Post

2026-08

2026-08

This release tracker is LLM-curated and based on the official Microsoft product sources listed below. It provides an architect-grade summary of recent features, changes, and announcements. Always verify critical details against the official documentation. List of all raw markdown files for the releases are at https://github.com/pisinger/pisinger.github.io/tree/main/_ms_release_radar

Microsoft Security Release Radar - August 2026


πŸ” Microsoft Sentinel

IndicatorFeatureTypeDescription
🟑New data sources for UEBA behaviors and anomaly detectionPreviewUEBA behaviors layer now supports Fortinet FortiGate firewall events from CommonSecurityLog table with 40+ new behaviors for administrative activity. Anomaly detection expanded to Check Point, Fortinet, Zscaler, and AWS GuardDuty events.
🟑UEBA anomalies on behaviorsPreviewMicrosoft Sentinel now adds contextual anomaly insights directly to UEBA behavior records, helping analysts identify first-seen activity, unusually high behavior volumes, uncommon values, and threat intelligence matches without manual correlation.
πŸ”΅SAP solution releasesNew/UpdatedSAP agentless solution v1.1.12 adds audit log performance enhancements; SAP BTP solution v3.1.1 adds analytic rule for unaudited custom apps; SAP LogServ solution v3.0.5 enables RISE with SAP customers to activate ASIM-based security content for standard SAP LogServ logs.

πŸ›‘οΈ Microsoft Defender Cloud

IndicatorFeatureTypeDescription
⚫Classic Defender for SQL APIs retirementDeprecationClassic Defender for SQL APIs for Vulnerability Assessment and Advanced Threat Protection will be retired on August 16, 2027. Migrate to supported configuration model and update dependent scripts/automation before retirement.
πŸ”΅On-demand malware scanning granularityNew/UpdatedOn-demand malware scanning in Microsoft Defender for Storage now supports targeted scanning of specific blobs, files, containers, or file shares instead of entire storage accounts. Use filters in REST API request body to scope scans.
πŸ”΅CIEM overprovisioned identity assessment changeNew/UpdatedBreaking change: Unused actions no longer included in AWS and GCP overprovisioned identity assessments to improve performance. Use native cloud provider tools (AWS IAM, GCP IAM) to validate permission usage.

πŸ›‘οΈ Microsoft Defender Cloud (Recommendations & Alerts

IndicatorFeatureTypeDescription
⚫Retirement of legacy grouped recommendationsDeprecationRetirement of legacy grouped recommendations (sub-assessments) has started as of July 31, 2026. Customers can no longer access deprecated data through API. Azure portal and Azure Resource Graph may take time to reflect changes.
🟒SQL server-level individual recommendationsGAMultiple individual recommendations released at database level as part of transitioning Defender for SQL Vulnerability Assessment from grouped to individual recommendations, including execute permissions, CLR settings, guest user access, and password policies.
🟒AKS vulnerability recommendationsGANew recommendations: β€œUpgrade Azure Kubernetes Service to remove vulnerabilities from AKS system pods” and β€œContainer images in Docker Hub registry should have vulnerability findings resolved.”
🟒200+ multicloud recommendations for AWS/GCPGAOver 200 new multicloud security recommendations for AWS and GCP resources now GA, affecting Secure Score across data, identity/access, networking, compute, and container categories for ~90 newly supported resource types.
🟒Azure Database for PostgreSQL recommendationsGAMultiple recommendations for PostgreSQL Flexible Servers including log retention, pgaudit settings, public IP access restrictions, private endpoints, secure transport, and geo-redundant backups.
🟒API endpoint security recommendationsGARecommendations for Function Apps and Logic Apps: unused API endpoints should be disabled/removed, and authentication should be enabled on API endpoints.
🟑EMR cluster security recommendationsPreviewSix preview recommendations for AWS EMR clusters covering custom IAM roles, security configuration, public network access, Kerberos authentication, termination protection, and logging encryption.
🟑AWS database service recommendationsPreviewMultiple preview recommendations for AWS services including IAM Database Authentication for DB Cluster, deletion protection for Neptune DB clusters, and public access restrictions for Neptune DB instances.
🟑AWS analytics service recommendationsPreviewPreview recommendations for AWS MSK, OpenSearch Service, App Engine, Certificate Manager, Athena workgroups, Amazon Comprehend, DMS, DataSync, FSx, Kendra, Keyspaces, Kinesis, MQ, and QuickSight.
🟑ECS Fargate and Container Apps recommendationsPreviewPreview recommendations for serverless containers including IAM task roles, privileged containers, read-only root filesystem, public exposure, ECS Exec logging, and Azure Container Apps authentication.

🎯 Microsoft Defender XDR

No new features or updates documented in this period.


πŸ” Microsoft Defender Endpoint

IndicatorFeatureTypeDescription
🟒macOS Build 101.26062.0012GARelease version 20.126062.12.0 with bug and performance fixes.
🟒macOS Build 101.26062.0011GARelease version 20.126062.11.0 with expanded local AI agent discovery (Preview) on macOS to include Model Context Protocol (MCP) server configurations, plus performance improvements.
🟑Vulnerability assessment for Microsoft Store applicationsPreviewMonitor vulnerabilities on devices running Microsoft Store applications including Teams, Firefox, WhatsApp, Slack, Dropbox, DuckDuckGo, Dell Command, HP Smart, and NVIDIA Control Panel. Use Software evidence area to view file paths and vulnerable app details.

πŸ’Ώ MDE Detailed Releases

Windows

IndicatorFeatureTypeDescription
πŸ”΅Windows cumulative rollup updatesNew/UpdatedRegular Windows cumulative updates include Defender for Endpoint EDR (MsSense.exe) version updates. Refer to Windows 11, Windows 10, Windows Server 2022/2019/2025 update history articles for file information.

macOS

IndicatorFeatureTypeDescription
πŸ”΅Build 101.26062.0012 (August 2026)New/Updated[macOS] Release version 20.126062.12.0 with engine version 1.1.26060.12000 and signature version 1.457.164.0. Bug and performance fixes.
πŸ”΅Build 101.26062.0011 (August 2026)New/Updated[macOS] Release version 20.126062.11.0 with engine version 1.1.26040.3000 and signature version 1.449.26.0. Expanded local AI agent discovery (Preview) to include MCP server configurations. Performance improvements and bug fixes.

Linux

IndicatorFeatureTypeDescription
πŸ”΅Monthly security updatesNew/Updated[Linux] Defender for Endpoint on Linux receives regular security fixes as part of monthly releases. Each version expires after nine months; expired versions continue receiving security intelligence updates but should be upgraded for full fixes and enhancements.

πŸ†” Microsoft Defender Identity

No new features or updates documented in this period.


🏒 Microsoft Entra ID

No new features or updates documented in this period.


πŸ“± Microsoft Intune

No new features or updates documented in this period.


☁️ Microsoft Defender Cloud Apps

No new features or updates documented in this period.


πŸ“§ Microsoft Defender Office 365

No new features or updates documented in this period.


🚨 Microsoft Security Exposure Management

IndicatorFeatureTypeDescription
πŸ”΅Codename MDASH - Cancel scanNew/UpdatedScan cancellation now available in Microsoft Defender portal (previously only in Defender CLI). Cancel queued or running scans from the Scans tab on the scan details page.
🟑Codename MDASH - Azure DevOps connectorPreviewAzure DevOps connector now in preview for agentic code scanner. Security teams can connect Azure DevOps organizations from Microsoft Defender portal, onboard repositories, and trigger remote on-demand agentic code scans.

β›΅ AKS

IndicatorFeatureTypeDescription
🟒Node Auto Provisioning with restricted publicNetworkAccessGANode Auto Provisioning can now be enabled on clusters with restricted publicNetworkAccess, including private API server VNet-integrated clusters using UDR, as long as AKS-wide networking guardrails pass.
🟒Automatic availability zone placementGAAutomatic availability zone placement now enabled globally. Customers can create new VMSS or VirtualMachines node pools with availabilityZones=[β€œauto”], and existing VMSS node pools can be updated after rollout completes.
🟒Control-plane only upgrades for LTSGAAKS now allows control-plane only upgrades to Long Term Support (LTS) clusters as long as version skew policy is satisfied, enabling safer upgrades by first upgrading control plane, validating, then upgrading node pools.
🟒AKS Node pool RollbackGANode pool version rollback is now GA, letting you restore a node pool to its previous Kubernetes version and node image after an upgrade issue, minimizing downtime and maintaining business continuity.
🟒Azure File CSI driver encryption and workload identityGAEncryption in Transit and use workload identity to access Azure Files storage are now GA for Azure File CSI driver.
🟑Prepared Image Specification (PIS)PreviewPIS now in public preview, allowing creation of preconfigured node images with required container images and node customizations already applied to reduce node startup times.
🟑Capacity Reservation Group association with existing node poolsPreviewCustomers using preview API version 2026-01-02-preview or later can associate Capacity Reservation Group with existing node pools. Zonal pools perform rolling cordon/drain/reboot; non-zero regional pools must scale to zero first.
πŸ”΅SSH node access changes trigger reimageNew/UpdatedFor Kubernetes 1.37+, SSH node access configuration changes now trigger immediate node reimage. Use Node Disruption Policy to block or schedule during maintenance window.
πŸ”΅Network configuration changes trigger reimageNew/UpdatedFor Kubernetes 1.37+, changes to IMDS restriction, network-isolated bootstrap profile, or cluster outbound type now trigger immediate node reimage. Use Node Disruption Policy to control timing.
πŸ”΅VMSS rolling upgrade concurrency calculationNew/UpdatedVMSS rolling upgrade concurrency for percentage-based maxSurge, maxUnavailable, and maxBlockedNodes is now calculated from current VMSS capacity and capped to remaining VMs to upgrade.
πŸ”΅Service principal to managed identity migrationNew/UpdatedUpdating cluster from service principal authentication to managed identity now triggers node reimages across node pools. Configure Node Disruption Policy to control when reimages are allowed.
πŸ”΅AKS upgrade validation for VMSS limitsNew/UpdatedAKS upgrade validation now rejects node pool upgrades where current pool size plus effective surge would exceed VMSS 1,000-instance limit, preventing mid-upgrade Azure Compute failures.
πŸ”΅Istio Gateway API security improvementNew/UpdatedIstio Gateway API deployments now set automountServiceAccountToken to false, improving default security posture and unblocking environments with Azure Policies requiring pods to disable service account token auto-mounting.
πŸ”΅GPU MIG slice width validationNew/UpdatedAKS now validates GPU MIG instance profile slice width against VM SKU capacity, preventing unsupported MIG profiles on lower-capacity GPU SKUs.
πŸ”΅Application Gateway for Containers ALB version alignmentNew/UpdatedALB add-on now aligned with AKS minor versions. AKS automatically selects compatible ALB controller image during cluster upgrades, reducing incompatibilities.
πŸ”΅AzureContainerLinux SSH rejectionNew/UpdatedAKS now rejects Entra ID SSH configuration on AzureContainerLinux node pools because the extension is incompatible with immutable OS nodes.
πŸ”΅AKS Automatic App Routing fixNew/UpdatedFixed issue where App Routing on Kubernetes 1.36+ clusters could incorrectly default to NGINX instead of Istio/Gateway API mode during cluster creation.
πŸ”΅Node Auto Provisioning Karpenter updateNew/UpdatedNode Auto Provisioning updated to Karpenter provider Azure v1.14.0, adding support for Balanced consolidation policy to reduce node churn.
πŸ”΅Azure Policy add-on updatesNew/UpdatedGatekeeper bumped to 3.23.0 and Azure Policy add-on bumped to 1.17.0.
πŸ”΅CSI Driver updatesNew/UpdatedAzure File CSI Driver upgraded to v1.34.7/v1.35.6, Azure Blob CSI Driver to v1.26.16/v1.27.9, Azure Disk CSI Driver to v1.33.11/v1.34.5 across AKS versions.
πŸ”΅Azure Monitor Prometheus and Container Insights updatesNew/UpdatedAzure Monitor managed service for Prometheus add-on updated to 07-27-2026 release; Container Insights upgraded to 3.6.0.
πŸ”΅Node image updatesNew/UpdatedAKS Azure Linux, Azure Container Linux, and Ubuntu images updated with latest vhd-notes releases from July 2026.

πŸ“¦ Azure Container Apps

IndicatorFeatureTypeDescription
🟑Azure Container Apps SandboxesPreviewAzure Container Apps Sandboxes in public preview for enhanced isolation.
🟒Confidential ComputeGAConfidential Compute generally available for Azure Container Apps.
πŸ”΅HTTP traffic logsNew/UpdatedHTTP traffic logs now available for traffic analysis and monitoring.
πŸ”΅Managed OpenTelemetry destinationsNew/UpdatedAdditional managed OpenTelemetry destinations for New Relic, Dynatrace, and Elastic.
πŸ”΅Custom KEDA scale rule overridesNew/UpdatedCustom KEDA scale rule overrides for Azure Functions on Container Apps.
πŸ”΅Regional expansionNew/UpdatedAzure Container Apps now available in six additional regions: Germany North, New Zealand North, Chile Central, Korea South, Belgium Central, and Jio India Central.
πŸ”΅Bring Your Own Orchestrator for JobsNew/UpdatedCommunity-maintained templates for connecting existing workflow engines (Airflow, Temporal, Argo Workflows, Durable Functions, Logic Apps Standard, Dapr Workflow) to Container Apps Jobs.
πŸ”΅Express deployment guidanceNew/UpdatedExpress deployment walkthrough with comparison to standard Container Apps, noting current preview gaps such as managed identity and VNet integration.

🧱 Azure Container Instances

No new features or updates documented in this period.


⚑ Azure Functions

No new features or updates documented in this period.


πŸ” Azure Logic Apps

No new features or updates documented in this period.


πŸ“Š Azure Monitor

IndicatorFeatureTypeDescription
⚫Azure Operations Center retirementDeprecationAzure Operations Center retired in August 2026. Use Azure Monitor for monitoring and analysis capabilities. Azure Copilot Observability Agent provides natural-language data exploration, guided investigations, and autonomous alert operations.
πŸ”΅Auxiliary/Lake table plans expansionNew/UpdatedAuxiliary/Lake table plans expanded with Azure tables support, plan switching between Analytics and Auxiliary/Lake, and availability in sovereign clouds. Helps teams keep more data without stretching budget.

πŸ”¬ Defender Container Sensor

IndicatorFeatureTypeDescription
🟒Sensor v0.11.5GAImproved pod inventory reliability by preventing failures when processing Kubernetes pod deletion events. Updated runtime and telemetry dependencies to address security vulnerabilities.
🟒Sensor v0.10.8GAImproved pod inventory reliability by preventing failures when processing Kubernetes pod deletion events. Updated runtime and networking dependencies to address security vulnerabilities.
🟒Sensor v0.9.65GAImproved pod inventory reliability by preventing failures when processing Kubernetes pod deletion events. Updated runtime and networking dependencies to address security vulnerabilities.

πŸ€– Microsoft Security Copilot

No new features or updates documented in this period.


πŸ”Ž Microsoft Purview

IndicatorFeatureTypeDescription
πŸ”΅Auto-labeling policy simulation modeNew/UpdatedBefore enforcing auto-labeling policy, run in simulation mode to identify which items it would label without making changes. Review match results and source distribution to determine policy readiness.
πŸ”΅Auto-labeling policy Insights tabNew/UpdatedInsights tab in policy details panel provides at-a-glance view of auto-labeling policy performance, with information varying based on simulation or enforcement mode.

πŸ—οΈ Microsoft Foundry

No new features or updates documented in this period.


🧠 Microsoft Copilot Studio

No new features or updates documented in this period.


πŸ“Š Microsoft Fabric

IndicatorFeatureTypeDescription
🟑Eventstream workspace monitoring with per-eventstream controlPreviewChoose which eventstreams emit performance, error, and node-health data to three KQL tables in workspace monitoring Eventhouse.
🟒Capacity Overview Events in Real-Time HubGAStream capacity summary and state signals to monitor utilization and health, detect throttling or lifecycle changes, and trigger alerts or automated actions.
πŸ”΅Publish Business Events from Fabric workloadsNew/UpdatedPublish versioned, schema-valid signals from notebook, User Data Function, Eventstream, or Activator that detects business conditions.
πŸ”΅Event pillar guidanceNew/UpdatedGuidance on choosing between Business Events (workload-published), Fabric Events (platform), and Azure Events (Azure Storage).
πŸ”΅Business Event schema design guidanceNew/UpdatedBusiness Event schema uses clear, factual, versioned contract so publishers and consumers share meaning while evolving independently.
πŸ”΅Eventhouse for data engineersNew/UpdatedEventhouse helps ingest, query, and analyze high-volume event data in near real time and share across Fabric through OneLake.

πŸ™ GitHub Security

IndicatorFeatureTypeDescription
πŸ”΅CodeQL 2.26.1New/UpdatedImproves analysis accuracy and framework coverage for Go (log/slog modeling), Java/Kotlin (Apache POI models), JavaScript/TypeScript (Angular @HostListener), C/C++ (models-as-data field names), and Rust (reduced false positives in cryptographic query).
πŸ”΅CodeQL 2.26.3New/UpdatedAdds JavaScript/TypeScript/Vue source modeling (Vue Router useRoute(), ref/reactive helpers), GitHub Actions improvements (merge_group event untrusted data, query accuracy fixes), C/C++ registry models, and Ruby vendoring false positive reduction. Breaking change: removed SelfHostedQuery module.
πŸ”΅Organization Code Quality trends dashboardNew/UpdatedOrganization-level Code Quality dashboard now includes Trends tab showing code quality changes across repositories over 7/14/30 days. View open findings trends, most improved repositories, and repositories needing attention. GA for Enterprise Cloud/Team with Code Quality enabled.
🟒Innersource security advisoriesGAGitHub Advanced Security enterprise customers can publish internal security advisories restricted to enterprise repositories. New REST API for managing innersource vulnerabilities. Dependabot notifies repositories using the component and opens upgrade PRs.
⚫npm install-time security defaultsDeprecationnpm v12 makes allowScripts, allow-git, and allow-remote opt-in (defaults off/none). Dependency lifecycle scripts and git/remote dependencies no longer run unless explicitly allowed. Review with npm approve-scripts.
⚫npm 2FA-bypass GAT deprecationDeprecationnpm granular access tokens configured to bypass 2FA will no longer skip 2FA for sensitive account/package/organization management actions (expected early August 2026). Perform these operations interactively with 2FA.
⚫npm 2FA-bypass direct publishing deprecationDeprecationFollowing 2FA-bypass GAT changes, these tokens will lose direct publishing ability. Publishing reduced to reading private packages and staging publish requiring human 2FA approval.
πŸ”΅npm publish-time malware scanningNew/UpdatedNewly published npm packages automatically scanned before availability, introducing ~5 minute delay (up to 15+ minutes at peak). Blocked packages may receive appeal option.
πŸ”΅npm dual-use content metadata requirementNew/UpdatedNew contentPolicy field in package.json for dual-use content with security-relevant capabilities. Requires DISCLOSURE file in package root describing dual-use functionality and intended legitimate use. May trigger additional scanning.
πŸ”΅Dependabot malware alerts expansionNew/UpdatedGitHub Advisory Database now ingests malware advisories from OpenSSF malicious-packages repository, expanding coverage across npm, PyPI, and more ecosystems. Automatic for users with malware alerting enabled.
πŸ”΅GitHub Actions malicious workflow holdsNew/UpdatedGitHub Actions now holds certain potentially malicious workflow runs for approval before execution on public repositories. Workflow won’t run until repository collaborator with write access reviews and approves via authenticated web session.
πŸ”΅Credential revocation by token typeNew/UpdatedEnterprise owners, organization admins, and users with Manage enterprise credentials permission can now revoke all tokens of specific credential type (PATs, SSH keys, OAuth tokens, GitHub App tokens) for finer-grained incident response. Organization-level parity available.
πŸ”΅Dependabot version update cooldownNew/UpdatedDependabot now waits until new release available for at least three days before opening version update PR (default, configurable). Security updates still open immediately. Applies across supported ecosystems on github.com, coming to GHES 3.23.
πŸ”΅Code scanning default setup customizationNew/UpdatedApply custom CodeQL configuration file to default setup via github-codeql-config-file repository property. Merge custom settings with built-in defaults. Organization-wide defaults supported; repositories can override if allowed. New syntax for referencing config files in other repositories.
πŸ”΅Dependabot branch name customizationNew/UpdatedNew pull-request-branch-name options in dependabot.yml for customizing branch names with prefix, separators, case, or custom templates. Keeps Dependabot branches compatible with CI/CD naming conventions.
πŸ”΅Code coverage automatic enablementPreviewCode Quality settings can generate coverage workflow automatically with AI. Opens PR with workflow that builds code, runs tests, generates coverage report, and uploads to GitHub with least-privilege permissions. Preview for Code Quality users on github.com.

Top 5 Action Items

PriorityActionDueAffected Product(s)
πŸ”΄Migrate from classic Defender for SQL APIs to supported configuration modelAugust 16, 2027Microsoft Defender Cloud
πŸ”΄Update npm automation to use 2FA for account/package management actionsEarly August 2026GitHub Security
πŸ”΄Review and approve npm dependency lifecycle scripts before upgrading to v12Before npm v12 upgradeGitHub Security
🟑Evaluate UEBA new data sources (Fortinet, Check Point, Zscaler, AWS GuardDuty) for SOC integrationQ3 2026Microsoft Sentinel
🟑Configure custom CodeQL configuration files for organization-wide code scanning defaultsQ4 2026GitHub Security

Security Architect Observations

  • SQL API deprecation requires proactive migration planning: The August 2027 retirement of classic Defender for SQL APIs gives teams a year to migrate, but automation/scripts using these APIs must be inventoried and updated. Start assessing impact now to avoid last-minute rush.

  • GitHub’s supply chain security hardening is comprehensive: Multiple overlapping controls (malware scanning, 2FA-bypass GAT deprecation, malicious workflow holds, credential revocation by token type, cooldown periods) significantly raise the bar for supply chain attacks. Enterprise architects should review GitHub Advanced Security policies to align with organizational risk tolerance.

  • AKS node disruption policies are critical for production clusters: Multiple behavioral changes in AKS 1.37+ trigger immediate node reimaging (SSH changes, network config changes, identity migrations). Node Disruption Policy configuration is essential to prevent unplanned workload disruptions during routine operations.

  • Multicloud security coverage expansion is substantial: 200+ new recommendations for AWS/GCP resources across 90 resource types significantly expand Defender for Cloud’s multicloud posture management. Security architects managing hybrid/multicloud environments should review the new recommendations to understand coverage gaps and remediation paths.

  • npm dual-use metadata requirement creates new compliance surface: The contentPolicy field and DISCLOSURE file requirement for dual-use packages introduces new governance considerations for organizations publishing security-relevant tooling. Legal and security teams should establish review processes for dual-use declarations.

  • UEBA expansion to firewall/proxy logs enhances detection depth: New anomaly detection for Check Point, Fortinet, Zscaler, and AWS GuardDuty provides richer context for identity-linked suspicious activity. Architects should ensure these data sources are properly integrated and normalized for maximum UEBA effectiveness.


Security Operations Observations

  • UEBA anomaly insights reduce analyst investigation time: Contextual anomaly insights added directly to UEBA behavior records (first-seen activity, unusual volumes, uncommon values, TI matches) reduce manual correlation effort. SOC teams should update investigation playbooks to leverage these enriched insights.

  • GitHub Actions malicious workflow holds may impact CI/CD velocity: Security teams managing public repositories should prepare for workflow approval delays and establish escalation paths for time-sensitive pipeline runs. Consider pre-approving trusted workflow patterns where possible.

  • Dependabot cooldown period reduces bad merge risk: The default 3-day cooldown for version updates gives security community time to identify malicious/broken releases. Operations teams should adjust dependency update SLAs to account for this delay and avoid manual override unless critical.

  • Sensor updates address pod inventory reliability: Defender Container Sensor v0.9-0.11 updates fix pod deletion event processing failures. Teams using container security monitoring should verify sensor versions and validate pod inventory completeness after upgrade.

  • On-demand malware scanning granularity improves incident response efficiency: Targeted scanning of specific blobs/files/containers instead of entire storage accounts enables faster triage during malware investigations. SOC teams should update IR playbooks to leverage scoped scanning.

  • Credential revocation by token type enables surgical incident response: Security teams can now revoke specific token types (PATs, SSH keys, OAuth tokens) without nuking all credentials. Update incident response runbooks to leverage token-type-specific revocation for contained blast radius.


References

ProductURL
Defender XDRhttps://learn.microsoft.com/en-us/defender-xdr/whats-new
Unified SecOpshttps://learn.microsoft.com/en-us/unified-secops/whats-new
Defender Endpointhttps://learn.microsoft.com/en-us/defender-endpoint/whats-new-in-microsoft-defender-endpoint
Defender Endpoint Releaseshttps://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-endpoint-releases
Defender Identityhttps://learn.microsoft.com/en-us/defender-for-identity/whats-new
Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/whats-new
Microsoft Entra IDhttps://learn.microsoft.com/en-us/entra/fundamentals/whats-new
Microsoft Intunehttps://learn.microsoft.com/en-us/intune/whats-new/
Defender Cloud Appshttps://learn.microsoft.com/en-us/defender-cloud-apps/release-notes
Defender Office 365https://learn.microsoft.com/en-us/defender-office-365/defender-for-office-365-whats-new
Defender Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/release-notes
AKShttps://github.com/Azure/AKS/releases
Azure Container Appshttps://learn.microsoft.com/en-us/azure/container-apps/whats-new
Azure Container Instanceshttps://www.microsoft.com/releasecommunications/api/v2/azure?search=Azure%20Container%20Instances&$top=100
Azure Functionshttps://www.microsoft.com/releasecommunications/api/v2/azure?search=Azure%20Functions&$top=100
Azure Logic Appshttps://www.microsoft.com/releasecommunications/api/v2/azure?search=Logic%20Apps&$top=100
Azure Monitorhttps://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/whats-new
Defender Container Sensorhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-sensor-change-log
Security Copilothttps://learn.microsoft.com/en-us/copilot/security/whats-new-copilot-security
Defender Exposure Managementhttps://learn.microsoft.com/en-us/security-exposure-management/whats-new
Microsoft Purviewhttps://learn.microsoft.com/en-us/purview/whats-new
Microsoft Foundryhttps://devblogs.microsoft.com/foundry/category/whats-new/
Microsoft Copilot Studiohttps://learn.microsoft.com/en-us/microsoft-copilot-studio/whats-new
Microsoft Fabrichttps://learn.microsoft.com/en-us/fabric/fundamentals/whats-new
GitHub Securityhttps://github.blog/changelog/
Defender Recommendations & Alertshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/release-notes-recommendations-alerts
This post is licensed under CC BY 4.0 by the author.