Microsoft Defender XDR
190 Message Center and Roadmap announcements for this Microsoft 365 service, shown 95 at a time.
Microsoft Defender XDR updates - page 1 of 2
Announcements 1-95 of 190, newest first.
202646 updates
- MC1387578 Microsoft Defender for Office 365: Localized default mark and notify email template
- MC1255406 Microsoft Purview | Data Security Triage Agent Summaries for DLP Alerts in Microsoft Defender XDR
- MC1455017 New Defender for Identity health alert for missing domain controller network traffic
- MC1455016 New Defender for Identity health issue for missing Windows events from a domain controller
- MC1454382 Action required: Update Microsoft Defender for Endpoint Android App
- MC1431377 Microsoft Defender for Office 365: AIR Investigation Experience Improvements
- MC1446794 Microsoft Teams: Report security concerns in Teams meetings
- MC1447673 Microsoft Teams: Users can report security concerns in group calls
- MC1279093 Microsoft Defender for Office 365: Enhancing how we handle promotional mail
- MC1438566 Action Required: Defer Upgrade to Microsoft Defender for Endpoint on Linux Build 101.26052.0009
- MC1440701 MDO Encrypted email attachment protection
- MC1422060 Microsoft Defender for Office 365: Prompt injection protection for email
- MC1330888 Upcoming change to Microsoft Defender for Endpoint Advanced Hunting: removal of SMB signature data
- MC1411577 Microsoft Defender: Automated investigation and response (AIR) integrated into antivirus with manual triggering removed
- MC1402307 Microsoft Defender for Cloud Apps: Improvements to threat protection capabilities
- MC1304290 2026 Microsoft 365 Packaging Update
- MC1392568 Microsoft Defender for Endpoint: Support for Amazon Linux 2 (ARM64) retiring October 31, 2026
- MC1388718 Microsoft Defender for Endpoint: Update to Linux connectivity requirements with new service URLs to allowlist
- MC1358832 Microsoft Secure Score: New recommendation to reduce inbound internet exposure
- MC1381122 Microsoft Defender XDR: Retirement of in-app OS update notifications in Defender for Endpoint (iOS)
- MC1381119 Microsoft Defender for Endpoint security updates move to Microsoft Update on Windows
- MC1324285 Microsoft Defender XDR: Password protection account action buttons
- MC1323263 Microsoft Defender for Office 365: ZAP expands cleanup to Deleted Items
- MC1293483 Microsoft Secure Score: New recommendation for Secure Boot 2023 certificate readiness in Microsoft Defender for Endpoint
- MC1281506 Planned breaking changes to ASIM KQL functions used by Microsoft Sentinel for Developers
- MC1276511 Upcoming retirement of older Microsoft Defender for Endpoint mobile app versions (iOS and Android)
- MC1268924 Microsoft Defender XDR: Email summary powered by Security Copilot on the email entity page
- MC1266905 Microsoft Secure Score: New recommendation for Microsoft Defender for Endpoint
- MC1261596 Notice: Security Copilot will be included as part of your Microsoft 365 E5 plan soon
- MC1254554 Upcoming retirement of select threat detections in Microsoft Defender for Cloud Apps
- MC1251207 Microsoft Secure Score: New recommendations for Microsoft Defender for Endpoint
- MC1237728 Advanced Hunting: new actions to block attachments and top-level URL domains
- MC1245219 Microsoft Defender for iOS: End of support for iOS 16 devices
- MC1239187 Defender for Office 365 URL click alerts now include Microsoft Teams
- MC1234542 Retirement of “Suspected identity theft (pass-the-ticket)” classic alert
- MC1230458 March 2026 Secure Score category update
- MC1227621 Microsoft Defender Antivirus: Change to exclusion storage when using MDE security settings management
- MC1219788 Microsoft Defender for Office 365: Enable users to report suspicious Teams messages in Plan 1
- MC1228325 (Public Preview) New built in alert tuning rules for Microsoft Defender for Endpoint in Microsoft Defender XDR
- MC1223828 Microsoft Teams: Report a suspicious call
- MC1220762 Retirement notice: MDE and XDR Advanced Hunting APIs retiring; migrate to Microsoft Graph Security API
- MC1222979 New Built-in Alert Tuning Rules optimize your incident and alert queues
- MC1222977 Microsoft Defender for Android: End of support for Android 10 devices
- MC1221927 Microsoft Defender for Android ending support for enrolled personal profiles
- MC1217650 Microsoft Defender for Cloud Apps – Improvements to Microsoft 365 connector configuration page
- MC1217649 Endpoint DLP-sensitive data alerting retiring in Defender; use Purview DLP
202549 updates
- MC1166867 Microsoft Defender for Office 365: Enhancing the quarantine email preview experience
- MC1200058 Microsoft Defender for Office 365: Admins can block external users in Microsoft Teams from Defender Portal
- MC1171845 Microsoft Defender for Office 365: Enhancing the quarantine experience for administrators
- MC1193410 Automatic Windows event auditing configuration availability for unified sensors (V3.x)
- MC1077861 Microsoft Defender for Cloud Apps: SIEM agents will retire
- MC1192257 Microsoft Defender Threat Intelligence: Convergence with Microsoft Defender and Microsoft Sentinel
- MC1133508 Microsoft Teams Integration with Microsoft Defender for Office Tenant Allow/Block List for blocking domains
- MC1194061 IP address changes in Defender for Identity v2.x sensor communication
- MC1192254 Microsoft Defender for Endpoint: New Microsoft Secure Score recommendations
- MC1191616 Microsoft Secure Score: New recommendations for Microsoft Defender for Endpoint
- MC1190195 Upcoming Changes to Entra Identity Protection Alert Settings in Defender XDR
- MC1183015 Fix/Update Microsoft Sentinel Account Entity Naming to avoid inconsistent account identification in incidents and alerts
- MC1187403 Automatic Windows event auditing configuration now available for unified sensors (V3.x)
- MC1187390 Unified sensor (v3.x) – new Remote Procedure Call (RPC) configuration health alert for Microsoft Defender for Identity
- MC1187837 Microsoft Defender for Office 365 Zero-hour auto-purge (ZAP) Teams protection capabilities to Defender for Office Plan 1
- MC1187672 Get ready for security agents: Microsoft Security Copilot will be included in Microsoft 365 E5
- MC1187397 Microsoft Defender for Endpoint: Threat actor attribution information will be removed from alert page
- MC1187386 Microsoft Defender for Identity alerts transitioning to XDR-based detection platform
- MC1147984 Microsoft Teams: User reporting for incorrectly identified security concerns
- MC1184997 Microsoft Defender for O365: New email actions available in Advanced Hunting
- MC1152320 Microsoft Defender for Office 365: Enhanced email entity page experience
- MC1179155 Microsoft Defender for Identity: New recommendation added to Microsoft Secure Score
- MC1181661 Vulnerable devices report enhancements - simplified filters and performance improvements
- MC1181656 Microsoft Secure Score: New recommendations for Microsoft Defender for Endpoint
- MC1155429 Microsoft Defender for Identity: New recommendations added to Microsoft Secure Score
- MC1179159 Microsoft Defender for Identity: Activate the Unified Sensor now generally available
- MC1177179 Microsoft Exchange Online: Remove-DkimSigningConfig cmdlet now available to tenant admins
- MC1172531 Protect your Windows 10 devices after Microsoft support ends
- MC1169078 Microsoft Defender for Cloud Apps: Improvements to threat protection capabilities
- MC1088729 Microsoft Defender for Office 365: Two new data tables in Advanced hunting (preview)
- MC1163763 Microsoft Secure Score: New recommendations for Microsoft Defender for Endpoint
- MC1163754 Enhancements to the Deep Analysis tab of Email Entity page by Microsoft Defender for Office 365
- MC1162274 New post-deployment configuration for unified sensors (preview)
- MC1142620 Microsoft Defender Core Service coming to Windows Server 2012 R2 and Windows Server 2016
- MC1154297 Microsoft Defender for Identity: New recommendations for Microsoft Secure Score
- MC1151684 Hard delete action now removes calendar entries from malicious meeting invite emails
- MC1151683 Microsoft Defender for Identity | Detections improvements to reduce noise and improve accuracy
- MC1151677 Updated Microsoft Defender Antivirus AVSignatureDue policy limit
- MC1134736 Quarantine experience update in Microsoft Defender and Exchange Online: Restore temporarily deleted items
- MC1150984 Microsoft Defender for Office 365: Message Warnings for Messages with Malicious URLs in Teams
- MC1150118 Microsoft Defender for Office 365: New records in Streaming API and Sentinel EmailEvents table
- MC1147387 Microsoft Defender for Office 365: Alert experience enhancements for faster triage
- MC1146813 Retirement of "Add to existing remediation" option in Microsoft Defender for Office 365
- MC1141957 Upcoming Retirement of Sub-Domains Feature in Defender for Cloud Apps – Cloud Discovery
- MC1130384 Microsoft Defender for Identity: New recommendations added to Microsoft Secure Score
- MC1137611 Deception feature in Microsoft Defender for Endpoint will be retired from public preview
- MC1137610 Microsoft Defender for Identity alerts transitioning to XDR-based detection platform
- MC1137606 Streaming API support for Data Security tables in Microsoft Defender XDR Advanced Hunting
- MC1108843 Microsoft Defender for Office 365: Ability to Disagree with admin submissions analysis