Hello everyone,
Welcome to the Microsoft Security Matters Newsletter – July 2026 Edition. Below is a curated roundup of Microsoft security updates, organized by topic to help you quickly find the news most relevant to your customers and conversations.
General
- Advanced Microsoft Intune capabilities now available in Microsoft 365 E3 and E5 (2026-07-01, Intune Blog)
Across industries, customers are already using advanced Microsoft Intune Suite capabilities to solve real endpoint challenges, such as reducing standing privilege, improving IT response times, modernizing certificate… - What’s new in Microsoft Intune – June (2026-07-06, Intune Blog)
Editor’s note (July 2026): This post has been updated since its original publication. Content related to Intune Endpoint Privilege Management capabilities for system-level network configuration has been removed. AI ag… - New Windows Features to Secure Today’s Data in a Post-Quantum World (2026-07-14, Microsoft Security Blog)
***July 14 Update: TLS Hybrid Key Exchange using ML-KEM groups is now available on Windows 11 starting with update KB5089573 for 24H2 and 25H2 and KB5095091 for 26H1. Composite algorithms are now available on Windows… - What’s new in Microsoft Intune – July (2026-07-28, Intune Blog)
Ask an IT admin what a good day looks like, and it usually comes down to one word: control. Control means you push a change and know it landed. It means you have a clear view into your device fleet, from compliance st… - Better security starts with better questions (2026-07-29, Microsoft Security Blog (official))
Learn how better questions, trusted AI, and human judgment help security leaders make confident decisions and build resilient systems. The post Better security starts with better questions appeared first on Microsof… - What’s new in Microsoft Security: July 2026 (2026-07-30, Microsoft Security Blog (official))
This month’s updates help security and IT teams secure their AI environments, use AI to defend, and strengthen the foundations that AI-powered operations depend on. The post What’s new in Microsoft Security: July…
AI Security
- Enhancing AI security through global AI red teaming (2026-07-27, Microsoft Security Blog (official))
Microsoft’s External Red Team Alliance (EXTRA) is a global AI security initiative designed to advance AI safety research and red teaming. By partnering with universities, researchers, and regional experts, EXTRA helps… - Rethinking security for the age of AI (2026-07-27, Microsoft Security Blog (official))
The physics of cybersecurity are changing. Introducing security’s new cyber stack: Project Perception. The post Rethinking security for the age of AI appeared first on Microsoft Security Blog . - The Microsoft AI and Agent Platform — The Platform Behind Intelligent Agents (2026-07-29, Microsoft Security Blog)
Why the platform around the model is the real enterprise differentiator Enterprise AI has reached a turning point. Beyond answering questions, it can now reason over business context, retrieve knowledge, use tools, co…
Agent 365
- Govern AI agent identities and access the same way you govern your employees (2026-07-07, Microsoft Entra Blog)
In our conversations with customers, we’ve heard consistent feedback: organizations want to embrace AI agents, but they need the same governance rigor they apply to human identities—adapted for the speed and scale of… - What’s new in Agent 365 – June 2026 (2026-07-08, Agent 365 Blog)
By Alex Pozin, Samer Baroudi, Brendan Powers As AI agents become a core part of enterprise operations, organizations need a consistent way to observe, manage, govern, and secure agents across an increasingly distribut… - AI agents are everywhere. Are your access controls ready? (2026-07-15, Microsoft Entra Blog)
At Identiverse 2026, Microsoft Security hosted a Power Breakfast that brought together 150 identity professionals across 10 simultaneous roundtable discussions. Participants came from industries including financial se… - Securing AI Agents at Runtime: Real-Time Protection and Threat Detection for Microsoft Agent 365 (2026-07-27, Microsoft Security Blog)
Organizations are rapidly adopting AI agents to automate workflows, access enterprise data, invoke tools, and take actions on behalf of users. This autonomy creates a fundamentally new security challenge. Unlike tradi…
Azure Security & Defender for Cloud
- Now generally available: Serverless posture coverage in Microsoft Defender CSPM (2026-07-01, Defender for Cloud Blog)
Serverless workloads are a foundation of modern application development, powering everything from low-code and no-code solutions to AI applications and agentic workflows. Development teams use functions, app services,… - Microsoft Defender for Cloud Customer Newsletter (2026-07-02, Defender for Cloud Blog)
What’s new in Defender for Cloud? Microsoft Defender for Open-Source Relational Databases is now generally available for Amazon Web Services Relational Database Service (AWS RDS) instances. Receive database threat pro… - Built to Protect: The Architecture Behind Codename MDASH (2026-07-30, Defender for Cloud Blog)
Information Table Defender Foundations Regional Operation AI & Data Containment Responsible Governance Built as a production Microsoft Security service, not an isolated research system. Operates alongside Microsoft De…
Threat Intelligence
- Microsoft Defender now integrates with Dragos, Forescout, & Armis for OT Security (2026-07-14, Microsoft Threat Protection Blog)
Co-author(s): Amit Cohen and Hadar Shindler Operational technology (OT) environments are unlike anything else in cybersecurity. The systems that run our factories, power grids, water treatment plants, pipelines, and t… - Real world incident response: Microsoft and AXA XL strengthen cyber resilience (2026-07-22, Microsoft Security Blog (official))
Our collaboration with AXA XL brings Microsoft Incident Response services directly to cyber insurance policyholders, helping organizations coordinate technical, business, and insurance decisions. The post Real world i… - Email threat landscape: Q2 2026 trends and insights (2026-07-23, Microsoft Security Blog (official))
In the second quarter of 2026, the continuing effects of Microsoft’s disruption of the Tycoon2FA phishing platform contributed to sustained declines in several major phishing techniques, while threat actors expanded i… - How Nationwide stays ahead of attackers with Project Perception (2026-07-27, Microsoft Security Blog)
Nationwide, the world’s largest building society, is among the first organizations to put Microsoft’s new agentic security system to work. Facing adversaries who now regularly weaponize AI, the society is using Projec… - Detecting CVE-2026-54121 (Certighost) with Microsoft Defender (2026-07-31, Microsoft Threat Protection Blog)
What is CVE-2026-54121? CVE-2026-54121 is an authentication-bypass vulnerability in Active Directory Certificate Services that allows an attacker to obtain certificates for arbitrary domain computer accounts, includin…
Microsoft Entra
- Bring business logic into PIM role activation workflows (2026-07-01, Microsoft Entra Blog)
Privileged access often depends on business context that lives outside Privileged identity Management (PIM)—ticket validity, HR status, compliance checks, or on-call schedules. With custom extensions for Microsoft Ent… - Plan your Azure AD B2C migration with the Migration Policy Analyzer (2026-07-20, Microsoft Entra Blog)
Migration planning starts with visibility One of the first challenges organizations face when planning a migration from Azure AD B2C to Microsoft Entra External ID is understanding exactly what is implemented in their… - Microsoft Entra ID enhances security of branded sign-ins (2026-07-21, Microsoft Entra Blog)
To align with Microsoft’s Secure Future Initiative and its focus on identity security and phishing resistance, we’re evolving Microsoft Entra custom branding to help customers deliver sign-in experiences that are more… - Secure AI, web, and private apps with Zero Trust (2026-07-21, Microsoft Entra Blog)
Today’s threats don’t respect boundaries. As AI agents proliferate across enterprise workflows, employees work from everywhere, and organizations adopt cloud-first architectures, the attack surface has fundamentally s… - Modernize SAP Identity Management with Microsoft Entra (2026-07-24, Microsoft Entra Blog)
Many organizations are rethinking how they manage identity across their SAP landscape as they move away from on-premises identity management systems and adopt a more unified cloud strategy. That shift often starts wit… - What’s New in Microsoft Entra: July 2026 (2026-07-24, Microsoft Entra Blog)
Welcome to the July edition of our monthly newsletter, summarizing the latest news and developments in the exciting, ever-evolving world of Microsoft Entra. What went into General Availability (GA) since June 2026? Mi…
Defender XDR & Sentinel
- Behind the Build with Gigamon: Enriching Microsoft Sentinel with Network-Derived Telemetry (2026-07-01, Microsoft Sentinel Blog)
Behind the Build is an ongoing series spotlighting standout Microsoft partner collaborations. Each edition dives into the technical and strategic decisions that shape real-world integrations—highlighting engineering e… - Monthly news – July 2026 (2026-07-01, Microsoft Threat Protection Blog)
Microsoft Defender Monthly news – July 2026 Edition This is our monthly “What’s new” blog post, summarizing product updates and various new assets we released over the past month across our Defender products. In this… - Building toward an Agentic SOC: A Portable, Autonomous Malware Investigation Agent (2026-07-13, Microsoft Sentinel Blog)
Modern Security Operations Centers are not short on tools. They are short on continuity. Analysts jump from alert consoles to data exploration, from enrichment to investigation, and from evidence gathering to response… - Announcing the ASIM Parser Creation Agentic Experience (2026-07-15, Microsoft Sentinel Blog)
Creating high-quality ASIM parsers has always required deep knowledge about source data and ASIM schemas, careful KQL design, and repeated validation cycles. That process is meaningful to understand the whole Sentinel… - Introducing scheduled antivirus scans on Microsoft Defender Linux (2026-07-15, Defender XDR Blog)
Security teams rely on scheduled scans to ensure consistent coverage across devices, detect dormant or missed threats, and meet compliance requirements. However, managing scans on Linux has traditionally required cust… - New Privileged Token Context Telemetry Boosts Advanced Hunting in Microsoft Defender (2026-07-15, Defender XDR Blog)
In brief: Defenders can now easily identify logons involving high-privilege identities or special logon flags to better hunt threats and fine-tune detections. When a user logs on, Windows’ Local Security Authority (LS… - Defending the Inbox Against Prompt Injection Attacks (2026-07-22, Defender for Office 365 Blog)
AI assistants are quickly becoming part of everyday work—summarizing emails, drafting responses, triaging requests, and even potentially acting across connected business systems. As email becomes an automated input to… - MDTI convergence in Microsoft Sentinel and Defender XDR is complete (2026-07-29, Microsoft Threat Protection Blog)
Beginning August 1, the final phase of Microsoft Defender Threat Intelligence (MDTI) convergence will be generally available in the Defender portal, giving customers real-time Microsoft threat intelligence across dete… - What’s new in Microsoft Sentinel: July 2026 (2026-07-31, Microsoft Sentinel Blog)
Welcome back to What’s new in Microsoft Sentinel. In July, Sentinel adds custom detections support in Sentinel repositories, so you can manage detections as code alongside your analytics rules, playbooks, parsers, and…
Purview
- Extend data security to the network with Microsoft Purview and Microsoft Entra (2026-07-01, Microsoft Security Blog)
Protection that keep s up with how data moves in the AI era Enterprise data used to be easier to contain. It lived in files, in apps you managed, within boundaries you controlled. Security teams could focus on endpoin… - Protect sensitive data in motion across SaaS and AI apps with Microsoft Purview and Microsoft Entra (2026-07-01, Microsoft Entra Blog)
Once, securing data meant protecting them within the confines of endpoints and managed apps. It lived inside boundaries you controlled. Today, those boundaries have disappeared—and with them, the old playbook for data…
Learning
- Level Up Your Security Skills This August with the Microsoft Defender Challenge and Learn Live (2026-07-27, Microsoft Security Blog)
Security teams face an increasingly complex landscape. Threats span identities, endpoints, email, cloud workloads, and emerging AI environments. The best defenders aren’t just reacting to threats—they’re continuously…