{"id":91759,"date":"2026-07-01T08:24:23","date_gmt":"2026-07-01T08:24:23","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/91759\/"},"modified":"2026-07-01T08:24:23","modified_gmt":"2026-07-01T08:24:23","slug":"whats-new-in-microsoft-security-june-2026","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/91759\/","title":{"rendered":"\u200b\u200bWhat\u2019s new in Microsoft Security: June 2026"},"content":{"rendered":"<p class=\"wp-block-paragraph\">As organizations scale AI and agents across environments, security teams need protection that covers every surface. The Microsoft vision is simple: security should be ambient and autonomous, just like the AI it protects. This month\u2019s updates help security and IT teams strengthen identity and multicloud foundations, protect data wherever it lives, and secure the developer workflows powering AI innovation. Here\u2019s what\u2019s new:<\/p>\n<p class=\"wp-block-paragraph\">Codename MDASH is a multi-model agentic scanning system designed to discover, validate, and help remediate software vulnerabilities across complex environments. MDASH orchestrates a panel of specialized AI agents that reason through proprietary code and systems, helping security teams surface elusive vulnerabilities quickly and systematically. For example, when security teams use MDASH to scan a complex application, it can identify and validate a previously undetected vulnerability in the underlying code and systems, and route it into <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/microsoft-defender\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Microsoft Defender<\/a> workflows and engineering pipelines for remediation. This closed loop connects discovery, validation, and remediation across the Microsoft stack. <a href=\"https:\/\/aka.ms\/AI-drivenScanningHarness\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Sign up to follow codename MDASH<\/a> and join the private preview to surface and validate hard-to-find vulnerabilities with multi-model AI.<\/p>\n<p><img decoding=\"async\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/Picture1-4-1024x576.webp\" alt=\"Flowchart diagram illustrating Codename MDASH Execution Lifecycle with six main stages: Prepare, Scan, Validate, Dedup, Prove, and Patch. Each stage contains specific tasks like recon, discovery, bug triage, and patch validation, with additional notes on tools, voting, and autosuggestions, highlighting a structured process for bug detection and resolution.\" class=\"wp-image-148384 webp-format\"  data-orig-src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/Picture1-4-1024x576.webp\"\/><\/p>\n<p>Microsoft Defender extends endpoint protection to local AI agents<\/p>\n<p class=\"wp-block-paragraph\">Microsoft Defender now discovers more than 25 types of local AI agents and Model Context Protocol (MCP) servers across managed Windows and macOS devices. Defender also protects at runtime: if a developer using a popular coding agent like GitHub Copilot Command-Line Interface (CLI) or Claude Code is targeted by a prompt injection attempts, Defender detects and blocks it before the malicious action executes. From there, security teams can investigate agent exposure across their environment with Advanced Hunting. These capabilities are <a href=\"https:\/\/aka.ms\/secure-local-ai-agents\/blog\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">now in preview<\/a>.<\/p>\n<p><img decoding=\"async\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/Picture7.webp\" alt=\"Screenshot of a network map from Microsoft Defender showing interconnected nodes representing devices, services, and agents within a security environment. Nodes are labeled with names and icons, with ChatGPT Desktop highlighted in blue, and a detailed pane on the right displays specific information about ChatGPT Desktop, including type, last update, and discovery source.\" class=\"wp-image-148392 webp-format\"  data-orig-src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/Picture7.webp\"\/><\/p>\n<p>Microsoft Entra Backup and Recovery restores critical identity data<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/microsoft-entra\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Microsoft Entra<\/a> Backup and Recovery is now generally available, delivering Microsoft-managed, always-on backups native to your environment that are protected from deletion or modification. Security teams gain clear visibility into what changed across their tenant and can back up core directory objects, compare and restore to previous timestamps, and configure Conditional Access policies to protect against permanent deletion. Together, these capabilities protect your tenant, helping you minimize downtime and recover quickly from accidental changes and security compromises. Strengthen identity resilience with <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/microsoft-entra-blog\/strengthen-identity-resilience-recover-with-confidence-using-microsoft-entra-bac\/4462426\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">rapid recovery capabilities in Microsoft Entra<\/a>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"521\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/image-14-1.webp\" alt=\"\" class=\"wp-image-148492\"  \/><\/p>\n<p>Microsoft Defender protects open-source relational databases on AWS RDS<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/cloud-security\/microsoft-defender-cloud\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Microsoft Defender for Cloud<\/a> now extends database threat protection to open-source relational databases on Amazon Web Services (AWS) Relational Database Service (RDS). Now generally available, built-in threat detection identifies anomalous access patterns and brute-force attempts, while automated sensitive data discovery helps teams understand where high-risk data resides. These insights, combined with integrated investigation across Microsoft Defender, help teams prioritize and respond to database risks more effectively. <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/microsoftdefendercloudblog\/now-generally-available-microsoft-defender-for-open-source-relational-databases-\/4514651\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Detect threats and discover sensitive data<\/a> across Azure and AWS with Microsoft Defender.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/Picture3-2-1024x540.webp\" alt=\"Screenshot of a cybersecurity dashboard showing a critical vulnerability in an AWS RDS database exposed to the internet with basic authentication. Diagram highlights attack path from internet to database, risk factors like weak authentication, and resource types with labeled nodes and connecting arrows.\" class=\"wp-image-148386 webp-format\"  data-orig-src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/Picture3-2-1024x540.webp\"\/><\/p>\n<p>Greater flexibility over data security insights with Microsoft Purview customizable reports<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/microsoft-purview\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Microsoft Purview<\/a> customizable reports, now generally available in Data Security Posture Management (DSPM), give teams greater control and flexibility to tailor reporting views, analyze trends, and quickly surface the insights that enable faster, more informed decisions. Choose from out-of-the-box reports or create custom reports tailored to your organization\u2019s specific needs, with easy options to export and share insights across teams and stakeholders. For example, security teams can create role-specific reports that highlight high-risk data exposure trends to guide policy decisions. Learn how to <a href=\"https:\/\/learn.microsoft.com\/en-us\/purview\/purview-reports\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">customize reporting experiences<\/a> to uncover your critical data security insights.<a href=\"https:\/\/techcommunity.microsoft.com\/blog\/microsoft-security-blog\/secure-data-as-ai-scales-new-microsoft-purview-innovations-at-rsa-2026\/4503665\" target=\"_blank\" rel=\"noopener noreferrer nofollow\"><\/p>\n<p><img decoding=\"async\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" alt=\"\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/Picture2-1.webp\" add=\"\" card=\"\" panel=\"\" on=\"\" the=\"\" right=\"\" for=\"\" customizing=\"\" report=\"\" elements.=\"\" class=\"wp-image-148381 webp-format\"  data-orig-alt=\"\"\/><\/p>\n<p>Broader visibility with expanded multi-cloud coverage in Defender for Cloud<\/p>\n<p class=\"wp-block-paragraph\">Microsoft Defender for Cloud is expanding multicloud coverage and visibility across AWS and Google Cloud, adding support for approximately 90 additional resource types and more than 200 new security recommendations. Security teams can better understand their attack surface with broader visibility across cloud-native applications, identities, data services, and workloads. Across multicloud environments, teams can better assess security posture and prioritize remediation based on exposure context, compliance posture, and business criticality to reduce risk more effectively. <a href=\"https:\/\/aka.ms\/mdc-multicloud-expansion\" rel=\"nofollow noopener\" target=\"_blank\">Gain broader visibility and prioritize risk <\/a>across multicloud environments with Defender for Cloud.<\/p>\n<p><img decoding=\"async\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/Picture6.webp\" alt=\"Screenshot of a cloud security dashboard showing recommendations summary and risk assessment for misconfigurations. Key elements include a green circular chart indicating 88.2% cloud secure score, a line graph tracking score history over 14 days, and a risk level section highlighting 17 critical issues with detailed recommendations and asset information.\" class=\"wp-image-148390 webp-format\"  data-orig-src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/Picture6.webp\"\/><\/p>\n<p>Prioritize risk with unified identity risk score<\/p>\n<p class=\"wp-block-paragraph\">A new unified identity risk score combines signals from across Microsoft Security into a single, explainable measure of an identity\u2019s risk. It brings together behavior, access patterns, and threat intelligence for all related accounts, sessions, and applications to provide a complete view of risk. The moment an identity acts suspiciously, the score helps your team cut through the noise, prioritize what\u2019s urgent, and can automatically trigger Conditional Access policies to enforce protection at the point of access.\u00a0Prioritize identity risk and enforce protection in real time with the <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/microsoft-entra-blog\/ai-is-accelerating-cyberattacks%E2%80%94here%E2%80%99s-how-to-stay-ahead\/4528592\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">new unified identity risk score<\/a>.<\/p>\n<p>Security innovations purpose built for developers<\/p>\n<p class=\"wp-block-paragraph\">To help developers secure code, agents, and models while giving security teams consistent visibility and control from development through runtime, Microsoft is integrating security into the tools and platforms developers already use. Organizations can use the new security tools and capabilities announced at Microsoft Build 2026 to innovate faster and scale AI adoption without sacrificing security. Read more about the <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/06\/02\/microsoft-build-2026-securing-code-agents-and-models-across-the-development-lifecycle\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Build 2026 security announcements<\/a>.<\/p>\n<p>Stay In the Loop<\/p>\n<p class=\"wp-block-paragraph\">Microsoft Security continually ships meaningful innovations across our portfolio and research-driven insights and reports for the security community. In the Loop posts are your reliable source of what\u2019s new across Microsoft Security and what it means for your security strategy. Check back for the next drop.<\/p>\n<p class=\"wp-block-paragraph\">To learn more about Microsoft Security solutions, visit our\u00a0<a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\" rel=\"nofollow noopener\" target=\"_blank\">website.<\/a>\u00a0Bookmark the\u00a0<a href=\"https:\/\/www.microsoft.com\/security\/blog\/\" rel=\"nofollow noopener\" target=\"_blank\">Security blog<\/a>\u00a0to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (<a href=\"https:\/\/www.linkedin.com\/showcase\/microsoft-security\/\" rel=\"nofollow noopener\" target=\"_blank\">Microsoft Security<\/a>) and X (<a href=\"https:\/\/twitter.com\/@MSFTSecurity\" rel=\"nofollow noopener\" target=\"_blank\">@MSFTSecurity<\/a>)\u00a0for the latest news and updates on cybersecurity.<\/p>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"As organizations scale AI and agents across environments, security teams need protection that covers every surface. The Microsoft&hellip;\n","protected":false},"author":2,"featured_media":91760,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11],"tags":[420,7853,416,48312,320,7852],"class_list":["post-91759","post","type-post","status-publish","format-standard","has-post-thumbnail","category-microsoft","tag-azure","tag-azure-copilot","tag-copilot","tag-in-the-loop","tag-microsoft","tag-microsoft-copilot"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/91759","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=91759"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/91759\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/91760"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=91759"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=91759"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=91759"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}