Security

Microsoft Security May 2026: Purview and Entra Updates

3 min read

Summary

Microsoft Security’s May 2026 updates focus on improving visibility and control across data, identities, and AI-driven environments. Highlights include the general availability of the new Purview Data Security Posture Management experience, deeper investigations with OCR and custom examinations, Entra ID Account recovery, and expanded preview for Windows 365 for Agents.

Need help with Security?Talk to an Expert

Introduction

Microsoft Security’s May 2026 updates are aimed at a growing challenge for IT and security teams: protecting data, identities, and AI agents across increasingly complex environments. As organizations adopt more AI services and third-party tools, Microsoft is adding stronger posture management, deeper investigations, and more secure identity recovery options.

What’s new in Microsoft Security

Microsoft Purview DSPM is now generally available

The new Microsoft Purview Data Security Posture Management (DSPM) experience is now generally available. Microsoft says the updated experience brings discovery, protection, investigation, and remediation into a more unified workflow.

Key improvements include:

  • Goal-oriented workflows for faster risk assessment
  • Expanded reporting and deeper remediation options
  • Better visibility across third-party environments
  • Streamlined investigation and action from a single experience

For administrators, this should make it easier to identify sensitive data exposure and respond at scale without jumping between multiple tools.

Purview Data Security Investigations adds OCR and custom examinations

Microsoft also expanded Purview Data Security Investigations with:

  • Optical character recognition (OCR) to extract text from images
  • Custom examinations for tailored investigation scenarios

This matters because sensitive information is not always stored in searchable text documents. With OCR, investigators can now bring image-based content into AI-powered analysis. Custom examinations also give security teams more flexibility to detect organization-specific risks beyond Microsoft’s built-in checks.

Entra ID Account recovery adds secure access restoration

Microsoft Entra ID Account recovery is designed to help users regain access when they have lost all registered authentication methods. Unlike standard password reset workflows, this feature focuses on re-establishing trust and verifying identity before authentication methods are replaced.

This is especially important for organizations strengthening phishing-resistant authentication and reducing help desk friction in account recovery scenarios.

Windows 365 for Agents expands in public preview

Windows 365 for Agents is expanding in public preview and works alongside Microsoft Agent 365 to provide a secure environment for AI agent execution.

According to Microsoft:

  • Agent 365 governs what an agent is authorized to do
  • Windows 365 for Agents provides the managed execution environment
  • Agents can run in auditable, policy-controlled Cloud PCs

This is a notable step for organizations exploring enterprise AI agents while maintaining governance and security controls.

Impact on IT administrators

Security and identity teams should view these updates as part of Microsoft’s broader push toward protecting AI, data, and identities together. The biggest practical benefits are improved data risk workflows in Purview, stronger investigation capabilities, and a more secure path for account recovery.

Next steps

  • Review the new Purview DSPM experience if your organization uses Microsoft Purview
  • Evaluate OCR and custom examinations for data investigation use cases
  • Assess Entra ID Account recovery for identity resilience planning
  • Monitor Windows 365 for Agents if you are testing or deploying AI agents in the enterprise

Need help with Security?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

Microsoft SecurityMicrosoft PurviewEntra IDWindows 365AI security

Related Posts

Security

Microsoft Digital Defense Report 2026: Key Security Insights

Microsoft's 2026 Digital Defense Report highlights how AI and growing system interconnectedness are reshaping both cyberattacks and defense strategies. The report emphasizes that organizations must secure AI, identities, data, and cloud environments together while improving signal correlation across tools to detect modern threats faster.

Security

Government Cyber Risk in 2026: Microsoft’s 5 Priorities

Microsoft says government agencies were the most targeted sector in 2026, accounting for 27% of observed cyber threat activity. The company urges public-sector leaders to focus on five resilience priorities, including faster response, AI security, bidirectional information sharing, and planning for incidents that spread across suppliers and essential services.

Security

Microsoft Ignite 2026 Security Guide: Key Sessions

Microsoft has published its security guide for Microsoft Ignite 2026, highlighting AI-first security themes, a dedicated Security Pre-Day, and technical sessions focused on securing identities, data, devices, clouds, and AI agents. For IT and security teams, the event offers an early look at Microsoft’s roadmap and practical guidance for building an AI-ready security strategy.

Security

CVE-2026-73570: Zimbra Mail Server Exploitation

Microsoft is tracking active exploitation of CVE-2026-73570, an unauthenticated command injection flaw affecting internet-facing Zimbra mail servers with the optional zimbra-snmp package installed and SNMP notifications enabled. The issue can lead to web shell deployment, privilege escalation, mailbox data theft, and persistent remote access, making immediate patching and configuration review critical for administrators.

Security

Phishing Abuses RMM Tools for Persistent Access

Microsoft security researchers observed phishing campaigns in July 2026 that used a legitimate MSP360 RMM installer disguised as meeting invites, PDF updates, and other lures to gain remote access. Attackers then deployed ConnectWise ScreenConnect for redundant persistence, highlighting the need for tighter controls on remote management tools and better detection of unapproved RMM activity.

Security

Azure DevOps Attack Path Exposed in New DART Report

Microsoft’s latest DART cyberattack report shows how a single compromised identity was used to access Azure DevOps, alter pipelines, and harvest Kubernetes credentials. The case highlights how tightly connected identity, DevOps, and cloud environments can let attackers move far beyond source code, making stronger identity and pipeline controls essential.