Smoke Test Microsoft Foundry Agents with GitHub Actions
July 1, 2026
Securing AI skill repositories with Nvidia SkillSpector and GitHub Actions
July 1, 2026Microsoft Defender
Monthly news – July 2026 Edition
This is our monthly “What’s new” blog post, summarizing product updates and various new assets we released over the past month across our Defender products. In this edition, we are looking at all the goodness from June 2026. We are now including news related to Defender for Cloud in the Defender portal. For all other Defender for Cloud news, have a look at the dedicated Defender for Cloud Monthly News here.
🚀 New Virtual Ninja Show episode:
- Redefining identity security for the modern enterprise
- One policy engine to govern them all: Securing agentic AI with Microsoft Purview
- Building a modern detection pipeline with ContentOps
- Securing local AI agents with Microsoft Defender
- Microsoft Defender: Extending critical protection for emerging threats in Team
Weekly Security News: We publish a short 1ish minute video every week with updates across our Microsoft Security stack. Subscribe to our YouTube channel, so you don’t miss the next episode.
Actionable threat insights (find all of them here)
- Securing AI agents: When AI tools move from reading to acting
- Chromium extension uses AI‑related branding to redirect browser search
- Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access
Microsoft Defender
- Two Workbooks capabilities in the unified Microsoft Defender portal moved to GA:
- Advanced Hunting connector – build custom dashboards directly on top of Advanced Hunting (XDR) dat. Query XDR tables and visualize them in Workbooks for richer investigations and reports.
- Workspace filter / multi-workspace experience – scope and filter workbooks by workspace, with workspace selection integrated into the workbook itself rather than relying on the global selector.
- MTO Tenant Groups let MSSPs and large enterprises organize their multitenant view in Microsoft Defender by grouping tenants logically (e.g., by region, business unit, or customer cohort). Learn more here.
Custom Detections support in Microsoft Sentinel Repositories. Custom Detections can now be managed as code in Microsoft Sentinel Repositories, the same way customers already manage analytic rules, playbooks, parsers and workbooks. Detection engineers connect a GitHub or Azure DevOps repo to their workspace; Custom Detections placed in the repo are reconciled on every commit. A standalone Bicep path via the Microsoft Security Bicep extension lets teams deploy from any CI/CD pipeline (ADO Pipelines, GitHub Actions, custom runners).
(General Availability) The following advanced hunting schema tables are now generally available:
The CloudAuditEvents table contains information about cloud audit events for various cloud platforms protected by the organization’s Defender for Cloud.
The CloudDnsEvents table contains information about DNS activity events from cloud infrastructure environments.
The CloudProcessEvents table contains information about process events in multicloud hosted environments.
(Public Preview) The AgentsInfo table in advanced hunting is now available in preview. The AIAgentsInfo table is transitioning to this new table, which provides a unified schema that supports agent inventory and governance for all agent types, including Copilot Studio, Microsoft Foundry, Microsoft 365 Copilot, third-party, and endpoint-discovered agents. Microsoft Agent 365 customers should use the AgentsInfo table today. The AIAgentsInfo table remains accessible until July 1, 2026. Update your queries to use AgentsInfo before this date. For more information, see Advanced hunting schema – Naming changes.
- For all other Sentinel News, have a look at the “What’s new in Microsoft Sentinel blog post – June edition“
Identity Security
- (Public Preview) The Identity Security dashboard now includes a new Human identities card that shows your human identities by source (Entra ID, SaaS, and on-premises), giving you a single view of where your human identities live. For more information, see Identity Security dashboard.
- (Public Preview) On the Coverage and maturity page, the Review and improve coverage side panel for SaaS Identities now includes an Observed column and a Show Only Observed Applications toggle. By default, the panel shows only SaaS applications detected in your environment. Turn off the toggle to see other supported SaaS applications you can onboard to expand your identity coverage. For more information, see Coverage and maturity.
New alerts were added to the Defender for Identity security alerts related to Microsoft Entra ID, Active Directory as well as other identity providers. For a full list of those new alerts, check out our documentation.
Recent ShinyHunters attacks on Salesforce show how OAuth tokens and connected apps are being weaponized to bypass MFA at scale. The upgraded Salesforce connector for Defender for Cloud Apps helps detect these attacks faster, with richer connected-app context and investigation-ready signals. Customers already using the connector are advised to enable the additional events in the Salesforce console for tighter protection, and eligible customers not yet using it are advised to connect Salesforce. Learn more.
Microsoft Defender for Endpoint / Microsoft Defender Vulnerability Management
(Public Preview) Local AI agent discovery: as part of the Defender AI agents experience, Microsoft Defender now automatically discovers supported local AI agents running on onboarded Windows & macOS devices. Discovered agents appear as assets in the AI agent inventory, exposure map, and advanced hunting, giving security teams visibility into local AI agent usage across the organization. For more information, see Discover local AI agents.
AI Assets page
(Preview) Local AI agent runtime protection on Windows endpoints is now available in public preview. Microsoft Defender inspects the agent loop (user prompts, tool calls, and tool responses) and can block risky activity before it executes, helping stop prompt injection and unsafe agent actions at the device level. Blocked and audited events appear as alerts in Microsoft Defender to support incident correlation and investigation workflows.
The new version of the Defender deployment tool for Windows streamlines onboarding and enhances security by:
Bundling the onboarding package directly into the tool’s executable.
Generating a key during deployment package creation that is required for running the tool.
Enabling users to configure an expiry date for the package to reduce the risk of unauthorized use.
In addition:
You have the option of downloading the package as either an .exe or a .zip file, whichever best suits your organization’s needs.
A new Deployment packages page in the Defender portal facilitates management of downloaded packages by providing centralized visibility into all the packages and their current status.
Now generally available: Selective Response Actions enables organizations to tailor high-impact security operations on devices during onboarding. It provides precise control over how response actions are applied on Tier-0 systems and other high-value assets, helping maintain operational stability while delivering strong protection.
Enable selective response actions
The new exposure score model in Defender Vulnerability Management is now generally available. This model improves risk prioritization and recommendation impact accuracy by incorporating exploit prediction data (EPSS) and asset context factors such as internet-facing status and criticality. More details here.
Microsoft Secure Score now includes the Reduce unnecessary inbound internet exposure on internet-facing devices recommendation, which helps identify devices that are accessible from the public internet and may represent unnecessary attack surface. This recommendation provides centralized visibility into internet-facing devices across the environment.
Many predefined SaaS application classification rules were added to the critical assets list. Have a look at our documentation for the full list. These classifications require onboarding to Microsoft Defender for Cloud Apps.