What’s new in Microsoft Security: July 2026
Every organization needs security that protects end to end with the speed and scale of AI. Microsoft’s vision is simple: security should be ambient and autonomous, just like the AI it protects. As organizations scale AI and expand across environments, security teams need protection that covers every surface. This month’s updates help security and IT teams secure their AI environments, use AI to defend at speed and scale, and strengthen the foundations that AI-powered operations depend on. Here’s what’s new: Project Perception brings agentic defense to security operations Project Perception , newly announced, is a coordinated system of specialized agents, cybersecurity-focused models, and enterprise-wide signals that transform how security operates. The agents work as a team: red team agents expose weaknesses, blue team agents investigate cyberthreats, and green agents harden what’s found. These multi-agent autonomous workflows work as a team to operate in continuous loops to execute end-to-end security workflows. Learn more about Project Perception Microsoft Defender secures the full AI attack surface, from inbox to cloud Expanded Microsoft Defender protections are designed to reduce risks associated with day-to-day AI interactions, from email inboxes to cloud agent environments. New prompt injection protection in Microsoft Defender, now in preview, identifies and isolates emails containing malicious AI instructions before delivery, reducing the risk of prompt injection attacks reaching the inbox. Unified Defender posture and runtime protection for cloud agents in Microsoft Agent 365 consolidates security posture assessment and runtime protection for Microsoft Foundry, Microsoft Copilot Studio, and third party-managed agents, helping teams reduce AI-specific risk across the agent estate. Accelerate detection, prioritization, and response with AI embedded in SecOps workflows Security teams can accelerate detection, prioritization, and response to cyberthreats with AI embedded directly into security operations (SecOps) workflows through Microsoft Defender. Threat intelligence enhancements, including Microsoft Defender Threat Intelligence convergence and an enhanced Threat Intelligence Agent , bring more out-of-the-box intelligence and automation into the unified SecOps workflow, so teams can move from summary to action. Strengthen the cloud, code, and identity foundations AI depends on Microsoft Defender is strengthening the foundational protections that AI-era operations depend on across cloud, code, and identity. Cloud Security Posture Management extends coverage to serverless containers , giving teams visibility and continuous posture assessment across containerized workloads running on Azure Container Apps, Azure Container Instances, and Amazon Web Services Elastic Container Service (AWS ECS) on Fargate. New interconnected experiences between Defender and Microsoft Entra empower the security operations center (SOC) to disable compromised identities directly using a role-based access control (RBAC) mode that maintains least privilege. Microsoft Defender Experts services are also expanding : Microsoft Defender Experts Threat Intelligence delivers human-led, curated insight into the cyberthreats most relevant to each organization, and Microsoft Defender Experts MDR extends expert-run detection and response beyond the Microsoft estate into third-party and multicloud signals through Microsoft Sentinel . Microsoft Entra strengthens identity across the AI-powered enterprise Strengthen identity foundations for AI-powered operations New capabilities in Microsoft Entra are designed to strengthen the identity foundations that AI-powered operations depend on. Tenant governance helps organizations discover, manage, and govern tenants across their environment with centralized policies and cross-tenant delegated administration. Microsoft Entra ID is making passkeys the default authentication experience , which helps reduce reliance on SMS…
AI Analysis
Technical Summary
The provided information outlines Microsoft's July 2026 security update announcements, which introduce new AI-powered security features and improvements across Microsoft Defender, Microsoft Entra, Microsoft Purview, and related services. These include Project Perception for autonomous security operations, prompt injection protections in email, unified cloud agent security posture, enhanced threat intelligence automation, identity governance improvements with passkeys as default authentication, and data loss prevention integrated with AI applications. The content is a product and feature update without details of any specific vulnerability or exploit.
Potential Impact
No direct impact from a specific vulnerability or exploit is described. The update aims to reduce risks associated with AI environments, improve detection and response capabilities, and strengthen identity and data protections. There is no indication of active exploitation or a newly discovered security flaw requiring immediate remediation.
Mitigation Recommendations
This content does not describe a vulnerability requiring patching or mitigation. It highlights new security features and enhancements that organizations can adopt to improve their AI and cloud security posture. No specific remediation actions or patches are indicated. Organizations should review and consider deploying these new capabilities as part of their ongoing security strategy.
What’s new in Microsoft Security: July 2026
Description
Every organization needs security that protects end to end with the speed and scale of AI. Microsoft’s vision is simple: security should be ambient and autonomous, just like the AI it protects. As organizations scale AI and expand across environments, security teams need protection that covers every surface. This month’s updates help security and IT teams secure their AI environments, use AI to defend at speed and scale, and strengthen the foundations that AI-powered operations depend on. Here’s what’s new: Project Perception brings agentic defense to security operations Project Perception , newly announced, is a coordinated system of specialized agents, cybersecurity-focused models, and enterprise-wide signals that transform how security operates. The agents work as a team: red team agents expose weaknesses, blue team agents investigate cyberthreats, and green agents harden what’s found. These multi-agent autonomous workflows work as a team to operate in continuous loops to execute end-to-end security workflows. Learn more about Project Perception Microsoft Defender secures the full AI attack surface, from inbox to cloud Expanded Microsoft Defender protections are designed to reduce risks associated with day-to-day AI interactions, from email inboxes to cloud agent environments. New prompt injection protection in Microsoft Defender, now in preview, identifies and isolates emails containing malicious AI instructions before delivery, reducing the risk of prompt injection attacks reaching the inbox. Unified Defender posture and runtime protection for cloud agents in Microsoft Agent 365 consolidates security posture assessment and runtime protection for Microsoft Foundry, Microsoft Copilot Studio, and third party-managed agents, helping teams reduce AI-specific risk across the agent estate. Accelerate detection, prioritization, and response with AI embedded in SecOps workflows Security teams can accelerate detection, prioritization, and response to cyberthreats with AI embedded directly into security operations (SecOps) workflows through Microsoft Defender. Threat intelligence enhancements, including Microsoft Defender Threat Intelligence convergence and an enhanced Threat Intelligence Agent , bring more out-of-the-box intelligence and automation into the unified SecOps workflow, so teams can move from summary to action. Strengthen the cloud, code, and identity foundations AI depends on Microsoft Defender is strengthening the foundational protections that AI-era operations depend on across cloud, code, and identity. Cloud Security Posture Management extends coverage to serverless containers , giving teams visibility and continuous posture assessment across containerized workloads running on Azure Container Apps, Azure Container Instances, and Amazon Web Services Elastic Container Service (AWS ECS) on Fargate. New interconnected experiences between Defender and Microsoft Entra empower the security operations center (SOC) to disable compromised identities directly using a role-based access control (RBAC) mode that maintains least privilege. Microsoft Defender Experts services are also expanding : Microsoft Defender Experts Threat Intelligence delivers human-led, curated insight into the cyberthreats most relevant to each organization, and Microsoft Defender Experts MDR extends expert-run detection and response beyond the Microsoft estate into third-party and multicloud signals through Microsoft Sentinel . Microsoft Entra strengthens identity across the AI-powered enterprise Strengthen identity foundations for AI-powered operations New capabilities in Microsoft Entra are designed to strengthen the identity foundations that AI-powered operations depend on. Tenant governance helps organizations discover, manage, and govern tenants across their environment with centralized policies and cross-tenant delegated administration. Microsoft Entra ID is making passkeys the default authentication experience , which helps reduce reliance on SMS…
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The provided information outlines Microsoft's July 2026 security update announcements, which introduce new AI-powered security features and improvements across Microsoft Defender, Microsoft Entra, Microsoft Purview, and related services. These include Project Perception for autonomous security operations, prompt injection protections in email, unified cloud agent security posture, enhanced threat intelligence automation, identity governance improvements with passkeys as default authentication, and data loss prevention integrated with AI applications. The content is a product and feature update without details of any specific vulnerability or exploit.
Potential Impact
No direct impact from a specific vulnerability or exploit is described. The update aims to reduce risks associated with AI environments, improve detection and response capabilities, and strengthen identity and data protections. There is no indication of active exploitation or a newly discovered security flaw requiring immediate remediation.
Defensive Guidance
This content does not describe a vulnerability requiring patching or mitigation. It highlights new security features and enhancements that organizations can adopt to improve their AI and cloud security posture. No specific remediation actions or patches are indicated. Organizations should review and consider deploying these new capabilities as part of their ongoing security strategy.
Technical Details
- Article Source
- {"url":"https://www.microsoft.com/en-us/security/blog/2026/07/30/whats-new-in-microsoft-security-july-2026/","fetched":true,"fetchedAt":"2026-07-31T01:32:11.534Z","wordCount":1958}
- Classification
- {"confidence":0.3,"severitySource":"heuristic","classifier":"rss-v2"}
Threat ID: 6a6bfb1c9c2644c7f81c07d5
Added to database: 07/31/2026, 01:32:12 UTC
Last enriched: 07/31/2026, 01:32:20 UTC
Last updated: 09/13/2026, 18:56:59 UTC
Views: 382
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.