2026-08
This release tracker is LLM-curated and based on the official Microsoft product sources listed below. It provides an architect-grade summary of recent features, changes, and announcements. Always verify critical details against the official documentation. List of all raw markdown files for the releases are at https://github.com/pisinger/pisinger.github.io/tree/main/_ms_release_radar
Microsoft Security Release Radar - August 2026
π Microsoft Sentinel
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π‘ | New data sources for UEBA behaviors and anomaly detection | Preview | UEBA behaviors layer now supports Fortinet FortiGate firewall events from CommonSecurityLog table with 40+ new behaviors for administrative activity. Anomaly detection expanded to Check Point, Fortinet, Zscaler, and AWS GuardDuty events. |
| π‘ | UEBA anomalies on behaviors | Preview | Microsoft Sentinel now adds contextual anomaly insights directly to UEBA behavior records, helping analysts identify first-seen activity, unusually high behavior volumes, uncommon values, and threat intelligence matches without manual correlation. |
| π΅ | SAP solution releases | New/Updated | SAP agentless solution v1.1.12 adds audit log performance enhancements; SAP BTP solution v3.1.1 adds analytic rule for unaudited custom apps; SAP LogServ solution v3.0.5 enables RISE with SAP customers to activate ASIM-based security content for standard SAP LogServ logs. |
π‘οΈ Microsoft Defender Cloud
| Indicator | Feature | Type | Description |
|---|---|---|---|
| β« | Classic Defender for SQL APIs retirement | Deprecation | Classic Defender for SQL APIs for Vulnerability Assessment and Advanced Threat Protection will be retired on August 16, 2027. Migrate to supported configuration model and update dependent scripts/automation before retirement. |
| π΅ | On-demand malware scanning granularity | New/Updated | On-demand malware scanning in Microsoft Defender for Storage now supports targeted scanning of specific blobs, files, containers, or file shares instead of entire storage accounts. Use filters in REST API request body to scope scans. |
| π΅ | CIEM overprovisioned identity assessment change | New/Updated | Breaking change: Unused actions no longer included in AWS and GCP overprovisioned identity assessments to improve performance. Use native cloud provider tools (AWS IAM, GCP IAM) to validate permission usage. |
π‘οΈ Microsoft Defender Cloud (Recommendations & Alerts
| Indicator | Feature | Type | Description |
|---|---|---|---|
| β« | Retirement of legacy grouped recommendations | Deprecation | Retirement of legacy grouped recommendations (sub-assessments) has started as of July 31, 2026. Customers can no longer access deprecated data through API. Azure portal and Azure Resource Graph may take time to reflect changes. |
| π’ | SQL server-level individual recommendations | GA | Multiple individual recommendations released at database level as part of transitioning Defender for SQL Vulnerability Assessment from grouped to individual recommendations, including execute permissions, CLR settings, guest user access, and password policies. |
| π’ | AKS vulnerability recommendations | GA | New recommendations: βUpgrade Azure Kubernetes Service to remove vulnerabilities from AKS system podsβ and βContainer images in Docker Hub registry should have vulnerability findings resolved.β |
| π’ | 200+ multicloud recommendations for AWS/GCP | GA | Over 200 new multicloud security recommendations for AWS and GCP resources now GA, affecting Secure Score across data, identity/access, networking, compute, and container categories for ~90 newly supported resource types. |
| π’ | Azure Database for PostgreSQL recommendations | GA | Multiple recommendations for PostgreSQL Flexible Servers including log retention, pgaudit settings, public IP access restrictions, private endpoints, secure transport, and geo-redundant backups. |
| π’ | API endpoint security recommendations | GA | Recommendations for Function Apps and Logic Apps: unused API endpoints should be disabled/removed, and authentication should be enabled on API endpoints. |
| π‘ | EMR cluster security recommendations | Preview | Six preview recommendations for AWS EMR clusters covering custom IAM roles, security configuration, public network access, Kerberos authentication, termination protection, and logging encryption. |
| π‘ | AWS database service recommendations | Preview | Multiple preview recommendations for AWS services including IAM Database Authentication for DB Cluster, deletion protection for Neptune DB clusters, and public access restrictions for Neptune DB instances. |
| π‘ | AWS analytics service recommendations | Preview | Preview recommendations for AWS MSK, OpenSearch Service, App Engine, Certificate Manager, Athena workgroups, Amazon Comprehend, DMS, DataSync, FSx, Kendra, Keyspaces, Kinesis, MQ, and QuickSight. |
| π‘ | ECS Fargate and Container Apps recommendations | Preview | Preview recommendations for serverless containers including IAM task roles, privileged containers, read-only root filesystem, public exposure, ECS Exec logging, and Azure Container Apps authentication. |
π― Microsoft Defender XDR
No new features or updates documented in this period.
π Microsoft Defender Endpoint
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π’ | macOS Build 101.26062.0012 | GA | Release version 20.126062.12.0 with bug and performance fixes. |
| π’ | macOS Build 101.26062.0011 | GA | Release version 20.126062.11.0 with expanded local AI agent discovery (Preview) on macOS to include Model Context Protocol (MCP) server configurations, plus performance improvements. |
| π‘ | Vulnerability assessment for Microsoft Store applications | Preview | Monitor vulnerabilities on devices running Microsoft Store applications including Teams, Firefox, WhatsApp, Slack, Dropbox, DuckDuckGo, Dell Command, HP Smart, and NVIDIA Control Panel. Use Software evidence area to view file paths and vulnerable app details. |
πΏ MDE Detailed Releases
Windows
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π΅ | Windows cumulative rollup updates | New/Updated | Regular Windows cumulative updates include Defender for Endpoint EDR (MsSense.exe) version updates. Refer to Windows 11, Windows 10, Windows Server 2022/2019/2025 update history articles for file information. |
macOS
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π΅ | Build 101.26062.0012 (August 2026) | New/Updated | [macOS] Release version 20.126062.12.0 with engine version 1.1.26060.12000 and signature version 1.457.164.0. Bug and performance fixes. |
| π΅ | Build 101.26062.0011 (August 2026) | New/Updated | [macOS] Release version 20.126062.11.0 with engine version 1.1.26040.3000 and signature version 1.449.26.0. Expanded local AI agent discovery (Preview) to include MCP server configurations. Performance improvements and bug fixes. |
Linux
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π΅ | Monthly security updates | New/Updated | [Linux] Defender for Endpoint on Linux receives regular security fixes as part of monthly releases. Each version expires after nine months; expired versions continue receiving security intelligence updates but should be upgraded for full fixes and enhancements. |
π Microsoft Defender Identity
No new features or updates documented in this period.
π’ Microsoft Entra ID
No new features or updates documented in this period.
π± Microsoft Intune
No new features or updates documented in this period.
βοΈ Microsoft Defender Cloud Apps
No new features or updates documented in this period.
π§ Microsoft Defender Office 365
No new features or updates documented in this period.
π¨ Microsoft Security Exposure Management
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π΅ | Codename MDASH - Cancel scan | New/Updated | Scan cancellation now available in Microsoft Defender portal (previously only in Defender CLI). Cancel queued or running scans from the Scans tab on the scan details page. |
| π‘ | Codename MDASH - Azure DevOps connector | Preview | Azure DevOps connector now in preview for agentic code scanner. Security teams can connect Azure DevOps organizations from Microsoft Defender portal, onboard repositories, and trigger remote on-demand agentic code scans. |
β΅ AKS
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π’ | Node Auto Provisioning with restricted publicNetworkAccess | GA | Node Auto Provisioning can now be enabled on clusters with restricted publicNetworkAccess, including private API server VNet-integrated clusters using UDR, as long as AKS-wide networking guardrails pass. |
| π’ | Automatic availability zone placement | GA | Automatic availability zone placement now enabled globally. Customers can create new VMSS or VirtualMachines node pools with availabilityZones=[βautoβ], and existing VMSS node pools can be updated after rollout completes. |
| π’ | Control-plane only upgrades for LTS | GA | AKS now allows control-plane only upgrades to Long Term Support (LTS) clusters as long as version skew policy is satisfied, enabling safer upgrades by first upgrading control plane, validating, then upgrading node pools. |
| π’ | AKS Node pool Rollback | GA | Node pool version rollback is now GA, letting you restore a node pool to its previous Kubernetes version and node image after an upgrade issue, minimizing downtime and maintaining business continuity. |
| π’ | Azure File CSI driver encryption and workload identity | GA | Encryption in Transit and use workload identity to access Azure Files storage are now GA for Azure File CSI driver. |
| π‘ | Prepared Image Specification (PIS) | Preview | PIS now in public preview, allowing creation of preconfigured node images with required container images and node customizations already applied to reduce node startup times. |
| π‘ | Capacity Reservation Group association with existing node pools | Preview | Customers using preview API version 2026-01-02-preview or later can associate Capacity Reservation Group with existing node pools. Zonal pools perform rolling cordon/drain/reboot; non-zero regional pools must scale to zero first. |
| π΅ | SSH node access changes trigger reimage | New/Updated | For Kubernetes 1.37+, SSH node access configuration changes now trigger immediate node reimage. Use Node Disruption Policy to block or schedule during maintenance window. |
| π΅ | Network configuration changes trigger reimage | New/Updated | For Kubernetes 1.37+, changes to IMDS restriction, network-isolated bootstrap profile, or cluster outbound type now trigger immediate node reimage. Use Node Disruption Policy to control timing. |
| π΅ | VMSS rolling upgrade concurrency calculation | New/Updated | VMSS rolling upgrade concurrency for percentage-based maxSurge, maxUnavailable, and maxBlockedNodes is now calculated from current VMSS capacity and capped to remaining VMs to upgrade. |
| π΅ | Service principal to managed identity migration | New/Updated | Updating cluster from service principal authentication to managed identity now triggers node reimages across node pools. Configure Node Disruption Policy to control when reimages are allowed. |
| π΅ | AKS upgrade validation for VMSS limits | New/Updated | AKS upgrade validation now rejects node pool upgrades where current pool size plus effective surge would exceed VMSS 1,000-instance limit, preventing mid-upgrade Azure Compute failures. |
| π΅ | Istio Gateway API security improvement | New/Updated | Istio Gateway API deployments now set automountServiceAccountToken to false, improving default security posture and unblocking environments with Azure Policies requiring pods to disable service account token auto-mounting. |
| π΅ | GPU MIG slice width validation | New/Updated | AKS now validates GPU MIG instance profile slice width against VM SKU capacity, preventing unsupported MIG profiles on lower-capacity GPU SKUs. |
| π΅ | Application Gateway for Containers ALB version alignment | New/Updated | ALB add-on now aligned with AKS minor versions. AKS automatically selects compatible ALB controller image during cluster upgrades, reducing incompatibilities. |
| π΅ | AzureContainerLinux SSH rejection | New/Updated | AKS now rejects Entra ID SSH configuration on AzureContainerLinux node pools because the extension is incompatible with immutable OS nodes. |
| π΅ | AKS Automatic App Routing fix | New/Updated | Fixed issue where App Routing on Kubernetes 1.36+ clusters could incorrectly default to NGINX instead of Istio/Gateway API mode during cluster creation. |
| π΅ | Node Auto Provisioning Karpenter update | New/Updated | Node Auto Provisioning updated to Karpenter provider Azure v1.14.0, adding support for Balanced consolidation policy to reduce node churn. |
| π΅ | Azure Policy add-on updates | New/Updated | Gatekeeper bumped to 3.23.0 and Azure Policy add-on bumped to 1.17.0. |
| π΅ | CSI Driver updates | New/Updated | Azure File CSI Driver upgraded to v1.34.7/v1.35.6, Azure Blob CSI Driver to v1.26.16/v1.27.9, Azure Disk CSI Driver to v1.33.11/v1.34.5 across AKS versions. |
| π΅ | Azure Monitor Prometheus and Container Insights updates | New/Updated | Azure Monitor managed service for Prometheus add-on updated to 07-27-2026 release; Container Insights upgraded to 3.6.0. |
| π΅ | Node image updates | New/Updated | AKS Azure Linux, Azure Container Linux, and Ubuntu images updated with latest vhd-notes releases from July 2026. |
π¦ Azure Container Apps
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π‘ | Azure Container Apps Sandboxes | Preview | Azure Container Apps Sandboxes in public preview for enhanced isolation. |
| π’ | Confidential Compute | GA | Confidential Compute generally available for Azure Container Apps. |
| π΅ | HTTP traffic logs | New/Updated | HTTP traffic logs now available for traffic analysis and monitoring. |
| π΅ | Managed OpenTelemetry destinations | New/Updated | Additional managed OpenTelemetry destinations for New Relic, Dynatrace, and Elastic. |
| π΅ | Custom KEDA scale rule overrides | New/Updated | Custom KEDA scale rule overrides for Azure Functions on Container Apps. |
| π΅ | Regional expansion | New/Updated | Azure Container Apps now available in six additional regions: Germany North, New Zealand North, Chile Central, Korea South, Belgium Central, and Jio India Central. |
| π΅ | Bring Your Own Orchestrator for Jobs | New/Updated | Community-maintained templates for connecting existing workflow engines (Airflow, Temporal, Argo Workflows, Durable Functions, Logic Apps Standard, Dapr Workflow) to Container Apps Jobs. |
| π΅ | Express deployment guidance | New/Updated | Express deployment walkthrough with comparison to standard Container Apps, noting current preview gaps such as managed identity and VNet integration. |
π§± Azure Container Instances
No new features or updates documented in this period.
β‘ Azure Functions
No new features or updates documented in this period.
π Azure Logic Apps
No new features or updates documented in this period.
π Azure Monitor
| Indicator | Feature | Type | Description |
|---|---|---|---|
| β« | Azure Operations Center retirement | Deprecation | Azure Operations Center retired in August 2026. Use Azure Monitor for monitoring and analysis capabilities. Azure Copilot Observability Agent provides natural-language data exploration, guided investigations, and autonomous alert operations. |
| π΅ | Auxiliary/Lake table plans expansion | New/Updated | Auxiliary/Lake table plans expanded with Azure tables support, plan switching between Analytics and Auxiliary/Lake, and availability in sovereign clouds. Helps teams keep more data without stretching budget. |
π¬ Defender Container Sensor
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π’ | Sensor v0.11.5 | GA | Improved pod inventory reliability by preventing failures when processing Kubernetes pod deletion events. Updated runtime and telemetry dependencies to address security vulnerabilities. |
| π’ | Sensor v0.10.8 | GA | Improved pod inventory reliability by preventing failures when processing Kubernetes pod deletion events. Updated runtime and networking dependencies to address security vulnerabilities. |
| π’ | Sensor v0.9.65 | GA | Improved pod inventory reliability by preventing failures when processing Kubernetes pod deletion events. Updated runtime and networking dependencies to address security vulnerabilities. |
π€ Microsoft Security Copilot
No new features or updates documented in this period.
π Microsoft Purview
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π΅ | Auto-labeling policy simulation mode | New/Updated | Before enforcing auto-labeling policy, run in simulation mode to identify which items it would label without making changes. Review match results and source distribution to determine policy readiness. |
| π΅ | Auto-labeling policy Insights tab | New/Updated | Insights tab in policy details panel provides at-a-glance view of auto-labeling policy performance, with information varying based on simulation or enforcement mode. |
ποΈ Microsoft Foundry
No new features or updates documented in this period.
π§ Microsoft Copilot Studio
No new features or updates documented in this period.
π Microsoft Fabric
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π‘ | Eventstream workspace monitoring with per-eventstream control | Preview | Choose which eventstreams emit performance, error, and node-health data to three KQL tables in workspace monitoring Eventhouse. |
| π’ | Capacity Overview Events in Real-Time Hub | GA | Stream capacity summary and state signals to monitor utilization and health, detect throttling or lifecycle changes, and trigger alerts or automated actions. |
| π΅ | Publish Business Events from Fabric workloads | New/Updated | Publish versioned, schema-valid signals from notebook, User Data Function, Eventstream, or Activator that detects business conditions. |
| π΅ | Event pillar guidance | New/Updated | Guidance on choosing between Business Events (workload-published), Fabric Events (platform), and Azure Events (Azure Storage). |
| π΅ | Business Event schema design guidance | New/Updated | Business Event schema uses clear, factual, versioned contract so publishers and consumers share meaning while evolving independently. |
| π΅ | Eventhouse for data engineers | New/Updated | Eventhouse helps ingest, query, and analyze high-volume event data in near real time and share across Fabric through OneLake. |
π GitHub Security
| Indicator | Feature | Type | Description |
|---|---|---|---|
| π΅ | CodeQL 2.26.1 | New/Updated | Improves analysis accuracy and framework coverage for Go (log/slog modeling), Java/Kotlin (Apache POI models), JavaScript/TypeScript (Angular @HostListener), C/C++ (models-as-data field names), and Rust (reduced false positives in cryptographic query). |
| π΅ | CodeQL 2.26.3 | New/Updated | Adds JavaScript/TypeScript/Vue source modeling (Vue Router useRoute(), ref/reactive helpers), GitHub Actions improvements (merge_group event untrusted data, query accuracy fixes), C/C++ registry models, and Ruby vendoring false positive reduction. Breaking change: removed SelfHostedQuery module. |
| π΅ | Organization Code Quality trends dashboard | New/Updated | Organization-level Code Quality dashboard now includes Trends tab showing code quality changes across repositories over 7/14/30 days. View open findings trends, most improved repositories, and repositories needing attention. GA for Enterprise Cloud/Team with Code Quality enabled. |
| π’ | Innersource security advisories | GA | GitHub Advanced Security enterprise customers can publish internal security advisories restricted to enterprise repositories. New REST API for managing innersource vulnerabilities. Dependabot notifies repositories using the component and opens upgrade PRs. |
| β« | npm install-time security defaults | Deprecation | npm v12 makes allowScripts, allow-git, and allow-remote opt-in (defaults off/none). Dependency lifecycle scripts and git/remote dependencies no longer run unless explicitly allowed. Review with npm approve-scripts. |
| β« | npm 2FA-bypass GAT deprecation | Deprecation | npm granular access tokens configured to bypass 2FA will no longer skip 2FA for sensitive account/package/organization management actions (expected early August 2026). Perform these operations interactively with 2FA. |
| β« | npm 2FA-bypass direct publishing deprecation | Deprecation | Following 2FA-bypass GAT changes, these tokens will lose direct publishing ability. Publishing reduced to reading private packages and staging publish requiring human 2FA approval. |
| π΅ | npm publish-time malware scanning | New/Updated | Newly published npm packages automatically scanned before availability, introducing ~5 minute delay (up to 15+ minutes at peak). Blocked packages may receive appeal option. |
| π΅ | npm dual-use content metadata requirement | New/Updated | New contentPolicy field in package.json for dual-use content with security-relevant capabilities. Requires DISCLOSURE file in package root describing dual-use functionality and intended legitimate use. May trigger additional scanning. |
| π΅ | Dependabot malware alerts expansion | New/Updated | GitHub Advisory Database now ingests malware advisories from OpenSSF malicious-packages repository, expanding coverage across npm, PyPI, and more ecosystems. Automatic for users with malware alerting enabled. |
| π΅ | GitHub Actions malicious workflow holds | New/Updated | GitHub Actions now holds certain potentially malicious workflow runs for approval before execution on public repositories. Workflow wonβt run until repository collaborator with write access reviews and approves via authenticated web session. |
| π΅ | Credential revocation by token type | New/Updated | Enterprise owners, organization admins, and users with Manage enterprise credentials permission can now revoke all tokens of specific credential type (PATs, SSH keys, OAuth tokens, GitHub App tokens) for finer-grained incident response. Organization-level parity available. |
| π΅ | Dependabot version update cooldown | New/Updated | Dependabot now waits until new release available for at least three days before opening version update PR (default, configurable). Security updates still open immediately. Applies across supported ecosystems on github.com, coming to GHES 3.23. |
| π΅ | Code scanning default setup customization | New/Updated | Apply custom CodeQL configuration file to default setup via github-codeql-config-file repository property. Merge custom settings with built-in defaults. Organization-wide defaults supported; repositories can override if allowed. New syntax for referencing config files in other repositories. |
| π΅ | Dependabot branch name customization | New/Updated | New pull-request-branch-name options in dependabot.yml for customizing branch names with prefix, separators, case, or custom templates. Keeps Dependabot branches compatible with CI/CD naming conventions. |
| π΅ | Code coverage automatic enablement | Preview | Code Quality settings can generate coverage workflow automatically with AI. Opens PR with workflow that builds code, runs tests, generates coverage report, and uploads to GitHub with least-privilege permissions. Preview for Code Quality users on github.com. |
Top 5 Action Items
| Priority | Action | Due | Affected Product(s) |
|---|---|---|---|
| π΄ | Migrate from classic Defender for SQL APIs to supported configuration model | August 16, 2027 | Microsoft Defender Cloud |
| π΄ | Update npm automation to use 2FA for account/package management actions | Early August 2026 | GitHub Security |
| π΄ | Review and approve npm dependency lifecycle scripts before upgrading to v12 | Before npm v12 upgrade | GitHub Security |
| π‘ | Evaluate UEBA new data sources (Fortinet, Check Point, Zscaler, AWS GuardDuty) for SOC integration | Q3 2026 | Microsoft Sentinel |
| π‘ | Configure custom CodeQL configuration files for organization-wide code scanning defaults | Q4 2026 | GitHub Security |
Security Architect Observations
SQL API deprecation requires proactive migration planning: The August 2027 retirement of classic Defender for SQL APIs gives teams a year to migrate, but automation/scripts using these APIs must be inventoried and updated. Start assessing impact now to avoid last-minute rush.
GitHubβs supply chain security hardening is comprehensive: Multiple overlapping controls (malware scanning, 2FA-bypass GAT deprecation, malicious workflow holds, credential revocation by token type, cooldown periods) significantly raise the bar for supply chain attacks. Enterprise architects should review GitHub Advanced Security policies to align with organizational risk tolerance.
AKS node disruption policies are critical for production clusters: Multiple behavioral changes in AKS 1.37+ trigger immediate node reimaging (SSH changes, network config changes, identity migrations). Node Disruption Policy configuration is essential to prevent unplanned workload disruptions during routine operations.
Multicloud security coverage expansion is substantial: 200+ new recommendations for AWS/GCP resources across 90 resource types significantly expand Defender for Cloudβs multicloud posture management. Security architects managing hybrid/multicloud environments should review the new recommendations to understand coverage gaps and remediation paths.
npm dual-use metadata requirement creates new compliance surface: The contentPolicy field and DISCLOSURE file requirement for dual-use packages introduces new governance considerations for organizations publishing security-relevant tooling. Legal and security teams should establish review processes for dual-use declarations.
UEBA expansion to firewall/proxy logs enhances detection depth: New anomaly detection for Check Point, Fortinet, Zscaler, and AWS GuardDuty provides richer context for identity-linked suspicious activity. Architects should ensure these data sources are properly integrated and normalized for maximum UEBA effectiveness.
Security Operations Observations
UEBA anomaly insights reduce analyst investigation time: Contextual anomaly insights added directly to UEBA behavior records (first-seen activity, unusual volumes, uncommon values, TI matches) reduce manual correlation effort. SOC teams should update investigation playbooks to leverage these enriched insights.
GitHub Actions malicious workflow holds may impact CI/CD velocity: Security teams managing public repositories should prepare for workflow approval delays and establish escalation paths for time-sensitive pipeline runs. Consider pre-approving trusted workflow patterns where possible.
Dependabot cooldown period reduces bad merge risk: The default 3-day cooldown for version updates gives security community time to identify malicious/broken releases. Operations teams should adjust dependency update SLAs to account for this delay and avoid manual override unless critical.
Sensor updates address pod inventory reliability: Defender Container Sensor v0.9-0.11 updates fix pod deletion event processing failures. Teams using container security monitoring should verify sensor versions and validate pod inventory completeness after upgrade.
On-demand malware scanning granularity improves incident response efficiency: Targeted scanning of specific blobs/files/containers instead of entire storage accounts enables faster triage during malware investigations. SOC teams should update IR playbooks to leverage scoped scanning.
Credential revocation by token type enables surgical incident response: Security teams can now revoke specific token types (PATs, SSH keys, OAuth tokens) without nuking all credentials. Update incident response runbooks to leverage token-type-specific revocation for contained blast radius.