What’s new in DefenderXDR? 05/26
Another month, another Defender XDR update. Several of the changes covered here quietly address operational topics: visibility, correlation and preparation instead of last‑minute firefighting.
One topic in particular deserves a closer look: Secure Boot 2023 certificates. It’s not new, it’s not spectacular, but it will hurt if ignored. Microsoft is now surfacing the problem directly via Secure Score!
My personal Highlights
New Microsoft Secure Score recommendation: Secure Boot 2023 certificates
Secure Boot keeps coming up for a reason. With the upcoming certificate expiration in June 2026, this is one of those topics that becomes critical if ignored. The new Secure Score recommendation provides clear, centralized visibility into which devices are ready and which are not from Defender perspective. From an operational standpoint, this is more about avoiding a situation where devices suddenly fall behind early‑boot protections.
At experience4you, we see this topic regularly in real environments, which is why we’ve also published a technical blog and offer a free Secure Boot 2026 toolkit to help assess exposure and plan remediation. I recommend to take a look at: Secure Boot Update 2026 .
Restrict response actions on high value assets (Preview)
This is a very pragmatic step for Tier‑0 assets. Being able to onboard Defender for Endpoint on domain controllers or other HVAs without automatically enabling all high‑impact response actions is a great addition. Detection stays intact, alerts still fire, but response capabilities are deliberately constrained. For organizations with strict privilege boundaries or operational risk concerns, this finally makes Defender onboarding on critical infrastructure a more controlled, defensible decision instead of an all‑or‑nothing trade‑off.
Defender for Endpoint
-
Status: Preview
Summary
Selective Response Actions allow organizations to restrict high‑impact response actions when onboarding critical systems such as Tier‑0 assets and other high‑value assets (HVAs). This provides fine‑grained control over which Defender for Endpoint response capabilities are allowed, while preserving full detection and alerting coverage.Key Details
Impact
Reduces operational risk on Tier‑0 systems like domain controllers and ADFS servers. Allows Defender for Endpoint onboarding without enabling all remote response actions. Balances strong protection with strict operational and compliance requirements How it works
The feature is enabled tenant‑wide via Advanced features. Restricted settings are applied during onboarding using the Defender Deployment Tool (DDT). Admins choose between Full and Restricted functionality per onboarding package. Allowed or disallowed actions are defined upfront and cannot be changed afterwardRestrictable response
Basic response actions (AV scan, collect file, collect investigation package)
Advanced response actions (isolate device, restrict app execution, request remediation)
Live Response access (script execution is disabled by design in restricted mode
Automated Investigation and Response (AIR)
Important notes
Detection, alerting, timelines, and sensor coverage are not affected. Live Response script execution is always blocked in restricted mode. Changes require offboarding and re‑onboarding to take effectWho’s affected
Organizations onboarding Defender for Endpoint on Tier‑0 systems. Environments with strict privileged access or cloud action restrictions. Security teams protecting high‑value or business‑critical infrastructureRequired Actions
Review which response actions are acceptable for Tier‑0 and HVA systems. Plan onboarding packages accordingly before deploying Defender for Endpoint
Learn more: Restrict response actions on high‑value assets (Selective Response Actions)
-
Status: Preview
Summary
You can now view the current status of automatic attack disruption and predictive shielding actions directly within an incident. The Activities tab shows whether actions such as contain user, GPO hardening, or SafeBoot hardening are still active, already reverted, or no longer applicable.Key Details
Impact
Provides stateful visibility into containment and hardening actions
Distinguishes historical execution from current enforcement state
Reduces uncertainty around whether automated protections are still active
Improves incident analysis in large environments with many parallel actions
How it works
Action status is exposed in the Activities tab of an incident
A new Policy status column shows the current state of related policies
The view applies to actions performed by AttackDisruption, including predictive shielding
Available policy statuses
Active
The policy is currently active and enforcedInactive
The policy was applied previously but is no longer activeNot applicable
Policy status does not apply to the action, for example uncontain actionsNo status
Policy status cannot be determined, for example while an action is still in progress
Who’s affected
SOC teams using automatic attack disruption. Organizations relying on predictive shielding at scale. Analysts evaluating the current blast radius of an incidentRequired Actions
Use the Activities tab to validate whether containment and hardening actions are still active
Adjust investigation workflows to rely on policy status instead of action history
Learn more: Track the action status in the Activities tab (Preview)
-
Status: Preview
Summary
Microsoft Secure Score now includes the new recommendation Ensure devices are updated to Secure Boot 2023 certificates and boot manager. It helps identify devices that have not yet transitioned to the new Secure Boot certificates required ahead of the June 2026 expiration of the older certificates.Key Details
Impact
Identifies devices still using legacy Secure Boot certificates
Highlights systems that may lose early boot security protections after certificate expiration
Provides centralized visibility into Secure Boot readiness across the environment
Supports risk-based prioritization and rollout tracking at scale
Background
Older Secure Boot certificates are set to expire in June 2026
Devices not updated in time may be unable to receive new early boot security protections
This primarily affects long-lived Windows installations and environments with slow OS or firmware update cycles
Who’s affected
Organizations managing Windows devices with Secure Boot enabled
Environments with mixed hardware generations or long support lifecycles
Security and endpoint teams tracking Secure Boot compliance and health
Required Actions
Review Secure Score for devices flagged by the recommendation
Plan and validate deployment of the Secure Boot 2023 certificates and updated boot manager
Prioritize remediation for devices that cannot be updated through standard servicing
Learn more: Assess Secure Boot status with Microsoft Defender (blog)
Defender for Identity
-
Status: Preview
Summary
Custom account correlation rules allow you to manually link multiple accounts that belong to the same identity. This is useful for scenarios with privileged or service accounts that do not share strong identifiers such as SID, object ID, or UPN, but still represent the same user.Key Details
Impact
Improves identity-centric investigations by correlating related accounts
Reduces blind spots caused by separate user objects with different naming conventions
Helps Defender XDR treat correlated accounts as a single identity context
Enhances signal correlation and investigative accuracy across incidents
How it works
Correlation rules are defined manually by administrators
Accounts can be linked based on weaker identifiers, including:
UPN prefix
UPN suffix
Domain UPN
Employee ID
Rules apply where automatic correlation is not possible due to missing strong identifiers
Common use cases
Privileged accounts with separate admin naming schemes. Hybrid environments with inconsistent identity attributes
Who’s affected
Organizations with multiple accounts per user identity. Environments using separate admin or privileged account models. SOC teams relying on identity correlation during investigations
Required Actions
Identify account patterns that represent the same user identity. Define and validate custom correlation rules. Review correlated identities to ensure accurate linking and avoid false associations
Learn more: Create custom account correlation rules
-
Status: GA
Summary
Automatic Windows event auditing configuration for Defender for Identity sensors v3.x is now generally available. Required Windows auditing settings are applied automatically to new sensors and corrected on existing ones if misconfigured.Key Details
Impact
Simplifies sensor deployment by removing manual auditing configuration. Ensures required Windows events are consistently collected. Automatically fixes misconfigurations on existing sensors. Reduces configuration drift and troubleshooting effort
Who’s affected
Organizations using Defender for Identity sensors v3.x
Required Actions
No action required
Learn more: Automatic Windows event auditing configuration for Defender for Identity sensors
Defender for Cloud Apps
Defender for Office365
-
Status: Announced
Summary
Microsoft Defender for Office 365 is enhancing how promotional email is identified and handled. Promotional messages are now tagged as Promotions (previously Bulk in preview) and can be automatically moved to a dedicated Promotions folder. The system learns from user actions and adapts future message handling accordingly.
Key Details
Impact
Reduces inbox clutter by separating promotional mail. Introduces a dedicated Promotions folder in user mailboxes.Learns from user behavior when messages are moved in or out of the folder. Allows inbox rules based on the Promotions tag
Timeline
Public Preview (limited): Mid‑April 2026 – End of April 2026
GA (Worldwide): Early July 2026 – Late July 2026
GA (GCC, GCC High, DoD): Early July 2026 – Mid‑August 2026
Who’s affected
All organizations using Microsoft Defender for Office 365
Required Actions
Optional: Apply for Public Preview via BulkMailPreviews@microsoft.com. Review mailbox handling guidance and user training if participating in preview
Learn more: Microsoft Defender for Office 365 promotional mail handling updates
DefenderXDR
-
Status: Preview
Summary
The AIAgentsInfo table in Advanced Hunting now includes additional columns that provide deeper visibility into AI agents across the Microsoft 365 environment. Coverage is expanded beyond Copilot Studio to include Microsoft Foundry, third‑party marketplace, and custom line‑of‑business agents.Key Details
Impact
Improved visibility into AI agent usage and properties. Broader coverage across all AI agent types. Supports more detailed hunting and investigation scenarios
Who’s affected
Security teams using Advanced Hunting to monitor AI usage
Required Actions
No action required
Learn more: Advanced Hunting documentation for AIAgentsInfo
-
Status: GA
Summary
Built‑in alert tuning rules are now generally available. These rules automatically suppress alerts generated by common benign activity in Defender for Endpoint and Defender for Office 365, without impacting Automated Investigation and Response (AIR) or email notifications.Key Details
Impact
Reduces alert noise from known benign behavior. Preserves AIR investigations and alert notifications. Improves SOC signal‑to‑noise ratio
Who’s affected
SOC teams working with Defender for Endpoint and Defender for Office 365
Required Actions
No action required
-
Status: Preview
Summary
Microsoft Defender XDR introduces Email summary powered by Security Copilot on the Email entity page. This capability uses Security Copilot to generate concise, AI‑driven summaries of email detection data to speed up investigation and response.Key Details
Impact
Provides a summarized view of email threats and actions taken. Reduces investigation time by consolidating key signals in one place. Adds contextual analysis without changing underlying detections or policies
What’s included
Email overview summarizing threats, actions, overrides, and indicators. Timeline analysis of the email lifecycle. URL analysis for extracted links. Attachment analysis highlighting suspicious or malicious files
Timeline
Public Preview: Mid‑April 2026 – Late April 2026
GA (Worldwide): Early May 2026 – Mid‑May 2026
Who’s affected
Security teams using Microsoft Defender XDR. Tenants with Security Copilot access and provisioned Security Compute Units (SCUs)
Required Actions
Ensure Security Copilot SCUs are provisioned. Verify analyst access to Security Copilot
Learn more: Microsoft Security Copilot in Microsoft Defender XDR

