Security

Microsoft Security Updates: Agent 365 and Defender

3 min read

Summary

Microsoft has announced new security capabilities across Agent 365, Defender for Cloud, GitHub Advanced Security, and Microsoft Purview. The updates focus on improving visibility into AI agent activity, strengthening code-to-runtime protection, and accelerating data security investigations for security and IT teams.

Need help with Security?Talk to an Expert

Microsoft Security updates focus on AI agents, apps, and data

Introduction

Microsoft has released a new round of security updates aimed at helping organizations secure AI-driven workflows, strengthen cloud and application protection, and improve data investigations. For IT and security administrators, these changes matter because they add more visibility, faster detection, and better coordination across security operations and development teams.

What’s new

Microsoft Defender capabilities for Agent 365 tooling gateway

Microsoft introduced new Microsoft Defender capabilities in preview for the Agent 365 tooling gateway. These features are designed to help security teams detect, block, and investigate threats targeting AI agents and agentic workflows.

Key highlights include:

  • Near real-time protection using webhooks to inspect agent actions.
  • Detection of anomalous or risky behavior before actions are executed.
  • Better visibility and control over how AI agents interact across systems.

This is especially important for organizations deploying autonomous AI agents that can access data and trigger actions across business environments.

Defender for Cloud and GitHub Advanced Security integration now GA

Microsoft also announced general availability of the Microsoft Defender for Cloud integration with GitHub Advanced Security.

This integration provides:

  • Unified visibility from code to production runtime.
  • Automatic mapping of code changes to production environments.
  • Alert prioritization based on real runtime context.
  • Coordinated remediation workflows for development and security teams.
  • AI-powered remediation tools to speed issue resolution.

For DevSecOps teams, this helps close the gap between developer findings and operational risk in production workloads.

New Microsoft Purview Data Security Investigations demo

Microsoft highlighted a new hands-on demo for Microsoft Purview Data Security Investigations. The demo shows how analysts can identify relevant data, use AI-powered deep content analysis, and investigate incidents such as breaches, leaks, fraud, or bribery.

Capabilities demonstrated include:

  • Proactive assessment of data security risks.
  • Reactive investigation of sensitive data involved in incidents.
  • Visualization of correlations between users, content, and activities through the data risk graph.

Impact on IT administrators

For security and IT teams, these updates support a more integrated security model across AI, applications, and data. Administrators can gain stronger oversight of AI agents, improve vulnerability management from source code to runtime, and streamline investigative workflows for sensitive data incidents.

Next steps

  • Evaluate the preview Defender capabilities for Agent 365 if your organization is adopting AI agents.
  • Review the Defender for Cloud and GitHub Advanced Security integration for DevSecOps workflows.
  • Explore the Purview Data Security Investigations demo to assess incident response and insider risk scenarios.
  • Monitor upcoming Microsoft Security announcements, especially ahead of Microsoft Build 2026.

These updates show Microsoft’s continued focus on Zero Trust for AI and more automated, context-aware security operations.

Need help with Security?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

Microsoft SecurityMicrosoft DefenderAgent 365GitHub Advanced SecurityMicrosoft Purview

Related Posts

Security

Microsoft Digital Defense Report 2026: Key Security Insights

Microsoft's 2026 Digital Defense Report highlights how AI and growing system interconnectedness are reshaping both cyberattacks and defense strategies. The report emphasizes that organizations must secure AI, identities, data, and cloud environments together while improving signal correlation across tools to detect modern threats faster.

Security

Government Cyber Risk in 2026: Microsoft’s 5 Priorities

Microsoft says government agencies were the most targeted sector in 2026, accounting for 27% of observed cyber threat activity. The company urges public-sector leaders to focus on five resilience priorities, including faster response, AI security, bidirectional information sharing, and planning for incidents that spread across suppliers and essential services.

Security

Microsoft Ignite 2026 Security Guide: Key Sessions

Microsoft has published its security guide for Microsoft Ignite 2026, highlighting AI-first security themes, a dedicated Security Pre-Day, and technical sessions focused on securing identities, data, devices, clouds, and AI agents. For IT and security teams, the event offers an early look at Microsoft’s roadmap and practical guidance for building an AI-ready security strategy.

Security

CVE-2026-73570: Zimbra Mail Server Exploitation

Microsoft is tracking active exploitation of CVE-2026-73570, an unauthenticated command injection flaw affecting internet-facing Zimbra mail servers with the optional zimbra-snmp package installed and SNMP notifications enabled. The issue can lead to web shell deployment, privilege escalation, mailbox data theft, and persistent remote access, making immediate patching and configuration review critical for administrators.

Security

Phishing Abuses RMM Tools for Persistent Access

Microsoft security researchers observed phishing campaigns in July 2026 that used a legitimate MSP360 RMM installer disguised as meeting invites, PDF updates, and other lures to gain remote access. Attackers then deployed ConnectWise ScreenConnect for redundant persistence, highlighting the need for tighter controls on remote management tools and better detection of unapproved RMM activity.

Security

Azure DevOps Attack Path Exposed in New DART Report

Microsoft’s latest DART cyberattack report shows how a single compromised identity was used to access Azure DevOps, alter pipelines, and harvest Kubernetes credentials. The case highlights how tightly connected identity, DevOps, and cloud environments can let attackers move far beyond source code, making stronger identity and pipeline controls essential.