Skip to main content
🦉
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderPortfolio
🦉
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderPortfolio

Connect

© 2026 M365 Message Center. Created with ❤️ by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center • Not affiliated with Microsoft

  1. Home
  2. /
  3. MC1077861

Microsoft Defender for Cloud Apps: SIEM agents will retire

Plan for Change
Major Change

Message ID

MC1077861
View in Admin Center

Services

Microsoft Defender XDR

Summary

Microsoft Defender for Cloud Apps will retire SIEM agents, with no new agents configurable after June 19, 2025. The rollout is paused, and users are advised to transition to unified APIs and SIEM solutions for alerts and activity data to ensure continuity and enhanced capabilities.

Details

Updated December 23, 2025: We have paused rollout of this feature. We will announce via Message center when we are ready to proceed. Thank you for your patience. 

As part of our ongoing convergence process for all Microsoft Defender workloads, we planned to retire SIEM (Security Information and Event Management) agents from Microsoft Defender for Cloud Apps in late December 2025 (previously mid-November) and ending early January 2026 (previously late November 2025). We have puased this release and will communicate via Message center when we are ready to proceed.

We recommend you transition to APIs that support the management of activities and alerts data from multiple workloads.

How this will affect your organization:

Existing Microsoft Defender for Cloud Apps SIEM agents will function as is until the SIEM agents retire, but no new SIEM agents can be configured starting June 19, 2025. Microsoft Sentinel agents will remain supported and can still be added.

Defender for Cloud Apps alerts and activities data currently supported in the SIEM agents are also available in the unified API and SIEM solutions that provide access to alerts and activity data for all Microsoft security products, for cross-workload visibility:

  • For alerts and activities, Defender XDR streaming API: Stream Microsoft Defender XDR events - Microsoft Defender XDR | Microsoft Learn
  • For Microsoft Entra ID Protection login events: IdentityLogonEvents table in the advanced hunting schema - Microsoft Defender XDR | Microsoft Learn
  • For alerts, Microsoft Graph security alerts API (v2): List alerts_v2 - Microsoft Graph v1.0 | Microsoft Learn
  • We also recommend viewing Defender for Cloud Apps alerts data in the Microsoft Defender XDR incidents API. Learn more: Microsoft Defender XDR incidents APIs and the incidents resource type - Microsoft Defender XDR | Microsoft Learn

These APIs enhance security monitoring and management and offer additional supported capabilities that utilize data from multiple Microsoft Defender workloads.

What you need to do to prepare:

To ensure continuity and access to the same data available before this retirement through Microsoft Defender for Cloud Apps SIEM agents, we recommend transitioning to the supported unified API and SIEM solutions. We encourage you to begin planning your migration to these solutions to take advantage of their enhanced capabilities.

Learn more: Generic SIEM integration - Microsoft Defender for Cloud Apps | Microsoft Learn

Timeline

📅
Published
May 19, 2025
Message published to Message Center
⚠️
Action Required By
Jun 18, 2025
Action deadline
✏️
Updated
Dec 23, 2025
Message content updated
🏁
End Date
Mar 31, 2026
Message timeline ends

Tags

#Updated message#Admin impact#Retirement

Category

📋Plan for Change

Related Messages

Similar updates

MC1220762●

Retirement notice: MDE and XDR Advanced Hunting APIs retiring; migrate to Microsoft Graph Security API

Jan 22, 2026
MC971037●

Exposure Management Recommendations Retirement

Jan 3, 2025
MC940078●

Upcoming changes to Defender for Identity activities and alerts in Defender for Cloud Apps experiences

Nov 22, 2024
MC912708●

Microsoft Defender for Identity: "Alert notifications" feature will retire starting in November 2024

Oct 17, 2024
MC889532●

Retirement: Investigation priority score feature

Sep 13, 2024