Security & Defender

What’s new in Microsoft Defender – August 2026: AI agents, MDI sensor v3.x and prompt injection

What’s new in Microsoft Defender for August 2026: AI agent posture risk, MDI sensor v3.x migration in GA, OT connectors and prompt injection detection.

What’s new in Microsoft Defender for August 2026: AI agent security, Defender for Identity sensor v3.x and OT connectors

🌐 This article was originally written in French and automatically translated. Read the original (FR)

TL;DR

The August 2026 edition of the Microsoft Defender monthly news covers July’s updates: AI agent posture risk in public preview, AI agent protection with Microsoft Agent 365 and migration to the Defender for Identity v3.x sensor now generally available, Defender Experts MDR P2, Armis, Dragos and Forescout OT connectors, a Linux deployment tool and detection of prompt injection in inbound email.

Microsoft Defender’s August 2026 updates are dominated by AI agent security, the migration to the Defender for Identity v3.x sensor, now generally available, and prompt injection detection in Defender for Office 365. As every month, the August edition of Microsoft’s monthly news covers the updates released in July 2026, and it now includes Defender for Cloud announcements visible in the Microsoft Defender portal.

On top of that come OT connectors, a Linux deployment tool, Defender Experts MDR P2 and the end of the Microsoft Defender Threat Intelligence (MDTI) convergence. Here is what to remember, and what it changes for you.

August’s updates at a glance

Feature Product Status
AI agent posture risk Microsoft Defender Public preview
AI agent protection with Microsoft Agent 365 Microsoft Defender Generally available
Active Directory domain investigation page Defender for Identity Generally available
Sensor migration from v2.x to v3.x Defender for Identity Generally available
Password risks from SaaS apps Defender for Identity Public preview
Automatic RPC auditing (sensor 3.0.8 and later) Defender for Identity New (status not specified)
Defender Experts MDR P2 Microsoft Defender Experts Generally available
Codename MDASH, agentic code scanner Security Exposure Management Private preview
Armis, Dragos and Forescout OT data connectors Security Exposure Management Public preview
AI agent runtime protection (enhancements) Defender for Endpoint Public preview
Defender Deployment Tool for Linux Defender for Endpoint Generally available
Prompt injection protection Defender for Office 365 New (status not specified)
Unified RBAC by default for new Plan 2 organizations Defender for Office 365 Since July 2026
MDTI convergence into the Microsoft Defender portal Defender XDR and Sentinel Generally available since August 1

Microsoft Defender: AI agent security takes center stage

Assess AI agent posture risk

In public preview, Microsoft Defender assesses posture risk for AI agents: enterprise agents, but also local agents discovered on endpoint devices. Risk levels are based on active risk indicators: configuration, access, runtime activity, endpoint and user context, and active alerts.

In practice, the security team gets a risk level and recommendations to prioritize the riskiest agents. This is useful as soon as agents multiply without a clear inventory. Details are in AI agent posture risk in Microsoft Defender.

Protect AI agents with Microsoft Agent 365

With a Microsoft Agent 365 license, Microsoft Defender provides discovery, security posture, threat detection and investigation and real-time protection for the AI agents in your tenant. This capability is generally available.

Onboarding involves three steps listed by Microsoft: enable data collection, connect the Microsoft 365 app connector, then connect Copilot Studio for real-time protection of Copilot Studio agents.

Easier access to Playbook Generator

Following its general availability on May 31, Playbook Generator is now easier to get started with. Microsoft reduced friction around Security Copilot wallet provisioning and initial setup. Important reminder: it remains included with Microsoft Sentinel and does not consume SCUs for generating, testing or running playbooks.

Defender for Identity: sensor v3.x generally available

This is the most anticipated identity announcement: migration of sensors from v2.x to v3.x is generally available. To support migrations, the Sensors page now shows a tooltip on servers marked Not ready for migration: it lists the specific reasons the server doesn’t meet the prerequisites. No more digging through documentation to understand a blocker. The reference guide is Migrate to Defender for Identity sensor v3.x.

More good news: Defender for Identity automatically enables RPC auditing on domain controllers when you upgrade to sensor version 3.0.8 or later. You no longer need to apply a tag manually.

Two other updates round out the picture:

  • the domain investigation page (generally available) shows the security of an Active Directory domain: properties, deployment health, identity summary, service account breakdown, sensitive entities, active recommendations, group policies and trust relationships;
  • in public preview, the Password protection page includes password risks from SaaS apps connected through Defender for Cloud Apps, in addition to Active Directory, Microsoft Entra ID and Okta. Apps that support SSPM, such as Salesforce and ServiceNow, appear on the Password Hygiene and Password Policies tabs. Each app requires a Defender for Cloud Apps app connector.

My take: the domain investigation page is a good starting point for a quick Active Directory review, especially for often-forgotten service accounts and trust relationships.

Microsoft Defender Experts MDR P2

Microsoft Defender Experts MDR (formerly Microsoft Defender Experts for XDR) launches the MDR P2 service, generally available. This 24/7 managed detection and response service extends to non-Microsoft sources ingested into Microsoft Sentinel: AWS, Okta, Proofpoint, Palo Alto Networks, Cisco, Fortinet, ZScaler and CrowdStrike. It will mainly interest organizations with heterogeneous environments that want a single MDR provider.

Exposure Management and vulnerability management

  • Codename MDASH (private preview): an agentic code scanner built on a multi-model AI system to detect code vulnerabilities. Scans run from Defender CLI or through a GitHub connector, and findings are reviewed in the Microsoft Defender portal.
  • MAI-Augmented scan profile (private preview): available from Defender CLI, it adds MAI-Cyber-1-Flash, a new cyber-specialized model. You can also keep using a profile based on the existing models.
  • OT data connectors: Microsoft Security Exposure Management supports Armis, Dragos and Forescout. OT assets and vulnerabilities flow into the Microsoft Defender portal, alongside your other assets. See OT data connectors.

Defender for Endpoint: AI agents and Linux deployment

In public preview, AI agent runtime protection gets several enhancements:

  • vendor-supported agent event interfaces now work with standard platform and engine update channels, with no Beta channel configuration required;
  • agent-native event inspection now supports Codex CLI and the GitHub Copilot app;
  • network inspection covers agents that don’t expose event interfaces, such as OpenClaw and similar Node.js-based Claw agents.

On Linux, the Defender Deployment Tool for Linux becomes generally available, starting with version 101.26042.0011. It combines installation, onboarding, upgrades and uninstallation into a single workflow, validates prerequisites and works with local repositories. Monitoring relies on the device timeline and advanced hunting, with the stage, exit code and failure reason for each error. See the Defender Deployment Tool for Linux.

Defender for Office 365: prompt injection and licensing

  • Prompt injection protection: Defender for Office 365 detects prompt injection attacks hidden in inbound email. With AI assistants reading mailboxes, this vector is becoming very real. See Prompt injection protection in Defender for Office 365.
  • Unified RBAC by default: since July 2026, new Defender for Office 365 Plan 2 organizations use the Microsoft Defender unified role-based access control (Unified RBAC) model by default.
  • Microsoft 365 E3 now includes Defender for Office 365 Plan 1.

Also announced this month

Dragos, Forescout and Armis OT integrations. The July 14 post specifies that these integrations are in public preview and can be enabled from the Microsoft Defender portal. The device inventory shows discovered OT devices, and the vulnerabilities view gains an OT Partner CVEs tab: the SOC sees OT and IT vulnerabilities in a single prioritized view.

MDTI convergence complete. Since August 1, the final phase of Microsoft Defender Threat Intelligence convergence is generally available, at no additional cost. Entity pages (IP addresses, domains, URLs, files) show a Threat Intelligence Insights tab. The free Microsoft Threat Intelligence connector in Sentinel now carries the premium data, and MDTI APIs no longer require a separate license. The Intel Profiles, Intel Explorer and Intel Projects pages are retired in favor of the Threat Analytics tab, with no migration needed.

Certighost (CVE-2026-54121). This Active Directory Certificate Services vulnerability allows an attacker to obtain certificates for domain computer accounts, including domain controllers. Fix: the July 14, 2026 security update. Defender for Identity raises the Potential Certighost (CVE-2026-54121) AD CS abuse alert. If the sensor isn’t deployed on your AD CS servers, enable Certificate Services auditing (configure Windows event auditing).

What I recommend doing this month

  1. Patch your Enterprise Certification Authorities with the July 14 update, then check that Defender for Identity covers your domain controllers and AD CS servers.
  2. Plan the migration to sensor v3.x: find the servers marked “Not ready for migration” and read the reasons shown. Target version 3.0.8 or later for automatic RPC auditing.
  3. Inventory your AI agents: try AI agent posture risk (preview) and, if you have Agent 365, connect the Microsoft 365 app connector and Copilot Studio.
  4. Standardize your Linux deployments with the Defender Deployment Tool and monitor them with advanced hunting.
  5. MDTI customers: head to Threat Analytics and talk to your Microsoft account team about adjusting your license.

Key takeaways

  • Microsoft Defender assesses posture risk for AI agents in public preview, including local agents discovered on endpoint devices.
  • With a Microsoft Agent 365 license, Defender provides discovery, posture, threat detection and real-time protection for the AI agents in your tenant (generally available).
  • Migration of Defender for Identity sensors from v2.x to v3.x is generally available, and RPC auditing is enabled automatically from sensor 3.0.8.
  • Microsoft Security Exposure Management adds OT data connectors for Armis, Dragos and Forescout, in public preview according to the announcement post.
  • The Defender Deployment Tool for Linux (version 101.26042.0011 and later) combines installation, onboarding, upgrades and uninstallation (generally available).
  • Defender for Office 365 detects prompt injection attacks in inbound email, and Microsoft 365 E3 now includes Defender for Office 365 Plan 1.

Frequently asked questions

What are the main Microsoft Defender updates for August 2026?

The August edition covers July 2026: AI agent posture risk (public preview), AI agent protection with Microsoft Agent 365 (generally available), migration to the Defender for Identity v3.x sensor (generally available), Defender Experts MDR P2, OT connectors and prompt injection detection in Defender for Office 365.

Is migration to the Defender for Identity v3.x sensor ready for production?

Yes, migration of sensors from v2.x to v3.x is generally available. The Sensors page now shows, when you hover over the “Not ready for migration” status, the specific reasons a server doesn’t meet the prerequisites.

Do I still need to tag domain controllers to enable RPC auditing?

No. Defender for Identity automatically enables RPC auditing on domain controllers when you upgrade to sensor version 3.0.8 or later, with no manual tag.

What does the Microsoft Defender Threat Intelligence convergence change?

Since August 1, MDTI capabilities are available in the Microsoft Defender portal at no additional cost, through the Threat Analytics tab. The standalone Intel Profiles, Intel Explorer and Intel Projects pages are retired, and no migration action is needed.

How does Microsoft Defender detect the Certighost vulnerability (CVE-2026-54121)?

Defender for Identity raises the “Potential Certighost (CVE-2026-54121) AD CS abuse” alert. Microsoft stresses that the primary fix remains the July 14, 2026 security update on Enterprise Certification Authorities.

Sources and documentation

#Microsoft Defender#What's new in Defender#Defender for Identity#Defender for Endpoint#Defender for Office 365#AI agent security#Exposure Management

Comments

    Leave a comment

    Comments are reviewed before being published. Your name and comment will be publicly visible. Personal data.