Skip to content
Jussi Metso
Jussi Metso

It's all about The Cloud and The Security

  • Posts
  • About the blog
  • Activity
  • Connect!
  • Privacy Policy
Jussi Metso

It's all about The Cloud and The Security

October 3, 2026October 3, 2026

What’s new with Defender for Endpoint and Defender XDR – September 2026

October and the global cybersecurity awareness month have begun.

I decide to start this whats new writing about Microsoft Security because i think those posts are not so known and customers does not usually know the latest features.

 

MDE Summary

September 2026 brings two production-ready gains and two previews worth piloting. Defender now protects Linux workloads running inside developer machines (WSL containers) and gives us a six-control “AI-Readiness” baseline to measure how well our devices resist AI-accelerated attacks.

The previews extend Defender to Linux desktops and add memory scanning on Linux, closing gaps attackers use to stay invisible. All four are delivered inside the existing Defender platform, so the main cost is rollout effort, not new tooling; Linux desktop licensing should be confirmed before scaling.

AI- Readiness recommendations in Exposure Management

Capability

Status

Why it matters to the business

Protection for WSL containers (WSLc)

GA

Developers’ Linux containers on Windows laptops were a blind spot; they now appear in the same alerts, incidents and investigations as everything else.

AI-Readiness recommendations in Secure Score

GA

Six controls, tracked as a score, that harden devices against faster, AI-driven attacks. A clear KPI the board can follow.

Defender for Linux desktops

Public Preview

One security tool for Linux servers and desktops, same deployment and features. Reduces tool sprawl and coverage gaps

Memory scanning on Linux

Public preview (early update channel)

Detects malware that runs only in memory and leaves no file behind, a growing technique in advanced attacks.

macOS agent update (build 101.26072.0017)

GA

Routine maintenance release.

Spotlight: the AI-Readiness baseline

The AI-Readiness set is the most board-relevant change: it turns “are we ready for AI-driven attacks?” into a measurable score. Attackers using AI move faster, so the baseline focuses on controls that stop them getting in, getting deep, and spreading.

Recommended next steps

  • Adopt the AI-Readiness score as a quarterly security KPI, with a target set by the CISO.
  • Enable WSL container protection on developer laptops now that it is generally available.
  • Approve a small pilot of Linux desktop protection and Linux memory scanning, ahead of general availability.
  • Confirm licensing for Linux desktops before any wider rollout.

XDR Summary

September 2026 brought two strategic Defender XDR updates, both aimed at consolidation. Microsoft’s Integrated Security Operations Center (ISOC) puts detection, SIEM, threat intelligence, automation and AI in a single Defender portal, and opened in preview on September 23 to eligible Microsoft Defender Suite, Microsoft 365 E5 and E7 customers without a Microsoft Sentinel workspace.

Separately, the Identity Security dashboard and Coverage & Maturity view are now generally available, giving leadership one measure of how well identities are protected across on-premises, cloud and SaaS. Because stolen identities are a common way in for attackers, this is the more immediately actionable of the two.

Capability

Status

Why it matters to the business

Integrated Security Operations Center (ISOC)

Restricted Public Preview

SIEM-style security operations built into Defender, with no separate SIEM project to start. Could reduce tool count and time to detect.

Identity Security dashboard and Coverage & Maturity

GA

One score (0–100) and maturity tier showing how well every identity source is protected, with a prioritised fix list. A ready-made board KPI.

Identity coverage with Defender for Identity and Defender for Cloud Apps

Spotlight: what each update means in practice

ISOC. Teams get case management, workbooks, automation rules and AI-generated playbooks inside Defender on day one, with no extra workspace. Adding behaviour analytics, threat intelligence or third-party data requires an ISOC workspace on an Azure subscription, and ingestion charges may apply beyond the 30 days of Defender data retention included in the preview.

Two cautions for leadership: it is a preview, so scope and availability may change, and organisations already running Microsoft Sentinel are not eligible yet. Microsoft explicitly advises against disconnecting a production Sentinel workspace to qualify.

Identity Coverage & Maturity. Requires a Defender for Identity or Defender for Cloud Apps licence. It scores identity protection from 0 to 100 and places us in one of four tiers:

Recommended next steps

  • Ask the security team for our current identity maturity tier and score, and set a target tier for next quarter.
  • Confirm whether we qualify for the ISOC preview (licence held, no active Sentinel workspace).
  • If eligible, approve a time-boxed ISOC evaluation, including an estimate of data ingestion costs.
  • If we already run Sentinel, keep it as is and track ISOC until it reaches general availability.
Picture of Jussi Metso
Jussi Metso

Author is a lifelong IT enthusiast, Microsoft Security MVP and interested in Cloud Security, XDR, SIEM and AI. Motto: Learning is the key for your future.

Share on Social Media
xfacebooklinkedinwhatsapp

Discover more from Jussi Metso

Subscribe to get the latest posts sent to your email.

WHATSNEW #defenderforendpoint#defenderxdr#whatsnew

Post navigation

Previous post

Link to my MVP profile:

Subscribe my blog to get updates!

Join 42 other subscribers

Recent Posts

  • What’s new with Defender for Endpoint and Defender XDR – September 2026
  • Microsoft ISOC – Integrated Security Operations Center
  • The PAW, PIM and the Conditional Access setup and some Entra ID attack vectors
  • Descriptions (& some instructions) for the Red Tenant
  • Enterprise Access Model (EAM) – part of Red tenant story

Top posts:

Defender for Cloud – Part 10: Cloud Workload protection (CWP)
NextGen Defender for Cloud: Phase 1 - public preview
Malware automated remediation in Defender for Storage
Defender for Cloud - Part 6: Attack Path Analysis
Defender for Cloud – Part 5: Security Alerts

Categories

  • AI (7)
  • AUTHOR (1)
  • BOOKREVIEW (1)
  • CSPM (2)
  • DATA SECURITY (1)
  • DEFENDER FOR CLOUD (19)
  • DEFENDER FOR DEVOPS (1)
  • entraid (1)
  • IDENTITY_ACCESS (3)
  • LEARNING (1)
  • MVP (1)
  • RED (3)
  • SECURITY (14)
  • SECURITYCOPILOT (1)
  • SENTINEL (5)
  • SOC (1)
  • THREAT INTELLIGENCE (1)
  • WHATSNEW (1)
  • XDR (3)

Tags

#activedirectory (1) #architecture (1) #azure (1) #bookreview (2) #cloudsecurity (18) #condiftionalaccess (1) #defenderforcloud (2) #defenderforendpoint (1) #defenderforstorage (1) #defenderxdr (5) #entraid (1) #identityaccess (2) #malwarescan (1) #mdcseries (13) #mitreattack (1) #redforest (1) #redtenant (4) #securitycopilot (1) #sentinel (4) #siem (3) #soc (4) #whatsnew (1) entraid (1) identityaccess (1)

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • March 2026
  • February 2026
  • December 2025
  • November 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • June 2024
  • April 2024
  • January 2024
  • December 2023
  • October 2023
  • August 2023
  • June 2023
  • May 2023
  • April 2023
  • January 2023
  • December 2022
  • November 2022

Visits on my site

28,399 hits

©2022-2026 Jussi Metso. All rights reserved.