You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/data-ingestion-benefit.md
-1Lines changed: 0 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -51,7 +51,6 @@ The following subset of [security data types](/azure/azure-monitor/reference/ta
51
51
-[Update](/azure/azure-monitor/reference/tables/update) and [UpdateSummary](/azure/azure-monitor/reference/tables/updatesummary) when the Update Management solution isn't running in the workspace or solution targeting is enabled.
> Although `WindowsEvent` is listed, only security events from the `Microsoft-SecurityEvent` stream that go to the `SecurityEvent` table qualify for the 500 MB/day allowance. Application, System, or other event log channels are not covered and are billed as regular ingestion.
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/release-notes.md
+33-5Lines changed: 33 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -29,13 +29,15 @@ This article summarizes what's new in Microsoft Defender for Cloud. It includes
29
29
30
30
## February 2026
31
31
32
-
|Date| Category|Update|
32
+
|Date| Category|Update|
33
33
| -------- | -------- | -------- |
34
34
| February 20, 2026 | Preview |[Container runtime antimalware detection and prevention (Preview)](#container-runtime-antimalware-detection-and-prevention-preview)|
35
35
| February 10, 2026| Preview |[Database-level recommendations experience for SQL Vulnerability Assessment findings (Preview)](#database-level-recommendations-experience-for-sql-vulnerability-assessment-preview)|
36
36
| February 10, 2026| GA |[Scanning support for Minimus and Photon OS container images](#scanning-support-for-minimus-and-photon-os-container-images)|
37
37
| February 9, 2026| GA |[Simulate alerts for SQL servers on machines](#simulate-alerts-for-sql-servers-on-machines)|
38
38
| February 3, 2026| Preview |[Threat protection for AI agents (Preview)](#threat-protection-for-ai-agentspreview)|
39
+
|February 2, 2026| GA |[Updated CIEM recommendation logic](#updated-ciem-recommendation-logic)|
40
+
|February 2, 2026| Preview |[Threat protection for AI agents (Preview)](#threat-protection-for-ai-agentspreview)|
39
41
40
42
### Container runtime antimalware detection and prevention (Preview)
41
43
@@ -45,7 +47,7 @@ Microsoft Defender for Cloud is announcing container runtime anti-malware detect
45
47
46
48
Learn more about [antimalware detection and prevention](anti-malware.md).
47
49
48
-
## Database-level recommendations experience for SQL Vulnerability Assessment (Preview)
50
+
###Database-level recommendations experience for SQL Vulnerability Assessment (Preview)
49
51
50
52
February 10, 2026
51
53
@@ -71,13 +73,13 @@ The SQL [vulnerability assessment rules reference](sql-azure-vulnerability-asses
71
73
72
74
The existing server-level (aggregated) experience remains available during preview.
73
75
74
-
## Scanning support for Minimus and Photon OS container images
76
+
###Scanning support for Minimus and Photon OS container images
75
77
76
78
February 10, 2026
77
79
78
80
Microsoft Defender for Cloud's vulnerability scanner, powered by Microsoft Defender Vulnerability Management, is extending its scanning coverage to Minimus and Photon OS container images, and identify vulnerabilities in Minimus Images and Photos OS to validate that they're shipping the most secure builds possible. As additional image types are being scanned, your bill might increase. For all supported distributions, see [Registries and images support for vulnerability assessment](support-matrix-defender-for-containers.md#registries-and-images-support-for-vulnerability-assessment).
79
81
80
-
## Simulate alerts for SQL servers on machines
82
+
###Simulate alerts for SQL servers on machines
81
83
82
84
February 9, 2026
83
85
@@ -87,6 +89,32 @@ Simulated alerts generates realistic alerts with full SQL and machine context on
87
89
88
90
Learn how to [simulate alerts for SQL servers on machines](simulate-alerts-sql-machines.md).
89
91
92
+
## Updated CIEM recommendation logic
93
+
94
+
February 2, 2026
95
+
96
+
Cloud Infrastructure Entitlement Management (CIEM) recommendations are now available as a native capability in Microsoft Defender for Cloud across Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP).
97
+
98
+
This update changes how inactive identities and over-permissioned roles are evaluated and improves recommendation accuracy. It may affect existing recommendation results.
99
+
100
+
### Key changes
101
+
102
+
- Inactive identity detection now evaluates unused role assignments instead of sign-in activity.
103
+
- The inactivity lookback window is extended to 90 days (previously 45 days).
104
+
- Identities created within the past 90 days aren’t evaluated as inactive.
105
+
- The Permissions Creep Index (PCI) metric is deprecated and no longer appears in recommendations.
106
+
- CIEM onboarding no longer requires elevated high-risk permissions.
107
+
108
+
### Cloud-specific considerations
109
+
110
+
| Cloud | Details |
111
+
|--------|---------|
112
+
|**Azure**| Inactive identity recommendations include evaluation of read-level permissions. |
113
+
|**AWS**| CIEM evaluates AWS users and roles whose permissions can be reliably assessed. SAML and SSO identities require [AWS CloudTrail Logs (Preview)](integrate-cloud-trail.md) to be enabled in the Defender CSPM plan. Serverless and compute identities are excluded from CIEM inactivity evaluation, which might affect recommendation counts. |
114
+
|**GCP**| CIEM evaluation requires [Cloud Logging ingestion (Preview)](logging-ingestion.md) to be enabled in the Defender CSPM plan. |
115
+
116
+
Learn more about [permissions management in Defender for Cloud](permissions-management.md).
117
+
90
118
## Threat protection for AI agents (Preview)
91
119
92
120
February 2, 2026
@@ -103,7 +131,7 @@ Learn more about [Threat Protection for AI Agents with Microsoft Defender for Cl
103
131
| -------- | -------- | -------- |
104
132
|January 8, 2026| Preview |[Microsoft Security Private Link (Preview)](#microsoft-security-private-link-preview)|
0 commit comments