​​What’s new in Microsoft Security: June 2026

Source: Microsoft Security Blog

Author: Alym Rayani

URL: https://www.microsoft.com/en-us/security/blog/2026/06/30/whats-new-in-microsoft-security-june-2026/

​​What’s new in Microsoft Security: June 2026

ONE SENTENCE SUMMARY:

Microsoft Security’s June 2026 updates deliver autonomous, multicloud, identity, data, endpoint, and developer-focused protections for scaled AI environments.

MAIN POINTS:

  1. Codename MDASH uses multi-model agents to find, validate, and remediate complex vulnerabilities.
  2. MDASH routes confirmed issues into Microsoft Defender workflows and engineering remediation pipelines.
  3. Defender discovers 25+ local AI agents and MCP servers on Windows and macOS.
  4. Runtime blocking stops prompt-injection attacks against coding agents before malicious actions execute.
  5. Advanced Hunting enables investigation of AI agent exposure across the environment.
  6. Microsoft Entra Backup and Recovery is GA with Microsoft-managed, tamper-protected backups.
  7. Entra restores directory objects to timestamps, compares changes, and protects against permanent deletion.
  8. Defender for Cloud adds GA threat protection for open-source databases on AWS RDS.
  9. Multicloud coverage expands with ~90 new resource types and 200+ new recommendations.
  10. Unified identity risk score correlates cross-product signals and can trigger Conditional Access automatically.

TAKEAWAYS:

  1. Agentic vulnerability scanning can close the loop from discovery through validated remediation.
  2. Endpoint security must recognize and defend local AI agents and their runtime behaviors.
  3. Identity resilience improves with immutable backups and rapid tenant recovery capabilities.
  4. Multicloud database and resource visibility strengthens posture management and prioritization at scale.
  5. Explainable identity risk scoring enables faster triage and automated access enforcement.