Security

Microsoft Security May 2026: Purview and Entra Updates

3 min read

Summary

Microsoft Security’s May 2026 updates focus on improving visibility and control across data, identities, and AI-driven environments. Highlights include the general availability of the new Purview Data Security Posture Management experience, deeper investigations with OCR and custom examinations, Entra ID Account recovery, and expanded preview for Windows 365 for Agents.

Need help with Security?Talk to an Expert

Introduction

Microsoft Security’s May 2026 updates are aimed at a growing challenge for IT and security teams: protecting data, identities, and AI agents across increasingly complex environments. As organizations adopt more AI services and third-party tools, Microsoft is adding stronger posture management, deeper investigations, and more secure identity recovery options.

What’s new in Microsoft Security

Microsoft Purview DSPM is now generally available

The new Microsoft Purview Data Security Posture Management (DSPM) experience is now generally available. Microsoft says the updated experience brings discovery, protection, investigation, and remediation into a more unified workflow.

Key improvements include:

  • Goal-oriented workflows for faster risk assessment
  • Expanded reporting and deeper remediation options
  • Better visibility across third-party environments
  • Streamlined investigation and action from a single experience

For administrators, this should make it easier to identify sensitive data exposure and respond at scale without jumping between multiple tools.

Purview Data Security Investigations adds OCR and custom examinations

Microsoft also expanded Purview Data Security Investigations with:

  • Optical character recognition (OCR) to extract text from images
  • Custom examinations for tailored investigation scenarios

This matters because sensitive information is not always stored in searchable text documents. With OCR, investigators can now bring image-based content into AI-powered analysis. Custom examinations also give security teams more flexibility to detect organization-specific risks beyond Microsoft’s built-in checks.

Entra ID Account recovery adds secure access restoration

Microsoft Entra ID Account recovery is designed to help users regain access when they have lost all registered authentication methods. Unlike standard password reset workflows, this feature focuses on re-establishing trust and verifying identity before authentication methods are replaced.

This is especially important for organizations strengthening phishing-resistant authentication and reducing help desk friction in account recovery scenarios.

Windows 365 for Agents expands in public preview

Windows 365 for Agents is expanding in public preview and works alongside Microsoft Agent 365 to provide a secure environment for AI agent execution.

According to Microsoft:

  • Agent 365 governs what an agent is authorized to do
  • Windows 365 for Agents provides the managed execution environment
  • Agents can run in auditable, policy-controlled Cloud PCs

This is a notable step for organizations exploring enterprise AI agents while maintaining governance and security controls.

Impact on IT administrators

Security and identity teams should view these updates as part of Microsoft’s broader push toward protecting AI, data, and identities together. The biggest practical benefits are improved data risk workflows in Purview, stronger investigation capabilities, and a more secure path for account recovery.

Next steps

  • Review the new Purview DSPM experience if your organization uses Microsoft Purview
  • Evaluate OCR and custom examinations for data investigation use cases
  • Assess Entra ID Account recovery for identity resilience planning
  • Monitor Windows 365 for Agents if you are testing or deploying AI agents in the enterprise

Need help with Security?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

Microsoft SecurityMicrosoft PurviewEntra IDWindows 365AI security

Related Posts

Security

npm Dependency Confusion Attack Targets Developer Environments

Microsoft Threat Intelligence uncovered 33 malicious npm packages that abused dependency confusion to impersonate internal corporate packages and silently profile developer systems during installation. The campaign matters because it targets developer workstations and CI/CD environments, creating a foothold for potential follow-on supply chain attacks.

Security

Microsoft Defender Named a 2026 Endpoint Leader

Microsoft says it has been named a Leader in the 2026 Gartner Magic Quadrant for Endpoint Protection for the seventh consecutive time. The announcement highlights recent Microsoft Defender for Endpoint enhancements, including attack disruption, custom telemetry, simplified onboarding, sovereign-ready deployment options, and protection for local AI agents.

Security

Typosquatted npm Packages Steal Cloud and CI/CD Secrets

Microsoft has uncovered an active npm supply chain attack in which 14 typosquatted packages stole AWS credentials, HashiCorp Vault tokens, GitHub Actions data, and npm publish tokens during installation. The campaign matters because it targets developer and build environments, creating risk of cloud lateral movement, CI/CD compromise, and downstream software supply chain attacks.

Security

The Gentlemen Ransomware: Self-Propagating Go Threat

Microsoft Threat Intelligence has published a deep technical analysis of The Gentlemen ransomware, a Go-based ransomware-as-a-service threat that combines strong file encryption with aggressive self-propagation. The research matters for defenders because the malware can rapidly spread across local systems and network shares, increasing the blast radius of a single compromise.

Security

Cryptojacking Campaign Abuses ScreenConnect and .NET

Microsoft has detailed an active cryptojacking campaign that uses poisoned search results and AI chatbot recommendations to lure users to fake software download sites. The attack abuses DLL sideloading, ScreenConnect, and Microsoft .NET utilities to gain persistent access and mine cryptocurrency on high-GPU systems, raising the risk of follow-on activity such as data theft or ransomware.

Security

Microsoft Security AI Foundations: Customer Success

Microsoft highlighted how St. Luke’s and ManpowerGroup are building AI-ready security foundations with Microsoft Security, Microsoft Sentinel, Microsoft Defender, and Security Copilot. The stories show why unified visibility, automation, and Zero Trust controls are becoming essential for organizations that want to scale AI without increasing risk.