customizations for faster node startup.
🟑Full caching mode for Ephemeral OSPreviewCache entire OS locally on nodes, enabling continued operation during remote storage unavailability.
πŸ”΄Istio security fixesSecurityIstio revisions asm-1-28, asm-1-29, and asm-1-30 include fixes for ISTIO-SECURITY-2026-005. Action required: restart Istio workload pods to re-inject newer istio-proxy patch versions.
πŸ”΄containerd CVE patchesSecurityUpdated from 1.7.32 to 1.7.33, including fixes for CVE-2026-53488, CVE-2026-47262, and CVE-2026-34986.
πŸ”΄Cilium security updatesSecurityCilium, Hubble, and ACNS security agent images updated across Kubernetes versions 1.32, 1.34, and 1.36 with security patches.
⚫enableCustomCATrust retirementDeprecationOn September 14, 2026, enableCustomCATrust preview property retires. Remove –disable-custom-ca-trust to avoid scaling failures.
⚫Windows Server Annual Channel retirementDeprecationAKS no longer supports creating node pools with Windows Server Annual Channel for Containers. Existing pools unaffected.
⚫Flatcar Container Linux retirementDeprecationAKS no longer supports creating node pools or clusters with Flatcar Container Linux. Existing node pools unaffected.
⚫Kubernetes 1.30 deprecationDeprecationKubernetes 1.30 deprecated. Upgrade to supported version or opt into long-term support.
πŸ”΅Windows Server 2025 defaultNew/UpdatedStarting with Kubernetes 1.37 (expected October 2026), Windows Server 2025 is default OS SKU for new Windows node pools.
πŸ”΅Node Auto-Provisioning improvementsNew/UpdatedSets kubernetes.azure.com/mode: user on default NodePool; uses In-VM spot rebalancing signal for improved eviction notifications.
πŸ”΅Network plugin case insensitivityNew/UpdatedAKS now accepts mixed-case networkPlugin values during cluster creation.
πŸ”΅CNI Overlay Dual-StackNew/UpdatedWindows CNI Overlay Dual-Stack no longer requires preview feature registration.
πŸ”΅Bug fixesNew/UpdatedMultiple fixes including API Server Authorized IP Ranges enforcement, Container Insights onboarding, kube-proxy configuration, App Routing Istio values, Static Egress Gateway reconciliation, Cilium source IP verification, and Node Auto Provisioning issues.

Security Bulletin: AKS-2026-0005

IndicatorFeatureTypeDescription
πŸ”΅Ubuntu 22.04 kernel CVE reclassificationsUpdateCanonical reclassified many Linux kernel CVEs from β€œNeeds evaluation” to β€œVulnerable” status, causing increased scanner findings. Many CVEs are unfixed upstream. AKS consumes kernel packages directly from Canonical and cannot independently remediate unfixed vulnerabilities. Upgrading node images alone may not clear findings until Canonical publishes upstream fixes.

πŸ“Š Azure Monitor

IndicatorFeatureTypeDescription
⚫Azure Diagnostics extension retirementDeprecationWAD and LAD retired March 31, 2026. Migration guidance now available: Azure Monitor Agent for storage, Log Analytics data export for Event Hubs, OpenTelemetry metrics for guest OS performance counters.
⚫Legacy Container Insights auth retirementDeprecationLegacy authentication retired; clusters running it after September 30, 2026 unsupported. Migrate to managed identity authentication.
⚫VM client data to Event Hubs/Storage retirementDeprecationPreview feature retires July 31, 2026. Alternatives: custom tables on Auxiliary plan, data export rules.
⚫VM Insights Map retirementDeprecationVM Insights Map and Dependency Agent retire June 30, 2028. Migration guidance and Azure Advisor recommendations available.
🟑Mirror Azure Monitor data in FabricPreviewExpose Log Analytics tables to Fabric through OneLake shortcuts without copying data for cross-domain operational intelligence.
🟑Export job for Log AnalyticsPreviewExport historical records from Log Analytics workspace to Azure Blob Storage in Parquet format for backup, analysis, and compliance.
🟑Advanced platform metricsPreviewPaid tier enabling more granular metrics collection with same Azure Monitor tools and APIs.
🟑Health Models CLIPreviewNew azure CLI extension for building, updating, and querying health models end-to-end.
πŸ”΅GenAI feedback captureNew/UpdatedNew section covering thumbs-up/thumbs-down feedback capture for agent responses via OpenTelemetry log records with gen_ai.evaluation.* attributes.
πŸ”΅DCR browse experience defaultNew/UpdatedNew data collection rule browse and creation experiences now default in Azure portal.
πŸ”΅Log Analytics autosaveNew/UpdatedAutomatically saves session state (query tabs, work mode, scope, time range) to browser local storage for 30 days.
πŸ”΅Table feature support referenceNew/UpdatedNew reference article listing every Azure Monitor Logs table and support for Basic plan, Auxiliary/Lake plan, DCR transformations, and Logs Ingestion API.
πŸ”΅Log Analytics table plan updatesNew/UpdatedMerged standalone Auxiliary plan article; highlights new features bringing Auxiliary logs up to Basic and Analytics standards.

☁️ Microsoft Defender Cloud Apps

No new features or updates documented for July 2026.

🧠 Microsoft Copilot Studio

No specific features documented for July 2026.

πŸ”¬ Defender Container Sensor

IndicatorFeatureTypeDescription
🟒Sensor v0.11.4GAGeneral Availability of EKS/GKE Private clusters support.
🟒Sensor v0.10.6GA/FixSecurity fixes patching vulnerabilities in authentication, runtime components, and dependencies addressing credential exposure risks. Performance improvements for process event filtering CPU usage. Improved authentication stability with projected service account tokens (PSAT).
🟒Sensor v0.9.62GA/FixSecurity fixes patching vulnerabilities in authentication, runtime components, and dependencies addressing credential exposure risks. Performance improvements for process event filtering CPU usage.
🟒Sensor v0.8.55GA/FixSecurity fixes patching vulnerabilities in authentication, runtime components, and dependencies addressing credential exposure risks. Performance improvements for process event filtering CPU usage.

🚨 Microsoft Security Exposure Management

IndicatorFeatureTypeDescription
🟑MAI-Augmented scan profile (on-demand)PreviewMAI-Augmented scan profile now available for on-demand scans triggered from Microsoft Defender portal. Security teams can select this profile when starting scans from Manage scans.
🟑MAI-Augmented scan profile (CLI)PreviewMAI-Augmented profile available via Defender CLI, including MAI-Cyber-1-Flash cyber-specialized model extending the agentic scanner.
πŸ”΅Agentic code scannerPrivate PreviewMulti-model agentic AI system detecting code vulnerabilities with greater depth and accuracy than traditional static analysis. Scans runnable from Defender CLI or GitHub connector.
πŸ”΅OT data connectorsNew/UpdatedSupport for Armis, Dragos, and Forescout OT data connectors bringing operational technology asset and vulnerability data into Defender portal for unified IT/OT visibility.

πŸ›‘οΈ Microsoft Defender Cloud

IndicatorFeatureTypeDescription
🟒Database-level SQL VA recommendationsGASQL vulnerability assessment recommendations transitioned from grouped to individual recommendations at database level. Each SQL VA rule surfaced as its own recommendation affecting Cloud Score.
🟒Container-level KSPM recommendationsGAAgentless container-level Kubernetes misconfiguration recommendations assessing individual containers. Deprecated cluster-level recommendations: HostPath volume mounts, allowed ports, host networking/ports, CAP_SYS_ADMIN capability, AppArmor profile restrictions.
🟒AKS version upgrade recommendationGAActionable recommendation identifying minimum AKS version upgrade required to remediate vulnerabilities in AKS-managed system pods.
🟒Runtime-discovered image VA for EKS/GKEGAVulnerability assessment extended to runtime-discovered container images on Amazon EKS and Google GKE for unified multicloud coverage.
🟒Kubernetes node VA for EKS/GKEGAKubernetes node (host) vulnerability assessment extended to EKS and GKE, providing parity with AKS capability.
🟒Docker Hardened image scanningGAVulnerability scanning support extended to Docker Hardened container images.
🟒Kubernetes misconfiguration enforcementGAEvaluates Kubernetes resource configurations at admission time with audit/block capabilities. Available via automatic provisioning for AKS, Azure Arc, AWS, and GCP.
🟒Serverless container discovery and postureGAInventory visibility, security recommendations, and attack path analysis for Azure Container Apps, Azure Container Instances, and Amazon ECS on AWS Fargate.
⚫Legacy grouped recommendationsDeprecationRetirement completed July 31, 2026. Deprecated data no longer accessible via API. Customers should migrate automation and queries to individual recommendations.
⚫Deprecated plan onboarding blockDeprecationPlan enablement API now blocks onboarding to five deprecated plans: Defender for AKS, Defender for ACR, Defender for Key Vault, Defender for DNS, Defender for ARM. Existing subscriptions unaffected.
πŸ”΅Foundational CSPM opt-in modelNew/UpdatedStarting October 27, 2026, Foundational CSPM moves to opt-in for new Azure subscriptions (no longer enabled by default). Existing subscriptions retain current configuration.

πŸ›‘οΈ Microsoft Defender Cloud - Recommendations & Alerts

IndicatorFeatureTypeDescription
🟒SQL VA individual recommendationsGAOver 20 new database-level SQL vulnerability assessment recommendations released in GA as part of grouped-to-individual transition.
🟒AKS system pods VA recommendationGAUpgrade Azure Kubernetes Service to remove vulnerabilities from AKS system pods.
🟒Docker Hub image VA recommendationGAContainer images in Docker Hub registry should have vulnerability findings resolved.
🟒Multicloud recommendations expansionGAOver 200 new multicloud security recommendations for AWS and GCP resources across data, identity and access, networking, compute, and container categories affecting Secure Score.
🟒PostgreSQL Flexible Server recommendationsGASeven new recommendations for Azure Database for PostgreSQL Flexible Servers including logging, secure transport, private endpoints, and backup configurations.
🟒API endpoint security recommendationsGAFour new recommendations for Function Apps and Logic Apps: disable unused endpoints, enable authentication on API endpoints.
🟑EMR cluster security recommendationsPreviewSix new preview recommendations for AWS EMR clusters covering IAM roles, security configuration, network access, Kerberos authentication, termination protection, and logging.
🟑AWS database and analytics recommendationsPreviewMultiple preview recommendations for Amazon AppFlow, Athena workgroups, EBS volumes, Comprehend, DMS, DataSync, FSx, Kendra, Keyspaces, Kinesis, Amazon MQ, Neptune, and QuickSight covering encryption, access control, backups, and network security.
🟑Serverless container recommendationsPreviewEight preview recommendations for ECS Fargate tasks and Azure Container Apps covering IAM/task roles, privileged containers, read-only filesystems, public exposure, ECS Exec logging, authentication, and managed identity least privilege.
πŸ”΅SQL data exfiltration alertPreviewNew preview alert: β€œAn abnormally large number of rows were extracted from your SQL server” for detecting potential data exfiltration.

🎯 Microsoft Defender XDR

IndicatorFeatureTypeDescription
🟑AI agent posture risk assessmentPreviewMicrosoft Defender now assesses posture risk for AI agents (enterprise and local) based on configuration, access, runtime activity, endpoint/user context, and active alerts. Provides recommendations to prioritize risky agents.
🟒Domain investigation pageGAActive Directory domain security investigation page showing domain properties, deployment health, identity summary, service account breakdown, sensitive entities, recommendations, group policies, and trust relationships.
🟑Threat detection for Agent 365 agentsPreviewAnalyzes runtime signals from agent interactions, tool usage, and execution patterns to surface alerts in Microsoft Defender XDR. Supports Copilot Studio, Foundry, M365 Copilot Agent Builder, and Agent 365 SDK integrations.
🟒Real-time protection for Agent 365 toolingGAEvaluates tool invocations and responses against security policies with allow/block capabilities for Work IQ MCP and customer MCP tools onboarded to Agent 365.

πŸ” Microsoft Defender Endpoint

IndicatorFeatureTypeDescription
🟑AI agent runtime protection updatesPreviewEnhanced AI agent runtime protection with vendor-supported agent event interfaces on standard channels (no Beta required). Support for Codex CLI, GitHub Copilot app, and network inspection for Node.js-based Claw agents including OpenClaw.
🟒Defender Deployment Tool for LinuxGASimplifies deployment by combining installation, onboarding, upgrades, and uninstallation into single workflow. Automates prerequisite validation, supports custom paths, specific versions from preferred update channels, and local repositories. Provides Device Timeline integration, Advanced Hunting queries, and detailed error reporting.
πŸ”΅macOS Build 101.26062.0009New/UpdatedRelease version 20.126062.9.0 with bug/performance fixes and extended network diagnostics via mdatp health --details network_configuration.
πŸ”΅macOS Build 101.26052.0016New/UpdatedRelease version 20.126052.16.0 with security and critical updates.
πŸ”΅Linux Build 101.26052.0012New/UpdatedImproved antivirus enforcement visibility via mdatp health command. More accurate connectivity tests with inline diagnostics. Fixed FIPS-enabled RHEL 8/9 installation issues and WordPress Core inventory detection.
πŸ”΅Windows Antivirus Platform 4.18.26070.9New/UpdatedImproved archive scanning performance with dynamic memory scaling. Improved cache builds on Lunar Lake CPUs. Fixed cloud protection service rescan loops and HTTPS connection stalls under Network Protection Block mode.

πŸ’Ώ MDE Detailed Releases

Windows

IndicatorFeatureTypeDescription
πŸ”΅Platform 4.18.26070.9 updatesNew/Updated[Windows] Improved archive scanning performance with dynamic memory scaling based on logical cores. Improved cache builds on Lunar Lake CPUs using TrustedImageIdentifier. Fixed excluded files being resubmitted to cloud protection service. Fixed HTTPS connection stalls under Network Protection Block mode from dropped TCP FIN segments.

macOS

IndicatorFeatureTypeDescription
πŸ”΅Build 101.26062.0009New/Updated[macOS] Bug and performance fixes. Extended network diagnostics with mdatp health --details network_configuration.
πŸ”΅Build 101.26052.0016New/Updated[macOS] Security and critical updates.

Linux

IndicatorFeatureTypeDescription
πŸ”΅Build 101.26052.0012New/Updated[Linux] Improved antivirus enforcement visibility showing real_time, passive, on_demand, or audit mode. More accurate connectivity tests validating offline security intelligence update paths with inline diagnostics. Fixed FIPS-enabled RHEL 8/9 installation failures. Fixed WordPress Core installations not appearing in software inventory.

πŸ†” Microsoft Defender Identity

IndicatorFeatureTypeDescription
🟒Sensor v2.x to v3.x migrationGAMigration from v2.x to v3.x sensors now generally available.
🟒Domain investigation pageGAActive Directory domain security investigation showing domain properties, deployment health, identity summary, service account breakdown, sensitive entities, recommendations, group policies, and trust relationships.
πŸ”΅Sensor v2.255.19295.47272New/UpdatedAdds support for new Event Tracing for Windows (ETW) provider with other improvements.
πŸ”΅Windows Server 2025 DC migration supportNew/UpdatedDomain controllers running Windows Server 2025 can now migrate from sensor v2.x to v3.x.
πŸ”΅Migration readiness visibilityNew/UpdatedServers marked β€œNot ready for migration” now show tooltips listing specific reasons when hovering over status.
πŸ”΅Automatic RPC auditingNew/UpdatedSensor v3.0.8+ automatically enables RPC auditing on domain controllers without manual tag application.
🟑Expanded SaaS app password protectionPreviewPassword protection page now includes risks from SaaS apps (Salesforce, ServiceNow) connected via Defender for Cloud Apps with SSPM support, in addition to AD, Entra ID, and Okta.

🏒 Microsoft Entra ID

No specific features documented for July 2026.

πŸ“± Microsoft Intune

IndicatorFeatureTypeDescription
πŸ”΅Samsung Knox E-FOTA integrationNew/UpdatedManage firmware updates for corporate-owned Samsung devices directly in Intune admin center. Control firmware versions, deploy without user interaction, schedule downloads/installations. Supports COSU, COBO, and COPE enrollment types.
πŸ”΅Windows settings catalog additionsNew/UpdatedNew settings for camera behavior, Keyboard Filter controls (Windows Insider), and Windows Subsystem for Linux (WSL).
πŸ”΅Microsoft Edge templates refreshedNew/UpdatedUpdated to Edge 149 with 15+ new policies including Local Fonts permissions, M365 authentication in work profiles, Copilot configurations, developer tools availability, and WebSocket connection controls.
πŸ”΅Windows App (AVD) settingsNew/UpdatedNew settings for automatic updates, inactive logoff, First Run Experience skip, release ring policy, and desktop shortcut creation.
πŸ”΅Microsoft Store package removalNew/UpdatedNew subsetting to specify additional package family names (PFNs) to remove beyond built-in defaults.
πŸ”΅Get Started app disable optionNew/UpdatedNew setting to prevent Windows Get Started app availability to users.
πŸ”΅OneDrive settings expansionNew/UpdatedSeven new settings including custom folder names, OIDC authentication for on-prem SharePoint, offline mode restrictions, and hard-delete behaviors for folder shortcuts.
πŸ”΅Visual Studio templates refreshedNew/UpdatedUpdated to version 1.0.184.40051 with Disable Model Context Protocol (MCP) policy.
πŸ”΅tvOS/visionOS Setup AssistantNew/UpdatedSupport for hiding/showing Setup Assistant screens (Apple ID, Diagnostics Data, Location Services) during automated enrollment for tvOS and visionOS.
πŸ”΅Zero-touch RBAC permissionNew/UpdatedDedicated RBAC permission for Google zero-touch enrollment portal access, independent from app management permissions.
πŸ”΅Windows registry data collectionNew/UpdatedCollect Windows registry data through properties catalog for richer device state visibility without custom scripts.
πŸ”΅Enhanced Windows on-demand syncNew/UpdatedComprehensive on-demand synchronization across configuration policies, apps, and scripts for faster change reflection.
πŸ”΅macOS custom compliance settingsNew/UpdatedDefine compliance checks using scripts and JSON rules for macOS, similar to Windows and Linux support.
🟑Controlled Configuration for Defender AVPreviewDefender antivirus settings from Intune/MDE become authoritative, overriding Group Policy, Config Manager, and local scripts. Extends Tamper Protection for consistent device states.
πŸ”΅Microsoft Store apps regional supportNew/UpdatedSelect region/market when adding Microsoft Store apps, enabling deployment of market-specific apps not available in US catalog.
πŸ”΅APP Multiple Managed AccountsNew/UpdatedOutlook on iOS/iPadOS (v5.2626.0+) now supports multiple managed accounts within same app. Gradual rollout.

πŸ“§ Microsoft Defender Office 365

IndicatorFeatureTypeDescription
πŸ”΅Localized notification templatesNew/UpdatedDefault Mark as and notify email templates now localized to user’s Outlook language preference. Custom templates unaffected.
πŸ”΅Unified RBAC default for new tenantsNew/UpdatedNew Defender for Office 365 Plan 2 organizations use Unified RBAC permission model by default starting July 2026.
πŸ”΅Defender for Office 365 Plan 1 in M365 E3New/UpdatedMicrosoft 365 E3 now includes Defender for Office 365 Plan 1.
🟑Prompt injection protectionPreviewDetects prompt injection attacks hidden in inbound email.

πŸ€– Microsoft Security Copilot

No specific features documented for July 2026.

πŸ”Ž Microsoft Purview

IndicatorFeatureTypeDescription
🟑Network Data Security (DLP)PreviewProtect sensitive data in text and prompts via Microsoft Entra Global Secure Access integration. Enables network-layer interception and inspection of text/AI interactions, enforcement of restrictive actions based on DLP policies, and Insider Risk Management detection. Prevents sensitive data sharing with untrusted cloud applications.
🟑Unified alert experiencePreviewCombines Triage Agent and Standard alert dashboards into single alerts list page for Insider Risk Management. View and manage classic and agent-triaged alerts together with agent summary previews.
🟑Expanded user profile detailsPreviewAdditional Microsoft Entra signals in unified alert experience: office location, employee type, department, last working date.
🟑Expanded note capabilitiesPreviewEnhanced note capabilities across alerts and cases. System-generated notes automatically applied on status changes, assignment changes, closure, or escalation.

πŸ“Š Microsoft Fabric

IndicatorFeatureTypeDescription
🟒Custom CA and mTLS in EventstreamGAUse custom CA and client certificates from Azure Key Vault with MQTT, Apache Kafka, AWS MSK, and Confluent Cloud for Apache Kafka source connectors.
🟒Folders in Eventhouse treeGACreate, rename, delete, and move folders in Eventhouse UI to organize tables, shortcuts, materialized views, functions, and data streams.
🟒Eventhouse update policies with shortcutsGAUpdate policy queries can now join to accelerated shortcut external tables for governed ingestion-time enrichment.
🟒Fabric Maps tilesetsGACreate PMTiles from OneLake geospatial data for fast, interactive map rendering in Fabric.
🟒Real-Time DashboardGAMonitor Eventhouse data with live refresh, Copilot-created tiles, drill-down exploration, Activator alerts, and team sharing.
🟒Eventstream SQL operatorGAFilter, aggregate, window, and route events with SQL. Supports multi-destination fan-out, event-time processing for late/out-of-order events, and built-in per-branch testing.
🟑Azure Event Hubs workspace identityPreviewEventstream Azure Event Hubs source can use workspace identity instead of shared access keys for Microsoft Entra ID-based access.
🟑Investigator insights in Operations AgentPreviewAnalyzes related data after operations agent alert and surfaces scope, observations, patterns, and recommended next steps in Teams.
🟑Microsoft Fabric EmbedPreviewEmbed Real-Time Dashboards in JavaScript or TypeScript apps with delegated Microsoft Entra access.
🟑Oracle Database CDC connectorPreviewStream changes from Oracle database into Fabric as structured change events with before/after values using Oracle LogMiner for on-premises or cloud databases (Oracle 12c+).
🟑Workspace outbound access protectionPreviewWorkspace-level outbound network controls for Eventstream, Eventhouse, KQL QuerySet, Activator, Real-Time Dashboards, and Azure/Fabric events. Block unwanted outbound connections by default, allow approved destinations via data connection rules.
πŸ”΅Enhanced IoT Hub connector metadataNew/UpdatedPreview support for enhanced metadata in IoT Hub connector.
πŸ”΅HTTP connector paginationNew/UpdatedPreview support for pagination in HTTP connector.
πŸ”΅Outbound access protection for EventstreamNew/UpdatedGovern Eventstream sources and destinations with workspace-level data connection rules.
πŸ”΅Business Events and UDFsNew/UpdatedPublish business events from User Data Functions and automate event-driven workflows in Fabric.
πŸ”΅Real-Time Hub architectureNew/UpdatedSeparate publishers from consumers across Business Events, Fabric Events, and Azure Events.
πŸ”΅Customer-intent streaming patternNew/UpdatedCapture CDC events, reshape with DeltaFlow, enrich with AI Functions, publish Business Events, and activate responses.
πŸ”΅Row-to-intelligent-action patternNew/UpdatedStadium operations scenario: capture database changes with CDC, reshape with DeltaFlow, classify with AI Functions in Spark Structured Streaming, route actionable items.
πŸ”΅Row-to-action with Mirrored DatabaseNew/UpdatedManufacturing quality scenario: mirror operational database, stream Delta Change Data Feed, filter with SQL operators, route to Activator and Eventhouse.
πŸ”΅Fabric IQ conversational analyticsNew/UpdatedAsk questions over governed Power BI semantic models in Microsoft 365 Copilot Chat and Copilot Cowork using data agents.
🟒Plan in Fabric IQGAUnified no-code platform for collaborative planning, reporting, analytics, data integration, and management.
πŸ”΅Fabric data agent public APINew/UpdatedManage data sources and data agents programmatically from local development, CI/CD pipelines, portals, containers, Azure Functions, and backend services.

πŸ™ GitHub Security

IndicatorFeatureTypeDescription
πŸ”΅CodeQL 2.26.1New/UpdatedImproves analysis accuracy and framework coverage for Go (log/slog modeling), Java/Kotlin (Apache POI models), JavaScript/TypeScript (Angular @HostListener), C/C++ (models-as-data field names), and Rust (reduced false positives for hard-coded cryptographic values).
πŸ”΅CodeQL 2.26.3New/UpdatedAdds JavaScript/TypeScript/Vue source modeling (Vue Composition API, Vue Router, Sails Action2), improves GitHub Actions queries (merge_group event, untrusted checkout paths, schedule event classification), removes SelfHostedQuery module, and adds C/C++ Windows registry models.
πŸ”΅Organization code quality trendsNew/UpdatedOrganization-level Code Quality dashboard now includes Trends tab showing open findings over 7/14/30 days, ranked repositories by improvement/decline, and respects repository filters. Available for GitHub Enterprise Cloud and Team plans with Code Quality enabled.
🟒Innersource security advisoriesGAGitHub Advanced Security enterprise customers can publish internal security advisories restricted to enterprise repositories. REST API for managing innersource vulnerabilities with Dependabot notifications and PRs for version updates.
⚫npm 2FA-bypass GAT deprecationDeprecationnpm v12 GA enables install-time security defaults (allowScripts off, –allow-git none, –allow-remote none). 2FA-bypass granular access tokens will stop skipping 2FA for account changes and direct publishing in early August 2026.
🟑Open source license compliancePreviewEnterprise-wide license policy with ruleset-based checks blocking noncompliant dependencies before merge. New Enterprise Open Source License Policy Manager role for reviewing closure requests. Available for GitHub Advanced Security Code Security licenses.
πŸ”΅npm publish-time malware scanningNew/UpdatedAutomatic scanning of packages at publish time before availability (typically ~5 min delay). Blocked packages may receive publisher notifications with appeal options. New contentPolicy field in package.json required for dual-use content with DISCLOSURE file.
πŸ”΅Dependabot malware alerts expansionNew/UpdatedGitHub Advisory Database now ingests malware advisories from OpenSSF malicious-packages repository, expanding coverage across npm, PyPI, and more ecosystems.
πŸ”΅GitHub Actions workflow approvalNew/UpdatedPotentially malicious workflow runs in public repositories held for approval before execution. Repository collaborators with write access must review and approve via authenticated web session.
πŸ”΅Credential revocation by token typeNew/UpdatedToken-type-specific bulk deauthorization and revocation during security incidents (personal access tokens, SSH keys, OAuth app tokens, GitHub App user tokens). Available at enterprise and organization levels via UI and REST APIs with audit logging.
πŸ”΅Dependabot version update cooldownNew/UpdatedDefault 3-day cooldown before opening version update PRs after release availability. Reduces supply chain attack risk from compromised releases. Security updates unaffected. Configurable via dependabot.yml.
πŸ”΅Code scanning default setup customizationNew/UpdatedApply custom CodeQL configuration files to default setup via github-codeql-config-file repository property. Supports cross-repository configuration references and Git Source private registries for private configs.
πŸ”΅Dependabot branch name customizationNew/UpdatedCustomizable Dependabot PR branch names via prefix, separators, case, and template placeholders in .github/dependabot.yml. Helps maintain CI/CD compatibility and naming conventions.
🟑Code coverage automatic enablementPreviewAI-generated code coverage workflow creation via repository settings. Generates PR with coverage workflow that builds code, runs tests, generates report, and uploads to GitHub with least-privilege permissions.

Top 5 Action Items

PriorityActionDueAffected Product(s)
HighRestart Istio workload pods to apply security patches for ISTIO-SECURITY-2026-005ImmediateAKS
HighMigrate from legacy grouped recommendations to individual recommendations APICompleted July 31, 2026Defender Cloud
HighUpdate containerd from 1.7.32 to 1.7.33 to patch CVE-2026-53488, CVE-2026-47262, CVE-2026-34986ImmediateAKS
HighMigrate legacy Container Insights authentication to managed identity before September 30, 2026September 30, 2026Azure Monitor
MediumRemove enableCustomCATrust preview property (–disable-custom-ca-trust) from AKS configurationsSeptember 14, 2026AKS
MediumPrepare for npm 2FA-bypass GAT deprecation by stopping use for account changes and direct publishingEarly August 2026GitHub Security
MediumMigrate automation using deprecated Defender plans (AKS, ACR, Key Vault, DNS, ARM) to supported plansTBDDefender Cloud
MediumPlan migration for Azure Diagnostics extension (WAD/LAD) retirementImmediate (retired March 31, 2026)Azure Monitor
LowReview Ubuntu 22.04 kernel CVE findings and verify actual exposure via Ubuntu CVE TrackerOngoingAKS
LowEvaluate AI agent posture risk assessment and runtime protection capabilities for Agent 365OngoingDefender XDR, Defender Endpoint

Security Architect Observations

  • AI agent security emergence: Microsoft is rapidly building out AI agent security capabilities across Defender XDR (posture risk assessment, threat detection, real-time protection), Defender Endpoint (runtime protection for Codex CLI, GitHub Copilot, Node.js agents), and Defender Office 365 (prompt injection detection). This reflects the industry’s recognition that AI agents represent a new attack surface requiring specialized security controls. Security architects should begin inventorying AI agent deployments and assessing current security posture.

  • Multicloud security coverage expansion: Over 200 new GA recommendations for AWS and GCP resources, plus EKS/GKE vulnerability assessment and Kubernetes node VA, demonstrate Microsoft’s commitment to unified multicloud security posture management. The serverless container posture capabilities (ACA, ACI, ECS Fargate) complete the container security story. Architects managing hybrid/multicloud environments should evaluate consolidating CSPM tooling.

  • Supply chain security hardening: GitHub’s npm v12 install-time security defaults (scripts off by default), publish-time malware scanning, Dependabot cooldown periods, and OpenSSF malware advisory ingestion represent significant supply chain security improvements. The innersource advisories capability extends enterprise security boundaries to internal components. Security architects should review dependency management policies and consider adopting these capabilities.

  • Kubernetes security maturation: AKS artifact streaming GA, container-level KSPM recommendations, Kubernetes misconfiguration enforcement at admission, and prepared image specifications show Kubernetes security moving from basic vulnerability scanning to runtime protection and prevention. The Ubuntu kernel CVE reclassification bulletin highlights the complexity of shared responsibility models. Architects should reassess Kubernetes security strategies beyond basic pod security standards.

  • Identity-centric Zero Trust expansion: Defender Identity sensor v3.x GA, expanded SaaS app password protection (Salesforce, ServiceNow), automatic RPC auditing, and domain investigation pages strengthen on-premises and hybrid identity security. Intune’s Controlled Configuration preview extends Tamper Protection to override Group Policy and Config Manager. These capabilities support Zero Trust identity pillars but require careful change management.

  • Data governance and AI convergence: Microsoft Purview’s Network Data Security preview (DLP for AI interactions via Entra GSA), Fabric’s Real-Time Dashboard GA, and Eventstream SQL operators blur lines between data governance, real-time analytics, and AI security. Security architects should consider how these capabilities enable new data protection patterns for AI workloads and streaming data.

Security Operations Observations

  • SOC workflow enhancements: Defender XDR’s domain investigation page GA, unified alert experience in Purview Insider Risk Management, expanded user profile details from Entra ID, and system-generated notes on alerts/cases will improve analyst efficiency and investigation quality. The AI agent posture risk dashboard provides new signals for prioritizing agent-related alerts. SOAR teams should update playbooks to leverage these capabilities.

  • New detection opportunities: SQL data exfiltration alert preview (β€œabnormally large number of rows extracted”), prompt injection protection in Defender Office 365, GitHub Actions malicious workflow approval, and expanded multicloud recommendations create new detection use cases. The MAI-augmented scan profiles in Exposure Management may surface previously missed vulnerabilities. Detection engineering teams should prioritize tuning these new signals.

  • Alert fatigue risk: Over 200 new multicloud recommendations, 20+ SQL VA individual recommendations, and expanded EMR/database recommendations could significantly increase alert volume if not properly scoped. The Ubuntu kernel CVE reclassification bulletin warns of inflated scanner findings that won’t resolve via upgrades. SOC teams should implement recommendation filtering and prioritization strategies before enabling all new capabilities.

  • Operational timeline pressures: Multiple deprecations with hard deadlines (Legacy Container Insights auth September 30, 2026; enableCustomCATrust September 14, 2026; VM Insights Map June 30, 2028) create migration workloads competing with BAU operations. The npm 2FA-bypass GAT changes (early August 2026) may disrupt CI/CD pipelines. Operations teams should triage these by business impact and create migration runbooks.

  • Container sensor improvements: Defender Container Sensor v0.8-v0.11 security fixes (authentication vulnerabilities, credential exposure), performance improvements (process event filtering CPU), and EKS/GKE private cluster support GA improve visibility into containerized workloads. However, operations teams must plan sensor upgrades across AKS versions and validate no performance regression in production environments.

  • Endpoint deployment simplification: Defender Deployment Tool for Linux GA with Device Timeline integration, Advanced Hunting queries, and detailed error reporting should reduce Linux onboarding friction and improve troubleshooting. The improved Windows on-demand sync and macOS custom compliance settings in Intune provide faster policy enforcement. Operations teams should test these capabilities in pilot groups before broad deployment.

References

ProductURL
Defender XDRhttps://learn.microsoft.com/en-us/defender-xdr/whats-new
Unified SecOpshttps://learn.microsoft.com/en-us/unified-secops/whats-new
Defender Endpointhttps://learn.microsoft.com/en-us/defender-endpoint/whats-new-in-microsoft-defender-endpoint
Defender Endpoint Releaseshttps://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-endpoint-releases
Defender Identityhttps://learn.microsoft.com/en-us/defender-for-identity/whats-new
Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/whats-new
Microsoft Entra IDhttps://learn.microsoft.com/en-us/entra/fundamentals/whats-new
Microsoft Intunehttps://learn.microsoft.com/en-us/intune/whats-new/
Defender Cloud Appshttps://learn.microsoft.com/en-us/defender-cloud-apps/release-notes
Defender Office 365https://learn.microsoft.com/en-us/defender-office-365/defender-for-office-365-whats-new
Defender Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/release-notes
AKShttps://github.com/Azure/AKS/releases
Azure Container Appshttps://learn.microsoft.com/en-us/azure/container-apps/whats-new
Azure Container Instanceshttps://www.microsoft.com/releasecommunications/api/v2/azure?search=Azure%20Container%20Instances&$top=100
Azure Functionshttps://www.microsoft.com/releasecommunications/api/v2/azure?search=Azure%20Functions&$top=100
Azure Logic Appshttps://www.microsoft.com/releasecommunications/api/v2/azure?search=Logic%20Apps&$top=100
Azure Monitorhttps://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/whats-new
Defender Container Sensorhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-sensor-change-log
Security Copilothttps://learn.microsoft.com/en-us/copilot/security/whats-new-copilot-security
Defender Exposure Managementhttps://learn.microsoft.com/en-us/security-exposure-management/whats-new
Microsoft Purviewhttps://learn.microsoft.com/en-us/purview/whats-new
Microsoft Foundryhttps://devblogs.microsoft.com/foundry/category/whats-new/
Microsoft Copilot Studiohttps://learn.microsoft.com/en-us/microsoft-copilot-studio/whats-new
Microsoft Fabrichttps://learn.microsoft.com/en-us/fabric/fundamentals/whats-new
GitHub Securityhttps://github.blog/changelog/
Defender Recommendations & Alertshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/release-notes-recommendations-alerts
This post is licensed under CC BY 4.0 by the author.