SecOps SignalMicrosoft Security Operations Intelligence

High - Microsoft Sentinel, Microsoft Sentinel UEBA, SAP agentless solution for Microsoft Sentinel, SAP BTP solution, SAP LogServ solution - Microsoft primary source

Microsoft Sentinel August 2026 Update: Enhanced UEBA, SAP Integrations, and Automation Consistency

Microsoft Sentinel's August 2026 update expands User and Entity Behavior Analytics (UEBA) with new data sources including Fortinet FortiGate and anomaly detections for multiple firewall and VPN events. SAP solutions receive performance and analytic rule enhancements. Notably, there is a critical change to analytics alert Account Name normalization to improve automation consistency, requiring updates to automation logic to handle UPN prefix/suffix separately.

What changed

UEBA now includes Fortinet FortiGate behaviors and supports Check Point, Fortinet, Zscaler, AWS GuardDuty anomalies, with mappings to MITRE ATT&CK techniques. UEBA behaviors gain contextual anomaly insights. SAP agentless and BTP solutions have new versions with audit and detection improvements. Analytics alert Account Name is normalized to UPN prefix only, adding new UPN fields to the SecurityAlert table, impacting automation rules and Logic Apps data handling.

Why it matters operationally

Existing automation rules, playbooks, or Logic Apps that rely on the AccountName field in analytics rule alerts may fail or behave unexpectedly due to changes in UPN handling. Organizations must update their automation to separate UPN prefix and suffix comparisons and avoid strict equality checks to maintain compatibility. Security operations can leverage enhanced UEBA and SAP integration capabilities to improve detection and investigation processes.

What the SOC should check

Validate affected Microsoft products, confirm whether controls or detections need tuning, and record any change-management or monitoring actions.

Recommended actions

  • Review and update all automation rules, Logic Apps, and playbooks that filter or compare analytics alerts based on AccountName to accommodate the Account Name change to UPN prefix only.
  • Modify conditions using strict AccountName equality checks to use Contains or Starts With operators and compare UPN prefix and UPNSuffix separately.
  • Leverage new UEBA data sources and anomaly detection types to enhance threat detection coverage, including Fortinet FortiGate and AWS GuardDuty findings.
  • Adopt contextual anomaly insights on UEBA behaviors to accelerate investigation and incident response.
  • Update SAP solution connectors and analytic rules to latest versions to benefit from performance and detection improvements.

KQL hunting context

The update introduces new UEBA behaviors and anomaly detection rules that map to MITRE ATT&CK techniques and supports queries that link behavior results to incidents, enabling custom advanced hunting queries.

Source links

https://learn.microsoft.com/en-us/azure/sentinel/whats-new