SecOps SignalMicrosoft Security Operations Intelligence

High - Microsoft Defender for Endpoint (Linux), Microsoft Defender for Endpoint (Windows), Microsoft Defender for Endpoint (macOS), Microsoft Defender for Endpoint (iOS), Microsoft Defender for Endpoint (Android) - Microsoft primary source

New Microsoft Defender for Endpoint Features and Enhancements (June-September 2026)

Microsoft Defender for Endpoint introduced multiple new features and enhancements between June and September 2026, including public preview support for WSL container protection, tamper protection audit mode on Linux, antivirus audit mode on Linux, macOS and iOS platform updates, vulnerability assessment for Microsoft Store apps, enhanced AI agent runtime protection, Linux deployment automation, local AI agent discovery on macOS, Windows Defender Secure Score updates, and features to reduce internet-facing device exposure. These improvements enhance cross-platform threat detection, response, deployment management, and risk prioritization capabilities.

What changed

Introduced preview and general availability features in Defender for Endpoint across Linux, macOS, Windows, and mobile platforms such as: WSL container protection, tamper protection audit mode on Linux, antivirus audit mode, offboarding API support for Linux, vulnerability assessment of Microsoft Store apps, enhanced AI agent runtime protection, local AI agent discovery expansion, enhanced deployment tools, and new risk scoring methodologies including internet exposure reduction recommendations.

Why it matters operationally

Security teams gain enhanced visibility and control over cross-platform endpoints including Linux containers and macOS devices, improved deployment and lifecycle management of Defender across Linux systems, and stronger risk prioritization for vulnerability management and internet-facing devices. Audit modes enable performance evaluation before enforcement, reducing risk during adoption. New selective response actions improve protection for critical systems without operational disruption.

What the SOC should check

Validate affected Microsoft products, confirm whether controls or detections need tuning, and record any change-management or monitoring actions.

Recommended actions

  • Evaluate and enroll in public preview features such as WSL container support and tamper protection audit mode for Linux where applicable.
  • Leverage antivirus audit mode on Linux to assess detection efficacy before enabling enforcement.
  • Adopt Offboarding API for Linux servers to automate device lifecycle management.
  • Review vulnerability assessment data for Microsoft Store applications to remediate exposed apps.
  • Utilize enhanced Defender deployment tools on Linux and Windows for streamlined onboarding and management.
  • Implement selected Secure Score recommendations to reduce unnecessary internet-facing device exposure.
  • Use local AI agent discovery capabilities to monitor AI agents on Windows and macOS endpoints.
  • Incorporate selective response actions in security operations for high-value assets to balance protection and stability.

KQL hunting context

Several new features and risk assessments update detection and response capabilities, enabling useful Advanced Hunting queries for tracking deployment status, tampering alerts, vulnerability details, AI agent discovery, and exposure scoring.

Source links

https://learn.microsoft.com/en-us/defender-endpoint/whats-new-in-microsoft-defender-endpoint