SecOps SignalMicrosoft Security Operations Intelligence

High - Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for Cloud, Microsoft Defender for Identity, Microsoft Defender for Office 365, Microsoft Defender Experts for Servers, Microsoft 365 Copilot agent ecosystem - Microsoft primary source

July 2026 Microsoft Defender XDR Updates: AI Agent Posture Risk, Domain Investigation, Threat Detection Enhancements, and More

Microsoft Defender XDR introduces multiple important new features including AI agent posture risk assessment for enterprise and local agents, a Domain investigation page for Active Directory security analysis, threat detection for Microsoft Agent 365 agents, real-time protection for Agent 365 tooling servers, and improvements to permissions, threat intelligence enrichments, AI agent discovery, and runtime protection. Advanced hunting improvements and new managed security services are also included.

What changed

- Added AI agent posture risk assessment feature evaluating risk indicators on endpoint AI agents. - GA Domain investigation page for Active Directory domain security analysis. - Preview threat detection for Microsoft Agent 365 agents analyzing runtime signals. - GA real-time protection blocking risky interactions on Agent 365 tooling servers. - Restricted phishing and security alert triage agent permissions to least privilege. - Preview entity threat intelligence enrichments integrated directly in investigation workflow. - Preview new Identity Security dashboard card for human identities across sources. - Enhancements to SaaS identity coverage and maturity views. - Preview local AI agent discovery on Windows endpoints showing inventory and exposure. - Preview local AI agent runtime protection to block risky activity. - Advanced hunting updates with new GA and preview schema tables for improved visibility. - New standalone managed detection and response services for servers. - Preview automatic attack disruption can isolate compromised devices during incidents. - Advanced hunting improvements including allow/block actions and new identity attack path scenarios. - Preview Defender Chat assistant to help SOC analysts investigate and query in natural language.

Why it matters operationally

Security operations teams gain enhanced visibility into AI agents and Active Directory security posture, improved threat detection including for AI agents, and greater control over automatic attack disruption actions. The new runtime protections and permission restrictions improve endpoint security posture and reduce unnecessary data access. Advanced hunting schema updates and new attack path scenarios enable more effective investigations and threat hunting. The Defender Chat assistant aims to improve SOC analyst efficiency. New managed services options provide extended detection and response for on-premises/multicloud servers.

What the SOC should check

Validate affected Microsoft products, confirm whether controls or detections need tuning, and record any change-management or monitoring actions.

Recommended actions

  • Review and integrate AI agent posture risk reports into risk prioritization workflows.
  • Utilize Domain investigation page for holistic Active Directory security analysis.
  • Investigate and respond to Microsoft Agent 365 agent threat alerts.
  • Update phishing and security alert triage agent permissions to least privilege model.
  • Leverage threat intelligence enrichments in entity investigations to speed response.
  • Explore and adopt local AI agent discovery and runtime protection features.
  • Update advanced hunting queries to use new AgentsInfo table before AIAgentsInfo deprecation.
  • Consider adopting new identity-focused advanced hunting scenarios for attack path discovery.
  • Evaluate and enable automatic attack disruption isolation features where applicable.
  • Train SOC staff on using Defender Chat and new hunting features to improve operational efficiency.

KQL hunting context

New advanced hunting schema updates and tables introduced requiring query updates and enabling more detailed hunting capabilities.

Source links

https://learn.microsoft.com/en-us/defender-xdr/whats-new