This blog post summarizes Microsoft Defender product updates from February 2026. Microsoft Defender for Cloud integrates into the Defender portal, offering a unified security experience. New AI-powered features include a SIEM migration experience and a SOAR playbook generator in Microsoft Sentinel. The Microsoft Copilot Data Connector for Sentinel now ingests Copilot audit logs. The sunset date for managing Sentinel in the Azure portal has been extended. Account Name in Sentinel will be standardized, and Microsoft Defender Experts for Hunting customers can configure notification contacts. Advanced hunting schema tables and lake-only ingestion are now generally available. Custom Guidebooks for Copilot Guided Response are now generally available. The UEBA behaviors layer in Sentinel is now generally available with a behaviors workbook. Defender for Endpoint now offers library management for live response and effective settings reporting. The Vulnerable components page is renamed Software components, and Windows 7 devices are now supported. The release notes pages for Endpoint are updated for improved access. A webinar recording on identity attack types is available. User reporting in Teams for Defender for Office 365 Plan 1 is expanding. Finally, Secure Score categories will be updated, potentially impacting identity and app scores.
techcommunity.microsoft.com
techcommunity.microsoft.com
