Resolve syncing conflicts from repo_sync_working_branch to public - #545
Resolve syncing conflicts from repo_sync_working_branch to public#545learn-build-service-prod[bot] wants to merge 775 commits into
Conversation
|
Learn Build status updates of commit 8332df8: ❌ Validation status: errorsPlease follow instructions here which may help to resolve issue.
For more details, please refer to the build report. Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them. |
|
Learn Build status updates of commit 9d5111c: ❌ Validation status: errorsPlease follow instructions here which may help to resolve issue.
For more details, please refer to the build report. Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them. |
|
Learn Build status updates of commit b346756: ❌ Validation status: errorsPlease follow instructions here which may help to resolve issue.
For more details, please refer to the build report. Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them. |
|
Learn Build status updates of commit a821c60: ❌ Validation status: errorsPlease follow instructions here which may help to resolve issue.
For more details, please refer to the build report. Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them. |
|
Learn Build status updates of commit 62701cf: ❌ Validation status: errorsPlease follow instructions here which may help to resolve issue.
For more details, please refer to the build report. Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them. |
|
Learn Build status updates of commit 55d87da: ❌ Validation status: errorsPlease follow instructions here which may help to resolve issue.
For more details, please refer to the build report. Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them. |
|
Learn Build status updates of commit f1d192e: ❌ Validation status: errorsPlease follow instructions here which may help to resolve issue.
For more details, please refer to the build report. Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them. |
|
Learn Build status updates of commit 668adfe: ❌ Validation status: errorsPlease follow instructions here which may help to resolve issue.
For more details, please refer to the build report. Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them. |
|
Learn Build status updates of commit a3973e4: ❌ Validation status: errorsPlease follow instructions here which may help to resolve issue.
For more details, please refer to the build report. Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them. |
|
Learn Build status updates of commit 901cb16: ❌ Validation status: errorsPlease follow instructions here which may help to resolve issue.
For more details, please refer to the build report. Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them. |
|
Learn Build status updates of commit 3658fe6: ❌ Validation status: errorsPlease follow instructions here which may help to resolve issue.
For more details, please refer to the build report. Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them. |
|
Learn Build status updates of commit 3715a56: ❌ Validation status: errorsPlease follow instructions here which may help to resolve issue.
For more details, please refer to the build report. Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them. |
|
Learn Build status updates of commit 498e5ff: ❌ Validation status: errorsPlease follow instructions here which may help to resolve issue.
For more details, please refer to the build report. Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them. |
|
Learn Build status updates of commit 3aa8717: ❌ Validation status: errorsPlease follow instructions here which may help to resolve issue.
For more details, please refer to the build report. Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them. |
* (AzureCXP) fixes MicrosoftDocs/defender-docs-pr#549432 I corrected the data types in the Submit or Update Indicator API by updating rbacGroupNames to String[] and generateAlert to Boolean to ensure accuracy and consistency. * Replace en dash with hyphen in 400 Bad Request response line Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 1606676c-58df-462d-8963-e12c68ae8080 --------- Co-authored-by: Paul Inbar <54644589+paulinbar@users.noreply.github.com> Co-authored-by: Chris Davis <chris.davis@microsoft.com> Copilot-Session: 1606676c-58df-462d-8963-e12c68ae8080
* Learn Editor: Update run-advanced-query-api.md * Learn Editor: Update run-advanced-query-api.md * Copy edit advanced hunting API retirement notice Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 1606676c-58df-462d-8963-e12c68ae8080 --------- Co-authored-by: Chris Davis <chris.davis@microsoft.com> Copilot-Session: 1606676c-58df-462d-8963-e12c68ae8080
…ation issue. (#6525) * Clarify operations in troubleshooting mode for macOS * Refine troubleshooting mode clarification wording Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 1606676c-58df-462d-8963-e12c68ae8080 --------- Co-authored-by: Chris Davis <chris.davis@microsoft.com> Copilot-Session: 1606676c-58df-462d-8963-e12c68ae8080
* Fix formatting in respond-machine-alerts.md Remove ) to fix format. * Update process path example in isolation exclusions C:\Windows\System\Notepad.exe is used legacy system, but it doesn't exist on latest Win11 device, * Delete broken anker * Fix typo in advanced hunting documentation --------- Co-authored-by: Chris Davis <chris.davis@microsoft.com>
* Learn Editor: Update device-control-policies.md * Learn Editor: Update device-control-policies.md * Remove stray duplicate front matter block and tidy ComputerSid note Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 1606676c-58df-462d-8963-e12c68ae8080 --------- Co-authored-by: Chris Davis <chris.davis@microsoft.com> Copilot-Session: 1606676c-58df-462d-8963-e12c68ae8080
Corrected the domain format for US government devices.
* Update iOS installation instructions for Defender Clarified enrollment requirements for iOS users regarding the Company Portal app and Just-In-Time registration. * Fix JIT registration link, product name, and typo in iOS install prerequisites Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 1606676c-58df-462d-8963-e12c68ae8080 --------- Co-authored-by: Chris Davis <chris.davis@microsoft.com> Copilot-Session: 1606676c-58df-462d-8963-e12c68ae8080
* Update RBAC model reference in documentation * Remove obsolete preview NOTE superseded by GA IMPORTANT callout The preview-framed NOTE describing Unified RBAC as a new opt-in experience is outdated. The following IMPORTANT callout states URBAC is GA and the only option for new Defender for Endpoint customers as of February 16, 2025. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 1606676c-58df-462d-8963-e12c68ae8080 --------- Co-authored-by: Chris Davis <chris.davis@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 1606676c-58df-462d-8963-e12c68ae8080
* Update command for background file download * Remove space before '-auto' in command examples * Change HTTP response status from 200 to 201
* Update live-response.md Adding note about limit in US GOV cloud * Refine US Government library upload limit note Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 1606676c-58df-462d-8963-e12c68ae8080 * Update metadata in live-response.md --------- Co-authored-by: Chris Davis <chris.davis@microsoft.com> Copilot-Session: 1606676c-58df-462d-8963-e12c68ae8080
* Remove SAP data connector agent guidance and links Delete agent-only reference/update articles; rename Connect page to deploy-data-connector-agentless.md; strip connection-agent zone pivots and zone_pivot_groups front matter from all dual-mode pages; rewrite stop-collection.md for the agentless connector; drop the deprecated agent tab from deployment-overview.md; sweep inbound links across the sentinel docs. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 813c3c2f-81b5-4ca1-9e2d-1808779079ff * Fix build warnings and remove XAL RFC entries from function reference - Add redirects for 6 deleted agent guidance files to the renamed agentless deploy article. - Drop XAL-only BAPI/RFC entries (BAPI_XMI_LOGON, BAPI_SYSTEM_MTE_*, BAPI_XMI_SET_AUDITLEVEL, BAPI_XMI_GET_LOGHISTORY, TH_SERVER_LIST) from the Sentinel solution KQL function reference; those are SAP RFC modules, not Sentinel workspace functions. - Repair broken bookmarks flagged by the Learn build: drop the removed container-log anchor in monitor-sap-system-health, remove the stale Agent name field, add an abap-security-audit-log anchor in the log reference, and drop dead intra-page fragments in sap-suspicious-configuration-security-parameters. - Bump ms.date and add ai-usage: ai-assisted on touched files. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 813c3c2f-81b5-4ca1-9e2d-1808779079ff * Rewrite SAP system health monitoring for the agentless connector - Drop the video demo that walks through the old agent flow. - Rework the connector-page procedure so it no longer scopes itself to the agent and no longer references the collector-agent configuration step. - Replace the Custom logs guidance with the standard Log Analytics tables the agentless connector streams to (ABAPAuditLog, ABAPAuthorizationDetails, ABAPChangeDocsLog, ABAPUserDetails). - Retire agent-specific phrasing in the alert-rule template section. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 813c3c2f-81b5-4ca1-9e2d-1808779079ff * Keep the agent deprecation notice only on the deployment overview Remove the data-connector-agent-deprecation include from the agentless connect article, the migration guide, and the troubleshooting article so the notice no longer suggests the agentless connector is deprecated. The overview still surfaces the notice. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 813c3c2f-81b5-4ca1-9e2d-1808779079ff * List the SAP BTP solution under extra deployment options Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 813c3c2f-81b5-4ca1-9e2d-1808779079ff * Merge upstream: include force-sal-filesystem in remediation lever list Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 813c3c2f-81b5-4ca1-9e2d-1808779079ff * Drop the preview callout from the SAP log and table reference Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 813c3c2f-81b5-4ca1-9e2d-1808779079ff * Restore ICF service handlers rule and link to community extensions Cherry-pick the audit-log-based 'SAP - New ICF Service Handlers' rule back into the Persistency table. Add a note under the analytics rules pointing to the Azure-Samples/Sentinel-For-SAP-Community solution for detections that depend on data sources the agentless connector doesn't stream (Spool, Change Requests, Table Data Log, AS Java). Community tracking issue: Azure-Samples/Sentinel-For-SAP-Community#12 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 813c3c2f-81b5-4ca1-9e2d-1808779079ff * Drop deletion CR note and rework SAP health/role guidance for agentless - stop-collection.md: remove the NPLK900259 deletion CR paragraph (agentless installs no CR to remove). - monitor-sap-system-health.md: rewrite the 'Check your SAP data connector's health and connectivity' section since the agentless connector page no longer shows a per-SID health table. Point readers to the SAPSystems KQL function for system role and to the SentinelHealth table for health signals; update the value tables to match. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 813c3c2f-81b5-4ca1-9e2d-1808779079ff * Drop preview note and collapse single-bullet prereq to a paragraph Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 813c3c2f-81b5-4ca1-9e2d-1808779079ff * Remove cross-workspace feature sections from SAP docs - Delete sentinel/sap/cross-workspace.md (multi-workspace feature not applicable to the agentless SAP data connector). - deploy-sap-security-content.md: drop the 'Some of the data is on a different workspace' step, the multi-workspace screenshot, and the follow-up TIP. - sap-audit-log-workbook.md: drop the IMPORTANT note about hosting the workbook on a different SOC workspace. - TOC.yml: remove the 'Integrate SAP across multiple workspaces' entry. - Add a redirect from the deleted cross-workspace.md to deployment-overview.md. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 813c3c2f-81b5-4ca1-9e2d-1808779079ff * Note cross-workspace removal in the SAP agent migration guide Add a short NOTE explaining that the cross-workspace deployment is no longer needed with the unified workspace in the Defender portal and has been removed from the UI. ARM APIs still support it for customers who need the split. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 813c3c2f-81b5-4ca1-9e2d-1808779079ff * user md default value fix --------- Copilot-Session: 813c3c2f-81b5-4ca1-9e2d-1808779079ff
* new ueba anomolies page in sentinel * new pages for each function anomalies * fixing bug * warnings * warnings * added preview to toc * Fix cross-docset UEBA links * saras feedback * added return value to AH pages * added example * fix * fix * release note * release note for ueba anomalies on behaviors * removing duplicate
Recreates the release-note update submitted by Kurt Sarens in #568. Co-authored-by: Kurt Sarens <ksarens@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 7d5b1992-f2f7-4d5d-81eb-15ecd2e9493d
Auto Publish – main to live - 2026-08-05 17:30 UTC
|
Learn Build status updates of commit 4d5183f: ❌ Validation status: errorsPlease follow instructions here which may help to resolve issue.
For more details, please refer to the build report. Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them. |
* Document Sentinel scoping and split prerequisites Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 29a360d4-c8d2-4d7b-907f-feeb3727fa33 * Consolidate split transformation prerequisites Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 48a8a460-d3e6-4a8b-9c74-115ba14a9844 * Fix documentation review blockers Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 176f1924-f9ab-4a87-b846-1028f2a5df07 * Fix Sentinel cross-docset link Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 176f1924-f9ab-4a87-b846-1028f2a5df07 * Add lightboxes to Sentinel scoping images Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 29a360d4-c8d2-4d7b-907f-feeb3727fa33 Copilot-Session: 48a8a460-d3e6-4a8b-9c74-115ba14a9844 Copilot-Session: 176f1924-f9ab-4a87-b846-1028f2a5df07
* Update anti-spam-bulk-complaint-level-bcl-about.md GA updates * Update anti-spam-bulk-complaint-level-bcl-about.md Minor updates * Update mail flow rule instructions for promotions tag @chrisda please review * Update anti-spam-bulk-complaint-level-bcl-about.md * Update anti-spam-bulk-complaint-level-bcl-about.md * Update anti-spam-bulk-complaint-level-bcl-about.md * Updates before publish * Update anti-spam-bulk-complaint-level-bcl-about.md * Clarify rollout note for bulk mail features @chrisda added this to the most reasonable place i could think of...please let me know if it aligns with you * Update anti-spam-bulk-complaint-level-bcl-about.md * Update anti-spam-bulk-complaint-level-bcl-about.md --------- Co-authored-by: faoquong <61523250+faoquong@users.noreply.github.com>
…#8945) * GA rename: Threat Hunting Assistant * GA rename: Threat Hunting Assistant * GA rename: Threat Hunting Assistant * GA rename: Threat Hunting Assistant * GA rename: Threat Hunting Assistant * GA rename: Threat Hunting Assistant * GA rename: Threat Hunting Assistant * GA rename: Threat Hunting Assistant * GA rename: Threat Hunting Assistant * GA rename: Threat Hunting Assistant * GA rename: Threat Hunting Assistant * GA rename: Threat Hunting Assistant * GA rename: Threat Hunting Assistant * Remove article renamed to Threat Hunting Assistant * Replace static table list with discovery-based description * Add schema-aware discovery and iterative refinement capabilities
Auto Publish – main to live - 2026-08-05 22:38 UTC
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…alware-scanning-1784819793 Update introduction-malware-scanning.md
…torage-introduct-1784819635 Update defender-for-storage-introduction.md
…pdate-clean Update ServiceNow connector guidance
Auto Publish – main to live - 2026-08-06 12:30 UTC
|
Learn Build status updates of commit e0615e8: ❌ Validation status: errorsPlease follow instructions here which may help to resolve issue.
For more details, please refer to the build report. Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them. |
* Add July 2026 Defender Antivirus release Recreates the release-note update submitted by Kurt Sarens in #568. Co-authored-by: Kurt Sarens <ksarens@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 7d5b1992-f2f7-4d5d-81eb-15ecd2e9493d * Update prompt-injection-protection-defender-for-office-365.md MDO P2 only --------- Copilot-Session: 7d5b1992-f2f7-4d5d-81eb-15ecd2e9493d
* Learn Editor: Update on-demand-malware-scanning.md * Learn Editor: Update on-demand-malware-scanning.md * Learn Editor: Update on-demand-malware-scanning.md * Learn Editor: Update on-demand-malware-scanning.md * Learn Editor: Update on-demand-malware-scanning.md * Learn Editor: Update on-demand-malware-scanning.md * Learn Editor: Update on-demand-malware-scanning.md * Fix formatting in on-demand malware scanning documentation
Auto Publish – main to live - 2026-08-06 17:30 UTC
|
Learn Build status updates of commit 45a6f8f: ❌ Validation status: errorsPlease follow instructions here which may help to resolve issue.
For more details, please refer to the build report. Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them. |
* Refactor Defender CLI installation and command usage Updated command syntax for Defender CLI installation and usage across platforms, including Windows, macOS, and Linux. Improved clarity by consolidating macOS instructions and correcting command usage. * Change PowerShell commands to Bash in defender-cli.md Updated command syntax from PowerShell to Bash for consistency and clarity. * Update section headings and command syntax in docs * Revise Defender CLI scan and job management instructions Updated the Defender CLI documentation to clarify scan submission and job management commands, including async scans and filtering by severity. * Update ai-code-security-overview.md * Revise release date and update language support details Updated the release date and refined the language support section to focus on specific programming languages. * Change code blocks to PowerShell syntax Updated code blocks to use PowerShell syntax highlighting instead of Bash. * Fix installation instructions and command syntax for Defender CLI Corrected the installation section and updated command syntax for the Defender CLI. Clarified usage examples for scanning and job management. * Fix typo in 'Install Defender CLI' section * Fix command syntax for Defender CLI usage Updated command syntax from '.\defender' to './defender' for consistency across platforms. * Update commands for Windows in defender-cli.md * Update installation instructions for Defender CLI
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Auto Publish – main to live - 2026-08-06 22:30 UTC
|
Learn Build status updates of commit 43d2cc1: ❌ Validation status: errorsPlease follow instructions here which may help to resolve issue.
For more details, please refer to the build report. Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them. |
* Docs: soft rebrand Defender XDR → Defender (batch 612-6) (#8027) * Docs: soft rebrand Defender XDR → Defender (batch 612-6) Replace 'Microsoft Defender XDR' with 'Microsoft Defender' and 'Defender XDR' with 'Defender' in body text, titles, descriptions, headings, and link display text across 20 files. Protected references (metadata, includes, UI navigation, image alt text, detection source names, acronym definitions, XDR detection engine names) are preserved. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Roll back changes. Updated the document to reflect the rebranding of Microsoft Defender to Microsoft Defender XDR. * Roll back changes. * Roll back changes. * Roll back changes. * Roll back changes. * Roll back changes. * Roll back changes. * Roll back changes. * Roll back changes. * Roll back Changes. * Roll back changes. * Roll back changes. * Roll back changes. * Roll back changes. * Roll back changes. * Roll back changes. * Roll back changes. * Fix conflict. --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: Chris Davis <chris.davis@microsoft.com> * Confirm merge from repo_sync_working_branch to main to sync with https://github.com/MicrosoftDocs/defender-docs (branch public) (#7591) * Add custom graph cost management link in graph charges section * Update mdb-faq.yml Updating public documentation because numerous support cases have been opened due to documentation being unclear. Government customers are not included in this section and should be clarified for customers when trying to understand what licensing is required. * Initialize Docs repository: https://github.com/MicrosoftDocs/defender-docs-pr of branch live * Merge for Defender deployment tool GA announcement (#8099) * Selective Response Actions: update from preview to GA - Remove (preview) tag from article title - Remove (preview) from link in defender-deployment-tool-windows.md - Add GA entry in June 2026 section of whats-new article - Update ms.date in both articles Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Deleted preview references, got rid of current ga behavior. * Mentioned the zip / exe choice * Added what's new entry * Updated date * Updated date * Enhance Sentinel graph visualization documentation (#7904) * Enhance Sentinel graph visualization documentation Clarified permissions for accessing Sentinel graphs and added details on query editor functionality. Expanded on graph visualization options and configuration settings for better user guidance. * Fix formatting and enhance graph visualization section * Update graph-visualization.md * docauthoring:copy/edit updates * updates * fix --------- Co-authored-by: EdB-MSFT <105771311+EdB-MSFT@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: Danielle Dennis <dandennis@microsoft.com> Co-authored-by: EdB-MSFT <105771311+EdB-MSFT@users.noreply.github.com> Co-authored-by: prmerger-automator[bot] <40007230+prmerger-automator[bot]@users.noreply.github.com> * Fix attack disruption docs: simplify TOC title and table entries (#525) - Shorten TOC entry from 'Attack disruption with Microsoft Sentinel' to 'Attack disruption' - Remove redundant '(through Microsoft Sentinel integration)' from Okta and AWS IAM identity service names - Move Microsoft Sentinel mention to Okta link text for clarity Co-authored-by: Ofer Schreiber <ofer@bigpanda.io> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Update advanced-hunting-emailattachmentinfo-table.md (#307) Describing "FileType" as "File extension type" is misleading and can make people think of the file's extension (e.g. `.exe`) while the field is actually a file content type (e.g. `txt;text` or `email;mime` or `png`). Co-authored-by: Tami Fosmark <v-tamif@microsoft.com> * Update advanced-hunting-take-action.md with query reference (#406) * Update advanced-hunting-take-action.md with query reference Added Kusto query reference for enabling 'Submit to Microsoft' and 'Initiate automated investigation'. To make it more clear after it was raised in the community * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --------- Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com> Co-authored-by: Paul Oliveria <pauloliveria@microsoft.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Update manage-event-based-updates-microsoft-defender-antivirus.md (#345) Co-authored-by: Tami Fosmark <v-tamif@microsoft.com> * Update with the correct GPO setting name (#365) Co-authored-by: Tami Fosmark <v-tamif@microsoft.com> * MDB: Update references to the onboarding (#377) * fix: MDB, update onboarding, rename MAM to WIP Azure Portal has slowly but progressively been moved to Entra admin center: Update the URL and the actual naming in the portal. MAM isn't mentioned it seems to be replaced by Windows Information Protection in the same screen. * fix: Further replace MAM occurrences by WIP MAM wording has been removed from both the old Azure portal, as well as in Entra admin center. * fix: MDB, add updated screenshot MDM and WIP user scopes While the structure is mostly unchanged, add new screenshot that includes current namings and same design of selector / radio buttons. * MDB: Include updated screenshot Include updated screenshot and update description of the picture. * MDB: Delete old screenshot of MEM/MAM user scope settings New picture was added with new name, this one is now obsolete. --------- Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com> * Change MDEConfig.txt to DefenderDTconfig.txt (#418) "DefenderDT.exe -makeconfig" crates a file named DefenderDTconfig.txt instead of MDEConfig.txt Co-authored-by: Tami Fosmark <v-tamif@microsoft.com> Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com> * Update configure-network-connections-microsoft-defender-antivirus.md (#448) Fixing broken link for https://learn.microsoft.com/en-us/windows/privacy/manage-windows-1709-endpoints#windows-update No longer works because of ham-fisted MS redirects. * Update advanced-hunting-microsoft-defender.md (#343) Add to "known Issues": When creating a new Microsoft Sentinel function in Log Analytics, there is a delay of up to 20 minutes until it appears in Advanced Hunting. Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com> * Fix grammar in Teams block entry instructions (#496) * Fix grammar in Teams block entry instructions Blocking a domain does not block the Teams meeting invitation itself. Blocking a domain will remove the user from the Teams meeting chat after the meeting ends. The current documentation (Teams Meetings) may be misleading as to suggest that it affects all meetings. * Fix grammar in Teams block entry instructions Corrected grammatical errors in the block entry explanation. --------- Co-authored-by: Chris Davis <chris.davis@microsoft.com> * Clarify instructions for running Client Analyzer shipped version (#498) * Clarify instructions for running Client Analyzer shipped version in live response Adjust the format which is clearer for binary version and python version separately. * Update run-analyzer-linux.md * Fix formatting and wording in run-analyzer-linux.md --------- Co-authored-by: Chris Davis <chris.davis@microsoft.com> * Update faqs-on-tamper-protection.yml (#532) Remove bracket so link properly connects to target URL * Update quarantine-shared-mailbox-messages.md (#528) * Update quarantine-shared-mailbox-messages.md Updated wording for clarity and expanded scope to include both shared and user mailboxes. * Update quarantine management instructions and date Updated the date for the document and refined the instructions for accessing quarantined messages in shared mailboxes. * Update shared mailbox quarantine management instructions Clarified that automapping is no longer required for managing quarantined messages in shared mailboxes. Updated conditions for accessing quarantined messages. --------- Co-authored-by: Chris Davis <chris.davis@microsoft.com> * Resolve syncing conflicts from repo_sync_working_branch to public (#529) * [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, 20260615-sentinel-guywi-ms-04) (#8059) * fix(COPY-EDIT): editorial Remediation for COPY-EDIT. Files affected: 10 Applied by AI Readiness Remediation Tool v1.0.0 Assessment source: assessment.csv * Fix fictional bookmarks AIRA created Removed redundant options for enabling UEBA and streamlined the text. * Remove bookmark to nonexistent content Removed redundant sentence in the UEBA documentation. --------- Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com> Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com> * Learn Editor: Update release-notes-recommendations-alerts.md * [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-f) [2/2] (#8088) * fix(COPY-EDIT): editorial Remediation for COPY-EDIT. Files affected: 9 Applied by AI Readiness Remediation Tool v1.0.0 Assessment source: assessment.csv * Fix metadata for PIM in MDO configuration document * Fix metadata for safe attachments configuration doc * Update ms.custom metadata in documentation * Fix formatting in submissions admin review document * Fix formatting for ms.custom in documentation --------- Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com> Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com> * Learn Editor: Update sql-azure-vulnerability-assessment-overview.md * [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, 20260615-sentinel-guywi-ms-06) (#8061) * fix(COPY-EDIT): editorial Remediation for COPY-EDIT. Files affected: 10 Applied by AI Readiness Remediation Tool v1.0.0 Assessment source: assessment.csv * Fix bad AIRA edit Updated section header from 'Next steps' to 'Next step'. --------- Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com> Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com> * [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, b5) (#8096) * fix(COPY-EDIT): editorial Remediation for COPY-EDIT. Files affected: 4 Applied by AI Readiness Remediation Tool v1.0.0 Assessment source: assessment.csv * Fix formatting of ms.custom metadata in document --------- Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com> Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com> * fix(COPY-EDIT): editorial (#8060) Remediation for COPY-EDIT. Files affected: 10 Applied by AI Readiness Remediation Tool v1.0.0 Assessment source: assessment.csv Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com> Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com> * fix(COPY-EDIT): editorial (#8062) Remediation for COPY-EDIT. Files affected: 10 Applied by AI Readiness Remediation Tool v1.0.0 Assessment source: assessment.csv Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com> Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com> * fix(COPY-EDIT): batch (#8072) Remediation for COPY-EDIT. Files affected: 1 Applied by AI Readiness Remediation Tool v1.0.0 Assessment source: assessment.csv Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com> Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com> * fix(COPY-EDIT): editorial (#8095) Remediation for COPY-EDIT. Files affected: 10 Applied by AI Readiness Remediation Tool v1.0.0 Assessment source: assessment.csv Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com> Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com> * Clarify that the Risky IP address category is dynamic (#8198) * Clarify that the Risky IP category is dynamic and can expire Add a note explaining that the Risky category is assigned automatically based on threat intelligence and is removed if no further malicious activity is detected. All other categories are assigned manually. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Apply suggestions from code review Co-authored-by: AbbyMSFT <88824859+AbbyMSFT@users.noreply.github.com> * Apply suggestion from @AbbyMSFT * Apply suggestion from @AbbyMSFT --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: Regan Downer <v-rdowner@microsoft.com> * new onboarding (#7970) * new onboarding * updates * updates --------- Co-authored-by: Regan Downer <v-rdowner@microsoft.com> * [AIRA] Bot Remediation - mberdugo (defender-docs-pr, 20260615-usp-test8a-mberdugo) (#8077) * fix(COPY-EDIT): editorial Remediation for COPY-EDIT. Files affected: 4 Applied by AI Readiness Remediation Tool v1.0.0 Assessment source: assessment.csv * Remove AIRA-duplicated ai-usage metadata Removed 'ai-usage' line from the document header. --------- Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com> Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com> * Update approval functionality (#8303) * Update approval functionality (#8304) * docs(sentinel): add parameterized notebook jobs Adds overview and detailed guidance for parameterized notebook jobs. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Learn Editor: Update sql-azure-vulnerability-assessment-overview.md * WI591424: GA transition for serverless containers docs * Restore historical preview note and keep separate GA release note * Move June 25 GA note to top of table and section list * Document Registry access requirement for full Serverless Containers features * Update defender-for-cloud/release-notes.md * Update defender-for-cloud/release-notes.md * Mark Serverless Containers as supported in Defender portal * Move serverless containers GA date to July 1 * Place July 1 release note under July table * Set July 1 ms.date across remaining PR pages * Version 26.1.1 (#8316) * Version 26.1.1 * Fixes * Mapping updates to transition from grouped to individual recommendations (#8151) * Transition from grouped to individual recommendations * Update transition article with end-state classification for deprecated assessments - Add explanation of 3 end-states (dynamic substitute, static substitute, no substitute) - Add End-state and New assessment ID columns to all reference tables - Change 'NA (Static)' to 'Unknown' in Category column for static substitutes (EDR, SQL) - Mark EDR and SQL rows as static substitutes with [TBD] new assessment IDs - Fix HostMisconfiguration → HostMisconfigurations per category list - Mark GitHub security posture management row as [TBD] pending DevOps partner input - Add placeholder section for Microsoft Defender for Identity (pending partner review) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add July 31 deprecation date and clarify static substitute guidance - Add July 31, 2026 as the grouped recommendation deprecation date - Clarify that static substitute recommendations use 'Unknown' category and users should filter by assessment ID, not category filter Per meeting with Roy Hirsch (June 21, 2026) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Revert "Add July 31 deprecation date and clarify static substitute guidance" This reverts commit c4f487921093d967d968310ed5e2773e07cf3291. * Update grouped-to-individual recommendations article per Roy Hirsch review - Remove IcM routing column from all tables (internal-only, not customer-facing) - Fix ARG query field: securityCategories -> recommendationCategory - Fix category name: 'Vulnerabilities' -> 'SoftwareUpdate' recommendation category - Replace 'assessment key/ID' with 'recommendation ID' throughout - Replace 'grouped assessment' with 'grouped recommendation' throughout - Remove 'No substitute' end-state (deprecated items not included in this guide) - Split each product table into Dynamic substitutes and Static substitutes sections - Simplify table columns: Dynamic (Recommendation | Recommendation ID | Category), Static (Recommendation | Recommendation ID | New recommendation ID) - Remove IcM routing reference from intro tip and reference section Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Rename 'Recommendation category reference' to 'Recommendation transition reference' Section now covers both dynamic (category-based) and static (recommendation ID-based) transitions, so 'category reference' was no longer accurate. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add July 31 deprecation date to transition guides - Add July 31, 2026 deprecation date in transition-grouped-individual-recommendations.md (overview callout, adopting section, what you should do now callout) - Add July 31, 2026 deprecation date in transition-disable-rules-exemptions.md Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Update transition guide with Roy's final feedback - SQL databases/servers recs: mark as deprecated, replace static substitute table with note and link to full SQL recommendations reference - Containers: add Azure (c609cf0f) and AWS (682b2595) running container images as dynamic substitutes mapped to SoftwareUpdate - GitHub security posture mgmt (fd104c01): update [TBD] with link to full DevOps recommendations reference - Linux secure boot rec (ad50b498): not added (status unknown per Roy) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Fix SQL recommendations link to point to VA rules mapping article Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Replace internal substitute terms with plain descriptions Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Apply manual edits and re-apply terminology changes - Remove Secure Score row from comparison table - Update vulnerability management example description - Rename old query label and add note before new query - Remove Secure Score during transition section - Change EDR recs to deprecated recommendations - Replace Dynamic/Static substitute terms with plain descriptions Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Fix terminology: replace 'Dynamic substitutes' with 'Replaced by individual recommendations' in Containers and DevOps sections; fix garbled text and table in Servers deprecated section Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Apply suggestion from @DebLanger --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix files moved in error (#8310) * fix files moved in error * fixes * [AIRA] Bot Remediation - AbbyMSFT (defender-docs-pr, 20260615-dfi-root-b-r1) (#8073) * fix(COPY-EDIT): batch Remediation for COPY-EDIT. Files affected: 10 Applied by AI Readiness Remediation Tool v1.0.0 Assessment source: assessment.csv * Apply suggestion from @GitHubber17 Co-authored-by: Beth Harvey <v-bharve@microsoft.com> --------- Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com> Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com> Co-authored-by: Beth Harvey <v-bharve@microsoft.com> * [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, b3) (#8094) * fix(COPY-EDIT): editorial Remediation for COPY-EDIT. Files affected: 10 Applied by AI Readiness Remediation Tool v1.0.0 Assessment source: assessment.csv * Fix ms.custom field formatting in documentation --------- Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com> Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com> * fix(COPY-EDIT): batch (#8074) Remediation for COPY-EDIT. Files affected: 2 Applied by AI Readiness Remediation Tool v1.0.0 Assessment source: assessment.csv Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com> Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com> * Restructure MDA TOC around customer journey (#7505) * Restructure MDA TOC around customer journey Reorganize from feature-based sections to a lifecycle flow: Deploy > Connect and discover > Assess risk > Control and protect > Detect threats > Investigate and respond > Stream to SIEM > Manage Key changes: - Dissolve app governance silo into relevant phases - Merge 'View and manage applications' into discovery - Merge 'Information protection' into 'Control access and protect data' - Move AI agent protection into discovery section - Rename SIEM section to clarify outbound direction - Move operations guide into 'Manage and configure' Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Rename section to 'Investigate and respond to threats' Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add PR target instruction to copilot-instructions.md Ensure PRs are always created against MicrosoftDocs/defender-docs-pr rather than the fork. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Move app governance setup articles to appropriate sections - 'Turn on app governance' moves into Configuration (it's a config task) - 'Get started with app governance' moves into 'Discover and manage OAuth apps' (it's a product walkthrough, not deployment) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Apply content audit: move articles to correct lifecycle phases Based on full-content audit of 35 cross-cutting articles: Moved to 'Control access and protect data': - manage-app-permissions.md (renamed to 'Manage OAuth app permissions') - app-governance-visibility-insights-sensitive-content.md - governance-discovery.md - mde-govern.md - ai-agent-protection.md and real-time-agent-protection (AI agent protection) Moved to 'Investigate and respond to threats': - app-governance-anomaly-detection-alerts.md - app-governance-investigate-predefined-policies.md - tutorial-flow.md (response automation, not SIEM) Kept ai-agent-inventory.md in discovery (primary entry point). AI agent discovery stays in Connect and discover; protection moves to Control access. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Rename discovery sections for clarity - 'Discover cloud apps (shadow IT)' -> 'Discover cloud apps and shadow IT' - 'Discover and manage OAuth apps' -> 'Discover and manage OAuth apps with app governance' Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Restructure MDA TOC: split discover/connect, rename access section - Split 'Connect and discover apps' into separate 'Discover apps' and 'Connect apps' sections, with discovery first - Rename 'Control access and protect data' to 'Manage access and app behavior' Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Consolidate app governance articles and clarify OAuth app scope in titles - Flatten Connect apps TOC node (remove unnecessary intermediate level) - Consolidate app governance articles: - Merge policies overview + get-started + predefined into single overview - Merge policies create + manage into single create-and-manage article - Merge threat detection overview + get-started + monitor into single article - Merge visibility insights overview + get-started into single article - Update all app governance TOC nodes and article titles to include 'OAuth' to distinguish from SaaS app content - Add redirects for 6 deleted articles - Fix all internal links to deleted articles Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Fix broken links in index.yml to deleted articles Update references to consolidated app governance articles that were deleted upstream. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Resolve PR review blocking issues: typos, casing, and alt-text fixes - Fix 'polcies' typo in alt-text (app-policies-overview) - Add graphic-type prefix to two image alt-texts (app-policies-overview) - Lowercase 'app governance' in alt-text (detect-remediate-overview) - Remove duplicate 'the' (secure-apps-access-non-graph-api) - Lowercase three 'app governance' instances (anomaly-detection-alerts) - Title case 'Zero Trust' (index.yml) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix(COPY-EDIT): batch (#8075) Remediation for COPY-EDIT. Files affected: 6 Applied by AI Readiness Remediation Tool v1.0.0 Assessment source: assessment.csv Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com> Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com> * [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, 20260615-usp-test8a-guywi) (#8076) * fix(COPY-EDIT): editorial Remediation for COPY-EDIT. Files affected: 7 Applied by AI Readiness Remediation Tool v1.0.0 Assessment source: assessment.csv * Update section title and content in mto-requirements.md Renamed 'Next steps' section to 'Related content' and updated its content. --------- Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com> Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com> * fix(COPY-EDIT): editorial (#8078) Remediation for COPY-EDIT. Files affected: 8 Applied by AI Readiness Remediation Tool v1.0.0 Assessment source: assessment.csv Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com> Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com> * [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-b) (#8081) * fix(COPY-EDIT): editorial Remediation for COPY-EDIT. Files affected: 10 Applied by AI Readiness Remediation Tool v1.0.0 Assessment source: assessment.csv * Improve formatting of simulation automation steps Formatted the configuration steps into a bulleted list for better readability. * Update attack-simulation-training-training-campaigns.md * Apply suggestions from code review Co-authored-by: Beth Harvey <v-bharve@microsoft.com> * Update ms.custom metadata in connectors-remove-blocked.md * Refactor ms.custom metadata in documentation Updated ms.custom metadata to include a list format. * Update ms.custom formatting in documentation * Update ms.custom format in preset-security-policies.md * Update quarantine-admin-manage-messages-files.md * Fix formatting of ms.custom property in markdown * Update ms.custom metadata format in markdown file --------- Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com> Co-authored-by: Chris Davis <chris.davis@microsoft.com> Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com> Co-authored-by: Beth Harvey <v-bharve@microsoft.com> * WI590578-table-insights (#8265) * WI590578-table-insights * quality fixes * additional work * updated conceptual page * page quality fixes * Refine Table insights guidance and restore Data Lake terminology * Update manage-table-tiers-retention.md * fixes to instructions * Update manage-table-tiers-retention.md * quality fixes * fix * fix title * small fixes * small fixes * fix based on Nikita's comment actually I realized there is one more change when in Whats new section when you click on tables, you can see data sources in side drawer. * fixing broken list --------- Co-authored-by: Diana Richards <103777760+v-dirichards@users.noreply.github.com> * [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-d) (#8083) * fix(COPY-EDIT): editorial Remediation for COPY-EDIT. Files affected: 9 Applied by AI Readiness Remediation Tool v1.0.0 Assessment source: assessment.csv * Fix formatting for ms.custom in alert policies document * Fix formatting for ms.custom in audit log document * Fix formatting of ms.custom in documentation * Fix formatting in connection filter policies document * Fix formatting in connectors-detect-respond-to-compromise.md * Remove section for new Microsoft 365 administrators Removed unnecessary section for new Microsoft 365 administrators and related content. There were no links or anything of value. It was essentially an ad, and even that ad didn't link to anything. --------- Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com> Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com> * Document AI agent awareness for Entra ID service principals - Add Used by AI agents (Preview) column to NHI details table - Add Used by AI agents (Preview) stat to NHI insight cards - Add what's-new entry for AI agent visibility Work item: 591169 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Chrisda to Main (#8323) * Update attack-surface-reduction-rules-reference.md Removed 'might not be available in Intune' call-out for 'Block executable files from running unless they meet a prevalence, age, or trusted list criterion' * Update attack-surface-reduction-rules-overview.md Consistency updates * ASR rules report screenshot updates More data * Remove A3 from E3 gets MDO P1 refs Per request * Added Teams to report suspicious * Update outbound-spam-high-risk-delivery-pool-about.md Content VSO 591495 * [AIRA] Bot Remediation - dansimp (defender-docs-pr, d365-test8b-dansimp) (#8085) * fix(COPY-EDIT): editorial Remediation for COPY-EDIT. Files affected: 1 Applied by AI Readiness Remediation Tool v1.0.0 Assessment source: assessment.csv * Update email-analysis-investigations.md --------- Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com> Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com> * [AIRA] Bot Remediation - deniseb (defender-docs-pr, d365-test8b-deniseb) (#8086) * fix(COPY-EDIT): editorial Remediation for COPY-EDIT. Files affected: 1 Applied by AI Readiness Remediation Tool v1.0.0 Assessment source: assessment.csv * Update authorship information in documentation * Change section title to 'Related content' Updated section title and added related content links. --------- Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com> Co-authored-by: Denise Vangel-MSFT <deniseb@microsoft.com> Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com> * [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-f) [1/2] (#8087) * fix(COPY-EDIT): editorial Remediation for COPY-EDIT. Files affected: 10 Applied by AI Readiness Remediation Tool v1.0.0 Assessment source: assessment.csv * Apply suggestions from code review Co-authored-by: Beth Harvey <v-bharve@microsoft.com> * Fix formatting in air-report-false-positives-negatives.md --------- Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com> Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com> Co-authored-by: Beth Harvey <v-bharve@microsoft.com> * [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-e) [2/2] (#8090) * fix(COPY-EDIT): editorial Remediation for COPY-EDIT. Files affected: 8 Applied by AI Readiness Remediation Tool v1.0.0 Assessment source: assessment.csv * Apply suggestions from code review Co-authored-by: Beth Harvey <v-bharve@microsoft.com> * Apply suggestion from @GitHubber17 Co-authored-by: Beth Harvey <v-bharve@microsoft.com> --------- Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com> Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com> Co-authored-by: Beth Harvey <v-bharve@microsoft.com> * [AIRA] Bot Remediation - unowned (defender-docs-pr, em-test8d) (#8091) * fix(COPY-EDIT): editorial Remediation for COPY-EDIT. Files affected: 2 Applied by AI Readiness Remediation Tool v1.0.0 Assessment source: assessment.csv * Apply suggestions from code review Co-authored-by: Beth Harvey <v-bharve@microsoft.com> --------- Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com> Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com> Co-authored-by: Beth Harvey <v-bharve@microsoft.com> * fix(COPY-EDIT): editorial (#8089) Remediation for COPY-EDIT. Files affected: 10 Applied by AI Readiness Remediation Tool v1.0.0 Assessment source: assessment.csv Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com> Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com> * CFA article updates (#8149) * Configure controlled folder access * Added Windows Security app procedures And removed them elsewhere * CFA overview article rename * CFA * CFA Overview * Delete customize-controlled-folders.md * Removed CFA article from MDB And also cleaned up ASR/ASR rule references and links, including any Intune procedure links. * Link and link title updates for CFA * Update address-unwanted-behaviors-mde.md * New monitor CFA article Remnants of the old evaluate CFA article + Windows event viewer steps/info from the CFA overview article. * Copy and Technical edits * CFA demonstrations * CFA demos * Update defender-endpoint-demonstration-attack-surface-reduction-rules.md * CFA/ASR demo updates * Update defender-endpoint-demonstration-attack-surface-reduction-rules.md * Final edits * Offending file name renames Per build report * [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-c) (#8082) * fix(COPY-EDIT): editorial Remediation for COPY-EDIT. Files affected: 10 Applied by AI Readiness Remediation Tool v1.0.0 Assessment source: assessment.csv * Update address-compromised-users-quickly.md * Fix formatting of ms.custom metadata in markdown * Fix formatting of custom metadata in markdown file * Correct 'ms.custom' formatting in documentation Fixed formatting of the 'ms.custom' metadata entry. * Update custom metadata in mdo-portal-permissions.md --------- Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com> Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com> * fix(COPY-EDIT): editorial (#8053) Remediation for COPY-EDIT. Files affected: 10 Applied by AI Readiness Remediation Tool v1.0.0 Assessment source: assessment.csv Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com> Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com> * docs(sentinel): add parameterized notebook job guidance Add steps for defining notebook parameters, refreshing job parameters, and overriding values when running a notebook job manually. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Docs: soft rebrand Defender XDR → Defender (batch 11) - NEW SERIES, IGNORE BATCH NUMBER (#7939) * Docs: soft rebrand Defender XDR to Defender (batch 11) Replace 'Defender XDR' and 'Microsoft Defender XDR' with 'Defender' and 'Microsoft Defender' in body text of 20 advanced hunting schema and feature articles, per Microsoft Defender branding guidelines. Preserved unchanged: - appliesto metadata fields - [!INCLUDE references - ms.service and other metadata fields - Link display text referencing external page titles - URL paths and fragments Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Roll back changes. * Roll back change. Updated description to specify Microsoft Defender XDR. --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: Paul Oliveria <pauloliveria@microsoft.com> * Docs: soft rebrand Defender XDR → Defender (batch 612-2) (#8016) * Docs: soft rebrand Defender XDR → Defender (batch 612-2) Update 18 advanced hunting files to replace 'Defender XDR' and 'Microsoft Defender XDR' with 'Defender' and 'Microsoft Defender' in body text per branding guidelines. Protected references (metadata, includes, API names, historical records, plugin names) are left unchanged. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Roll back change. * Roll back change. * Roll back change. Updated the description to include 'XDR' in the title. * Roll back change. * Roll back changes. Updated references to Microsoft Defender XDR in the document. * Roll back changes. Updated references from Microsoft Defender for Endpoint to Microsoft Defender XDR in the migration guide. * Roll back changes. * Roll back changes. Updated title and references to reflect Microsoft Defender XDR. --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: Paul Oliveria <pauloliveria@microsoft.com> * Docs: soft rebrand Defender XDR → Defender (batch 612-9) (#8030) * Docs: soft rebrand Defender XDR → Defender (batch 612-9) Replace 'Microsoft Defender XDR' with 'Microsoft Defender' and 'Defender XDR' with 'Defender' in body text, titles, descriptions, headings, and link display text across 10 files. 1 file had no eligible changes (all XDR refs were protected product names). Protected references preserved: metadata fields, [!INCLUDE] lines, image alt text, historical changelog entries in whats-new.md, API endpoint names, external blog post titles, 'Defender Experts for XDR' product name, XDR capability descriptions (XDR solution, XDR tools, XDR/SIEM). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Roll back changes. * Roll back changes. * Roll back changes. Updated the document to reflect the rebranding of Microsoft Defender to Microsoft Defender XDR, including changes to titles and descriptions throughout the content. * Roll back changes. * Roll back changes. * Roll back changes. * Fix typo in Microsoft Defender XDR description --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: Paul Oliveria <pauloliveria@microsoft.com> * Fix directory path and update checksum commands (#8334) Command errors caused by folder structure or incorrect quotation/space within a zip file. * Clarify prerequisites for attack disruption exclusions based on Unified RBAC state (#8276) Split the Prerequisites section into Device and Identity exclusion permissions, showing the required roles when Unified RBAC is enabled versus disabled. Cross-link to Unified RBAC activation and custom permissions docs. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Fix attack disruption docs: simplify TOC title and table entries (#8341) - Shorten TOC entry from 'Attack disruption with Microsoft Sentinel' to 'Attack disruption' - Remove redundant '(through Microsoft Sentinel integration)' from Okta and AWS IAM identity service names - Move Microsoft Sentinel mention to Okta link text for clarity Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Update value-data-connectors.md with onboarding notes (#8254) * Update value-data-connectors.md with onboarding notes Added note about device onboarding requirements and limitations. * Apply suggestion from @DebLanger * Update date and permissions in get-machines.md (#8344) Updated the date and permissions section in the API documentation. * wi-589516: Remove '| Microsoft Docs' suffix from title metadata (#8255) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> * Update email post delivery events documentation * Learn Editor: Update fixed-reported-inaccuracies.md (#8308) * DisruptionAndResponseEvents table in the advanced hunting schema - GA (#8354) * DisruptionAndResponseEvents table in the advanced hunting schema - GA * Updating what's new * Removing preview note * Docs: soft rebrand Defender XDR → Defender (batch 2) (#8191) * Docs: soft rebrand Defender XDR → Defender (batch 2) Replace 'Microsoft Defender XDR' with 'Microsoft Defender' and 'Defender XDR' with 'Defender' in eligible locations per branding guidelines. Files updated: - critical-asset-management.md (1 replacement) - get-started-exposure-management.md (4 replacements) - prerequisites.md (3 replacements) - whats-new.md (0 - all references in historical What's New entries) Preserved XDR references in: - Bold UI navigation paths (prerequisites.md line 67) - Historical What's New entries (whats-new.md lines 179, 310) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Roll back changes. * Roll back changes. --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Docs: soft rebrand Defender XDR → Defender (batch 13) (#7941) * docs: soft rebrand Defender XDR → Defender (batch 13) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * roll back change. --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Document Security findings (Preview) Azure Policy limitation in Defender for Containers (#8350) * Document Security findings (Preview) Azure Policy limitation in Defender for Containers - Add limitation note to Security findings (Preview) component in AKS, EKS, and GKE tabs stating it cannot be enabled through Azure Policy and must be toggled in plan Settings - Rename 'Security findings' to 'Security findings (Preview)' for accuracy - Remove 'This article explains' from opening line per style guide Addresses US585115 / IcM 662676555 / CxE WI 19929 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Apply suggestion from @DebLanger * Apply suggestion from @DebLanger * Apply suggestion from @DebLanger * Apply suggestion from @DebLanger * Apply suggestions from code review Co-authored-by: Deborah Langer <169067075+DebLanger@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add identity assessment key mappings to transition reference article (#8351) * Add identity assessment key mappings to transition reference article Replace placeholder in Microsoft Defender for Identity section with assessment key mapping table for 5 guest/disabled account assessments. Uses 'assessment' terminology per Roy's guidance. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Apply suggestion from @DebLanger --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix(COPY-EDIT): editorial (#8050) Remediation for COPY-EDIT. Files affected: 10 Applied by AI Readiness Remediation Tool v1.0.0 Assessment source: assessment.csv Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com> Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com> * fix(COPY-EDIT): editorial (#8048) Remediation for COPY-EDIT. Files affected: 7 Applied by AI Readiness Remediation Tool v1.0.0 Assessment source: assessment.csv Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com> Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com> * [AIRA] Bot Remediation - mberdugo (defender-docs-pr, 20260615-sentinel-mberdugo-02) (#8047) * fix(COPY-EDIT): editorial Remediation for COPY-EDIT. Files affected: 10 Applied by AI Readiness Remediation Tool v1.0.0 Assessment source: assessment.csv * Update section title from 'Next steps' to 'Related content' * Fix formatting of title in integration guide --------- Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com> Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com> * Cloud security reporting GA (#8267) * Cloud security reporting GA: remove preview, add release note and card customization - Remove (Preview) from title and H1 in cloud-security-reporting.md - Remove preview features prerequisite - Add card customization capability - Add June 30 GA release note entry Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add customize cards section with screenshots to cloud reporting article Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Clarify that card customization is only for cards labeled Customizable Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add migration guidance for Sentinel incident creation rules to Defender alert grouping (#7952) * Add Sentinel-to-Defender alert grouping migration guidance * Relocate Sentinel migration article to unified-secops docset * Update migration images and include restored xdr article copy * Remove duplicate defender-xdr migration article copy * Update image alt text for incident correlation migration doc * Fix validation issues for incident correlation migration docs * Fix broken migration link and update image references * israel review * Fix PR validation issues for links, metadata, and image naming * Fix broken unified secops migration links * Remove image from incident creation migration article * Remove unused onboarding image file * Fix broken cross-docset link to migrate-sentinel-incident-creation-rules-alert-grouping * Fix broken cross-docset link to migrate-sentinel-incident-creation-rules-alert-grouping * Revert to correct cross-docset URL link for new migrate-sentinel article * Revert to correct cross-docset URL link for new migrate-sentinel article --------- Co-authored-by: Guy Wild <98332688+guywi-ms@users.noreply.github.com> * Clarify DlpInfo description in deviceinfo table Updated DlpInfo description to clarify its content and added a reference link for further information. * GA multicloud recommendations June 30: release notes, score impact, new tag docs, reference updates (#8275) * Docs: GA multicloud recommendations June 30 - score impact, new tag, ref updates - Add June 30 GA release note for expanded multicloud coverage (~150 recommendations, ~90 resource types, score impact) - Add GA/Preview rows to recommendations release notes - Document 'New' tag (30-day window), change log, and portal banner in review-security-recommendations.md (both portal pivots) - Add Secure Score impact callout to secure-score-security-controls.md - Remove (Preview) from 217 multicloud recommendations across 6 reference files (networking, data, identity-access, app-services, compute, container) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Fix: restore deleted category tabs and select step in review-security-recommendations.md Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Apply suggestion from @DebLanger * Apply suggestion from @DebLanger * Apply suggestion from @DebLanger * Apply suggestion from @DebLanger * Apply suggestion from @DebLanger * Apply suggestion from @DebLanger * Apply suggestion from @DebLanger --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Fix DlpInfo reference link in deviceinfo-table.md Updated the reference link for DlpInfo properties to ensure it points to the correct documentation. * Add event-driven response guide for Defender for Storage malware scanning (#8345) - Expand Event Grid setup walkthrough in configure-malware-scan article with 3-step process - Add 3 Azure Functions templates: quarantine, auto-delete, and alert/notification - Add sample payloads for No threats found and Not Scanned result types - Add event delivery troubleshooting section covering permissions, networking, and subscription validation - Add Event-driven response feature bullet to introduction article Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Align identity risk score GA heading with what's-new convention Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add Widespread Local Admin predefined classification rules (#8289) * Add Widespread Local Admin classification rules and release note - Add three new Identity classification rules to predefined classifications: Widespread Local Admin on Servers (High), Widespread Local Admin on Workstations (High), and Widespread Local Admin on Servers and Workstations (Very High) - Add June 2026 release note entry for the new Identity classifications Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Reorder Widespread Local Admin rules and add dependency note - Reorder to: Servers, Workstations, Servers and Workstations in both files - Add note to 'Servers and Workstations' rule indicating it relies on the Servers and Workstations classifications Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * wi-586653-USX-transition-docs-improvements-CxE (#8183) * wi-586653-USX-transition-docs-improvements-CxE Changes: Investigation row (line 50): - Added hyperlinks to "Attack story" and "incident graph" â�� /defender-xdr/investigate-incidents#attack-story - Added blast radius analysis mention with link â�� /defender-xdr/investigate-incidents#blast-radius-analysis - Removed "(Sentinel Graph)" label â�� the actual feature name is just "incident graph" Security Copilot row (line 58): - Added "autonomous Security Copilot agents" with link â�� /defender-xdr/security-copilot-agents-defender - Added "threat hunting" agent link â�� /defender-xdr/advanced-hunting-security-copilot-threat-hunting-agent - Added "Included capacity for E5/E7 customers" with link â�� /copilot/security/security-copilot-inclusion - Updated Benefits column: "agentic defense" added * mto - playbooks and lighthouse Changes in sentinel/move-to-defender.md: - Added IMPORTANT callout clarifying that MTO doesn't replace Azure Lighthouse (gap 10), listing operations that still require Lighthouse - Added note that playbooks can't be distributed through MTO content distribution, with CI/CD workaround (gap 11) * Update move-to-defender.md Changes in sentinel/move-to-defender.md: - Gap 13 (SCU inclusion): Added E5/E7 included Security Copilot capacity mention with link to the existing NOTE callout about transition costs - Gap 15 (Investigation visuals): Added paragraph about attack story, incident graph, and blast radius analysis with links, under "Update incident triage processes" - Gap 8 (AAD/UEBA): Added note at end of UEBA section explaining that Sentinel UEBA signals feed into automatic attack disruption after transition, with link - Gap 12 (SOC Optimization): Added new "Use SOC optimization recommendations" subsection explaining cross-service vs Sentinel-only differences, with links to docs and API * fix build error * added "prioritize containment actions" * small tweaks * corrections * Update move-to-defender.md * Alert trigger scope limitation updates 1. In create-manage-use-automation-rules.md, after the trigger table, a NOTE now says: “In the Defender portal, alert triggers work only on Microsoft Sentinel alerts,” and links to Enhanced Alert Trigger (Public Preview). 2. Updated core automation rules limitation text to include the solution path: In automate-incident-handling-with-automation-rules.md, the NOTE under alert-triggered automation now explicitly says Defender XDR alert-triggered automation isn’t available in the Defender portal and points to Enhanced Alert Trigger (Public Preview). 3. Standardized migration/transition include messaging so the limitation points to the preview workaround: In automation-in-defender.md, the “Automation rules with alert triggers” row now includes the limitation plus a direct link to Enhanced Alert Trigger (Public Preview). 4. Made the destination feature explicitly labeled as preview: In generate-playbook.md, the section heading was updated to “Enhanced alert trigger (Public Preview).” * Bookmark deprecation * 5–10 minute batching window updated note in sentinel\automate-incident-handling-with-automation-rules.md * data lake - regional data processing limitation * mutli-tenant: Playbooks not distributable via MTM * Multitenant operations (MTO) and Azure Lighthouse * PR build errors + bookmarks- advanced hunting * Adjusting spacing between tables * Clarify bookmarks note * Removed "Public" from "Public Preview" * bookmarks update * bookmarks tweak * 5-10 min lag - formatting * ueba update * Update advanced-hunting-microsoft-defender.md * Remove (Preview) from enhanced triggers Confirmed with PM Guy Shmeltzer, enhanced triggers are already GA * Move MTO vs Azure Lighthouse content to separate branch/PR (wi-592684) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Move WIP content to part-2 branch; revert unresolved items to main Removes still-in-progress content (AAD context, E5/E7 Copilot capacity, SOC optimization subsection, regional workspace support, MTM playbook distribution) from the publishing branch. Adaptations reverted to main; pure additions removed. Approved content retained. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Fix broken link to migrate-sentinel-incident-creation-rules-alert-grouping Correct the docset path from /unified-secops/ to /unified-secops-platform/ where the target article actually resides. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Fix broken migrate-rules link in Defender-Sentinel integration article Correct /unified-secops/ to /unified-secops-platform/ for the migrate article path. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * mshta recommendation - GA * Add AI agent predefined classification rules (#8317) - Add new AI agent category to predefined classifications - Add Executive-Sponsored AI Agent rule (Medium criticality) - Add AI Agent with Privileged Business System Write Access rule (Medium criticality) - Add what's new entry for June 2026 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Eliminate redundant click-through procedures in Defender for Endpoint content (1 of 2) (#8339) * Eliminate redundant click-through procedures in Defender for Endpoint content * Fix bullets * Add docs * Add files * Add files * Eliminate redundant click-through procedures in Defender for Endpoint content (2 of 2) (#8359) * Eliminate redundant click-through procedures in Defender for Endpoint content (2 of 2) * Fix warning * Update release-notes.md (#8365) * Learn Editor: Update release-notes.md * Learn Editor: Update release-notes.md * Update support-matrix-defender-for-cloud.md (#8364) * Learn Editor: Update support-matrix-defender-for-cloud.md * Learn Editor: Update support-matrix-defender-for-cloud.md * Update regional-availability.md (#8363) * Learn Editor: Update regional-availability.md * Learn Editor: Update regional-availability.md * Add UAE North and UAE Central support for Defender for APIs and API security posture management in DCSPM (#8325) * Add UAE North and UAE Central support for Defender for APIs and API security posture Microsoft Defender for APIs and API security posture management in Defender CSPM now support the UAE North and UAE Central Azure regions. Update region lists and add a release note for the June 29, 2026 release. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Apply suggestion from @DebLanger --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: Deborah Langer <169067075+DebLanger@users.noreply.github.com> * docs: soft rebrand Defender XDR → Defender (batch 23) (#7959) * docs: soft rebrand Defender XDR → Defender (batch 23) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Roll back change. --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * docs: soft rebrand Defender XDR → Defender (batch 18) (#7954) * docs: soft rebrand Defender XDR → Defender (batch 18) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Roll back change. --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * docs: soft rebrand Defender XDR → Defender (batch 21) (#7957) * docs: soft rebrand Defender XDR → Defender (batch 21) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Roll back changes. * Roll back changes. * Roll back changes. * Address build warning. Added a section on required permissions for Defender for Identity in Microsoft Defender. --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Revert "[AIRA] Bot Remediation - mberdugo (defender-docs-pr, 20260615-sentine…" (#8373) This reverts commit 7138bc781bf3c32c0099bd2c8b5d60ccaa4f1ab9. * Revert "fix(COPY-EDIT): editorial (#8048)" (#8374) This reverts commit b7e81b8cbc50a5adb4b767a180ec86ce16857156. * Revert "fix(COPY-EDIT): editorial (#8050)" (#8375) This reverts commit d054038bbad2c30c31aa5a112a18cdfffd9f9f1f. * Add Simple Flows automation rules article (AB#570290) (#7690) * Update Simple Flows action references table and TOC * Fix broken bookmark in permissions link The target article doesn't have a #permissions-for-automation-rules anchor. Drop the anchor and link to the article generally. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Dissolve Known limitations section into action context Move each limitation next to the action it constrains: - Email-wide constraints (fixed template, fixed sender, no CC/BCC, no audit log) consolidated into a single NOTE callout after the Actions reference table. - Assign SLA Policy: existing-policy caveat appended to the action's Behavior cell. - 10-tasks-per-rule limit was already documented in the Add Task row, so the duplicate bullet is dropped. Also align Update Case field labels with the feature spec (Email recipients, Grace period). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Cross-link Simple Flows from existing automation-rules articles Add NOTE callouts pointing to the new Simple Flows article from: - automate-incident-handling-with-automation-rules.md (Triggers + Actions sections) - create-manage-use-automation-rules.md (Choose your trigger + Add actions sections) Each callout is gated on Defender-portal onboarding to match the new feature's availability. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Apply review must-fixes: title preview tag, capitalization, link text, missing space Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Remove em-dashes from prose; convert two cross-link NOTEs to inline Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Expand SOC/SLA/SOAR acronyms; reorder What is before Prerequisites Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add portal navigation to Examples 2-4; clearer phrasing on case-trigger cross-link Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Apply Guy's feedback: broaden to Defender portal scope; drop Assign SLA Policy; new examples; case custom fields Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Drop SLA examples; keep Update Alert and Add Task examples only Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Simplify rule-layering tip Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Remove SLA Exceeded Email action and update examples Removed the 'Send Case SLA Exceeded Email' action from the automation rules table and updated example instructions for creating automation rules. --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: Guy Wild <98332688+guywi-ms@users.noreply.github.com> Co-authored-by: Dennis Rea <v-denrea@microsoft.com> * Chrisda to Main (#8377) * Update attack-surface-reduction-rules-reference.md Removed 'might not be available in Intune' call-out for 'Block executable files from running unless they meet a prevalence, age, or trusted list criterion' * Update attack-surface-reduction-rules-overview.md Consistency updates * ASR rules report screenshot updates More data * Remove A3 from E3 gets MDO P1 refs Per request * Added Teams to report suspicious * Update outbound-spam-high-risk-delivery-pool-about.md Content VSO 591495 * Update anti-phishing-policies-about.md Per IM request * Approval update (#8379) * URBAC by default updates (#7804) * URBAC by default updates * URBAC edits/additions per PM feedback * Fix renamed Defender portal icon links after merging main Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Update configure-unified-rbac-for-mdo.md Removed Sample deployment models section per PM request prior to publish * Copy edits * File rename per build report * File rename per build report * File rename per build report * File rename per build report --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * WI593231 malware detection GA * Update triage agents to use least-privilege email permission (#8034) * Update triage agents to use least-privilege email permission Replace the broad 'Email & collaboration content (read)' permission with the more limited 'Email & collaboration content: Emails associated with alerts (read)' permission in the Phishing Triage Agent and Security Alert Triage Agent docs. This restricts agent access to only emails associated with alerts, improving security posture. Also adds a what's-new entry for June 2026. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Replace permission screenshots with updated UI showing least-privilege option Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * WI593234-agentless scanning vm update * Add get started article for Defender security for AI agents (#8296) * Add get started article for Defender security for AI agents Create get-started-defender-security-for-ai.md covering the onboarding flow: enabling data collection, connecting Microsoft 365 connector, and onboarding Copilot Studio real-time protection. Add TOC entry. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add screenshots to Defender security for AI get started article Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Remove redundant Power Platform integration URL screenshot Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * updates * Update security-for-ai-setup-checklist.png * Update get-started-defender-security-for-ai.md * Update get-started-defender-security-for-ai.md * Split AI agent detection/protection doc into detect-investigate and real-time protection pages - Repurpose ai-agent-detection-protection.md to focus on detection and investigation - Add ai-agent-real-time-protection.md covering RTP, policy rules, and prompt evidence - Add real-time protection policy experience screenshots - Update TOC, cross-links, and Next steps in related articles Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Group AI agent security articles under 'Protect AI agents' subnode Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Rename real-time protection TOC node to 'Block agent threats in real time' Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Order real-time protection before detect and investigate in agent security TOC Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Align agent security articles: standardize AgentsInfo table, RTP policy path, remove Preview labels Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Fix legacy table name to AIAgentsInfo and remove appliesto block from inventory article Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Rename real-time protection node and move it after Get started in agent security TOC Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Remove temporary Defender for Cloud Apps onboarding notes from agent security articles Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Rework agent onboarding to drop MDA framing: move prereqs, remove extended-detection section, point Copilot Studio to Get started Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Remove Agent 365 subscription notes and preview-feature prerequisites from agent articles Co-authored-by: Copilot…
|
Learn Build status updates of commit 7d06d19: ❌ Validation status: errorsPlease follow instructions here which may help to resolve issue.
For more details, please refer to the build report. Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them. |
Pull request opened by Docs to resolve syncing conflicts from repo_sync_working_branch to public.