> ## Content Index
> Fetch the complete content index at: https://f4n6.co.uk/llms.txt
> Use this file to discover other available public pages before exploring further.

# ​​​​​​What’s new in Microsoft Security: August 2026
- URL: https://f4n6.co.uk/security-feed/whats-new-in-microsoft-security-august-2026/
- Published: 2026-08-27T20:37:38.000Z
- Updated: 2026-08-27T20:37:38.000Z
- Author: Jeff Davies
- Tags: #security-feed

## 1\. Executive summary

On 27 August 2026, Microsoft published its monthly security portfolio update, announcing feature expansions across Defender Experts, Entra, Intune, Purview, and Security Exposure Management. The headline items are: Defender Experts MDR now ingests third-party data sources (Palo Alto Networks, AWS, Okta) via Sentinel for 24/7 managed detection; Entra Tenant Governance consolidates multi-tenant visibility to reduce shadow-tenant risk; Purview auto-labeling throughput increased fivefold to 500,000 files/day; and new Secure Now guidance addresses agentic containment for autonomous AI agents. No CVEs, threat actors, or active exploitation campaigns are described. For EMEA financial services, the most operationally relevant items are the expanded MDR third-party telemetry coverage and the agentic containment guidance, both of which bear on operational resilience and governance of AI-driven processes.

## 2\. Regulatory framing

No specific DORA/NIS2 article is directly engaged by this item. The update describes product feature releases and guidance rather than a specific incident, vulnerability, or third-party risk event that would trigger a distinctive obligation under the cited regulatory articles.

## 3\. Technical analysis & attack chain

This is a strategic product-update item, not a vulnerability or threat campaign. No attack chain, CVE, or exploitation activity is described in the source material. The following capabilities and changes are announced:

**Microsoft Defender Experts MDR — third-party data source expansion.** Defender Experts MDR P2 now provides around-the-clock managed detection, response, and threat hunting across third-party data sources ingested through Microsoft Sentinel. Named supported sources include Palo Alto Networks, AWS, and Okta. This extends MDR beyond Microsoft-native telemetry. Defender Experts Threat Intelligence now delivers expert-led, curated intelligence tailored to geography, industry, and risk profile.

**Microsoft Entra Tenant Governance.** Brings an organisation's tenants into a single view. Capabilities include centralized policies, cross-tenant delegated administration, configuration drift monitoring, and shadow-tenant discovery. The stated goal is to strengthen identity foundations for AI-powered operations.

**Microsoft Intune / Windows Autopilot.** Device association now lets admins link devices to their tenant and configure pre-enrollment experiences, including renaming devices during the out-of-box experience. Windows Unattended Support with Remote Sign-In allows IT/support staff to remotely sign in to devices without user involvement; role-based permissions, compliance checks, and session auditing are built in.

**Microsoft Purview auto-labeling.** Throughput increased from 100,000 to 500,000 SharePoint and OneDrive files per day. Sensitivity labels apply encryption and DLP controls. The increase is positioned as supporting broader data protection coverage and Microsoft 365 Copilot adoption.

**Microsoft Security Exposure Management — Secure Now agentic containment guidance.** New guidance for constraining agent-initiated actions that occur without explicit user approval. Recommendations cover: hardening attack surfaces, limiting impact, governing identities and permissions, and increasing visibility across the environment. This is guidance, not a product control.

**Confidence caveat:** All claims are single-sourced (Microsoft Security Blog). No independent corroboration is available. The JPCERT/CC related source references August 2026 Microsoft security updates but contains no body text in the fetched content and does not corroborate the product-update claims in the primary source.

## 4\. Mitigation & containment

No containment actions are required — this is a product feature announcement, not an active threat or vulnerability disclosure. The following actions are recommended for EMEA financial services clients to operationalise the announced capabilities:

**P1 — within 24h:** No immediate action required.

### P2 — within 72h

- Review whether your Defender Experts MDR P2 licence covers the newly supported third-party sources (Palo Alto Networks, AWS, Okta). If Sentinel is already ingesting these data sources, confirm with your Microsoft account team that MDR coverage is active and that hunting rules are deployed against the third-party telemetry.
- Identify shadow tenants in your environment. If Entra Tenant Governance is licensed, enumerate all tenants associated with your organisation and flag any without documented ownership or governance.

### P3 — within 7 days

- Review the Secure Now agentic containment guidance and map it against any autonomous AI agents currently deployed in your environment. Prioritise agents that initiate actions without explicit user approval. Document the identities, permissions, and attack surfaces each agent can reach.
- If Purview auto-labeling is in use, assess whether the increased 500,000-file/day limit warrants policy adjustments to avoid over-labeling or performance impacts on SharePoint/OneDrive.
- Evaluate Windows Unattended Support with Remote Sign-In against your remote access policy. Confirm that role-based permissions, compliance checks, and session auditing are enabled before deployment to support staff.

## 5\. Indicators of compromise

No indicators of compromise available in the source material.

## 6\. Detection

Insufficient indicators to author detection rules.

## 7\. Sources

- Microsoft Security Blog, "What's new in Microsoft Security: August 2026," https://www.microsoft.com/en-us/security/blog/2026/08/27/whats-new-in-microsoft-security-august-2026/, 2026-08-27
- Microsoft Security Blog, "What's new in Microsoft Security: July 2026," https://www.microsoft.com/en-us/security/blog/2026/07/30/whats-new-in-microsoft-security-july-2026/, 2026-07-30
- Microsoft Security Blog, "What's new in Microsoft Security: June 2026," https://www.microsoft.com/en-us/security/blog/2026/06/30/whats-new-in-microsoft-security-june-2026/, 2026-06-30
- JPCERT/CC, "Security Alert: Microsoft Releases August 2026 Security Updates," https://www.jpcert.or.jp/english/at/2026/at260022.html, 2026 (no body content retrieved)

## 8\. Adverse Trace position

This is a low-severity product-update advisory. No vulnerabilities, threat actors, or active exploitation are described. The operational value for EMEA financial services clients lies in three areas: (1) Defender Experts MDR's expanded third-party telemetry coverage may reduce blind spots in multicloud environments — clients should verify licensing and Sentinel ingestion pipelines; (2) Entra Tenant Governance directly addresses shadow-tenant risk, which is a persistent gap in large financial institutions with acquired entities; (3) the Secure Now agentic containment guidance is timely given the accelerating adoption of autonomous AI agents in financial services, but it is guidance only — clients should treat it as a starting framework and enforce concrete technical controls (least-privilege agent identities, action approval gates, runtime monitoring) rather than relying on the document alone. All claims are single-sourced from Microsoft; we will monitor for independent validation and for any subsequent CVE disclosures tied to the August 2026 update cycle.

---

[Read the original source →](https://www.microsoft.com/en-us/security/blog/2026/08/27/whats-new-in-microsoft-security-august-2026/?ref=f4n6.co.uk)

*Published via PulseTrace — Adverse Trace threat intelligence.*