October 3, 2026October 3, 2026 What’s new with Defender for Endpoint and Defender XDR – September 2026 October and the global cybersecurity awareness month have begun.I decide to start this whats new writing about Microsoft Security because i think those posts are not so known and customers does not usually know the latest features. MDE Summary September 2026 brings two production-ready gains and two previews worth piloting. Defender now protects Linux workloads running inside developer machines (WSL containers) and gives us a six-control “AI-Readiness” baseline to measure how well our devices resist AI-accelerated attacks.The previews extend Defender to Linux desktops and add memory scanning on Linux, closing gaps attackers use to stay invisible. All four are delivered inside the existing Defender platform, so the main cost is rollout effort, not new tooling; Linux desktop licensing should be confirmed before scaling. AI- Readiness recommendations in Exposure Management Capability Status Why it matters to the business Protection for WSL containers (WSLc) GA Developers’ Linux containers on Windows laptops were a blind spot; they now appear in the same alerts, incidents and investigations as everything else. AI-Readiness recommendations in Secure Score GA Six controls, tracked as a score, that harden devices against faster, AI-driven attacks. A clear KPI the board can follow. Defender for Linux desktops Public Preview One security tool for Linux servers and desktops, same deployment and features. Reduces tool sprawl and coverage gaps Memory scanning on Linux Public preview (early update channel) Detects malware that runs only in memory and leaves no file behind, a growing technique in advanced attacks. macOS agent update (build 101.26072.0017) GA Routine maintenance release. Spotlight: the AI-Readiness baseline The AI-Readiness set is the most board-relevant change: it turns “are we ready for AI-driven attacks?” into a measurable score. Attackers using AI move faster, so the baseline focuses on controls that stop them getting in, getting deep, and spreading. Recommended next steps Adopt the AI-Readiness score as a quarterly security KPI, with a target set by the CISO.Enable WSL container protection on developer laptops now that it is generally available.Approve a small pilot of Linux desktop protection and Linux memory scanning, ahead of general availability.Confirm licensing for Linux desktops before any wider rollout. XDR Summary September 2026 brought two strategic Defender XDR updates, both aimed at consolidation. Microsoft’s Integrated Security Operations Center (ISOC) puts detection, SIEM, threat intelligence, automation and AI in a single Defender portal, and opened in preview on September 23 to eligible Microsoft Defender Suite, Microsoft 365 E5 and E7 customers without a Microsoft Sentinel workspace.Separately, the Identity Security dashboard and Coverage & Maturity view are now generally available, giving leadership one measure of how well identities are protected across on-premises, cloud and SaaS. Because stolen identities are a common way in for attackers, this is the more immediately actionable of the two. Capability Status Why it matters to the business Integrated Security Operations Center (ISOC) Restricted Public Preview SIEM-style security operations built into Defender, with no separate SIEM project to start. Could reduce tool count and time to detect. Identity Security dashboard and Coverage & Maturity GA One score (0–100) and maturity tier showing how well every identity source is protected, with a prioritised fix list. A ready-made board KPI. Identity coverage with Defender for Identity and Defender for Cloud Apps Spotlight: what each update means in practice ISOC. Teams get case management, workbooks, automation rules and AI-generated playbooks inside Defender on day one, with no extra workspace. Adding behaviour analytics, threat intelligence or third-party data requires an ISOC workspace on an Azure subscription, and ingestion charges may apply beyond the 30 days of Defender data retention included in the preview.Two cautions for leadership: it is a preview, so scope and availability may change, and organisations already running Microsoft Sentinel are not eligible yet. Microsoft explicitly advises against disconnecting a production Sentinel workspace to qualify.Identity Coverage & Maturity. Requires a Defender for Identity or Defender for Cloud Apps licence. It scores identity protection from 0 to 100 and places us in one of four tiers: Recommended next steps Ask the security team for our current identity maturity tier and score, and set a target tier for next quarter.Confirm whether we qualify for the ISOC preview (licence held, no active Sentinel workspace).If eligible, approve a time-boxed ISOC evaluation, including an estimate of data ingestion costs.If we already run Sentinel, keep it as is and track ISOC until it reaches general availability. Jussi Metso Author is a lifelong IT enthusiast, Microsoft Security MVP and interested in Cloud Security, XDR, SIEM and AI. Motto: Learning is the key for your future. Share on Social Mediaxfacebooklinkedinwhatsapp Discover more from Jussi Metso Subscribe to get the latest posts sent to your email. Type your email… Subscribe WHATSNEW #defenderforendpoint#defenderxdr#whatsnew