Microsoft’s July 2026 security updates put AI agents at the center of both the threat model and the defense model, with new Microsoft Defender, Entra, Purview, and Intune capabilities aimed at reducing exposure from Copilot, cloud agents, unmanaged AI apps, and compromised identities.
As detailed in Microsoft’s July In the Loop security roundup, the headline is Project Perception, a newly announced system of coordinated red-, blue-, and green-team agents. Microsoft describes it as an autonomous security workflow in which offensive agents identify weaknesses, defensive agents investigate threats, and hardening agents remediate findings in continuous cycles. It is an ambitious vision, though organizations will want to distinguish the announcement from features that are actually available in their tenants today.

Neon cybersecurity dashboard with three AI robots monitoring threats, authentication, cloud systems, and networks.Defender Moves Upstream Into AI Prompts​

The most immediately relevant preview is new prompt-injection protection in Microsoft Defender for Office 365. Microsoft says it can identify and isolate email messages carrying malicious AI instructions before delivery, targeting a growing risk where an attacker embeds commands intended for an employee’s AI assistant rather than for the employee directly.
Defender is also gaining unified posture-management and runtime protection for agents built in Microsoft Foundry and Microsoft Copilot Studio, as well as third-party managed agents through Microsoft Agent 365. For security operations teams, the practical promise is a single view of agent configuration risk and suspicious runtime behavior rather than separate controls for each AI platform.
Microsoft is also converging Defender Threat Intelligence experiences and expanding its Threat Intelligence Agent. The intended result is less manual pivoting between intelligence summaries and investigation actions inside the unified Defender portal.

Cloud Containers and Compromised Accounts Get More Attention​

Microsoft Defender for Cloud is extending Cloud Security Posture Management coverage to serverless containers running on Azure Container Apps, Azure Container Instances, and Amazon ECS on Fargate. That matters for Windows-focused enterprises that are increasingly responsible for mixed cloud estates: security ownership rarely stops at Azure, even where Windows and Microsoft 365 remain the core platforms.
The company is also linking Defender and Microsoft Entra more closely so SOC analysts can disable a compromised identity from the security workflow while retaining role-based, least-privilege controls. This should reduce the handoff between an analyst who detects an account takeover and an identity administrator who has authority to stop it.
Microsoft Defender Experts is expanding as well. Defender Experts Threat Intelligence is positioned as a human-curated service for organization-specific threat insight, while Defender Experts MDR is extending managed detection and response beyond Microsoft signals through Microsoft Sentinel and third-party or multicloud telemetry.

Entra’s Passkey Transition Has a Firm Deadline​

Microsoft Entra ID is making passkeys its default authentication experience as it prepares to retire Microsoft-provided SMS and voice authentication delivery. Microsoft’s Entra documentation sets two key dates: on September 1, 2026, affected SMS and voice users will be automatically enabled for passkeys; on February 1, 2027, tenants without a customer-managed telecom provider will no longer be able to use Microsoft-provided SMS or voice for MFA.
That is more than a product-default change. Administrators should identify users whose only usable MFA method is SMS or voice, test passkey registration campaigns, and decide whether a customer-managed telecom provider is needed for regulatory or operational exceptions. Microsoft says an opt-out will be available during the transition period, but not for the February 2027 enforcement.
Entra is also introducing tenant governance tools for discovering and governing tenants centrally, including cross-tenant delegated administration. That will be most relevant to large organizations with acquisitions, subsidiaries, or decentralized Microsoft 365 environments.

Purview Adds Controls for Copilot and Shadow AI​

Microsoft Purview’s new preview DLP policy for Microsoft 365 Copilot lets administrators exclude externally sent email from being used as grounding data for Copilot responses. The control is narrowly targeted but useful: external email threads can include confidential material, untrusted instructions, or information an organization does not want incorporated into AI-generated output.
Purview is also integrating with Microsoft Entra Internet Access to detect and block sensitive text and file uploads to unmanaged SaaS and AI applications. Microsoft is pitching the integration as a network-layer control for shadow AI—a way to prevent a user from pasting customer data into an unapproved AI service before the information leaves the organization.
For insider-risk teams, a redesigned Purview alert experience combines classic alerts with Data Security Triage Agent findings. Microsoft says the agent’s advanced reasoning layer is now generally available and can analyze user, device, and data signals in multiple steps to prioritize cases worth investigation.

Intune Suite Features Land in E3 and E5​

For endpoint administrators, the clearest licensing change is already in effect: as of July 1, Microsoft has distributed Intune Suite capabilities across Microsoft 365 tiers. Microsoft 365 E3 now includes Intune Plan 2, Remote Help, and Advanced Analytics; Microsoft 365 E5 and E7 add Endpoint Privilege Management, Microsoft Cloud PKI, and Enterprise Application Management.
That expansion could materially change endpoint-management planning for organizations that previously treated Intune Suite as a separate add-on. The immediate task is to review which capabilities are now available in the tenant, then prioritize controls that remove standing local-admin rights and modernize certificate management—two foundations that matter well beyond Microsoft’s current AI narrative.

References​

  1. Primary source: Microsoft
    Published: 2026-07-30T16:00:00+00:00
  2. Related coverage: learn.microsoft.com