What’s new in DefenderXDR? 02/26

January didn’t bring a major headline feature, but several Defender XDR updates popped up that are worth a closer, technical look in this edition of the series.

 

My personal Highlights

  • Retirement of MDE/XDR Advanced Hunting APIs

    • The retirement of the classic MDE and Defender XDR Advanced Hunting APIs is probably the most impactful change this month. Every automation, relying on these endpoints must migrate to the Microsoft Graph Security API before February 2027 to avoid breaking.

  • New Identity Security Posture Assessments

    • The new assessments for stale Active Directory accounts and dual‑privileged Entra ID/AD identities gap closes visibility in hybrid identity environments. For SecOps teams, this is a small but nice upgrade in attack‑surface management and identity risk detection.

 

Defender for Endpoint

 

Defender for Identity

 

Defender for Cloud Apps

 

Defender for Office365

 

DefenderXDR

 
Previous
Previous

DefenderBase.cloud is rebranding to SecOpsBase.cloud

Next
Next

Zero to Hero –How to Onboard Microsoft Defender for Endpoint for Windows Server – Complete Guide