SecOps SignalMicrosoft Security Operations Intelligence

Medium - Microsoft Defender for Cloud, Azure Resource Graph, Microsoft Defender for Storage, AWS Identity and Access Management, Google Cloud IAM - Microsoft primary source

Microsoft Defender for Cloud Updates - August and July 2026 Highlights

Recent updates to Microsoft Defender for Cloud include improved CVE data consumption for vulnerability assessments, retirement plans for classic Defender for SQL APIs, enhanced on-demand malware scanning with item-specific scanning support, changes to AWS and GCP overprovisioned identity assessments excluding unused actions, and several deprecations and GA releases related to SQL vulnerability assessments, container security, and Foundational CSPM opt-in model.

What changed

- CVE details data used in Azure Resource Graph queries for vulnerability assessments updated to a new resource type improving performance and scalability. - Classic Defender for SQL APIs for Vulnerability Assessment and Advanced Threat Protection scheduled for retirement on August 16, 2027. - On-demand malware scanning now supports scanning specific blobs, files, containers, and file shares. - Unused actions removed from AWS and GCP overprovisioned identity assessments, impacting related recommendations and workflows. - Legacy grouped recommendations deprecated and replaced by individual recommendations. - Foundational CSPM changed to an opt-in model for new Azure subscriptions starting October 27, 2026. - SQL Vulnerability Assessment database-level recommendations generally available. - Plan enablement API now blocks onboarding to five deprecated Defender plans.

Why it matters operationally

Users and administrators must update related Azure Resource Graph queries to align with new CVE detail data model to avoid incomplete data. Migration away from classic Defender for SQL APIs is necessary before retirement. Security scanning workflows can be optimized with targeted on-demand malware scanning. Existing automated workflows relying on unused actions in AWS and GCP identity assessments need review due to their removal. Customers need to adjust to individual recommendations from legacy grouped recommendations and prepare for Foundational CSPM opt-in changes for new subscriptions. Deprecated plans must not be onboarded using the plan enablement API.

What the SOC should check

Validate affected Microsoft products, confirm whether controls or detections need tuning, and record any change-management or monitoring actions.

Recommended actions

  • Review and update Azure Resource Graph queries to consume CVE details from the microsoft.security/cvedetails resource type.
  • Plan and execute migration from classic Defender for SQL APIs to the supported configuration model before August 16, 2027.
  • Leverage on-demand malware scanning filters to scope scans for specific blobs, containers, or file shares as needed.
  • Adjust workflows dependent on AWS and GCP unused actions list; use native cloud provider tools for permission usage verification.
  • Validate and migrate automation and queries from legacy grouped recommendations to individual recommendations.
  • Prepare for Foundational CSPM opt-in model for any new Azure subscriptions starting October 27, 2026.
  • Avoid onboarding deprecated Defender plans using the plan-enablement API and transition to supported plans.

Source links

https://learn.microsoft.com/en-us/azure/defender-for-cloud/release-notes