Microsoft Defender XDR Updates & Release Notes

Follow

11 updates curated from 1 source by the Releasebot Team. Last updated: Jul 20, 2026

Get this feed:
  • July 2026
    • Date parsed from source:
      Jul 1, 2026
    • First seen by Releasebot:
      Jul 20, 2026
    Microsoft logo

    Microsoft Defender XDR by Microsoft

    (Preview) AI agent posture risk in Microsoft Defender

    Microsoft Defender XDR adds preview AI agent posture risk to assess and prioritize risky enterprise and local agents.

    (Preview) AI agent posture risk in Microsoft Defender: Microsoft Defender now assesses posture risk for AI agents, including enterprise agents and local agents discovered on endpoint devices. Risk levels are based on active risk indicators, such as configuration, access, runtime activity, endpoint and user context, and active alerts. Security teams can use posture risk and recommendations to prioritize risky agents and improve agent security posture. For more information, see AI agent posture risk in Microsoft Defender.

    Original source
  • July 2026
    • Date parsed from source:
      Jul 1, 2026
    • First seen by Releasebot:
      Jul 20, 2026
    Microsoft logo

    Microsoft Defender XDR by Microsoft

    (GA) The Domain investigation page allows you to investigate an Active Directory domain.

    Microsoft Defender XDR adds a GA Domain investigation page for Active Directory security, health, identities, and recommendations.

    (GA) The Domain investigation page allows you to investigate an Active Directory domain. It shows Active Directory domain security, including domain properties, deployment health, identity summary, service account breakdown, sensitive entities, active recommendations, group policies, and trust relationships. For more information, see Investigate a domain.

    Original source
  • All of your release notes in one feed

    Join Releasebot and get updates from Microsoft and hundreds of other software products.

    Create account
  • July 2026
    • Date parsed from source:
      Jul 1, 2026
    • First seen by Releasebot:
      Jul 20, 2026
    Microsoft logo

    Microsoft Defender XDR by Microsoft

    (GA) Security for Microsoft Agent 365 with Defender

    Microsoft Defender XDR adds GA security for Microsoft Agent 365, bringing discovery, protection, and threat detection for AI agents.

    (GA) Security for Microsoft Agent 365 with Defender

    With a Microsoft Agent 365 license, Microsoft Defender provides discovery, security posture, threat detection and investigation, and real-time protection for the AI agents in your tenant. Onboarding includes enabling data collection, connecting the Microsoft 365 app connector, and connecting Copilot Studio for real-time protection of Copilot Studio agents. For more information, see Protect AI agents using Microsoft Defender and Enable security for AI agents using Microsoft Defender.

    Original source
  • June 2026
    • Date parsed from source:
      Jun 1, 2026
    • First seen by Releasebot:
      Jul 20, 2026
    Microsoft logo

    Microsoft Defender XDR by Microsoft

    The Phishing Triage Agent and Security Alert Triage Agent now use the more limited Email & collaboration content: Emails associated with alerts (read) permission

    Microsoft Defender XDR now uses least-privilege email permissions for Phishing and Security Alert Triage Agents.

    The Phishing Triage Agent and Security Alert Triage Agent now use the more limited Email & collaboration content: Emails associated with alerts (read) permission instead of the broader Email & Collaboration content: All Emails (read) permission. This least-privilege permission restricts agent access to only email content associated with alerts, improving the security posture of your agent configuration.

    Original source
  • June 2026
    • Date parsed from source:
      Jun 1, 2026
    • First seen by Releasebot:
      Jul 20, 2026
    Microsoft logo

    Microsoft Defender XDR by Microsoft

    (Preview) Entity enrichments with threat intelligence

    Microsoft Defender XDR adds Threat Intelligence Insights tabs to entity pages for faster IP, domain, URL, and file investigations.

    (Preview) Entity enrichments with threat intelligence: Entity pages for IP addresses, domains, URLs, and files now include a Threat Intelligence Insights tab that surfaces enrichment data from Microsoft Threat Intelligence directly in the investigation workflow. Enrichments include reputation scores, attributed threat reports, infrastructure relationships, and sandbox analysis, eliminating the need to switch between separate tools during investigations. For more information, see View threat intelligence in entity pages.

    Original source
  • Similar to Microsoft Defender XDR with recent updates:

  • June 2026
    • Date parsed from source:
      Jun 1, 2026
    • First seen by Releasebot:
      Jul 20, 2026
    Microsoft logo

    Microsoft Defender XDR by Microsoft

    (Preview) The Identity Security dashboard now includes a new Human identities card

    Microsoft Defender XDR adds a preview Human identities card to the Identity Security dashboard for a single view by source.

    (Preview)

    The Identity Security dashboard now includes a new Human identities card that shows your human identities by source (Entra ID, SaaS, and on-premises), giving you a single view of where your human identities live. For more information, see Identity Security dashboard.

    Original source
  • June 2026
    • Date parsed from source:
      Jun 1, 2026
    • First seen by Releasebot:
      Jul 20, 2026
    Microsoft logo

    Microsoft Defender XDR by Microsoft

    (Preview) On the Coverage and maturity page, the Review and improve coverage side panel for SaaS Identities now includes an Observed column and a Show Only Observed Applications toggle

    Microsoft Defender XDR adds an Observed filter and column to the SaaS Identities coverage panel in Preview.

    (Preview) On the Coverage and maturity page, the Review and improve coverage side panel for SaaS Identities now includes an Observed column and a Show Only Observed Applications toggle. By default, the panel shows only SaaS applications detected in your environment. Turn off the toggle to see other supported SaaS applications you can onboard to expand your identity coverage. For more information, see Coverage and maturity.

    Original source
  • June 2026
    • Date parsed from source:
      Jun 1, 2026
    • First seen by Releasebot:
      Jul 20, 2026
    Microsoft logo

    Microsoft Defender XDR by Microsoft

    (Preview) Local AI agent discovery on Windows endpoints

    Microsoft Defender XDR adds preview local AI agent discovery on Windows endpoints for better inventory, exposure map, and hunting visibility.

    (Preview) Local AI agent discovery on Windows endpoints: as part of the Defender AI agents experience, Microsoft Defender now automatically discovers supported local AI agents running on onboarded Windows devices - including coding agents and IDE extensions, desktop AI assistants, local AI runtimes, and agent platforms. Discovered agents appear as assets in the AI agent inventory, exposure map, and advanced hunting, giving security teams visibility into local AI agent usage across the organization. For more information, see Discover local AI agents.

    Original source
  • June 2026
    • Date parsed from source:
      Jun 1, 2026
    • First seen by Releasebot:
      Jul 20, 2026
    Microsoft logo

    Microsoft Defender XDR by Microsoft

    (Preview) Local AI agent runtime protection on Windows endpoints

    Microsoft Defender XDR adds public preview runtime protection for supported local AI agents on Windows endpoints, inspecting agent loops and blocking risky activity before it runs to help stop prompt injection and unsafe actions, with alerts for investigation.

    (Preview) Local AI agent runtime protection on Windows endpoints

    As part of the Defender AI agents experience, runtime protection for supported local AI agents on Windows endpoints is now available in public preview. Microsoft Defender inspects the agent loop (user prompts, tool calls, and tool responses) and can block risky activity before it executes, helping stop prompt injection and unsafe agent actions at the device level. Blocked and audited events appear as alerts in Microsoft Defender to support incident correlation and investigation workflows. For more information, see Set up AI agent runtime protection with Microsoft Defender for Endpoint.

    Original source
  • June 2026
    • Date parsed from source:
      Jun 1, 2026
    • First seen by Releasebot:
      Jul 20, 2026
    Microsoft logo

    Microsoft Defender XDR by Microsoft

    (GA) The following advanced hunting schema tables are now generally available

    Microsoft Defender XDR adds generally available advanced hunting schema tables for disruption, cloud audit, DNS, and process events.

    (GA) The following advanced hunting schema tables are now generally available:

    • The DisruptionAndResponseEvents table contains information about automatic attack disruption events in Microsoft Defender XDR.
    • The CloudAuditEvents table contains information about cloud audit events for various cloud platforms protected by the organization's Microsoft Defender for Cloud.
    • The CloudDnsEvents table contains information about DNS activity events from cloud infrastructure environments.
    • The CloudProcessEvents table contains information about process events in multicloud hosted environments.
    Original source
  • June 2026
    • Date parsed from source:
      Jun 1, 2026
    • First seen by Releasebot:
      Jul 20, 2026
    Microsoft logo

    Microsoft Defender XDR by Microsoft

    (Preview) The AgentsInfo table in advanced hunting is now available in preview

    Microsoft Defender XDR adds the AgentsInfo table in preview for advanced hunting, bringing a unified schema for agent inventory and governance across Copilot Studio, Microsoft Foundry, Microsoft 365 Copilot, third-party, and endpoint-discovered agents.

    (Preview)

    The AgentsInfo table in advanced hunting is now available in preview. The AIAgentsInfo table is transitioning to this new table, which provides a unified schema that supports agent inventory and governance for all agent types, including Copilot Studio, Microsoft Foundry, Microsoft 365 Copilot, third-party, and endpoint-discovered agents. Microsoft Agent 365 customers should use the AgentsInfo table today. The AIAgentsInfo table remains accessible until July 1, 2026. Update your queries to use AgentsInfo before this date. For more information, see Advanced hunting schema - Naming changes.

    Original source

This is the end. You've seen all the release notes in this feed!

Releasebot

Curated by the Releasebot team

Releasebot is an aggregator of official product update announcements from hundreds of software vendors and thousands of sources.

Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.