What’s new in Microsoft Security: August 2026
As organizations incorporate AI agents into more processes across business and operations, security teams can benefit from greater visibility and new purpose-built tools that help manage, secure, and govern AI. This month’s updates provide new capabilities to help organizations gain insights into agent activity, expand security coverage across supported environments, and enhance security management across their environments. Here’s what’s new: Extend expert-led protection with new capabilities from Microsoft Defender Experts Microsoft Defender Experts Threat Intelligence delivers expert-led threat intelligence and actionable insights tailored to your geography, industry, and risk profile to help security teams anticipate cyberthreats, assess risk, and take informed action. Microsoft Defender Experts MDR now covers third-party data sources ingested through Microsoft Sentinel . This extends around-the-clock managed detection and response and threat hunting to deliver protection across both Microsoft native and third-party data sources , including Palo Alto Networks, Amazon Web Services (AWS), Okta, and more. This coverage is available through Microsoft Defender Experts MDR P2. Get started with Microsoft Defender Experts MDR Strengthen identity foundations for the AI era with Microsoft Entra Microsoft Entra Tenant Governance brings an organization’s tenants into a single view to help address security gaps and blind spots. Centralized policies and cross-tenant delegated administration of multi-tenant environments help reduce shadow-tenant risk, configure policies, monitor configuration drift, and strengthen identity foundations for AI-powered operations. The configuration drifts report, showing drift details including types, properties and timestamps, enabling continuous tenant configuration monitoring for a consistent security and compliance posture. Accelerate your move to cloud-native endpoint management with Microsoft Intune Windows Autopilot device association lets admins link devices to their tenant and configure pre-enrollment experiences. Admins can optimize the out-of-box experience and rename devices, reducing onboarding friction. Windows Unattended Support with Remote Sign-In allows IT and support staff to sign in to devices remotely, without involving the user. Role-based permissions, compliance checks, and session auditing are built in. Protect endpoints with Microsoft Intune Speed up Microsoft Copilot readiness with scalable Microsoft Purview auto-labeling Auto-labeling policies in Microsoft Purview now process up to 500,000 SharePoint and OneDrive files per day, up from 100,000. This increased limit helps organizations label and protect more content, extending data protection coverage. Because sensitivity labels help apply key security controls, including encryption and data loss prevention (DLP), organizations can extend data protection across more content and support their Microsoft 365 Copilot adoption efforts. Secure and govern data with Microsoft Purview Contain agents with Microsoft Security Exposure Management New Secure Now guidance for agentic containment helps organizations put controls in place before autonomous agent action expands across the environment. The recommendations focus on constraining agent-initiated actions that occur without explicit user approval, and hardening attack surfaces, limiting impact, governing identities and permissions, and increasing visibility across the environment. Learn more about Microsoft Security Exposure Management Stay in the Loop Microsoft Security is focused on delivering innovations across our portfolio, along with research-driven insights and reports for the security community. In the Loop posts are your reliable source of what’s new across Microsoft Security and what it means for your security strategy. Check back for the next drop . To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage…
What’s new in Microsoft Security: August 2026
Description
As organizations incorporate AI agents into more processes across business and operations, security teams can benefit from greater visibility and new purpose-built tools that help manage, secure, and govern AI. This month’s updates provide new capabilities to help organizations gain insights into agent activity, expand security coverage across supported environments, and enhance security management across their environments. Here’s what’s new: Extend expert-led protection with new capabilities from Microsoft Defender Experts Microsoft Defender Experts Threat Intelligence delivers expert-led threat intelligence and actionable insights tailored to your geography, industry, and risk profile to help security teams anticipate cyberthreats, assess risk, and take informed action. Microsoft Defender Experts MDR now covers third-party data sources ingested through Microsoft Sentinel . This extends around-the-clock managed detection and response and threat hunting to deliver protection across both Microsoft native and third-party data sources , including Palo Alto Networks, Amazon Web Services (AWS), Okta, and more. This coverage is available through Microsoft Defender Experts MDR P2. Get started with Microsoft Defender Experts MDR Strengthen identity foundations for the AI era with Microsoft Entra Microsoft Entra Tenant Governance brings an organization’s tenants into a single view to help address security gaps and blind spots. Centralized policies and cross-tenant delegated administration of multi-tenant environments help reduce shadow-tenant risk, configure policies, monitor configuration drift, and strengthen identity foundations for AI-powered operations. The configuration drifts report, showing drift details including types, properties and timestamps, enabling continuous tenant configuration monitoring for a consistent security and compliance posture. Accelerate your move to cloud-native endpoint management with Microsoft Intune Windows Autopilot device association lets admins link devices to their tenant and configure pre-enrollment experiences. Admins can optimize the out-of-box experience and rename devices, reducing onboarding friction. Windows Unattended Support with Remote Sign-In allows IT and support staff to sign in to devices remotely, without involving the user. Role-based permissions, compliance checks, and session auditing are built in. Protect endpoints with Microsoft Intune Speed up Microsoft Copilot readiness with scalable Microsoft Purview auto-labeling Auto-labeling policies in Microsoft Purview now process up to 500,000 SharePoint and OneDrive files per day, up from 100,000. This increased limit helps organizations label and protect more content, extending data protection coverage. Because sensitivity labels help apply key security controls, including encryption and data loss prevention (DLP), organizations can extend data protection across more content and support their Microsoft 365 Copilot adoption efforts. Secure and govern data with Microsoft Purview Contain agents with Microsoft Security Exposure Management New Secure Now guidance for agentic containment helps organizations put controls in place before autonomous agent action expands across the environment. The recommendations focus on constraining agent-initiated actions that occur without explicit user approval, and hardening attack surfaces, limiting impact, governing identities and permissions, and increasing visibility across the environment. Learn more about Microsoft Security Exposure Management Stay in the Loop Microsoft Security is focused on delivering innovations across our portfolio, along with research-driven insights and reports for the security community. In the Loop posts are your reliable source of what’s new across Microsoft Security and what it means for your security strategy. Check back for the next drop . To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage…
Technical Details
- Classification
- {"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.microsoft.com/en-us/security/blog/2026/08/27/whats-new-in-microsoft-security-august-2026/","fetched":true,"fetchedAt":"2026-08-28T17:11:10.785Z","wordCount":1268}
Threat ID: 6a91c13facd9273b491ea70b
Added to database: 08/28/2026, 17:11:27 UTC
Last updated: 08/29/2026, 13:08:23 UTC
Views: 16
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.