{"id":124704,"date":"2026-07-30T18:38:39","date_gmt":"2026-07-30T18:38:39","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/124704\/"},"modified":"2026-07-30T18:38:39","modified_gmt":"2026-07-30T18:38:39","slug":"whats-new-in-microsoft-security-july-2026","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/124704\/","title":{"rendered":"\u200b\u200b\u200b\u200bWhat\u2019s new in Microsoft Security: July 2026"},"content":{"rendered":"<p class=\"wp-block-paragraph\">Every organization needs security that protects end to end with the speed and scale of AI. Microsoft\u2019s vision is simple: security should be ambient and autonomous, just like the AI it protects.<\/p>\n<p class=\"wp-block-paragraph\">As organizations scale AI and expand across environments, security teams need protection that covers every surface. This month\u2019s updates help security and IT teams secure their AI environments, use AI to defend at speed and scale, and strengthen the foundations that AI-powered operations depend on. Here\u2019s what\u2019s new:<\/p>\n<p>Project Perception brings agentic defense to security operations<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/blogs.microsoft.com\/blog\/2026\/07\/27\/rethinking-security-for-the-age-of-ai\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Project Perception<\/a>, newly announced, is a coordinated system of specialized agents, cybersecurity-focused models, and enterprise-wide signals that transform how security operates. The agents work as a team: red team agents expose weaknesses, blue team agents investigate cyberthreats, and green agents harden what\u2019s found. These multi-agent autonomous workflows work as a team to operate in continuous loops to execute end-to-end security workflows.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/image-18-1.webp\" alt=\"Diagram illustrating roles of Red, Blue, and Green team agents in continuous, proactive protection. Red team simulates attacks to identify exploits, Blue team detects and triages threats quickly, and Green team fixes and remediates issues to close gaps and ensure safe resolution.\" class=\"wp-image-148897 webp-format\"  data-orig-src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/image-18-1.webp\"\/><\/p>\n<p>Microsoft Defender secures the full AI attack surface, from inbox to cloud<\/p>\n<p class=\"wp-block-paragraph\">Expanded <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/microsoft-defender\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Microsoft Defender<\/a> protections are designed to reduce risks associated with day-to-day AI interactions, from email inboxes to cloud agent environments. New <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/microsoftdefenderforoffice365blog\/defending-the-inbox-against-prompt-injection-attacks\/4534636\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">prompt injection protection<\/a> in Microsoft Defender, now in preview, identifies and isolates emails containing malicious AI instructions before delivery, reducing the risk of prompt injection attacks reaching the inbox. Unified Defender posture and runtime protection for cloud agents in <a href=\"https:\/\/www.microsoft.com\/en-us\/microsoft-agent-365\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Microsoft Agent 365<\/a> consolidates security posture assessment and runtime protection for Microsoft Foundry, Microsoft Copilot Studio, and third party-managed agents, helping teams reduce AI-specific risk across the agent estate.<\/p>\n<p>Accelerate detection, prioritization, and response with AI embedded in SecOps workflows<\/p>\n<p class=\"wp-block-paragraph\">Security teams can accelerate detection, prioritization, and response to cyberthreats with AI embedded directly into security operations (SecOps) workflows through Microsoft Defender. Threat intelligence enhancements, including <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/siem-and-xdr\/microsoft-defender-threat-intelligence\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Microsoft Defender Threat Intelligence<\/a> convergence and an enhanced Threat Intelligence Agent, bring more out-of-the-box intelligence and automation into the unified SecOps workflow, so teams can move from summary to action.<\/p>\n<p>Strengthen the cloud, code, and identity foundations AI depends on<\/p>\n<p class=\"wp-block-paragraph\">Microsoft Defender is strengthening the foundational protections that AI-era operations depend on across cloud, code, and identity. Cloud Security Posture Management <a href=\"https:\/\/aka.ms\/mdc-serverless-posture\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">extends coverage to serverless containers<\/a>, giving teams visibility and continuous posture assessment across containerized workloads running on Azure Container Apps, Azure Container Instances, and Amazon Web Services Elastic Container Service (AWS ECS) on Fargate. New interconnected experiences between Defender and Microsoft Entra empower the security operations center (SOC) to disable compromised identities directly using a role-based access control (RBAC) mode that maintains least privilege. <a href=\"https:\/\/aka.ms\/blackhat-services\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Microsoft Defender Experts services are also expanding<\/a>: Microsoft Defender Experts Threat Intelligence delivers human-led, curated insight into the cyberthreats most relevant to each organization, and Microsoft Defender Experts MDR extends expert-run detection and response beyond the Microsoft estate into third-party and multicloud signals through <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/siem-and-xdr\/microsoft-sentinel-siem\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Microsoft Sentinel<\/a>.<\/p>\n<p>Microsoft Entra strengthens identity across the AI-powered enterprise<\/p>\n<p>Strengthen identity foundations for AI-powered operations<\/p>\n<p class=\"wp-block-paragraph\">New capabilities in <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/microsoft-entra\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Microsoft Entra<\/a> are designed to strengthen the identity foundations that AI-powered operations depend on. Tenant governance helps organizations discover, manage, and govern tenants across their environment with centralized policies and cross-tenant delegated administration. Microsoft Entra ID is <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/07\/13\/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">making passkeys the default authentication experience<\/a>, which helps reduce reliance on SMS and voice, strengthens phishing-resistant security, and makes for an easier transition away from Microsoft-provided telecom delivery, which will retire in 2027. Through new interconnected Entra and Defender experiences, identity and access management and SOC teams share user experience, RBAC, and agentic workflows that eliminate product seams so identity and security operations can work together.<\/p>\n<p>Protect sensitive data in motion across software as a service (SaaS) and AI apps with Microsoft Purview and Microsoft Entra<\/p>\n<p class=\"wp-block-paragraph\">Microsoft Purview <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/microsoft-entra-blog\/protect-sensitive-data-in-motion-across-saas-and-ai-apps-with-microsoft-purview-\/4529310\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">now integrates<\/a> with Microsoft Entra Internet Access to extend data security to the network layer, enabling real-time protection of sensitive data shared with unmanaged cloud and AI apps over the network. For example, when an employee attempts to upload sensitive customer data or proprietary information, including text and files, into shadow AI apps, sharing is detected and blocked before the data is leaked from the organization. Organizations now have a unified Microsoft solution to gain visibility into where organizational data is shared externally, to detect and block sensitive data in transit, and to enable consistent data protection across their environment without relying on third-party solutions.<\/p>\n<p>Microsoft Purview strengthens data security, compliance, and investigation for AI<\/p>\n<p class=\"wp-block-paragraph\">A new Microsoft Purview Data Loss Prevention (DLP) for Microsoft 365 Copilot protection, available in preview, now gives data security teams <a href=\"https:\/\/learn.microsoft.com\/en-us\/purview\/dlp-microsoft365-copilot-location-learn-about#block-external-email-from-being-processed-preview\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">greater control over how Copilot leverages email content<\/a>, given external sources can introduce sensitive, third-party, or unvetted information that organizations may not want to rely on. Now admins can exclude emails from external senders from being referenced, summarized, or used as grounding data for Copilot. For example, with this DLP policy in place, an employee working with an external collaborator can still rely on Copilot to leverage internal insights, while external conversations are automatically excluded from Copilot-generated responses. With the native integration between <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/microsoft-purview\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Microsoft Purview<\/a> and Microsoft 365 Copilot, organizations can extend controls to AI interactions with minimal additional configuration, resulting in a more predictable and policy-aligned AI environment.<\/p>\n<p class=\"wp-block-paragraph\">A new centralized Microsoft Purview Insider Risk Management alert experience simplifies the prioritization of the most pressing data risks by bringing <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/microsoft-security-blog\/introducing-a-unified-alert-experience-for-microsoft-purview-insider-risk-manage\/4530714\" rel=\"nofollow noopener\" target=\"_blank\">agentic alert triage, enriched user details, and expanded analysis capabilities<\/a> (such as notes infused on the Insider Risk Management case) into a single view. Helping power this experience, the <a href=\"https:\/\/aka.ms\/InsiderRiskInvestigations\" rel=\"nofollow noopener\" target=\"_blank\">Data Security Triage Agent<\/a> includes an advanced AI reasoning layer, now generally available, that performs deeper, multi-step analysis across user, device, and data activity signals to surface the incidents most likely to require investigation while reducing noise. Analysts can filter across classic and Data Security Triage Agent attributes on a single page, preview agent summaries and user details without switching views, and document findings while the system automatically records status changes and escalations to maintain a clear investigation history. Together, the Insider Risk Management alert experience and Data Security Triage Agent help security teams investigate faster and with greater confidence.<\/p>\n<p><img decoding=\"async\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/1785436719_528_Picture1.webp\" alt=\"\" class=\"wp-image-148850 webp-format\"  data-orig-src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/1785436719_528_Picture1.webp\"\/><\/p>\n<p>\t\tThe unified Insider Risk Management alerts list, showing inline agent summaries, the new Categorization column, and combined classic and agent filtering on a single page.<\/p>\n<p>Advanced endpoint management now broadly available<\/p>\n<p class=\"wp-block-paragraph\">As of July 1, 2026, the capabilities of the <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/microsoft-intune\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Microsoft Intune Suite<\/a> are included in Microsoft 365 E5, with select capabilities also available in Microsoft 365 E3, bringing advanced endpoint management to more organizations without added cost. IT and security teams can now apply advanced endpoint management capabilities to reduce standing admin rights, modernize certificate management, resolve issues quickly, streamline app delivery, and bring AI into workflows with Microsoft Security Copilot in Intune. Together, these capabilities strengthen the endpoint foundations that AI-powered operations depend on. <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/microsoftintuneblog\/advanced-microsoft-intune-capabilities-now-available-in-microsoft-365-e3-and-e5\/4529335\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">See everything that\u2019s now included in your plan<\/a> and how to start putting it to work.<\/p>\n<p>Stay In the Loop<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.microsoft.com\/en-us\/security\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Microsoft Security<\/a> is focused on delivering innovations across our portfolio, along with research-driven insights and reports for the security community. <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/tag\/in-the-loop\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">In the Loop posts<\/a> are your reliable source of what\u2019s new across Microsoft Security and what it means for your security strategy. Check back for the next drop.<\/p>\n<p class=\"wp-block-paragraph\">To learn more about Microsoft Security solutions, visit our\u00a0<a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">website.<\/a>\u00a0Bookmark the\u00a0<a href=\"https:\/\/www.microsoft.com\/security\/blog\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Security blog<\/a>\u00a0to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (<a href=\"https:\/\/www.linkedin.com\/showcase\/microsoft-security\/\" rel=\"nofollow noopener\" target=\"_blank\">Microsoft Security<\/a>) and X (<a href=\"https:\/\/twitter.com\/@MSFTSecurity\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">@MSFTSecurity<\/a>)\u00a0for the latest news and updates on cybersecurity.<\/p>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"Every organization needs security that protects end to end with the speed and scale of AI. Microsoft\u2019s vision&hellip;\n","protected":false},"author":2,"featured_media":124705,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11],"tags":[420,7853,416,48312,320,9025,7852],"class_list":["post-124704","post","type-post","status-publish","format-standard","has-post-thumbnail","category-microsoft","tag-azure","tag-azure-copilot","tag-copilot","tag-in-the-loop","tag-microsoft","tag-microsoft-agent-365","tag-microsoft-copilot"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/124704","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=124704"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/124704\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/124705"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=124704"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=124704"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=124704"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}